Description
ECR encrypts images even with its default AES256 setting. A customer managed KMS key gives you control over key policies and lifecycle. Selecting KMS without specifying a key uses an AWS managed key.
Potential impact
Default encryption may not meet organizational requirements that mandate customer control of encryption keys.
Remediation
If a customer managed key is required, set encryption_type = "KMS" and provide its ARN. Encryption settings cannot be changed after repository creation, so plan to move existing images to a new repository.
Examples
The examples compare default AES256 with a customer managed KMS key. Replace the example ARN with an actual key in the repository’s Region.
Before
hcl
resource "aws_ecr_repository" "example" {
name = "bar"
image_tag_mutability = "IMMUTABLE"
encryption_configuration {
encryption_type = "AES256"
}
}
After
hcl
resource "aws_ecr_repository" "example" {
name = "bar"
image_tag_mutability = "IMMUTABLE"
encryption_configuration {
encryption_type = "KMS"
kms_key = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
}
}