ECR repository without a customer managed KMS key

Choose ECR encryption settings that meet key-management requirements.

Description

ECR encrypts images with S3-managed keys by default. A customer managed KMS key can meet separate key-policy and audit requirements; specifying KMS without a key uses an AWS managed key.

Potential impact

The default encryption configuration may not meet a requirement to use customer managed keys.

Remediation

At repository creation, set EncryptionType: KMS and a customer managed KmsKey in the same Region under EncryptionConfiguration. Encryption settings cannot be changed after creation, so existing repositories require migrating images to a new repository.

Examples

These examples compare alternative creation configurations, not an in-place update of an existing repository. Replace the key ARN with the actual key.

Before

json
{
  "Resources": {
    "MyRepository": {
      "Type": "AWS::ECR::Repository",
      "Properties": {
        "RepositoryName": "test-repository"
      }
    }
  }
}

After

json
{
  "Resources": {
    "MyRepository": {
      "Type": "AWS::ECR::Repository",
      "Properties": {
        "RepositoryName": "test-repository",
        "EncryptionConfiguration": {
          "EncryptionType": "KMS",
          "KmsKey": "arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012"
        }
      }
    }
  }
}

References