Official agent skill

Azure Containerregistry Py

by microsoft in microsoft/skills

Azure Container Registry SDK for Python. An agent skill from microsoft/skills.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Containerregistry Py

skills CLI
$ npx skills add microsoft/skills --skill azure-containerregistry-py -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-containerregistry-py --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-python/skills/azure-containerregistry-py .claude/skills/azure-containerregistry-py && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-containerregistry-py
GitHub stars
3.1k
Token cost
~2.2k tokens
SKILL.md length
386 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Container Registry SDK for Python. An agent skill from microsoft/skills.

  • Works in 9 steps: Pick sync OR async and stay consistent.… → Always use context managers for clients… → Use Microsoft Entra ID for… → …
  • Managing container images
  • SKILL.md covers Installation, Environment Variables, Authentication & Lifecycle and List Repositories, plus 10 more sections
  • Calls pip; reaches mcr.microsoft.com and learn.microsoft.com; needs AZURE_TOKEN_CREDENTIALS

What it does

Azure Containerregistry Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Container Registry SDK for Python. Use for managing container images, artifacts, and repositories. Triggers: "azure-containerregistry", "ContainerRegistryClient", "container images", "docker registry", "ACR".

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/capabilities.md` and `references/non-hero-scenarios.md`).

It sits in DevOps & Cloud, covering Containers. It works with Microsoft Azure, Python, Visual Studio Code and Docker. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Managing container images
  • Tasks that involve Containers

Example prompts

  • “azure-containerregistry”
  • “ContainerRegistryClient”
  • “container images”
  • “/azure-containerregistry-py”

Requirements

  • Python 3
  • Docker

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose…
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with…
  3. Use Microsoft Entra ID for authentication in production
  4. Delete by digest not tag to avoid orphaned images
  5. Lock production images with can_delete=False
  6. Clean up untagged manifests regularly
  7. Use async client for high-throughput operations
  8. Order by last_updated to find recent/old images
  9. Check manifest.tags before deleting to avoid removing tagged images

What it can do on your machine

Read from SKILL.md and the folder at commit 3898ec8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • mcr.microsoft.com
    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_TOKEN_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Containerregistry Py loads about 2.2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 386 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 3898ec8, republished under its MIT licence (© microsoft). 386 words, ~2,178 tokens.

Download SKILL.mdSave it as .claude/skills/azure-containerregistry-py/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-containerregistry-py
description
Azure Container Registry SDK for Python. Use for managing container images, artifacts, and repositories. Triggers: "azure-containerregistry", "ContainerRegistryClient", "container images", "docker registry", "ACR".
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
azure-containerregistry

Azure Container Registry SDK for Python

Manage container images, artifacts, and repositories in Azure Container Registry.

Installation

bash
pip install azure-containerregistry

Environment Variables

bash
AZURE_CONTAINERREGISTRY_ENDPOINT=https://<registry-name>.azurecr.io  # Required for all auth methods
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production

Authentication & Lifecycle

🔑 Two rules apply to every code sample below:

  1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
    • Local dev: DefaultAzureCredential works as-is.
    • Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.
  2. Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically:
    • Sync: with <Client>(...) as client:
    • Async: async with <Client>(...) as client: and async with DefaultAzureCredential() as credential: (from azure.identity.aio)

Snippets may abbreviate this setup, but production code should always follow both rules.

python
import os
from azure.containerregistry import ContainerRegistryClient
from azure.identity import DefaultAzureCredential, ManagedIdentityCredential

# Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
credential = DefaultAzureCredential(require_envvar=True)
# Or use a specific credential directly in production:
# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes
# credential = ManagedIdentityCredential()

with ContainerRegistryClient(
    endpoint=os.environ["AZURE_CONTAINERREGISTRY_ENDPOINT"],
    credential=credential
) as client:
    # Use client here (see following sections for operations)
    ...
Anonymous Access (Public Registry)
python
from azure.containerregistry import ContainerRegistryClient

with ContainerRegistryClient(
    endpoint="https://mcr.microsoft.com",
    credential=None,
    audience="https://mcr.microsoft.com"
) as client:
    # Use client here (see following sections for operations)
    ...

