An Azure container registry has public access disabled and exposes a private endpoint in a virtual network. An App Service app is already integrated with that virtual network and resolves the registry's private address. Which site setting routes container image pulls through the virtual network?