Incident Report: Deployment Compliance Violations in New Container App Environment
- Incident ID:
dc920bcc-4b71-0665-88f3-20d74c1ef000
- Service: Azure Container Apps —
ca-api-deployment-compliance-dem (rg: rg-deployment-compliance-demo)
- Subscription:
2c14ac17-ac47-4a4d-b2a4-4607601eab49
- FQDN:
ca-api-deployment-compliance-dem.politehill-cd450ee4.eastus2.azurecontainerapps.io
- Active revision:
ca-api-deployment-compliance-dem--d3nx0bb (100% traffic, status: Activating)
Summary
A deployment compliance alert fired at 23:41:49 UTC on 2026-08-31 after a full environment provisioning was detected in resource group rg-deployment-compliance-demo. The entire infrastructure — including resource group, ACR, managed environment, container app, monitoring resources, and an SRE agent — was created in a single deployment batch by user shannichols@MngEnvMCAP776009.onmicrosoft.com. The compliance review identified 10 findings across security, reliability, and operational readiness categories: ACR admin credentials enabled, no VNet integration, no health probes, placeholder image deployed, and a failed SRE agent deployment among the most critical.
Impact
- Security: ACR admin credentials (password-based auth) are enabled and stored as a container app secret, violating the principle of least-privilege identity-based access
- Reliability: No health probes configured, no zone redundancy, single revision mode — the app has no self-healing or high-availability capabilities
- Operational: SRE agent deployment failed due to invalid name length, leaving the environment without automated monitoring/response
- Compliance: Container registry has public network access enabled, no content trust, no soft delete protection, and Basic SKU without private endpoint support
Timeline (UTC)
| Time |
Event |
Status |
| ~23:34:41 |
Resource group rg-deployment-compliance-demo created |
Succeeded |
| ~23:34:42 |
ACR acrdeploymentcompliancedemol3ym45 created (Basic, admin enabled) |
Succeeded |
| ~23:34:42 |
Log Analytics workspace law-cae-deployment-compliance-demo created |
Succeeded |
| ~23:35:03 |
Managed Environment cae-deployment-compliance-demo created (no VNet, no zone redundancy) |
Succeeded |
| ~23:35:04 |
Container App ca-api-deployment-compliance-dem write started |
Accepted |
| ~23:35:21 |
Container App provisioned with helloworld placeholder image |
Succeeded |
| ~23:35:25 |
Action Group and Activity Log Alert created |
Succeeded |
| ~23:35:46 |
Monitoring Log Analytics workspace created |
Succeeded |
| ~23:35:52 |
User-assigned managed identity created |
Succeeded |
| ~23:35:53 |
SRE Agent deployment — FAILED (InvalidAgentName: name truncated, exceeded 32 chars) |
Failed |
| ~23:41:49 |
Deployment compliance alert fired |
Alert |
Evidence
Activity Log — Container App Write Operations
Correlation ID: 9722ae4d-cb47-ca0b-e255-14be55ccde8f
Caller: shannichols@MngEnvMCAP776009.onmicrosoft.com
23:35:04.853Z Microsoft.App/containerApps/write Started
23:35:05.853Z Microsoft.App/containerApps/write Accepted (subStatus: Created)
23:35:21.329Z Microsoft.App/containerApps/write Succeeded
SRE Agent Deployment Failure
{
"error": {
"code": "InvalidAgentName",
"message": "Invalid agent name 'sreagent-deployment-compliance-d (trimmed)'. A name must consist of alphanumeric characters or '-', start with an alphabetic character, and end with an alphanumeric character and cannot have '--'. The length must be between 2 and 32 characters inclusive."