List Repositories

python
with ContainerRegistryClient(endpoint, DefaultAzureCredential()) as client:
    for repository in client.list_repository_names():
        print(repository)

Repository Operations

Get Repository Properties
python
properties = client.get_repository_properties("my-image")
print(f"Created: {properties.created_on}")
print(f"Modified: {properties.last_updated_on}")
print(f"Manifests: {properties.manifest_count}")
print(f"Tags: {properties.tag_count}")
Update Repository Properties
python
from azure.containerregistry import RepositoryProperties

client.update_repository_properties(
    "my-image",
    properties=RepositoryProperties(
        can_delete=False,
        can_write=False
    )
)
Delete Repository
python
client.delete_repository("my-image")

List Tags

python
for tag in client.list_tag_properties("my-image"):
    print(f"{tag.name}: {tag.created_on}")
Filter by Order
python
from azure.containerregistry import ArtifactTagOrder

# Most recent first
for tag in client.list_tag_properties(
    "my-image",
    order_by=ArtifactTagOrder.LAST_UPDATED_ON_DESCENDING
):
    print(f"{tag.name}: {tag.last_updated_on}")

Manifest Operations

List Manifests
python
from azure.containerregistry import ArtifactManifestOrder

for manifest in client.list_manifest_properties(
    "my-image",
    order_by=ArtifactManifestOrder.LAST_UPDATED_ON_DESCENDING
):
    print(f"Digest: {manifest.digest}")
    print(f"Tags: {manifest.tags}")
    print(f"Size: {manifest.size_in_bytes}")
Get Manifest Properties
python
manifest = client.get_manifest_properties("my-image", "latest")
print(f"Digest: {manifest.digest}")
print(f"Architecture: {manifest.architecture}")
print(f"OS: {manifest.operating_system}")
Update Manifest Properties
python
from azure.containerregistry import ArtifactManifestProperties

client.update_manifest_properties(
    "my-image",
    "latest",
    properties=ArtifactManifestProperties(
        can_delete=False,
        can_write=False
    )
)
Delete Manifest
python
# Delete by digest
client.delete_manifest("my-image", "sha256:abc123...")

# Delete by tag
manifest = client.get_manifest_properties("my-image", "old-tag")
client.delete_manifest("my-image", manifest.digest)

Tag Operations

Get Tag Properties
python
tag = client.get_tag_properties("my-image", "latest")
print(f"Digest: {tag.digest}")
print(f"Created: {tag.created_on}")
Delete Tag
python
client.delete_tag("my-image", "old-tag")

Upload and Download Artifacts

python
from azure.containerregistry import ContainerRegistryClient

with ContainerRegistryClient(endpoint, DefaultAzureCredential()) as client:
    # Download manifest
    manifest = client.download_manifest("my-image", "latest")
    print(f"Media type: {manifest.media_type}")
    print(f"Digest: {manifest.digest}")

    # Download blob
    blob = client.download_blob("my-image", "sha256:abc123...")
    with open("layer.tar.gz", "wb") as f:
        for chunk in blob:
            f.write(chunk)

Async Client

python
from azure.containerregistry.aio import ContainerRegistryClient
from azure.identity.aio import DefaultAzureCredential

async def list_repos():
    async with DefaultAzureCredential() as credential:
        async with ContainerRegistryClient(endpoint, credential) as client:
            async for repo in client.list_repository_names():
                print(repo)

Clean Up Old Images

python
from datetime import datetime, timedelta, timezone

cutoff = datetime.now(timezone.utc) - timedelta(days=30)

for manifest in client.list_manifest_properties("my-image"):
    if manifest.last_updated_on < cutoff and not manifest.tags:
        print(f"Deleting {manifest.digest}")
        client.delete_manifest("my-image", manifest.digest)

Client Operations

OperationDescription
list_repository_namesList all repositories
get_repository_propertiesGet repository metadata
delete_repositoryDelete repository and all images
list_tag_propertiesList tags in repository
get_tag_propertiesGet tag metadata
delete_tagDelete specific tag
list_manifest_propertiesList manifests in repository
get_manifest_propertiesGet manifest metadata
delete_manifestDelete manifest by digest
download_manifestDownload manifest content
download_blobDownload layer blob
Show full SKILL.md (149 more words)Show less

