Skip to content

Elastic Container Registry (ECR)

A private Docker image registry. ECS Fargate and Lambda pull images from ECR when deploying your application. All ECR repositories are hosted in the shared BYM AWS account.

Byks guides

GitHub actions

Terraform configuration

terraform-byks-module doesn't create ECR repositories. Provision each repository directly with the terraform-aws-ecr module in BYM-IKT/SharedKontoInfrastruktur, then point ecs_services or lambda_functions at the resulting repository through their ecr_uri option. See Fargate Terraform configuration and Lambda Function Terraform configuration.

For the full steps to set up a new repository, see Create an ECR repository. Each instance of the module creates one repository.

SharedKontoInfrastruktur/Shared/<application-name>/eu-west-1/ecr/main.tf
module "example" {
  source = "git@github.com:BYM-IKT/terraform-aws-ecr.git?ref=v3"
  application_name = "example"
  service           = "api"
  # options go here
}

Options

Option Type Default Description
application_name string required Name of the application using the repository. Prefixes the repository name unless override_name is set.
service string required Name of the service within the application. Appended to the repository name unless override_name is set.
override_name string null Override the generated repository name.
ecr_scan_on_push bool true Scan pushed images for vulnerabilities.
max_images_retained number 10 Maximum images kept by the catch-all lifecycle rule. Images tagged release-, prod, test, dev, or latest follow their own fixed retention counts, and untagged images beyond the most recent one expire regardless of this setting.
account_access list(string) [] AWS account IDs granted pull and push access to the repository, besides the account the repository is created in.
service_access list(string) ["codebuild.amazonaws.com", "lambda.amazonaws.com"] AWS service principals granted pull and push access to the repository.

Resources