Java / Azure Container Instances (ACI) Interview questions
Last updated
1. What is Azure Container Instances (ACI)?
Azure Container Instances is Azure's serverless way to run containers. You supply an image plus CPU and memory values, and Azure runs it for you. There are no VMs to provision and no orchestrator to operate, and containers usually start within seconds.
The unit you deploy is a container group. ACI runs both Linux and Windows containers, and you pay per second for the vCPU and memory you request.
- Public IP with a DNS label, or a private IP inside a virtual network
- Azure Files volumes, managed identities and private registry pulls
- Optional Spot (cheaper, interruptible) and confidential (hardware-protected) containers
ACI is not a full orchestrator. It has no built-in autoscaling, rolling updates or service discovery, so it fits short-lived and bursty workloads best.
Take quiz
A node pool
A Kubernetes namespace
An App Service plan
A container group
Per-second billing
Built-in autoscaling and rolling updates
A public IP with a DNS label
Support for Linux containers
2. What is a container group in ACI?
A container group is the top-level ACI resource (Microsoft.ContainerInstance/containerGroups). It holds one or more containers that are scheduled on the same host and share a lifecycle, network and storage. It is the closest thing ACI has to a Kubernetes pod.
- One IP address and port space; containers talk to each other over
localhost - Shared volumes that any container in the group can mount
- One restart policy and one start/stop/delete lifecycle for the whole group
- Billing based on the sum of the containers' CPU and memory requests
Multi-container groups are Linux only, and a group can hold up to 60 containers. Windows groups are limited to a single container.
Take quiz
A pod
A node
A ReplicaSet
An Ingress
Only through the public internet
Through a Kubernetes Service DNS name
Through localhost on the shared network namespace
Through a separate load balancer per container
3. How is ACI billed?
ACI charges per second for the vCPU and memory GB you request for a container group, for as long as it runs. You pay for what you request, not what the process actually uses.
Billing starts when ACI begins pulling the image and ends when the group stops, is deleted, or finishes running to completion.
- Windows containers add a software charge on top of compute
- GPU resources are billed per GPU-second
- Spot containers can be up to 70% cheaper than regular ones
- Public IPs, Log Analytics ingestion and Azure Files are billed separately
Because requests drive the bill, right-sizing CPU and memory is the easiest saving.
Take quiz
Peak CPU the process actually consumed
A flat hourly rate per container group
Requested vCPU and memory multiplied by running seconds
The number of HTTP requests served
Only when the resource group is deleted
When the group stops running, for example after stop, delete or run-to-completion
At the end of the calendar month
When CPU use falls below 10 percent
4. Which operating systems and image architectures does ACI support?
ACI runs Linux and Windows containers through the same API. You pick the OS with --os-type (Linux is the default). Images must be built for x64 (AMD64); ARM64 images are not supported.
The two operating systems do not have identical features:
| Feature | Linux | Windows |
| Multi-container groups | Yes | No (one container) |
| Azure Files volume mount | Yes | No |
| Confidential containers | Yes | No |
If an image fails to start right away, check the OS type and architecture before anything else.
Windows base images are also much larger than Linux ones, so cold starts take noticeably longer on Windows.
Take quiz
ARM64 only
Both ARM64 and x64
32-bit x86 only
x64 (AMD64)
--platform-os
--os-type
--image-os
--container-kind
5. How do you deploy a container to ACI using Azure CLI?
Create a resource group, then run az container create with the image, size and ports. A DNS label gives you a public name.
az group create --name rg-aci-demo --location eastus az container create \ --resource-group rg-aci-demo \ --name aci-hello \ --image mcr.microsoft.com/azuredocs/aci-helloworld \ --cpu 1 --memory 1.5 \ --ports 80 \ --dns-name-label aci-hello-12345
- Check progress with
az container show --query instanceView.state. - Browse to the FQDN (for example
aci-hello-12345.eastus.azurecontainer.io). - Clean up with
az container deleteso billing stops.
The command returns once the group is created, and the first start is slower because the image has to be pulled from the registry.
Take quiz
--dns-name-label
--hostname
--fqdn
--domain-name
az container inspect
az container describe
az container show
az container status --all
6. List the restart policies available in ACI?
ACI has three restart policies, set once on the whole container group with --restart-policy:
| Policy | Behaviour | Typical use |
| Always (default) | Restarts containers whenever they exit | Web apps, APIs, daemons |
| OnFailure | Restarts only on a non-zero exit code | Jobs that should retry on error |
| Never | Runs once and stays stopped | One-off tasks, scripts |
With Never or OnFailure, the group ends once its containers finish, and billing stops. A batch image left on Always will loop forever.
Choose the policy to match how your process behaves: a web server should never exit, so Always fits, while a script that ends on purpose should not be restarted.
Take quiz
Always
Persistent
Never
Default
Never
Always
OnFailure
None
7. How do you expose an ACI container group to clients?
There are two network modes. A public group gets a public IP (--ip-address Public), the ports you list with --ports, and an optional DNS label that produces label.region.azurecontainer.io. A private group is deployed into a virtual network and only gets a private IP.
Ports must be declared on the group and the application must actually listen on them. TCP and UDP are both supported.
ACI does not terminate TLS for you. For HTTPS, put a sidecar proxy such as nginx or Caddy in the group, or place Application Gateway or Front Door in front.
