Tạo IAM Roles để truy cập ECR

Cấu hình Policy

  1. Tại giao diện AWS Console, tìm kiếm và chọn IAM

3.3.1

  1. Trong menu lựa chọn bên phải:
  • Chọn Policies
  • Nhấp vào Create policy

3.3.1

  1. Trong Policy Editor, tìm kiếm và chọn Elastic Container Registry

3.3.1

  1. Một bảng chọn quy tắc xuất hiện. Trong phần List:
  • Chọn DescribeImage
  • Chọn ListImages
  1. Trong phần Read:
  • Chọn BatchGetImage
  • Chọn DescribeRegistry
  • Chọn DescribeRepositories
  • Chọn GetAccountSetting
  • Chọn GetAuthorizationToken

3.3.1

  1. Trong phần Resources:
  • Chọn Specific
  • Chọn Any in this account
  • Nhấp Next

3.3.1

  1. Trong phần Chi tiết Policy:
  • Policy name: ReadECRRepositoryContent
  • Description: Allow pull images, describe repositories
  • Nhấp Create policy

3.3.1

  1. Tương tự, chúng ta sẽ tạo thêm một policy để ghi vào ECR bằng cách nhấp Create Policy:

3.3.1

  1. Một bảng chọn quy tắc xuất hiện:
  • Trong phần Read:

    • Chọn BatchCheckLayerAvailability
    • Chọn GetAuthorizationToken
  • Trong phần Write:

    • Chọn CompleteLayerUpload
    • Chọn InitiateLayerUpload
    • Chọn PutImage
    • Chọn UploadLayerPart

3.3.1

  1. Trong phần Resources:
  • Chọn Specific
  • Chọn Any in this account
  • Nhấp Next

3.3.1

  1. Bảng chi tiết Policy xuất hiện:
  • Policy name: WriteECRRepositoryContent
  • Description: Allow push and delete images
  • Nhấp Next và chọn Create policy 3.3.1

Tạo Role cho ECR

  1. Trong giao diện quản lý EC2:
  • Chọn Roles
  • Nhấp vào Create role

3.3.1

  1. Trong phần Chi tiết Role:
  • Trusted entity type: AWS service
  • Use case: EC2
  • Nhấp Next 3.3.1
  1. Trong phần Permissions policies:
  • Chọn hai policy chúng ta vừa tạo: ReadECRRepositoryContentWriteECRRepositoryContent
  • Sau đó nhấp Next

3.3.1

  1. Trong phần Chi tiết Role:
  • Role name: CustomRWECRRole
  • Description: Custom Read and Write role ECS
  • Nhấp Create role

3.3.1