AWS ECR

· 1 min read · AWS

Amazon Elastic Container Registry (ECR) is a fully managed registry for container images and other OCI artifacts such as Helm charts. It integrates with ECS, Fargate, EKS and Lambda, and uses IAM for authentication.

Key concepts #

  • Repository: holds the images of an application, identified by tags and digests. A private registry belongs to your account and Region; ECR Public shares images with everyone.
  • Authentication: aws ecr get-login-password | docker login ... gets a temporary token. Docker clients, CI/CD pipelines and AWS services authenticate with IAM roles, not with long-lived passwords.
  • Image scanning: basic scanning on push, or enhanced scanning with Amazon Inspector for OS and programming language vulnerabilities.
  • Lifecycle policies delete old or untagged images automatically to control the cost.
  • Tag immutability prevents overwriting a tag such as 1.4.2.
  • Replication copies images to other Regions or accounts, and pull through cache caches images from public registries.
  • Images are encrypted at rest, with KMS if required.

Pricing #

Per GB of images stored per month, plus data transfer out of the Region. See the ECR pricing.

With Terraform #

The resources are aws_ecr_repository, aws_ecr_lifecycle_policy, aws_ecr_repository_policy and aws_ecr_replication_configuration.

See tutorials:

#AWS #Containers #Docker