Take quiz
A custom domain with a managed certificate
An address ending in .cloudapp.net
A Kubernetes Ingress hostname
A name such as myapp.eastus.azurecontainer.io
Automatically by ACI with a managed certificate
In a sidecar proxy or a gateway in front of the group
By the Azure Files share
By the restart policy
8. How do you pull images from a private registry in ACI?
There are three options, listed from least to most preferred: registry username and password, a service principal, or a managed identity. The managed identity needs the AcrPull role on the registry, so no password has to be stored.
az container create \ --resource-group rg-aci-demo --name aci-private \ --image myregistry.azurecr.io/app:1.0 \ --assign-identity <identity-resource-id> \ --acr-identity <identity-resource-id> \ --registry-login-server myregistry.azurecr.io
Keep the registry in the same region as the group to speed up pulls. If the registry is behind a firewall or private endpoint, make sure the ACI subnet can reach it.
Take quiz
AcrPull
AcrPush
Reader on the subscription
Contributor on the container group
The shared admin account password in YAML
Anonymous pull
A managed identity
An SSH key
9. How do you view logs of a container in ACI?
Use az container logs. It returns what the container process wrote to stdout and stderr, so your application has to log to the console and not only to files.
az container logs -g rg-aci-demo -n aci-hello az container logs -g rg-aci-demo -n aci-multi --container-name sidecar az container attach -g rg-aci-demo -n aci-hello
az container attach streams output live and also shows container events, which helps when a container is slow to start. For retention and queries, send logs to a Log Analytics workspace.
Take quiz
Only kernel messages
Everything under /var/log automatically
The container's stdout and stderr output
Azure Activity Log entries
az container watch
az container attach
az container tail
az container exec
10. How do you run a command inside a running ACI container?
Run az container exec with the command you want, for example a shell. It opens an interactive session through the Azure management API, so you need the right RBAC permissions on the group and the container must be running.
az container exec -g rg-aci-demo -n aci-hello --exec-command "/bin/sh" # multi-container group: pick the target container az container exec -g rg-aci-demo -n aci-multi \ --container-name app --exec-command "/bin/sh"
The image has to contain the binary you call. Minimal or distroless images often have no shell, in which case you debug with logs and events instead.
Take quiz
An SSH daemon on port 22
The Azure CLI
A kubelet agent
The shell binary you ask for, such as /bin/sh
--pod
--container-name
--target
--sidecar
11. What volume types does ACI support?
ACI supports four volume types, and only one of them is persistent.
| Volume | Persistent? | Typical use |
| Azure Files share | Yes | Shared data, job output, state that must outlive the group |
| emptyDir | No | Scratch space shared by containers in the group |
| secret | No | Sensitive values exposed as in-memory files |
| gitRepo | No | Clone a repository into the container at startup |
A group can have up to 20 volumes. Anything not on Azure Files disappears when the group is stopped or deleted.
Use Azure Files for anything you cannot afford to lose, and keep emptyDir for temporary files such as caches or hand-offs between containers.
Take quiz
Azure Files share
emptyDir
secret
gitRepo
Mounting a managed disk
Backing up logs to Blob storage
Exposing sensitive values as in-memory files
Caching image layers
12. What are environment variables and secure environment variables in ACI?
Both pass configuration into the container. A normal variable (--environment-variables) is visible in the group's properties in the portal and API output. A secure variable (--secure-environment-variables, or secureValue in YAML) is not returned when you read the group back.
az container create -g rg-aci-demo -n aci-env --image myapp:1.0 \ --environment-variables MODE=prod \ --secure-environment-variables DB_PASSWORD=S3cr3t!
The process inside the container can still read the secure value, so never print it. For stronger secret handling, fetch secrets from Key Vault using a managed identity.
Take quiz
It is stored in Key Vault automatically
It can only be read by init containers
Its value is not shown in the group's properties
It is encrypted inside process memory
secret: true
secureValue
hidden
vaultRef
13. How do you stop, start, restart and delete a container group?
Each action has its own CLI command, and they behave differently:
| Command | Effect |
az container stop |
Stops containers and releases compute; billing stops, definition is kept |
az container start |
Starts a stopped group again, possibly on a different host |
az container restart |
Restarts the containers in the group |
az container delete |
Removes the group and its definition permanently |
Ephemeral data (emptyDir, container filesystem) is lost when a group is stopped, and its IP address is not guaranteed to stay the same after a start.
Take quiz
It continues until the group is deleted
It drops to half rate
It switches to Spot pricing
It stops while the group definition is kept
az container stop
az container delete
az container reset
az container deallocate
14. What are the CPU and memory resource settings in ACI?
Each container declares requests (the guaranteed, billed amount) and optionally limits (a ceiling). The group total is the sum of all container requests. CPU can be fractional and memory is in GB.
containers: - name: app properties: image: myapp:1.0 resources: requests: cpu: 1.0 memoryInGB: 1.5 limits: cpu: 2.0 memoryInGB: 2.0
A container that goes over its CPU limit is throttled, and one that goes over its memory limit is killed. The maximum group size varies by region and OS (commonly 4 vCPU and 16 GB), so check the region availability page before sizing.
Take quiz
Sum of each container's CPU request
The largest single container request
The average of all requests
Whatever the first container requests
It is throttled like CPU
It gets more memory automatically
It is terminated by an out-of-memory kill
It is moved to a bigger host
15. What is a managed identity in ACI?
A managed identity gives a container group a Microsoft Entra identity, so code inside it can call Azure services without storing credentials. Typical targets are Key Vault, Storage, SQL and Container Registry.
| Type | Lifecycle | Sharing |
| System-assigned | Created with the group, deleted with it | One group only |
| User-assigned | Independent resource you manage | Reusable across many groups |
Enable it with --assign-identity, then grant the identity an Azure role on the target resource. Code gets tokens through the Azure SDK or the token endpoint in the container.
