ECR

Elastic Container Registry stores the images that ECS, EKS, Lambda, and App Runner pull and run. That makes it a two-way target: images are a source of secrets (credentials and internal detail baked into layers), and a writable repository is a supply-chain foothold, because a poisoned tag runs on the next deploy under whatever role the workload holds.

What folds in here#

  • Public repository: pulling from public or loosely-scoped repositories to mine secrets.
  • Repository policy: cross-account pull and push through a permissive repository policy.
  • Image poisoning: pushing a backdoored tag that downstream compute will run.

Authenticating to ECR#

bash
aws ecr get-login-password | docker login --username AWS --password-stdin \
  <acct>.dkr.ecr.<region>.amazonaws.com
aws ecr describe-repositories ; aws ecr list-images --repository-name <r>

References#

Cookie Consent

We use cookies to enhance your experience. Learn more