You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2实例无法认证AWS ECR仓库,配置IAM角色仍报错

ECR GetAuthorizationToken权限错误排查与解决

错误信息

An error occurred (AccessDeniedException) when calling the GetAuthorizationToken operation: User: arn:aws:sts::1224**:assumed-role/deshtestrole11/i-0462b0f*4 is not authorized to perform: ecr:GetAuthorizationToken on resource: * because no identity-based policy allows the ecr:GetAuthorizationToken action

问题根源

你的IAM策略将ecr:GetAuthorizationToken与其他ECR仓库级操作绑定在同一个Statement中,并指定了具体ECR仓库ARN作为Resource。但ecr:GetAuthorizationToken属于账户级操作,不支持绑定单个仓库资源,必须将Resource设置为*才能生效。

修正后的IAM策略

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "ecr:GetAuthorizationToken",
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ecr:GetDownloadUrlForLayer",
                "ecr:BatchCheckLayerAvailability",
                "ecr:BatchGetImage",
                "ecr:CompleteLayerUpload",
                "ecr:InitiateLayerUpload",
                "ecr:PutImage",
                "ecr:UploadLayerPart",
                "iam:PassRole"
            ],
            "Resource": "arn:aws:ecr:us-east-1:12243*****:repository/d***testecr"
        }
    ]
}

说明

  • 拆分两个Statement:第一个单独配置账户级的GetAuthorizationToken操作,资源设为*;第二个保留原有的仓库级操作及对应仓库ARN。
  • 调整后,EC2实例可正常获取授权令牌,同时拥有指定仓库的操作权限。

内容的提问来源于stack exchange,提问作者Desh Deepak Dhobi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 05:03:14