Take quiz
System-assigned
Container-assigned
User-assigned
Registry-assigned
A new SSH key
An Azure role assignment on the target resource
A DNS name label
A volume mount
16. What are common use cases of ACI?
ACI shines wherever you need containers quickly, for a short time, with no cluster to run.
- Batch and ETL jobs that run on a schedule or trigger
- CI/CD build agents that appear for a pipeline run and vanish afterwards
- Event-driven tasks started from Logic Apps, Functions or Event Grid
- Dev/test environments and quick demos
- Burst capacity for AKS through virtual nodes
It is a poor fit for large, always-on microservice estates that need autoscaling, rolling deployments and service discovery. Those belong on AKS or Azure Container Apps.
Take quiz
A 24/7 autoscaled microservice mesh
A stateful database cluster
A workload that needs custom kernel modules
A short-lived batch job triggered on demand
Cluster autoscaler alone
Virtual nodes
Azure Batch pools
kubenet networking
17. What are init containers in ACI?
Init containers run before your application containers, one after another, and each must finish successfully before the next starts. If an init container fails, the application containers do not start.
They suit one-time setup such as downloading config, waiting for a dependency, or preparing a shared volume. They are defined in YAML, ARM or Bicep, not through simple CLI flags.
properties: initContainers: - name: prep properties: image: busybox command: ["/bin/sh", "-c", "echo ready > /mnt/shared/ready"] volumeMounts: - name: shared mountPath: /mnt/shared
Take quiz
Before the application containers, one after another until each completes
Alongside the application containers
After the application containers exit
Only when a liveness probe fails
Serving production traffic
Scaling the group out
Preparing a shared volume with config files
Rotating the registry password
18. What are Spot containers in ACI?
Spot containers run on spare Azure capacity at a discount of up to 70% compared with regular ACI. The catch is that Azure can preempt them when it needs the capacity back.
That makes them a good match for fault-tolerant work such as retryable batch jobs, rendering, or test runs. Design the workload to checkpoint progress and be safely restarted.
You select them with --priority Spot at creation. Spot groups do not support availability zones, and they are the wrong choice for anything with strict uptime needs.
Take quiz
Higher price for guaranteed uptime
No networking support
Lower price in exchange for possible preemption
Windows only
A single-instance payment API
Retryable batch processing
A TLS-terminating front proxy
An in-memory-only database
19. What are confidential containers in ACI?
Confidential containers run Linux container groups inside a hardware-based trusted execution environment built on AMD SEV-SNP. Memory is encrypted and protected, even from the Azure host operators, which protects data while it is in use.
You create them with the Confidential SKU and a confidential computing enforcement (CCE) policy. The policy pins the exact images, commands and settings allowed to run, and is typically generated with the az confcom extension.
Workloads can prove their environment through remote attestation. Region availability is more limited than for regular containers.
Take quiz
Setting billing alerts
Choosing the DNS label
Selecting the restart behaviour
Defining exactly what may run inside the trusted environment
Per-process Intel SGX enclaves
AMD SEV-SNP
ARM TrustZone
TPM-only secure boot
20. How do you deploy a container group using a YAML file?
Describe the group in a YAML file and pass it to az container create --file. YAML is the easiest route for things the simple CLI flags cannot express, such as multiple containers, init containers and probes.
apiVersion: 2023-05-01 location: eastus name: aci-yaml-demo type: Microsoft.ContainerInstance/containerGroups properties: osType: Linux restartPolicy: Always containers: - name: web properties: image: mcr.microsoft.com/azuredocs/aci-helloworld ports: - port: 80 resources: requests: cpu: 1.0 memoryInGB: 1.5 ipAddress: type: Public ports: - protocol: tcp port: 80
az container create --resource-group rg-aci-demo --file deploy-aci.yaml
Note the ports appear twice: once on the container and once on the group's ipAddress block. Forgetting the second one is a common reason a deployed container is unreachable.
Take quiz
az container create --resource-group rg --file app.yaml
az container apply -f app.yaml
az deploy yaml app.yaml
kubectl apply -f app.yaml
Microsoft.Web/sites
Microsoft.ContainerService/managedClusters
Microsoft.ContainerInstance/containerGroups
Microsoft.App/containerApps
21. What is the difference between ACI and AKS?
ACI runs individual container groups with no cluster. AKS is a managed Kubernetes cluster where you manage node pools and workloads, and Azure manages the control plane.
| Aspect | ACI | AKS |
| Unit of deployment | Container group | Pod, Deployment, Service |
| Scaling | Manual or scripted, no built-in autoscale | HPA, cluster autoscaler, KEDA |
| Service discovery and rollouts | None built in | Services, Ingress, rolling updates |
| Infrastructure to manage | None | Node pools, upgrades, networking |
| Billing | Per second of requested vCPU and memory | Per node VM, running or idle |
| Best for | Bursty, short-lived or simple workloads | Large, long-running microservice platforms |
The two also combine: AKS virtual nodes can run overflow pods on ACI.
