Azure / Azure/acr

Allow configuration of CORS headers for ACR API access from other web clients and OCI registry explorer UI clients

Open
#752 5 comments 1 reaction 1 assignee Claimed by @terencet-dev View on GitHub
feature-networking feature-request triaged
Dominant language
No language data
Stars
177
Forks
137
PR merge metrics
No merged PRs in 30d

Description

**What is the problem you're trying to solve**
I want to use something like JoxIt/docker-registry-ui as a custom user interface for an Azure Container Registry because the Azure Portal UI doesn't support filtered access based on tokens and scope maps but only based on Entra Security Principals.

**Describe the solution you'd like**
CORS config UI section and API for ACR allowing to set the usual "Access-Control-Allow-..." headers for this resource.
With a custom domain configured ACR should support configuring allowance for same-site requests in contrast to the default same-origin requests so that a self-hosted registry UI under the same site but a different origin is possible (i.e. common parent domain name with different subdomain).

**Additional informstion**
Currently, this can be worked around by setting up a reverse proxy server in the backend and rewrite the requests on pass-through to the ACR endpoints. But this is very cumbersome and there seem to be no good reasons why the API should not usable from external web clients directly.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.