FAQ about configuring VPC access control
If connectivity or domain resolution issues occur when you configure virtual private cloud (VPC) access control for a Container Registry (ACR) Enterprise Edition instance, this FAQ helps you troubleshoot them and manually configure private domain name resolution.
The VPC and the Enterprise Edition instance fail to connect
Symptom
The access IP address of the ACR Enterprise Edition instance is not found in the VPC. This means the VPC failed to connect to the Enterprise Edition instance.
Solution
Delete the VPC and add it again. If the issue persists, submit a ticket for troubleshooting.
VPC domain resolution errors
Symptom
After you enable VPC access control, ACR automatically configures private domain name resolution (PrivateZone) in the VPC. ACR then resolves the private domain name of the Enterprise Edition instance to the assigned access IP address. If the access IP address appears in the list but is marked with a red exclamation point, automatic resolution has failed. Troubleshoot the issue based on the error code, as described in the following table.
Common error codes and solutions
Error code | Solution |
| The Private Zone service is not enabled. Log on to the Alibaba Cloud DNS-Private Zone console to enable the service, and then configure access control again for the target VPC. For more information, see Configure VPC access control. |
| The Private Zone service has temporarily throttled your account. After the throttling is lifted, add access control again for the VPC. Alternatively, see Manually configure VPC domain name resolution. |
| The Private Zone service encountered an error while resolution was being configured. After the service recovers, add access control again for the VPC. Alternatively, see Manually configure VPC domain name resolution. |
| ACR has no service-linked role configured for Private Zone, or the role has insufficient permissions. See Service-linked role for PrivateZone to complete the authorization. |
| ACR detected that the target zone ( To avoid affecting existing workloads, perform the following steps:
After you remove the unnecessary VPCs, add access control again for the target VPC. Alternatively, see Manually configure VPC domain name resolution. |
| The related domain name records changed while ACR was automatically configuring Private Zone. Add access control again for the target VPC. For more information, see Configure VPC access control. |
Manually configure VPC domain name resolution
If you manually configured VPC domain name resolution for a VPC and later removed access control for that VPC from the Enterprise Edition instance, manually delete the corresponding resolution records in Alibaba Cloud DNS - Private Zone. Otherwise, the records may affect your workloads. Assess and resolve any resulting issues at your own discretion.
The following example points the private domain name test-vpc.cn-hangzhou.cr.aliyuncs.com of an Enterprise Edition instance to the IP address 192.168.0.1 in the target VPC.
Log on to the Alibaba Cloud DNS-Private Zone console.
On the User Defined Zones tab, click Add Zone.
In the Add Zone sidebar, configure the following parameters and then click OK.
Parameter
Example value
Authoritative Zone
cn-hangzhou.cr.aliyuncs.com
For example, if the private domain name is
test-vpc.cn-hangzhou.cr.aliyuncs.com, its domain name suffix iscn-hangzhou.cr.aliyuncs.com.Subdomain Recursive Proxy
Enabled
Effective in VPCs
Select the ID of the target VPC.
On the User Defined Zones tab, find the zone you created and click Settings in the Actions column.
Click Add Record. In the Add Record dialog box, configure the following parameters and click OK.
Parameter
Example value
Record Type
A
Hostname
test-vpc
For example, if the private domain name is
test-vpc.cn-hangzhou.cr.aliyuncs.com, its prefix istest-vpc.Record Value
192.168.0.1
The access IP address in the corresponding VPC.
for the target VPC, and then click
.