Take quiz
ACI
Both equally
AKS
Neither
AKS with a dedicated node pool
ACI
A VM scale set
Azure Batch with custom VMs
22. What is the difference between ACI and Azure Container Apps?
Both are serverless, but they sit at different levels. Container Apps is a platform for apps and microservices, built on Kubernetes with KEDA and Dapr behind the scenes. ACI is a lower-level building block that just runs container groups.
| Capability | ACI | Container Apps |
| Autoscaling (including to zero) | No | Yes, rule-based via KEDA |
| Built-in HTTPS ingress | No | Yes |
| Revisions and traffic splitting | No | Yes |
| Multi-container group with shared localhost | Yes | Yes (sidecars) |
| Run-once jobs | Yes (restart policy Never) | Yes (Jobs) |
Use ACI when you want the simplest, fastest way to run a container for a bounded task. Use Container Apps when you are running a service that needs scale rules, ingress and safe rollouts.
Take quiz
ACI
Both
Neither
Azure Container Apps
Azure Container Apps
ACI
Both
Neither
23. What is the difference between ACI and Web App for Containers?
Web App for Containers (Azure App Service) hosts a containerized web app on an App Service plan. ACI runs any container, web or not, and has no plan to pay for.
| Aspect | ACI | Web App for Containers |
| Billing | Per second while running | Per plan, whether busy or idle |
| Custom domain and managed TLS | No, add a proxy or gateway | Yes |
| Deployment slots | No | Yes |
| Autoscale rules | No | Yes |
| Non-HTTP and batch workloads | Good fit | Not designed for it |
Choose App Service when you are hosting a web app and want slots, domains and scaling out of the box. Choose ACI for tasks, jobs and short-lived workloads.
Take quiz
Web App for Containers
ACI
ACI Spot containers
Run-once ACI jobs
ACI
ACI with init containers
Web App for Containers
Neither
24. How do containers in a multi-container ACI group share resources?
All containers in a group run on one host inside the same sandbox, so they share the network namespace, the volumes declared on the group, and the group's lifecycle.
- Network: one IP, one port space. Containers call each other on
localhost, and two containers cannot listen on the same port. - Storage: any volume on the group can be mounted by several containers, which is how a sidecar reads files the app writes.
- Compute: each container has its own CPU and memory request, and the group size is the sum.
- Lifecycle: the restart policy and start/stop/delete apply to the whole group.
Common patterns are an app plus a TLS-terminating nginx proxy, or an app plus a log-shipping sidecar. This is Linux only.
Take quiz
ACI blocks port 80 by default
Each container needs its own public IP
They share a single network namespace and port space
Ports are reserved by the restart policy
Two replicas of the same app behind a load balancer
An app container plus a TLS proxy sidecar
A database cluster spread over several hosts
One container per Availability Zone
25. How do you deploy ACI into a virtual network?
Create a subnet delegated to Microsoft.ContainerInstance/containerGroups, then deploy the group into it. The group gets a private IP from that subnet and can talk to other VNet resources, peered networks and on-premises over VPN or ExpressRoute.
az container create -g rg-aci-demo -n aci-vnet \ --image myapp:1.0 \ --vnet vnet-demo --subnet snet-aci \ --ip-address Private
- The delegated subnet is dedicated to ACI; other resource types cannot share it.
- A VNet group cannot be given a public IP or DNS label directly; use Application Gateway or Front Door for internet traffic.
- NSGs and route tables on the subnet control traffic.
- Add a NAT gateway if you need a fixed outbound IP.
Take quiz
Microsoft.ContainerService/managedClusters
Microsoft.Web/serverFarms
Microsoft.App/environments
Microsoft.ContainerInstance/containerGroups
A public IP with a DNS label
A private IP from the delegated subnet
A shared IP from the ACI service
An IPv6-only address
26. How do you mount an Azure Files share in ACI?
Create the storage account and file share first, then pass the account name, key, share name and mount path at deployment. The share is mounted over SMB, so it persists after the group is stopped or deleted. Azure Files mounts work on Linux containers only.
az container create -g rg-aci-demo -n aci-files \ --image myapp:1.0 \ --azure-file-volume-account-name mystorageacct \ --azure-file-volume-account-key "$STORAGE_KEY" \ --azure-file-volume-share-name appdata \ --azure-file-volume-mount-path /mnt/appdata
Several groups can mount the same share, but your application has to handle file locking. For throughput-sensitive jobs, consider a premium file share, and remember the storage key is a secret that should come from a pipeline or vault.
Take quiz
An Azure Files share
emptyDir
A secret volume
The container writable layer
A SAS token for each file
The registry admin password
The storage account name and key
The subscription ID only
27. How do liveness and readiness probes work in ACI?
A liveness probe checks that a container is still healthy. After the configured number of consecutive failures, ACI restarts the container. A readiness probe checks whether it is ready to serve; a failing readiness probe does not restart anything, it just marks the container as not ready for traffic.
Each probe is either an exec command or an httpGet request, tuned with delay, period, timeout and threshold values:
livenessProbe: httpGet: path: /healthz port: 8080 initialDelaySeconds: 10 periodSeconds: 15 failureThreshold: 3 readinessProbe: exec: command: ["cat", "/tmp/ready"] periodSeconds: 5
Set initialDelaySeconds high enough for slow starters, or the liveness probe will kill the container before it finishes booting.
