Add Tag Exclusions to ACR Purge
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Start with the acr purge command and its existing --filter, --ago, --keep, --max-tags, and --untagged paths, using prior work in Azure/acr-cli#59, #60, #256, and #428 for context. Add repeatable --exclude-tags and --exclude-filter handling, then cover the listed retention, dry-run, pagination, untagged, and ACR Task cases; update command help and the README with task examples.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Add Tag Exclusions to ACR Purge
What is the problem you're trying to solve?
acr purge --filter lets users select tags for deletion, but there is no straightforward way to protect a known set of tags.
Common examples include:
- Tags currently deployed to a Kubernetes cluster
latestorstable- Release tags
- A generated list of tags that are still in use
Negative lookaheads can cover some of these cases, but they become difficult to build and maintain, especially for a long list of exact tags.
This also needs to work with the normal ACR Task flow:
az acr run \
--registry example \
--cmd '{{ .Run.Registry }}/acr:latest purge ...' \
/dev/null
Because purge tasks commonly use /dev/null as their context, requiring an exclusion file would not be practical.
Describe the solution you'd like
Add two optional, repeatable flags:
--exclude-tags <repository-regex>:<tag>[,<tag>...]
--exclude-filter <repository-regex>:<tag-regex>
--exclude-tags would be used for exact tag names:
# Keep several tags in the app repository
--exclude-tags "^app$:v1.2.3,v1.2.4,v1.2.5"
# Keep v1.0 in all repositories beginning with app
--exclude-tags "^app.*$:v1.0"
# Keep latest in every repository
--exclude-tags ".*:latest"
--exclude-filter would be used when the tags themselves follow a pattern:
# Keep release tags in all repositories beginning with app
--exclude-filter "^app.*$:^release-.*$"
The flags could be combined:
az acr run \
--registry example \
--cmd '{{ .Run.Registry }}/acr:latest purge -r {{ .Run.Registry }} --filter ".*:.*" --exclude-tags ".*:latest,stable" --exclude-tags "^app.*$:v1.0,v1.1" --exclude-filter "^worker.*$:^production-.*$" --ago 7d' \
/dev/null
The repository portion would use the same regex behavior as --filter. Tags passed to --exclude-tags would be treated as literal values.
Any matching exclusion would take precedence over --filter. In other words, a tag would only be considered for deletion when it matches --filter and does not match any exclusion.
Exclusions should be applied before --ago, --keep, or --max-tags. This is important so protected tags do not consume positions in count-based retention.
Expected behavior
- Both flags are optional and repeatable.
- Values from every occurrence are combined.
--exclude-tagsaccepts comma-separated literal tags for one repository expression.- Whitespace around comma-separated tags is ignored.
--exclude-filteraccepts a repository regex and a tag regex.- Duplicate exact tags are harmless.
- Invalid expressions and malformed tag lists fail before deletion begins.
- Dry-run and actual purge use the same exclusion logic.
- Exclusions apply to both the age/
--keepand--max-tagspaths. - Existing behavior is unchanged when no exclusions are supplied.
- The existing numeric
--keepflag is unchanged. - When
--untaggedis used, manifests referenced by excluded tags are not considered dangling. - The exclusion flags are invalid with
--untagged-only, since that mode does not evaluate tags.
Acceptance criteria
- Exact tags can be excluded from one repository, a matching set of repositories, or all repositories.
- Multiple exact tags can be supplied without repeating the repository for each tag.
- Exact exclusions and regex exclusions can be used together.
- Excluded tags are never selected for deletion and do not count toward
--keepor--max-tags. - The behavior works through
az acr runwithout requiring a task source context. - Tests cover multiple flags, repository patterns, pagination, dry-run,
--ago,--keep,--max-tags, and--untagged. - Command help and the README include ACR Task examples.
Prior work
This has been requested and worked on a few times:
- Azure/acr-cli#59 was opened by @dominicdejacomo in 2019 for protecting tags used by Kubernetes workloads.
- Azure/acr-cli#60 was implemented by @angrox in 2019. Review requested precompiled expressions and additional tests, but the PR was not completed.
- Azure/acr-cli#256 was opened by @jan-dolejsi in 2024 for maintaining an explicit list of tags that should survive purge.
- Azure/acr-cli#428 was opened by @sashokbg in 2025 based on the earlier work. It added exclusion precedence, documentation, and tests, but was not updated after review.
Any implementation should build on and credit that prior work while fitting into the current purge retention paths.
Potential follow-up
ACR Tasks can run with a source context, so a future --exclude-tags-file option may be useful for very large or generated exclusion lists. The file could contain one repository and tag entry per line and be included in the task context.
File input is outside the initial scope of this proposal. Command-line exclusions work with the common /dev/null task flow and avoid defining a file format, path behavior, and task-context requirements as part of the first implementation.
- Ngôn ngữ chính
- Go
- Star
- 71
- Fork
- 52
- Merge trung bình
- 8 ngày 10 giờ
- Pull request đã merge (30 ngày)
- 4
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Azure/acr-cli
-
Proposal: Add Minimum and Maximum Retention Policies to Acr PurgeCó thể đã có người làm @gildardogmsft đã nhận 9 ngày trước. Đang mởenhancement
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
Azure/acr-cli#670 · 2 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
Azure/acr-cli#644 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
Azure/acr-cli#621 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 30/100
Azure/acr-cli#611 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của Azure/acr-cli
Issue tương tự
-
kind/bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 4 ngày
-
bug needs-acceptance
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
vllm-project/semantic-router#4744 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
jaegertracing/jaeger#9794 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
ScalingModifiers formula fails with "formula returned non-float result" when expression evaluates to an integerCó thể đã có người làm @Sarthak-Pandey đã nhận hôm nay. Đang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 73/100
kedacore/keda#8270 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày