{"meta":{"title":"Deploying Docker to Azure App Service","intro":"Learn how to deploy a Docker container to Azure App Service as part of your continuous deployment (CD) workflows.","product":"GitHub Actions","breadcrumbs":[{"href":"/en/actions","title":"GitHub Actions"},{"href":"/en/actions/how-tos","title":"How-tos"},{"href":"/en/actions/how-tos/deploy","title":"Deploy"},{"href":"/en/actions/how-tos/deploy/deploy-to-third-party-platforms","title":"Deploy to third-party platforms"},{"href":"/en/actions/how-tos/deploy/deploy-to-third-party-platforms/docker-to-azure-app-service","title":"Docker to Azure App Service"}],"documentType":"article"},"body":"# Deploying Docker to Azure App Service\n\nLearn how to deploy a Docker container to Azure App Service as part of your continuous deployment (CD) workflows.\n\n## Prerequisites\n\nBefore creating your GitHub Actions workflow, you will first need to complete the following setup steps:\n\n1. Create an Azure App Service plan.\n\n   For example, you can use the Azure CLI to create a new App Service plan:\n\n   ```bash copy\n   az appservice plan create \\\n      --resource-group MY_RESOURCE_GROUP \\\n      --name MY_APP_SERVICE_PLAN \\\n      --is-linux\n   ```\n\n   In the command above, replace `MY_RESOURCE_GROUP` with your pre-existing Azure Resource Group, and `MY_APP_SERVICE_PLAN` with a new name for the App Service plan.\n\n   See the Azure documentation for more information on using the [Azure CLI](https://docs.microsoft.com/cli/azure/):\n\n   * For authentication, see [Sign in with Azure CLI](https://docs.microsoft.com/cli/azure/authenticate-azure-cli).\n   * If you need to create a new resource group, see [az group](https://docs.microsoft.com/cli/azure/group?view=azure-cli-latest#az_group_create).\n\n2. Create a web app.\n\n   For example, you can use the Azure CLI to create an Azure App Service web app:\n\n   ```shell copy\n   az webapp create \\\n       --name MY_WEBAPP_NAME \\\n       --plan MY_APP_SERVICE_PLAN \\\n       --resource-group MY_RESOURCE_GROUP \\\n       --deployment-container-image-name nginx:latest\n   ```\n\n   In the command above, replace the parameters with your own values, where `MY_WEBAPP_NAME` is a new name for the web app.\n\n3. Configure an Azure publish profile and create an `AZURE_WEBAPP_PUBLISH_PROFILE` secret.\n\n   Generate your Azure deployment credentials using a publish profile. For more information, see [Generate deployment credentials](https://docs.microsoft.com/azure/app-service/deploy-github-actions?tabs=applevel#generate-deployment-credentials) in the Azure documentation.\n\n   In your GitHub repository, create a secret named `AZURE_WEBAPP_PUBLISH_PROFILE` that contains the contents of the publish profile. For more information on creating secrets, see [Using secrets in GitHub Actions](/en/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets#creating-secrets-for-a-repository).\n\n4. Set registry credentials for your web app.\n\n   Create a personal access token (classic) with the `repo` and `read:packages` scopes. For more information, see [Managing your personal access tokens](/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens).\n\n   Set `DOCKER_REGISTRY_SERVER_URL` to `https://ghcr.io`, `DOCKER_REGISTRY_SERVER_USERNAME` to the GitHub username or organization that owns the repository, and `DOCKER_REGISTRY_SERVER_PASSWORD` to your personal access token from above. This will give your web app credentials so it can pull the container image after your workflow pushes a newly built image to the registry. You can do this with the following Azure CLI command:\n\n   ```shell\n    az webapp config appsettings set \\\n        --name MY_WEBAPP_NAME \\\n        --resource-group MY_RESOURCE_GROUP \\\n        --settings DOCKER_REGISTRY_SERVER_URL=https://ghcr.io DOCKER_REGISTRY_SERVER_USERNAME=MY_REPOSITORY_OWNER DOCKER_REGISTRY_SERVER_PASSWORD=MY_PERSONAL_ACCESS_TOKEN\n   ```\n\n5. Optionally, configure a deployment environment. Environments are used to describe a general deployment target like `production`, `staging`, or `development`. When a GitHub Actions workflow deploys to an environment, the environment is displayed on the main page of the repository. You can use environments to require approval for a job to proceed, restrict which branches can trigger a workflow, gate deployments with custom deployment protection rules, or limit access to secrets. For more information about creating environments, see [Managing environments for deployment](/en/actions/how-tos/deploy/configure-and-manage-deployments/manage-environments).