Take quiz
Deletion of the whole group
A scale-out event
A container restart
A change of restart policy
ICMP ping or DNS lookup
An exec command or an HTTP GET request
SSH or RDP login
Azure Monitor alert rule
28. How do you troubleshoot an ACI image pull failure?
Start with the container events, which usually name the exact reason.
az container show -g rg-aci-demo -n aci-app \ --query "containers[0].instanceView.events" -o table
| Likely cause | How to confirm | Fix |
| Wrong image name or tag | Event says image not found | Correct the reference; avoid typos in the tag |
| Missing or wrong registry credentials | Inaccessible image or unauthorized error | Add credentials or assign AcrPull to the managed identity |
| Registry firewall or private endpoint | Timeouts reaching the registry | Allow the ACI subnet or use a reachable endpoint |
| Wrong OS or architecture | Platform mismatch error | Match --os-type and use an x64 image |
Try pulling the same image locally with the same credentials. If that works, the problem is in the ACI configuration, not the image.
Take quiz
In the Azure Monitor billing blade
In the registry's push history only
In the subnet's NSG flow logs
In the container's instanceView events
Images from Docker Hub
ARM64-only images
Images larger than 1 GB
Images with a custom entrypoint
29. How do you troubleshoot an ACI container that keeps restarting?
Look at the restart count and the previous state to see why the last run ended.
az container show -g rg-aci-demo -n aci-app \ --query "containers[0].instanceView.{restarts:restartCount,prev:previousState,cur:currentState}"
- Read the exit code. Zero with policy
Alwaysmeans the process simply finished; useNeverorOnFailurefor jobs. - Exit code 137 usually points to a kill, often out of memory. Raise the memory request or fix the leak.
- Check logs with
az container logsfor startup errors such as missing config or a port bind failure. - Review probes. An aggressive liveness probe can kill a healthy but slow container.
Fix one cause at a time and redeploy, since a restart loop often has more than one reason stacked up behind it.
Take quiz
Never or OnFailure
Always
Default
Persistent
A clean successful exit
A failed image pull
The process was killed, often by an out-of-memory condition
A DNS label conflict
30. When would you choose ACI over Azure virtual machines?
Choose ACI when the workload is already containerized, short-lived or bursty, and you do not want to patch or manage an OS. You pay only while it runs and it starts in seconds, whereas a VM needs to boot and bills while allocated.
- Pick ACI for: on-demand jobs, build agents, quick test environments, event-triggered tasks.
- Pick a VM for: steady 24/7 workloads where reserved pricing wins, custom kernels or drivers, full OS control, persistent local disks, or software that is not containerized.
Keep in mind that ACI storage is ephemeral unless you mount Azure Files, and per-second pricing can cost more than a reserved VM when a container runs all month.
Take quiz
A service needing a custom kernel module
A 24/7 workload on a reserved-price VM
A containerized task that runs for a few minutes on demand
Software that is not containerized
ACI charges extra for every restart
Per-second pricing can exceed a reserved VM over a full month
ACI always bills by instance count
ACI requires a paid support plan
31. How do virtual nodes let AKS burst into ACI?
A virtual node is a virtual-kubelet based node in your AKS cluster that backs pods with ACI instead of VMs. When you schedule a pod onto it, AKS creates a container group in ACI. You skip waiting for the cluster autoscaler to add a VM, and you pay per second for that burst.
spec: nodeSelector: type: virtual-kubelet tolerations: - key: virtual-kubelet.io/provider operator: Exists
- The cluster needs Azure CNI networking and a delegated subnet for the virtual node.
- Not everything is supported: DaemonSets, for example, do not run on virtual nodes.
- Only pods that carry the nodeSelector and toleration land there; other pods stay on regular nodes.
Take quiz
Extra VM scale set nodes
Azure Batch tasks
App Service instances
ACI container groups
Deployments
DaemonSets
Jobs
Plain pods
32. How do you get a static outbound IP address for ACI?
Deploy the group into a virtual network subnet and attach a NAT gateway with a static public IP (or IP prefix) to that subnet. All outbound traffic then leaves from that address, which you can add to partner firewalls and allow lists.
- Create a public IP and a NAT gateway.
- Attach the NAT gateway to the subnet delegated to ACI.
- Deploy the container group into that subnet.
Without a VNet and NAT gateway, a public group's outbound address is not guaranteed and can change when it restarts, so you should not allow-list it.
A NAT gateway also offers a much larger pool of outbound ports than default outbound access, which helps chatty workloads that open many connections.
Take quiz
A NAT gateway on the delegated subnet
A DNS name label
The restart policy Always
An emptyDir volume
ACI blocks all outbound traffic by default
Outbound traffic uses a random port only
It is not guaranteed to stay the same
Allow lists are unsupported in Azure
33. How do you monitor ACI with Azure Monitor and Log Analytics?
Azure Monitor gives you platform metrics for free: CPU usage, memory usage and network bytes in and out. You can chart them and attach alert rules to them.
For logs, link the group to a Log Analytics workspace at creation with --log-analytics-workspace and its key. Container output and events then land in the ContainerInstanceLog_CL and ContainerEvent_CL tables.
ContainerInstanceLog_CL | where ContainerGroup_s == "aci-app" | where Message contains "ERROR" | order by TimeGenerated desc | take 50
Without a workspace, logs only live as long as the group. Set it up before you need it.
An alert on memory usage close to the group's request gives early warning before an out-of-memory kill restarts the container.
