Description
ECR encrypts images with S3-managed keys by default. A customer managed KMS key can meet separate key-policy and audit requirements; specifying KMS without a key uses an AWS managed key.
Potential impact
The default encryption configuration may not meet a requirement to use customer managed keys.
Remediation
At repository creation, set EncryptionType: KMS and a customer managed KmsKey in the same Region under EncryptionConfiguration. Encryption settings cannot be changed after creation, so existing repositories require migrating images to a new repository.
Examples
These examples compare alternative creation configurations, not an in-place update of an existing repository. Replace the key ARN with the actual key.
Before
{
"Resources": {
"MyRepository": {
"Type": "AWS::ECR::Repository",
"Properties": {
"RepositoryName": "test-repository"
}
}
}
}
After
{
"Resources": {
"MyRepository": {
"Type": "AWS::ECR::Repository",
"Properties": {
"RepositoryName": "test-repository",
"EncryptionConfiguration": {
"EncryptionType": "KMS",
"KmsKey": "arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012"
}
}
}
}
}