Skip to content

Incident: Deployment Compliance Violations Detected — New Container App Provisioning (ca-api-deployment-compliance-dem) #14

Description

@TraderShan

Incident Report: Deployment Compliance Violations in New Container App Environment

  • Incident ID: dc920bcc-4b71-0665-88f3-20d74c1ef000
  • Service: Azure Container Apps — ca-api-deployment-compliance-dem (rg: rg-deployment-compliance-demo)
  • Subscription: 2c14ac17-ac47-4a4d-b2a4-4607601eab49
  • FQDN: ca-api-deployment-compliance-dem.politehill-cd450ee4.eastus2.azurecontainerapps.io
  • Active revision: ca-api-deployment-compliance-dem--d3nx0bb (100% traffic, status: Activating)

Summary

A deployment compliance alert fired at 23:41:49 UTC on 2026-08-31 after a full environment provisioning was detected in resource group rg-deployment-compliance-demo. The entire infrastructure — including resource group, ACR, managed environment, container app, monitoring resources, and an SRE agent — was created in a single deployment batch by user shannichols@MngEnvMCAP776009.onmicrosoft.com. The compliance review identified 10 findings across security, reliability, and operational readiness categories: ACR admin credentials enabled, no VNet integration, no health probes, placeholder image deployed, and a failed SRE agent deployment among the most critical.

Impact

  • Security: ACR admin credentials (password-based auth) are enabled and stored as a container app secret, violating the principle of least-privilege identity-based access
  • Reliability: No health probes configured, no zone redundancy, single revision mode — the app has no self-healing or high-availability capabilities
  • Operational: SRE agent deployment failed due to invalid name length, leaving the environment without automated monitoring/response
  • Compliance: Container registry has public network access enabled, no content trust, no soft delete protection, and Basic SKU without private endpoint support

Timeline (UTC)

Time Event Status
~23:34:41 Resource group rg-deployment-compliance-demo created Succeeded
~23:34:42 ACR acrdeploymentcompliancedemol3ym45 created (Basic, admin enabled) Succeeded
~23:34:42 Log Analytics workspace law-cae-deployment-compliance-demo created Succeeded
~23:35:03 Managed Environment cae-deployment-compliance-demo created (no VNet, no zone redundancy) Succeeded
~23:35:04 Container App ca-api-deployment-compliance-dem write started Accepted
~23:35:21 Container App provisioned with helloworld placeholder image Succeeded
~23:35:25 Action Group and Activity Log Alert created Succeeded
~23:35:46 Monitoring Log Analytics workspace created Succeeded
~23:35:52 User-assigned managed identity created Succeeded
~23:35:53 SRE Agent deployment — FAILED (InvalidAgentName: name truncated, exceeded 32 chars) Failed
~23:41:49 Deployment compliance alert fired Alert

Evidence

Activity Log — Container App Write Operations

Correlation ID: 9722ae4d-cb47-ca0b-e255-14be55ccde8f
Caller: shannichols@MngEnvMCAP776009.onmicrosoft.com

23:35:04.853Z  Microsoft.App/containerApps/write  Started
23:35:05.853Z  Microsoft.App/containerApps/write  Accepted (subStatus: Created)
23:35:21.329Z  Microsoft.App/containerApps/write  Succeeded

SRE Agent Deployment Failure

{
  "error": {
    "code": "InvalidAgentName",
    "message": "Invalid agent name 'sreagent-deployment-compliance-d (trimmed)'. A name must consist of alphanumeric characters or '-', start with an alphabetic character, and end with an alphanumeric character and cannot have '--'. The length must be between 2 and 32 characters inclusive."
  }
}

Container App Configuration

Property Value Compliance Issue
Image mcr.microsoft.com/azuredocs/containerapps-helloworld:latest Placeholder — not production code
CPU / Memory 0.5 vCPU / 1Gi —
Min/Max Replicas 1 / 3 —
Health Probes None configured No liveness/readiness checks
Ingress External, port 8080 Publicly accessible
Registry Auth ACR admin password (acr-password secret) Should use managed identity
Revision Mode Single No blue/green deployment support
Tags commit-sha: initial, pipeline-run-id: initial Non-pipeline deployment

ACR Configuration

Property Value Compliance Issue
Admin Enabled true Should be disabled; use RBAC
SKU Basic No private endpoint, geo-rep, or content trust support
Public Network Access Enabled Should restrict to VNet
Content Trust Disabled Images not signed
Soft Delete Disabled No protection against accidental deletion
Quarantine Policy Disabled No image scanning gate

Managed Environment

Property Value Compliance Issue
VNet Configuration None No network isolation
Zone Redundancy false No HA across availability zones
Workload Profiles None Consumption-only

Metrics Snapshot (Azure Monitor)

  • Provisioning State: Succeeded
  • Running Status: Running
  • Revision State: Activating (1 replica)
  • System-assigned MI: Enabled (principalId: 23d268de-5d56-41d8-89e8-4e191541bfa3)

Root Cause

This is not a failure incident but a compliance gap detection event. A new Container App environment was provisioned as a deployment compliance demo with multiple security and reliability anti-patterns: ACR admin credentials instead of managed identity RBAC, no VNet integration, no health probes, a placeholder image instead of production code, and a failed SRE agent deployment due to a name length validation error. The deployment was initiated by user shannichols@MngEnvMCAP776009.onmicrosoft.com as part of an initial environment setup.

Remediation

  • Security: Disable ACR admin credentials; configure the container app to pull images using its system-assigned managed identity with AcrPull role. Restrict ACR public network access. Upgrade ACR to Standard SKU minimum to enable content trust and consider Premium for private endpoints.
  • Reliability: Add liveness and readiness probes to the container app. Enable zone redundancy on the managed environment. Configure VNet integration for network isolation.
  • Deployment: Replace the placeholder helloworld image with the actual application image. Set up proper CI/CD pipeline tagging (update commit-sha and pipeline-run-id tags). Consider multi-revision mode for safe deployments.
  • Monitoring: Fix the SRE agent name (shorten to ≤32 characters, e.g., sreagent-deploy-compliance) and redeploy. Enable ACR soft delete and quarantine policies.
  • Observability: Configure diagnostic settings to send container app logs to the Log Analytics workspace. Instrument the application with App Insights.

Action Items

# Action Priority
1 Disable ACR admin credentials; configure managed identity (AcrPull) for image pulls High
2 Add liveness and readiness health probes to the container app High
3 Enable VNet integration on the managed environment High
4 Fix SRE agent name length and redeploy (≤32 chars) High
5 Replace placeholder helloworld image with production application image Medium
6 Restrict ACR public network access Medium
7 Enable zone redundancy on the managed environment Medium
8 Upgrade ACR SKU to Standard or Premium; enable content trust and soft delete Medium
9 Configure proper CI/CD pipeline with commit SHA and run ID tagging Medium
10 Set up App Insights instrumentation and diagnostic settings Low

References

  • Container App: /subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.App/containerapps/ca-api-deployment-compliance-dem
  • Managed Environment: /subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.App/managedEnvironments/cae-deployment-compliance-demo
  • ACR: /subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.ContainerRegistry/registries/acrdeploymentcompliancedemol3ym45
  • Log Analytics Workspace ID (environment): b51d4293-b00b-4483-8738-5359895a0206
  • Log Analytics Workspace (monitoring): law-compliance-deployment-compliance-demo
  • Alert ID: dc920bcc-4b71-0665-88f3-20d74c1ef000
  • App Insights: Not configured for this environment

This issue was created by sre-agent-zltoweask56oi--b504a391
Tracked by the SRE agent here

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions