ECR repository policy uses a wildcard principal

A wildcard principal in an ECR repository policy can grant image permissions more broadly than intended. Grant access only to the required identities and allow only necessary operations.

Description

Setting Principal to * in an allow statement for a private ECR repository can broaden who may perform image operations. Effective permissions depend on Action, Condition, explicit denies and applicable IAM policies. Even when sharing with another account is required, limit access to the necessary identities and operations.

AWS::ECR::Repository is a private repository. A wildcard principal does not turn it into a public ECR repository or enable anonymous downloads. Authenticating to a private registry requires permission for ecr:GetAuthorizationToken through an IAM policy.

Potential impact

  • Unintended readers may obtain application code and configuration information contained in images.
  • If upload or deletion is also allowed, images used in deployments could be changed or become unavailable. The impact depends on the operations actually permitted.

Remediation

  • Specify only the required IAM roles, users or accounts as principals and limit Action to necessary repository operations. If using Condition with a wildcard principal, verify that it adequately restricts the intended access scope.
  • Review the applicable policies together, including registry authentication permissions and explicit denies. For cross-account access, also check the caller's IAM permissions.
  • Check the existing resource's logical ID and update impact before changing its policy. Test that required image operations succeed and requests from unintended identities are denied.

Examples

These examples compare the principals allowed by a repository policy. Their logical IDs differ, so retain the target resource's ID when updating an existing stack. Replace the account and user ARNs with the intended identities. Although Sid is AllowPushPull, the three listed operations are used to read images. Configure authentication permissions and other policies separately.

Before

yaml
Resources:
  MyRepository3:
    Type: AWS::ECR::Repository
    Properties:
      RepositoryName: "test-repository"
      RepositoryPolicyText:
        Version: "2012-10-17"
        Statement:
          - Sid: AllowPushPull
            Effect: Allow
            Principal: "*"
            Action:
              - "ecr:GetDownloadUrlForLayer"
              - "ecr:BatchGetImage"
              - "ecr:BatchCheckLayerAvailability"

After

yaml
Resources:
  MyRepository1:
    Type: AWS::ECR::Repository
    Properties:
      RepositoryName: "test-repository"
      RepositoryPolicyText:
        Version: "2012-10-17"
        Statement:
          - Sid: AllowPushPull
            Effect: Allow
            Principal:
              AWS:
                - "arn:aws:iam::123456789012:user/Bob"
                - "arn:aws:iam::123456789012:user/Alice"
            Action:
              - "ecr:GetDownloadUrlForLayer"
              - "ecr:BatchGetImage"
              - "ecr:BatchCheckLayerAvailability"

Explanation:

  • Before: The statement uses * as its principal, broadening permission for image-reading operations. Private-registry authentication and restrictions in other policies still apply.
  • After: The statement limits its principals to two IAM users. Verify that the ARNs identify the intended users and that other policies do not add unnecessary permissions.

References