Module 2 - Introduction To Amazon ECR
Module 2 - Introduction To Amazon ECR
Container Registry
Containers Immersion Day: Module 2
Amazon Elastic
Management Amazon Elastic
Container Service
Deployment, Scheduling, Container Service
for Kubernetes
Scaling & Management of
containerized applications
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
Amazon
ECR
Amazon ECR Repositories
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
Amazon
ECR
team-a/web-app team-b/web-app
Container Images
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
Amazon
ECR
team-a/web-app team-b/web-app
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
My app
Amazon image
:1
ECR
team-a/web-app
My app
image
:<no tag>
My app
image
My app
image :3
Container Images: Lifecycle policies
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
{
"rules": [
My app
{
"rulePriority": 1,
image
:1
"description": "Expire images older thanAmazon
14 days",
"selection": { ECR
team-a/web-app
"tagStatus": "untagged",
"countType": "sinceImagePushed",
"countUnit": "days",
"countNumber": 14
My app
image
:<no tag>
},
My app "action": {
image "type": "expire"
My app
}
}
image :3
]
}
Container Images: Image scanning
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
Amazon
ECR
team-a/web-app
My app
image
Amazon
EventBridge
Security in Amazon Elastic Container Registry
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
Amazon "ecr:GetAuthorizationToken",
"ecr:BatchCheckLayerAvailability",
ECR
team-a/web-app "ecr:GetDownloadUrlForLayer",
"ecr:GetRepositoryPolicy",
"ecr:DescribeRepositories",
"ecr:ListImages",
"ecr:DescribeImages",
"ecr:BatchGetImage",
"ecr:GetLifecyclePolicy",
"ecr:GetLifecyclePolicyPreview",
"ecr:ListTagsForResource",
"ecr:DescribeImageScanFindings"
],
"Resource": "*"
Team B }
]
}
Security in Amazon Elastic Container Registry
https://205094881157.dkr.ecr.us-west-2.amazonaws.com
{
"Version": "2008-10-17",
"Statement": [
{
"Sid": "AllowPushPull",
"Effect": "Allow",
"Principal": { Amazon
"AWS": [
ECR
"arn:aws:iam::account-id:user/push-pull-user-1",
"arn:aws:iam::account-id:user/push-pull-user-2" team-b/web-app
]
Another AWS Account
},
"Action": [
"ecr:GetDownloadUrlForLayer",
"ecr:BatchGetImage",
"ecr:BatchCheckLayerAvailability",
"ecr:PutImage",
"ecr:InitiateLayerUpload",
"ecr:UploadLayerPart",
]
"ecr:CompleteLayerUpload" Team C
}
]
}
Questions?
Introduction to Amazon ECR