\n\n## Creating the workflow\n\nOnce you've completed the prerequisites, you can proceed with creating the workflow.\n\nThe following example workflow demonstrates how to build and deploy a Docker container to Azure App Service when there is a push to the `main` branch.\n\nEnsure that you set `AZURE_WEBAPP_NAME` in the workflow `env` key to the name of the web app you created.\n\nIf you configured a deployment environment, change the value of `environment` to be the name of your environment. If you did not configure an environment or if your workflow is in a private repository and you do not use GitHub Enterprise Cloud, delete the `environment` key.\n\n```yaml copy\n# This workflow uses actions that are not certified by GitHub.\n# They are provided by a third-party and are governed by\n# separate terms of service, privacy policy, and support\n# documentation.\n\n# GitHub recommends pinning actions to a commit SHA.\n# To get a newer version, you will need to update the SHA.\n# You can also reference a tag or branch, but the action may change without warning.\n\nname: Build and deploy a container to an Azure Web App\n\nenv:\n  AZURE_WEBAPP_NAME: MY_WEBAPP_NAME   # set this to your application's name\n\non:\n  push:\n    branches:\n      - main\n\npermissions:\n  contents: 'read'\n  packages: 'write'\n\njobs:\n  build:\n    runs-on: ubuntu-latest\n\n    steps:\n      - uses: actions/checkout@v6\n\n      - name: Set up Docker Buildx\n        uses: docker/setup-buildx-action@7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b\n\n      - name: Log in to GitHub container registry\n        uses: docker/login-action@8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d\n        with:\n          registry: ghcr.io\n          username: ${{ github.actor }}\n          password: ${{ secrets.GITHUB_TOKEN }}\n\n      - name: Lowercase the repo name\n        run: echo \"REPO=${GITHUB_REPOSITORY,,}\" >>${GITHUB_ENV}\n\n      - name: Build and push container image to registry\n        uses: docker/build-push-action@9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f\n        with:\n          push: true\n          tags: ghcr.io/${{ env.REPO }}:${{ github.sha }}\n          file: ./Dockerfile\n\n  deploy:\n    runs-on: ubuntu-latest\n\n    needs: build\n\n    environment:\n      name: 'production'\n      url: ${{ steps.deploy-to-webapp.outputs.webapp-url }}\n\n    steps:\n      - name: Lowercase the repo name\n        run: echo \"REPO=${GITHUB_REPOSITORY,,}\" >>${GITHUB_ENV}\n\n      - name: Deploy to Azure Web App\n        id: deploy-to-webapp\n        uses: azure/webapps-deploy@85270a1854658d167ab239bce43949edb336fa7c\n        with:\n          app-name: ${{ env.AZURE_WEBAPP_NAME }}\n          publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }}\n          images: 'ghcr.io/${{ env.REPO }}:${{ github.sha }}'\n```\n\n## Further reading\n\n* For the original workflow template, see [`azure-container-webapp.yml`](https://github.com/actions/starter-workflows/blob/main/deployments/azure-container-webapp.yml) in the GitHub Actions `starter-workflows` repository.\n* The action used to deploy the web app is the official Azure [`Azure/webapps-deploy`](https://github.com/Azure/webapps-deploy) action.\n* For more examples of GitHub Action workflows that deploy to Azure, see the [actions-workflow-samples](https://github.com/Azure/actions-workflow-samples) repository."}