Take quiz
AzureActivity and AzureMetrics
KubePodInventory and ContainerLog
ContainerInstanceLog_CL and ContainerEvent_CL
AppServiceConsoleLogs
Per-request latency percentiles
CPU and memory usage
Number of HTTP 500 errors
Dependency call duration
34. How do you update a running container group in ACI?
You re-deploy with the same group name and an updated definition (az container create, a YAML file, or an ARM/Bicep template). ACI supports updating only a limited set of properties, such as the image or environment variables, and applying the change restarts the containers.
Anything structural, such as the OS type, CPU and memory, or moving to a different network, means deleting and recreating the group.
- There is no rolling update, so expect a short outage.
- For zero downtime, deploy a second group, test it, then switch DNS or the gateway backend.
- Keep the definition in Bicep or YAML so every change is repeatable.
Take quiz
ACI performs a rolling update with no downtime
The group is moved to a new region
Only the logs are reset
The containers restart with the new configuration
Changing an environment variable
Changing the CPU and memory size
Changing the image tag
Adding a tag to the group
35. How can you optimize ACI startup time?
Most of the startup time goes into pulling the image, so the biggest wins come from making that step smaller and closer.
- Shrink the image. Use slim or distroless bases and multi-stage builds, and avoid bundling build tools.
- Keep the registry close. Use ACR in the same region, or geo-replicate it, to cut pull time.
- Prefer Linux. Windows base images are very large and start slower.
- Trim the app start. Lazy-load heavy components and avoid long init work.
- Use standby pools when you need ready-to-go groups for bursts.
Measure with the events timeline from az container show; it separates pull time from container start time.
Take quiz
Pulling the container image
Provisioning a VM
Waiting for a Kubernetes control plane
DNS propagation
Raising the CPU request only
Adding more restart policies
A smaller image from a registry in the same region
Using a longer DNS label
36. How can you optimize ACI costs?
Because billing is per second on requested resources, cost control is mostly about requesting less and running for less time.
- Right-size CPU and memory using the usage metrics, not guesses.
- Delete or stop groups that are idle; use
NeverorOnFailurefor jobs so they stop on their own. - Use Spot for interruptible work to save up to 70%.
- Prefer Linux to avoid the Windows software charge.
- Move steady 24/7 workloads to a VM, Container Apps or AKS, where flat or reserved pricing is cheaper.
Also watch the side costs: public IPs, Log Analytics ingestion and Azure Files storage can add up for large fleets.
Take quiz
Always
Always with a liveness probe
Never or OnFailure
Persistent
ACI refunds unused CPU at month end
You are billed on requested vCPU and memory, not used amounts
Smaller images cost less per GB
Public IPs are free for small groups
37. How does ACI handle DNS name labels and IP address changes?
A public group can have a DNS name label, which becomes label.region.azurecontainer.io. The IP is not guaranteed to be stable: stopping and starting or recreating a group can give it a new address. Clients should use the DNS name, not the IP.
Labels are unique per region. To reduce the risk of someone claiming a name you released (a subdomain takeover), ACI offers a DNS name label reuse policy (dnsNameLabelReusePolicy in ARM/Bicep) with scopes such as tenant, subscription and resource group, or no reuse at all.
- VNet groups get private IPs that can also change after a restart.
- For a stable front door, use Application Gateway, Front Door or a NAT gateway for outbound.
Take quiz
The IP address recorded at first deployment
The container ID
The resource group name
The DNS name label's FQDN
Image pull failures
Subdomain takeover of a released name
Out-of-memory kills
Volume mount errors
38. How do you run scheduled or batch jobs on ACI?
ACI has no built-in scheduler. You set the restart policy to Never (or OnFailure) and trigger creation of the group from something that does schedule.
- Logic Apps with the ACI connector on a recurrence trigger
- Azure Functions with a timer trigger that calls the management API or SDK
- Data Factory or pipelines that start a group as a step
- Event Grid or queue messages for event-driven runs
az container create -g rg-jobs -n nightly-etl \ --image myregistry.azurecr.io/etl:2.1 \ --restart-policy Never \ --assign-identity <identity-resource-id>
Write results to Azure Files or Blob storage, not the container disk. The group stops billing when the process exits, but you should still delete finished groups to keep the resource group tidy.
Take quiz
Never
Always
OnFailure with infinite retries
Persistent
The container's writable layer
An emptyDir volume
Azure Files or Blob storage
The group's DNS label
39. How do you secure an ACI deployment?
Security comes from layering several controls rather than one switch:
- Network: deploy into a VNet with no public IP, and control traffic with NSGs. Use Application Gateway for any inbound internet traffic.
- Identity: use managed identities instead of keys, and give them least-privilege roles.
- Secrets: use secure environment variables or secret volumes, and prefer Key Vault fetched at runtime.
- Images: pull from a private registry with a managed identity and scan images for vulnerabilities.
- Data: use customer-managed keys for the data ACI stores, and the Confidential SKU for data-in-use protection.
- Access: restrict who can run
az container execor create groups with Azure RBAC.
Take quiz
The ACR admin user in YAML
A longer DNS name label
A managed identity with AcrPull
A bigger CPU request
Use the restart policy Never
Deploy into a VNet and use a private IP
Use an emptyDir volume
Pick the Spot priority
40. What are the quotas and limits of ACI?
A few limits come up in almost every design discussion. Many can be raised with a support request.
| Limit | Value |
| Containers per container group | 60 |
| Volumes per container group | 20 |
| Group creates per hour | 300 |
| Group creates per 5 minutes | 100 |
| Image architecture | x64 (AMD64) only |
| Max CPU and memory per group | Varies by region and OS; commonly 4 vCPU and 16 GB |
You also have regional vCPU quotas per subscription. Always check the region availability page before choosing sizes, since limits are per region and deployments are subject to available capacity.
