You have an Azure Kubernetes Service (AKS) cluster that must connect to an Azure Container Registry.
You need to use the AKS cluster’s automatically generated service principal to authenticate to the Azure Container Registry.
What should you create?
Azure Container Registry access for a service principal is granted through Azure RBAC. Assigning the service principal an appropriate registry role—such as AcrPull for pull access on a non-ABAC-enabled registry—authorizes the AKS cluster to retrieve container images.
AcrPull
Community Discussion