Review ECR repository encryption key management

Configure ECR encryption for the required level of key control.

Description

ECR encrypts images even with its default AES256 setting. A customer managed KMS key gives you control over key policies and lifecycle. Selecting KMS without specifying a key uses an AWS managed key.

Potential impact

Default encryption may not meet organizational requirements that mandate customer control of encryption keys.

Remediation

If a customer managed key is required, set encryption_type = "KMS" and provide its ARN. Encryption settings cannot be changed after repository creation, so plan to move existing images to a new repository.

Examples

The examples compare default AES256 with a customer managed KMS key. Replace the example ARN with an actual key in the repository’s Region.

Before

hcl
resource "aws_ecr_repository" "example" {
  name                 = "bar"
  image_tag_mutability = "IMMUTABLE"

  encryption_configuration {
    encryption_type = "AES256"
  }
}

After

hcl
resource "aws_ecr_repository" "example" {
  name                 = "bar"
  image_tag_mutability = "IMMUTABLE"

  encryption_configuration {
    encryption_type = "KMS"
    kms_key         = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
  }
}

References