Quota increases go through a support request in the Azure portal. Even inside your quota, capacity in a region is never guaranteed at the moment you deploy.
Take quiz
10
20
250
60
ARM64
x64 (AMD64)
RISC-V
Any architecture through emulation
41. What are standby pools in ACI?
A standby pool keeps a set of pre-provisioned container groups ready so a new container can be handed out almost immediately, instead of waiting through scheduling and image pull each time. It is aimed at bursty workloads that need very fast start.
- Create a container group profile that describes how pooled groups are configured.
- Create a standby pool that references the profile and a target pool size.
- Request a container from the pool by referencing the profile and pool when you create a group.
- The pool only hands out groups that are fully provisioned and ready.
- If the pool is empty, ACI falls back to creating a new group normally.
- The refill policy is Always, so the pool is topped up after groups are taken.
- Confidential SKU, managed identity and zones are supported.
Standby pools are for speed, not resilience, and they were in preview when this was written, so check current status.
Take quiz
Defines how the pooled groups are configured
Sets the billing tier
Generates the DNS label
Assigns the managed identity role
The request fails with an error
The request waits for a refill indefinitely
ACI creates a new group the normal way
The group is created on AKS instead
42. What are NGroups in ACI?
NGroups is an ACI feature for managing several related container groups as one unit. It brings some of the orchestration that a single group lacks.
- Maintain a desired number of container groups
- Perform rolling upgrades across them
- Spread groups across availability zones
- Place a load balancer in front for ingress
- Deploy confidential containers
It sits between plain ACI and a full cluster: you get replica count, rolling updates and load balancing without running Kubernetes. Like standby pools, it uses container group profiles to describe the group template. The feature was in preview in the docs I checked, so confirm its current status before you commit to it.
Standby pools speed up how fast a group can be created, while NGroups controls how many groups exist and how they are updated. They solve different problems, so decide which one your workload actually needs.
Take quiz
The nodes of an AKS cluster
Azure Files shares
Several related container groups as one unit
Registry replication
Windows Server containers
Rolling upgrades across multiple groups
ARM64 image support
GPU-only scheduling
43. How does ACI isolate container groups from one another?
ACI isolates each container group at the hypervisor level. A group runs in its own sandboxed environment, so it does not share a kernel with groups from other customers or other deployments. That is stronger than a typical container host where containers from different apps share the host kernel.
- Between groups: hypervisor-level isolation, plus separate network configuration.
- Inside a group: containers share the network namespace and volumes on purpose, so they are not isolated from each other on the network.
- Extra hardening: the Confidential SKU adds hardware memory encryption, and VNet deployment adds network-level control.
This is why ACI is considered a safe choice for running untrusted or multi-tenant jobs without managing your own node isolation.
Since the isolation boundary is the group, put workloads that must not share a network namespace into separate groups.
Take quiz
Only by Linux namespaces on a shared kernel
Only by NSG rules
They are not isolated
The hypervisor level
Separate image layers
Network, since they share one namespace
CPU requests
Process IDs of other groups
44. How do you scale a workload on ACI?
ACI has no built-in autoscaling. A group is a fixed size, and scaling out means creating more groups. You scale up by recreating a group with a bigger size.
| Approach | How it works |
| Scripted scale-out | A Function or Logic App creates or deletes groups based on a queue depth or schedule |
| NGroups | Maintain a desired count of groups with rolling upgrades and a load balancer |
| AKS virtual nodes | Burst extra pods onto ACI when the cluster is full |
| Standby pools | Pre-warm groups so scale-out is near instant |
| Switch platform | Use Container Apps for rule-based autoscaling and scale to zero |
For queue-driven batch work, a common pattern is one short-lived group per message or batch, which gives you parallelism without managing capacity.
Take quiz
Create more container groups
Increase the replica count on the group
Turn on autoscale in the portal
Add nodes to a node pool
ACI standalone
A single Web App slot
Azure Container Apps
Azure Files
45. How do you put a gateway or load balancer in front of ACI?
ACI has no built-in ingress, so you add one. The right choice depends on whether the group is public or in a VNet.
- Application Gateway: deploy the group into a VNet and add its private IP as a backend. It gives you TLS termination and a WAF.
- Azure Front Door: use the group's public FQDN as an origin for global routing and caching.
- Traffic Manager: use DNS-based routing across groups in different regions.
- NGroups with a load balancer: spread traffic over several groups.
Watch out for IP changes. A group's private IP can change when it is recreated, so automate updating the gateway backend, or put the stable name in front of the group, whenever you redeploy.
As a rule of thumb, pick Application Gateway when you need a WAF and path-based routing inside one region, and Front Door when you need global reach and edge caching.
Take quiz
Azure Files
Azure Container Registry
Application Gateway
Azure Batch
ACI changes its port numbers hourly
A recreated group's private IP can change
Gateways cannot cache DNS
The restart policy forces a new subnet
46. How do you use Key Vault secrets with ACI?
ACI has no native Key Vault reference syntax, so the group's own code usually fetches secrets using its managed identity. Give the identity a role like Key Vault Secrets User, then have the app read the secret at startup with the Azure SDK.
sequenceDiagram
participant App as Container app
participant IMDS as Token endpoint
participant AAD as Microsoft Entra ID
participant KV as Key Vault
App->>IMDS: Request token for vault.azure.net
IMDS->>AAD: Authenticate managed identity
AAD-->>App: Access token
App->>KV: Get secret with token
KV-->>App: Secret value
The alternative is to resolve the secret in your pipeline and inject it as a secure environment variable or secret volume. That is simpler but puts the value in the deployment, so the runtime fetch is the stronger option.