Best Practices

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with Client(...) as client: (async). For async DefaultAzureCredential from azure.identity.aio, also use async with credential: so tokens and transports are cleaned up.
  3. Use Microsoft Entra ID for authentication in production
  4. Delete by digest not tag to avoid orphaned images
  5. Lock production images with can_delete=False
  6. Clean up untagged manifests regularly
  7. Use async client for high-throughput operations
  8. Order by last_updated to find recent/old images
  9. Check manifest.tags before deleting to avoid removing tagged images

Reference Files

FileContents
references/capabilities.mdAdditional non-hero capabilities, operation-group coverage, and production checklists.
references/non-hero-scenarios.mdDedicated non-hero examples for secondary/advanced scenarios.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/plugins/azure-sdk-python/skills/azure-containerregistry-py of microsoft/skills.

  • SKILL.md
  • references/capabilities.md
  • references/non-hero-scenarios.md

Open the folder on GitHubat commit 3898ec8

Compare with similar skills

Azure Containerregistry Py next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Containerregistry Py compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Containerregistry Py this skillmicrosoft/skills3.1k—~2.2kAutomated safety check: PassMIT
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Unraiddinglebear-ai/unraid135—~5.4kAutomated safety check: NotesMIT
Devsydevsy-org/devsy111—~1.7kAutomated safety check: PassMPL-2.0
Image Managementdotnet/dotnet-docker4.9k—~1.1kAutomated safety check: PassMIT
Generate Nemo Gym Envadithya-s-k/FineEnvs456—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Unraid

    dinglebear-ai/unraid

    This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…

    135 GitHub stars~5.4k tokensUpdated 5 days ago
    DevOps & CloudAuto-check: notes
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    111 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Image Management

    dotnet/dotnet-docker

    Official

    Manages .NET Docker images including adding images for new .NET versions, new Linux distros (Alpine, Ubuntu, Azure Linux), and new Windows versions.

    4.9k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Generate Nemo Gym Env

    adithya-s-k/FineEnvs

    Builds a NeMo Gym (NVIDIA) variant of an RL environment. An agent skill from adithya-s-k/FineEnvs.

    456 GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Cosmos3 Env Troubleshoot

    NVIDIA/cosmos-framework

    Official

    Diagnose and fix Cosmos3 environment, installation, and runtime errors.

    559 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Categories

Questions about Azure Containerregistry Py

What does Azure Containerregistry Py do?

Azure Container Registry SDK for Python. An agent skill from microsoft/skills. Azure Containerregistry Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Container Registry SDK for Python.

When should I use Azure Containerregistry Py?

Azure Containerregistry Py fits situations like: managing container images; tasks that involve Containers.

How do I install Azure Containerregistry Py in Claude Code?

Run `npx skills add microsoft/skills --skill azure-containerregistry-py -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-containerregistry-py in microsoft/skills) into .claude/skills/azure-containerregistry-py in your project. Claude Code loads it when a task matches its description.

How do I install Azure Containerregistry Py in Codex?

Run `npx skills add microsoft/skills --skill azure-containerregistry-py -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-containerregistry-py in microsoft/skills) into .agents/skills/azure-containerregistry-py in your project. Codex loads it when a task matches its description.

Can I use Azure Containerregistry Py in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-containerregistry-py -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-containerregistry-py, .gemini/skills/azure-containerregistry-py, .github/skills/azure-containerregistry-py and .opencode/skills/azure-containerregistry-py in your project.

What does Azure Containerregistry Py need to run?

Going by SKILL.md and its folder, Azure Containerregistry Py needs the command-line tools its instructions call (pip) and credentials named AZURE_TOKEN_CREDENTIALS. Our summary lists: Python 3; Docker.

Does Azure Containerregistry Py access the network?

SKILL.md names 2 domains. In commands or code: mcr.microsoft.com and learn.microsoft.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Azure Containerregistry Py safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Containerregistry Py use?

Azure Containerregistry Py is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Containerregistry Py use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Azure Containerregistry Py?

Skills that share tags, products or a category with Azure Containerregistry Py: Minimega (sandia-minimega/minimega, 160 stars), Unraid (dinglebear-ai/unraid, 135 stars), Devsy (devsy-org/devsy, 111 stars) and Image Management (dotnet/dotnet-docker, 4.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Containerregistry Py?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,094 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.