Mastering Azure Containers and App Service

Learn what containers are and how to deploy apps on Azure through analogies and scenarios. Quickly grasp the differences between ACR, ACI, Container Apps, and App Service.

In the AZ-104 exam, containers and App Service are important topics that are also frequently used in real-world practice. The terminology may seem unfamiliar at first, but with real-life analogies, you'll find it much easier to understand than you might expect.

 

What Is a Container?

Let's start by getting a clear picture of what a container is.

A container is like a moving box you use when relocating. When you move, you pack furniture, clothes, and kitchen items into separate boxes, and when you arrive at your new home, you simply unpack the boxes and everything is ready to use. Apps work the same way. When you package an app together with all the libraries and configuration files it needs into a single container image, it runs exactly the same way on any server. The "it worked on my machine..." problem disappears.

Azure offers several services for working with containers. Let's take a look at what each one is used for.

---

 

Azure Container Registry (ACR)

What Is ACR?

ACR is your own private warehouse for storing container images.

Think of an e-commerce warehouse. When products are manufactured, they are stored in the warehouse, and when an order comes in, they are retrieved and shipped. ACR works exactly the same way. When the development team creates an app as a container image, they store it in ACR and pull it out to deploy to servers whenever needed.

Why do you need your own warehouse? If you push images to a public registry like Docker Hub, anyone can see them. Company internal apps or security-sensitive images should not be exposed externally. Because ACR is a private registry, only authorized users can access images.

ACR SKU Comparison

| Tier | Features | Best For | |------|----------|----------| | Basic | Small storage, basic features | Dev/test environments | | Standard | More capacity, webhook support | General production | | Premium | Geo-replication, private endpoints | Large-scale enterprise |

The geo-replication feature of the Premium tier places copies of images in multiple Azure regions. Servers in Korea and servers in the United States can all pull images quickly from the nearest location.

ACR Access Control (RBAC)

A warehouse has roles, and so does ACR.

AcrPull: Permission to pull (read) images. Typically granted to deployment servers. AcrPush: Permission to push (write) images. Granted to CI/CD pipelines or developers. AcrDelete: Permission to delete images. Best granted only to administrators.

Exam tip: "Need to store Docker images privately" → think ACR.

---

 

Azure Container Instances (ACI)

What Is ACI?

ACI is the fastest and simplest way to run a container.

Think of a courier service. If you only occasionally need to move items, it would be wasteful to buy a truck or rent a warehouse. You simply call a courier. ACI works the same way. Use it when you want to immediately run a single container without complex server configuration or cluster management.

When Should You Use ACI?

Batch jobs: A task that cleans up data every night at 2 a.m. There is no need to keep it running at other times — just start the container when needed and stop it when done. Event-driven processing: Cases where you only need to run something briefly when a specific event occurs, such as converting an image when a file is uploaded. Quick testing: When you want to rapidly test a new container image.

ACI Advantages and Limitations

With ACI you can specify CPU and memory directly and use only as much as you need. However, it is better suited for one-time or short-lived tasks than for continuously running web services. For microservice architectures that require complex interconnections between multiple containers, the services introduced below are a better fit.

Exam tip: "Run a single container as quickly as possible" or "Run a container without cluster management" → think ACI.

---

 

Azure Container Apps

What Is Container Apps?

Container Apps is a serverless container platform. It is well-suited for managing complex apps where multiple containers are interconnected and work together, like microservices.

Imagine a franchise restaurant. The kitchen, the dining floor, and the cashier each operate independently but collaborate with one another. During a busy lunch rush, more kitchen staff are added; during slow hours, staff are reduced. Container Apps plays exactly this role. It runs each microservice (kitchen, dining floor, cashier) as a container and automatically adjusts scale according to traffic.

KEDA-Based Auto Scaling

KEDA (Kubernetes Event-Driven Autoscaling) watches various signals and automatically adjusts the number of containers.

For example, when HTTP requests surge, more containers are created; when messages pile up in a message queue, additional containers are spun up to process them. When there is no traffic, containers can be scaled down to zero to save costs. This is what "serverless" means — not that there are no servers, but that you don't have to worry about servers.

Revision Management (Blue/Green, Canary Deployments)

If you switch 100% of traffic to a new version all at once, every user is affected if something goes wrong. Container Apps handles this safely.

Blue/Green deployment: Run the old version (Blue) and the new version (Green) simultaneously, then switch all traffic at once after verification. Canary deployment: Initially send only 5% of traffic to the new version, and gradually increase it if there are no issues. Just like a canary bird detects gas in a mine first, this approach tests with a small number of users before a full rollout.

Dapr Integration

Dapr is a tool that makes communication between microservices easier. It provides a standardized way for Service A to send messages to Service B, or to store and read shared state, without having to write complex distributed system code yourself.

Exam tip: "Serverless containers", "KEDA scaling", "microservices" → think Container Apps.

---

 

Azure App Service

What Is App Service?

App Service is a PaaS (Platform as a Service) that makes it easy to host web apps, REST APIs, and mobile backends.

Think of a rental apartment. You don't have to build the apartment yourself — when you move in, electricity, water, and heating are all ready. App Service works the same way. Without worrying about infrastructure such as server OS installation, security patching, or load balancing, you can run a web service by simply uploading your code. It supports a wide range of languages including Node.js, Python, .NET, Java, and PHP.

App Service Plan

An App Service Plan is a pricing tier that defines the compute resources (CPU, memory) on which your app runs. Using the apartment analogy, it's like choosing between a studio, a one-bedroom, or a multi-level unit.

| Tier | Features | Best For | |------|----------|----------| | Free/Shared | Free or shared environment, no custom domain | Development and learning | | Basic | Small apps, no auto-scaling | Small-scale production | | Standard | Auto-scaling + deployment slots | General production | | Premium | High performance, VNet integration | High-traffic or network isolation needs | | Isolated (ASE) | Dedicated isolated environment, App Service Environment | Cases requiring complete isolation, e.g. finance, healthcare |

The important point is that auto-scaling and deployment slots are only available on Standard or higher. This is a topic that appears frequently in the exam.

Deployment Slots

Deployment slots let you create a staging environment alongside your production app.

Think of a restaurant kitchen. When changing the menu, testing directly in the operating kitchen would affect customers. Instead, you finalize the new menu in a separate test kitchen, and if it looks good, you swap it in for the existing menu.

Deployment slots work exactly the same way. Deploy the new version to the staging slot. Test thoroughly in staging. If everything looks good, swap the staging and production slots. The new version is deployed with no service interruption. If a problem occurs, swap again to roll back immediately.

Back to blog list