2 Antworten
- Neueste
- Die meisten Stimmen
- Die meisten Kommentare
6
Yes but you need to watch out for:
- Repository policies must be explicit: You’ll need to enumerate account IDs in your ECR repository policy to grant access.
- Lambda service principal quirks: Lambda accesses ECR as a service principal, so aws:PrincipalOrgID conditions won’t work — you’ll need to use aws:sourceArn and service-specific conditions.
- GovCloud limitations: Public registries and pull-through cache rules are not supported in GovCloud.
1
- ECR repositories in GovCloud support resource-based policies, so you can share images across GovCloud accounts.
- However, Lambda in GovCloud does NOT support pulling images cross-account, even if ECR allows it.
- For cross-account usage, you’d either: replicate images to the other account’s ECR repo, or use ECS or other services that support pulling images cross-account (and have correct IAM permissions).
beantwortet vor 4 Monaten
Relevanter Inhalt
- AWS OFFICIALAktualisiert vor 7 Monaten
- AWS OFFICIALAktualisiert vor 3 Jahren
- AWS OFFICIALAktualisiert vor 3 Monaten