}
}
Container App Configuration
| Property |
Value |
Compliance Issue |
| Image |
mcr.microsoft.com/azuredocs/containerapps-helloworld:latest |
Placeholder — not production code |
| CPU / Memory |
0.5 vCPU / 1Gi |
— |
| Min/Max Replicas |
1 / 3 |
— |
| Health Probes |
None configured |
No liveness/readiness checks |
| Ingress |
External, port 8080 |
Publicly accessible |
| Registry Auth |
ACR admin password (acr-password secret) |
Should use managed identity |
| Revision Mode |
Single |
No blue/green deployment support |
| Tags |
commit-sha: initial, pipeline-run-id: initial |
Non-pipeline deployment |
ACR Configuration
| Property |
Value |
Compliance Issue |
| Admin Enabled |
true |
Should be disabled; use RBAC |
| SKU |
Basic |
No private endpoint, geo-rep, or content trust support |
| Public Network Access |
Enabled |
Should restrict to VNet |
| Content Trust |
Disabled |
Images not signed |
| Soft Delete |
Disabled |
No protection against accidental deletion |
| Quarantine Policy |
Disabled |
No image scanning gate |
Managed Environment
| Property |
Value |
Compliance Issue |
| VNet Configuration |
None |
No network isolation |
| Zone Redundancy |
false |
No HA across availability zones |
| Workload Profiles |
None |
Consumption-only |
Metrics Snapshot (Azure Monitor)
- Provisioning State: Succeeded
- Running Status: Running
- Revision State: Activating (1 replica)
- System-assigned MI: Enabled (principalId:
23d268de-5d56-41d8-89e8-4e191541bfa3)
Root Cause
This is not a failure incident but a compliance gap detection event. A new Container App environment was provisioned as a deployment compliance demo with multiple security and reliability anti-patterns: ACR admin credentials instead of managed identity RBAC, no VNet integration, no health probes, a placeholder image instead of production code, and a failed SRE agent deployment due to a name length validation error. The deployment was initiated by user shannichols@MngEnvMCAP776009.onmicrosoft.com as part of an initial environment setup.
Remediation
- Security: Disable ACR admin credentials; configure the container app to pull images using its system-assigned managed identity with
AcrPull role. Restrict ACR public network access. Upgrade ACR to Standard SKU minimum to enable content trust and consider Premium for private endpoints.
- Reliability: Add liveness and readiness probes to the container app. Enable zone redundancy on the managed environment. Configure VNet integration for network isolation.
- Deployment: Replace the placeholder
helloworld image with the actual application image. Set up proper CI/CD pipeline tagging (update commit-sha and pipeline-run-id tags). Consider multi-revision mode for safe deployments.
- Monitoring: Fix the SRE agent name (shorten to ≤32 characters, e.g.,
sreagent-deploy-compliance) and redeploy. Enable ACR soft delete and quarantine policies.
- Observability: Configure diagnostic settings to send container app logs to the Log Analytics workspace. Instrument the application with App Insights.
Action Items
| # |
Action |
Priority |
| 1 |
Disable ACR admin credentials; configure managed identity (AcrPull) for image pulls |
High |
| 2 |
Add liveness and readiness health probes to the container app |
High |
| 3 |
Enable VNet integration on the managed environment |
High |
| 4 |
Fix SRE agent name length and redeploy (≤32 chars) |
High |
| 5 |
Replace placeholder helloworld image with production application image |
Medium |
| 6 |
Restrict ACR public network access |
Medium |
| 7 |
Enable zone redundancy on the managed environment |
Medium |
| 8 |
Upgrade ACR SKU to Standard or Premium; enable content trust and soft delete |
Medium |
| 9 |
Configure proper CI/CD pipeline with commit SHA and run ID tagging |
Medium |
| 10 |
Set up App Insights instrumentation and diagnostic settings |
Low |
References
- Container App:
/subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.App/containerapps/ca-api-deployment-compliance-dem
- Managed Environment:
/subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.App/managedEnvironments/cae-deployment-compliance-demo
- ACR:
/subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.ContainerRegistry/registries/acrdeploymentcompliancedemol3ym45
- Log Analytics Workspace ID (environment):
b51d4293-b00b-4483-8738-5359895a0206
- Log Analytics Workspace (monitoring):
law-compliance-deployment-compliance-demo
- Alert ID:
dc920bcc-4b71-0665-88f3-20d74c1ef000
- App Insights: Not configured for this environment
This issue was created by sre-agent-zltoweask56oi--b504a391
Tracked by the SRE agent here
Incident Report: Deployment Compliance Violations in New Container App Environment
dc920bcc-4b71-0665-88f3-20d74c1ef000ca-api-deployment-compliance-dem(rg:rg-deployment-compliance-demo)2c14ac17-ac47-4a4d-b2a4-4607601eab49ca-api-deployment-compliance-dem.politehill-cd450ee4.eastus2.azurecontainerapps.ioca-api-deployment-compliance-dem--d3nx0bb(100% traffic, status: Activating)Summary
A deployment compliance alert fired at 23:41:49 UTC on 2026-08-31 after a full environment provisioning was detected in resource group
rg-deployment-compliance-demo. The entire infrastructure — including resource group, ACR, managed environment, container app, monitoring resources, and an SRE agent — was created in a single deployment batch by usershannichols@MngEnvMCAP776009.onmicrosoft.com. The compliance review identified 10 findings across security, reliability, and operational readiness categories: ACR admin credentials enabled, no VNet integration, no health probes, placeholder image deployed, and a failed SRE agent deployment among the most critical.Impact
Timeline (UTC)
rg-deployment-compliance-democreatedacrdeploymentcompliancedemol3ym45created (Basic, admin enabled)law-cae-deployment-compliance-democreatedcae-deployment-compliance-democreated (no VNet, no zone redundancy)ca-api-deployment-compliance-demwrite startedInvalidAgentName: name truncated, exceeded 32 chars)Evidence
Activity Log — Container App Write Operations
SRE Agent Deployment Failure
{ "error": { "code": "InvalidAgentName", "message": "Invalid agent name 'sreagent-deployment-compliance-d (trimmed)'. A name must consist of alphanumeric characters or '-', start with an alphabetic character, and end with an alphanumeric character and cannot have '--'. The length must be between 2 and 32 characters inclusive." } }Container App Configuration
mcr.microsoft.com/azuredocs/containerapps-helloworld:latestacr-passwordsecret)commit-sha: initial,pipeline-run-id: initialACR Configuration
trueManaged Environment
falseMetrics Snapshot (Azure Monitor)
23d268de-5d56-41d8-89e8-4e191541bfa3)Root Cause
This is not a failure incident but a compliance gap detection event. A new Container App environment was provisioned as a deployment compliance demo with multiple security and reliability anti-patterns: ACR admin credentials instead of managed identity RBAC, no VNet integration, no health probes, a placeholder image instead of production code, and a failed SRE agent deployment due to a name length validation error. The deployment was initiated by user
shannichols@MngEnvMCAP776009.onmicrosoft.comas part of an initial environment setup.Remediation
AcrPullrole. Restrict ACR public network access. Upgrade ACR to Standard SKU minimum to enable content trust and consider Premium for private endpoints.helloworldimage with the actual application image. Set up proper CI/CD pipeline tagging (updatecommit-shaandpipeline-run-idtags). Consider multi-revision mode for safe deployments.sreagent-deploy-compliance) and redeploy. Enable ACR soft delete and quarantine policies.Action Items
AcrPull) for image pullsReferences
/subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.App/containerapps/ca-api-deployment-compliance-dem/subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.App/managedEnvironments/cae-deployment-compliance-demo/subscriptions/2c14ac17-ac47-4a4d-b2a4-4607601eab49/resourceGroups/rg-deployment-compliance-demo/providers/Microsoft.ContainerRegistry/registries/acrdeploymentcompliancedemol3ym45b51d4293-b00b-4483-8738-5359895a0206law-compliance-deployment-compliance-demodc920bcc-4b71-0665-88f3-20d74c1ef000This issue was created by sre-agent-zltoweask56oi--b504a391
Tracked by the SRE agent here