ACR unauthorized 🔷 Azure

Azure Container Registry: unauthorized: authentication required, visit https://aka.ms/acr/authorization (AKS ErrImagePull 401)

Pulling/pushing to ACR wasn’t authenticated — Docker not logged in, or AKS/App Service lacks AcrPull on the registry.

Seen on: Azure Kubernetes Docker

Meaning

AKS needs the cluster’s kubelet identity to have AcrPull (az aks update --attach-acr). App Service/Container Apps need a managed identity with AcrPull or admin credentials. Locally, az acr login refreshes Docker credentials (tokens last 3 hours).

Common causes

  • AKS kubelet identity without AcrPull
  • az acr login token expired
  • Admin user disabled and no other auth configured
  • Pulling from the wrong registry/subscription

⚡ Quick fix

  1. az aks update -n aks -g rg --attach-acr myacr
  2. az acr login --name myacr
  3. Grant AcrPull to the app’s managed identity

Detailed fix by platform

Azure CLI

  1. bash
    az aks update -n aks1 -g rg --attach-acr myacr
    az aks check-acr -n aks1 -g rg --acr myacr.azurecr.io
    az acr login --name myacr

How to diagnose

  1. Identity — Which identity pulls?
  2. Role — AcrPull on the registry
  3. Registry — Correct login server

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.