Elastic Container Registry (ECR)
A private Docker image registry. ECS Fargate and Lambda pull images from ECR when deploying your application. All ECR repositories are hosted in the shared BYM AWS account.
Byks guides
-
Create an ECR repository
Set up a new ECR repository in the shared AWS account.
-
Push Docker Image to ECR
Build a Docker image in a GitHub Actions workflow and push it to ECR.
GitHub actions
Terraform configuration
terraform-byks-module doesn't create ECR repositories. Provision each repository directly with the terraform-aws-ecr module in BYM-IKT/SharedKontoInfrastruktur, then point ecs_services or lambda_functions at the resulting repository through their ecr_uri option. See Fargate Terraform configuration and Lambda Function Terraform configuration.
For the full steps to set up a new repository, see Create an ECR repository. Each instance of the module creates one repository.
module "example" {
source = "git@github.com:BYM-IKT/terraform-aws-ecr.git?ref=v3"
application_name = "example"
service = "api"
# options go here
}
Options
| Option | Type | Default | Description |
|---|---|---|---|
application_name |
string |
required | Name of the application using the repository. Prefixes the repository name unless override_name is set. |
service |
string |
required | Name of the service within the application. Appended to the repository name unless override_name is set. |
override_name |
string |
null |
Override the generated repository name. |
ecr_scan_on_push |
bool |
true |
Scan pushed images for vulnerabilities. |
max_images_retained |
number |
10 |
Maximum images kept by the catch-all lifecycle rule. Images tagged release-, prod, test, dev, or latest follow their own fixed retention counts, and untagged images beyond the most recent one expire regardless of this setting. |
account_access |
list(string) |
[] |
AWS account IDs granted pull and push access to the repository, besides the account the repository is created in. |
service_access |
list(string) |
["codebuild.amazonaws.com", "lambda.amazonaws.com"] |
AWS service principals granted pull and push access to the repository. |
Resources
-
AWS documentation
Official AWS documentation for ECR