ECR repository policy uses a wildcard principal

Review wildcard principals in private ECR repository policies and the image operations they permit.

Description

An ECR repository policy specifies who can access the repository and which operations they can perform. Using Principal: "*" in an Allow statement broadens the set of principals, so verify that access is adequately restricted to the accounts and roles that need the images. In Ansible, the policy parameter of community.aws.ecs_ecr manages this policy.

The policy controls access to a private ECR repository. A wildcard does not convert it to an ECR Public repository or enable anonymous image downloads. Registry authentication requires ecr:GetAuthorizationToken permission through an IAM policy, and the operations available depend on the applicable policies and conditions.

Potential impact

  • Code or internal configuration may be exposed if unintended principals can authenticate, satisfy policy conditions, and perform image-read operations.
  • If permitted operations include image uploads or deletions, unauthorized changes or service disruption may be possible.

Remediation

  • Specify the required accounts, roles, or service principals, and review the permitted operations and conditions. A role that only pulls images should not also receive upload or deletion permissions.
  • Check registry authentication and repository permissions together. For cross-account access, also review permissions on the caller's side.
  • If conditions restrict access, confirm that they apply to the intended requests and principals. After changing the policy, test that required image pulls and deployments still work.

Examples

These examples illustrate the difference in principal scope. Replace the account and role ARN with actual values and configure the caller's permissions separately. The existing examples use the older policy language version 2008-10-17; use 2012-10-17 for new or updated policies.

Before

yaml
- name: set-policy as object
  community.aws.ecs_ecr:
    name: needs-policy-object
    policy:
      Version: "2008-10-17"
      Statement:
        - Sid: read-only
          Effect: Allow
          Principal: "*"
          Action:
            - ecr:GetDownloadUrlForLayer
            - ecr:BatchGetImage
            - ecr:BatchCheckLayerAvailability

After

yaml
- name: set restricted policy
  community.aws.ecs_ecr:
    name: backend-api
    policy:
      Version: "2008-10-17"
      Statement:
        - Sid: ci-read-only
          Effect: Allow
          Principal:
            AWS: "arn:aws:iam::123456789012:role/ci-ecr-reader"
          Action:
            - ecr:GetDownloadUrlForLayer
            - ecr:BatchGetImage
            - ecr:BatchCheckLayerAvailability

Explanation:

  • Before: Principal: "*" is combined with image-read operations. Actual downloads still require authentication and the relevant permissions.
  • After: The statement names a specific IAM role and allows only image-read operations. Review the IAM policies and conditions that apply alongside this policy to confirm the effective access scope.

References