AWS ECR
Amazon Elastic Container Registry (ECR) is a fully managed registry for container images and other OCI artifacts such as Helm charts. It integrates with ECS, Fargate, EKS and Lambda, and uses IAM for authentication.
Key concepts #
- Repository: holds the images of an application, identified by tags and digests. A private registry belongs to your account and Region; ECR Public shares images with everyone.
- Authentication:
aws ecr get-login-password | docker login ...gets a temporary token. Docker clients, CI/CD pipelines and AWS services authenticate with IAM roles, not with long-lived passwords. - Image scanning: basic scanning on push, or enhanced scanning with Amazon Inspector for OS and programming language vulnerabilities.
- Lifecycle policies delete old or untagged images automatically to control the cost.
- Tag immutability prevents overwriting a tag such as
1.4.2. - Replication copies images to other Regions or accounts, and pull through cache caches images from public registries.
- Images are encrypted at rest, with KMS if required.
Pricing #
Per GB of images stored per month, plus data transfer out of the Region. See the ECR pricing.
With Terraform #
The resources are aws_ecr_repository, aws_ecr_lifecycle_policy, aws_ecr_repository_policy and aws_ecr_replication_configuration.
See tutorials: