You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/iot-edge/production-checklist.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -133,21 +133,21 @@ When moving from test scenarios to production scenarios, remember to remove debu
133
133
134
134
Before you deploy modules to production IoT Edge devices, ensure that you control access to your container registry so that outsiders can't access or make changes to your container images. Use a private, not public, container registry to manage container images.
135
135
136
-
In the tutorials and other documentation, we instruct you to use the same container registry credentials on your IoT Edge device as you use on your development machine. These instructions are only intended to help you set up testing and development environments more easily, and should not be followed in a production scenario. Azure Container Registry recommends [authenticating with service principals](../container-registry/container-registry-auth-service-principal.md) when applications or services pull container images in an automated or otherwise unattended manner, as IoT Edge devices do.
136
+
In the tutorials and other documentation, we instruct you to use the same container registry credentials on your IoT Edge device as you use on your development machine. These instructions are only intended to help you set up testing and development environments more easily, and should not be followed in a production scenario. Azure Container Registry recommends [authenticating with service principals](../container-registry/container-registry-auth-service-principal.md) when applications or services pull container images in an automated or otherwise unattended manner (headless), as IoT Edge devices do.
137
137
138
-
To create a service principal, run the two scripts as described in [Create a service principal](../container-registry/container-registry-auth-aci.md#create-a-service-principal). These scripts do the following tasks:
138
+
To create a service principal, run the two scripts as described in [create a service principal](../container-registry/container-registry-auth-aci.md#create-a-service-principal). These scripts do the following tasks:
139
139
140
-
* The first script creates the service principal. It outputs the `Service principal ID` and the `Service principal password`. Store these values securely in your records.
140
+
* The first script creates the service principal. It outputs the Service principal ID and the Service principal password. Store these values securely in your records.
141
141
142
-
* The second script creates role assignments to grant to the service principal, which can be run subsequently if needed. We recommend applying the **acrPull** or **arcPush** user roles for the `--role` parameter. For a list of roles, see [Azure Container Registry roles and permissions](../container-registry/container-registry-roles.md)
142
+
* The second script creates role assignments to grant to the service principal, which can be run subsequently if needed. We recommend applying the **acrPull** or **arcPush** user roles for the `role` parameter. For a list of roles, see [Azure Container Registry roles and permissions](../container-registry/container-registry-roles.md)
143
143
144
-
To authenticate using a service principal, provide the service principal ID and password that you obtained from the first script. Provide the credentials as follows:
144
+
To authenticate using a service principal, provide the service principal ID and password that you obtained from the first script.
145
145
146
-
* For username or client ID, specify the service principal ID.
146
+
* For the username or client ID, specify the service principal ID.
147
147
148
148
* For the password or client secret, specify the service principal password.
149
149
150
-
For an example of launching Azure Container instances using a service principal, see [](../container-registry/container-registry-auth-aci.md#authenticate-using-the-service-principal).
150
+
For an example of launching a container instance with Azure CLI, see [Authenticate using the service principal](../container-registry/container-registry-auth-aci.md#authenticate-using-the-service-principal).
0 commit comments