ECR repository policy uses wildcard principals

Check whether wildcard principals grant unintended access to an ECR repository, and restrict permissions to the required roles and actions.

Description

Principal: "*" in an ECR repository policy does not restrict principals to particular accounts or roles. Combined with Effect: "Allow" and broad actions, it can grant unintended principals access to images or repository administration. Effective permissions also depend on policy conditions, related IAM policies, and explicit denies.

Private ECR repositories differ from Amazon ECR Public. Pulling or pushing images requires authentication and IAM permission for ecr:GetAuthorizationToken; a wildcard principal therefore does not mean anonymous image access.

Potential impact

  • External principals that do not need read access may retrieve internal images.
  • Unnecessary upload, image-deletion, or policy-management permissions can disrupt deployments or allow further unintended access. The impact depends on the actions actually permitted.

Remediation

  • Specify the accounts and roles that need access. Grant pull, push, deletion, and policy-management permissions only to the principals that need each capability. Review conditions used to restrict a policy.
  • Check the complete repository policy and related IAM policies together. An account's :root ARN delegates authority to that account; it does not restrict access to its root user.
  • After the change, confirm that deployment systems retain required access and unapproved principals are denied access.

Examples

The following examples replace broad permissions with image-read access for a specific role. Define trusted_role_arn with the ARN of an existing, approved role.

Before

hcl
resource "aws_ecr_repository" "public_example" {
  name = "public-example"
}

resource "aws_ecr_repository_policy" "public_policy" {
  repository = aws_ecr_repository.public_example.name

  policy = <<EOF
{
    "Version": "2008-10-17",
    "Statement": [
        {
            "Sid": "RepositoryAccess",
            "Effect": "Allow",
            "Principal": "*",
            "Action": [
                "ecr:GetDownloadUrlForLayer",
                "ecr:BatchGetImage",
                "ecr:BatchCheckLayerAvailability",
                "ecr:PutImage",
                "ecr:InitiateLayerUpload",
                "ecr:UploadLayerPart",
                "ecr:CompleteLayerUpload",
                "ecr:DescribeRepositories",
                "ecr:GetRepositoryPolicy",
                "ecr:ListImages",
                "ecr:DeleteRepository",
                "ecr:BatchDeleteImage",
                "ecr:SetRepositoryPolicy",
                "ecr:DeleteRepositoryPolicy"
            ]
        }
    ]
}
EOF
}

The policy grants all principals upload, deletion, and policy-management actions as well as image reads. Private-registry authentication requirements still apply.

After

hcl
resource "aws_ecr_repository" "private_example" {
  name = "private-example"
}

resource "aws_ecr_repository_policy" "private_policy" {
  repository = aws_ecr_repository.private_example.name

  policy = <<EOF
{
    "Version": "2008-10-17",
    "Statement": [
        {
            "Sid": "ImageRead",
            "Effect": "Allow",
            "Principal": {
                "AWS": "${var.trusted_role_arn}"
            },
            "Action": [
                "ecr:GetDownloadUrlForLayer",
                "ecr:BatchGetImage",
                "ecr:BatchCheckLayerAvailability"
            ]
        }
    ]
}
EOF
}

The approved role receives only the actions needed to pull images. Also check its authentication permissions and other applicable policies.

References