Cache the secret in memory and refresh it on a schedule instead of calling Key Vault on every request. Also scope the role so the identity can read only the secrets it needs, not the whole vault.
Take quiz
A public DNS name label
An emptyDir volume
A larger memory request
A managed identity with a Key Vault role assignment
Plain environment variables
Fetching them from Key Vault at runtime
Hard-coding them in the image
Passing them in the DNS label
47. Explain the lifecycle of a container group in ACI?
A group moves through a small set of states, and the restart policy decides what happens when its containers exit.
flowchart TD
A[Create] --> B["Pending: scheduling and image pull"]
B --> C[Running]
C -->|Policy Always| C
C -->|Exit 0 with Never or OnFailure| D[Succeeded]
C -->|Non-zero exit with Never| E[Failed]
C -->|az container stop| F[Stopped]
F -->|az container start| B
D --> G[Delete]
E --> G
F --> G
- Pending: ACI schedules the group, sets up networking and pulls images. Billing begins with the pull.
- Running: containers are up; each has its own state of Waiting, Running or Terminated.
- Succeeded or Failed: reached when a run-to-completion group finishes.
- Stopped: compute released, no billing, definition kept.
- Deleted: the resource is removed.
Container-level states are tracked separately from the group state. Each container reports Waiting while its image is pulled or a restart is pending, Running while the process is alive, and Terminated with an exit code once it stops. With the Always policy a terminated container goes straight back to Waiting, which is why a crashing app shows a rising restart count instead of a Failed group.
Take quiz
Pending
Succeeded
Stopped
Terminated
az container delete
az container logs
az container start
az container exec
48. Explain the execution flow when a container group is deployed to ACI?
Deploying a group is an Azure Resource Manager operation followed by scheduling, networking, image pulls and container start.
flowchart TD
A["az container create or Bicep"] --> B["ARM validates request and quota"]
B --> C["ACI scheduler picks a host with capacity"]
C --> D["Network set up: public IP or VNet private IP"]
D --> E["Volumes mounted: Azure Files, secret, emptyDir"]
E --> F["Images pulled from the registry"]
F --> G["Init containers run in order"]
G --> H["Application containers start"]
H --> I["Probes run and the group reports Running"]
- ARM checks the request, permissions and quota.
- The scheduler places the group on a host in the region.
- Network and volumes are attached, then images are pulled with the supplied credentials.
- Init containers run to completion, then the app containers start.
Failures at each step have distinct symptoms: quota or capacity errors fail early, pull errors leave containers in Waiting, and crashes show up as restarts after start.
Because billing starts with the image pull, a slow pull costs money as well as time. If the group sits in Pending for a long time, look at the events first, since they show whether the delay is scheduling, the registry, or an init container that never finishes.
Take quiz
Application containers start immediately
The group is billed for a full hour
Networking and volumes are set up, then images are pulled
Logs are written to Blob storage
The restart policy is changed
Init containers run to completion
A load balancer is created
The group is replicated to a second region
49. How do you troubleshoot ACI deployments failing with quota or capacity errors?
There are two different problems that look similar. A quota error means your subscription is out of allowance. A capacity error, often a ServiceUnavailable message saying the resources are not available in the location, means the region cannot fit your request right now.
- Read the full error to see which of the two it is, and which resource (CPU, memory, GPU) is named.
- Check regional vCPU usage in the portal under Usage + quotas and request an increase if you are at the limit.
- Reduce the request: a smaller CPU and memory combination is easier to place.
- Retry in another region, or in another availability zone setting if you use zones.
- Check the hard limits: 60 containers and 20 volumes per group, and creation rate limits of 300 per hour and 100 per 5 minutes.
If you create many groups, add retry with backoff in your automation, and consider NGroups or standby pools so capacity is requested in a more controlled way.
Take quiz
Your registry password expired
The DNS label is already in use
Your image is too old
The region cannot currently fit the requested size
Increase the restart count
Try a smaller CPU and memory combination or another region
Rename the container
Switch the OS from Linux to Windows
50. How do you automate ACI deployments with Bicep?
Declare the group as a Microsoft.ContainerInstance/containerGroups resource and deploy it with az deployment group create. Bicep keeps the definition in source control, so every change is reviewed and repeatable, which matters because ACI cannot be edited freely in place.
param location string = resourceGroup().location resource aci 'Microsoft.ContainerInstance/containerGroups@2023-05-01' = { name: 'aci-bicep-demo' location: location properties: { osType: 'Linux' restartPolicy: 'Always' containers: [ { name: 'web' properties: { image: 'mcr.microsoft.com/azuredocs/aci-helloworld' ports: [ { port: 80 } ] resources: { requests: { cpu: 1, memoryInGB: 2 } } } } ] ipAddress: { type: 'Public' ports: [ { protocol: 'TCP', port: 80 } ] dnsNameLabel: 'aci-bicep-demo-12345' } } }
az deployment group create -g rg-aci-demo --template-file aci.bicep
Use parameters for image tag and secrets, and run the deployment from a pipeline with a managed identity or service principal.