EC2实例无法认证AWS ECR仓库,配置IAM角色仍报错
错误信息
An error occurred (AccessDeniedException) when calling the GetAuthorizationToken operation: User: arn:aws:sts::1224**:assumed-role/deshtestrole11/i-0462b0f*4 is not authorized to perform: ecr:GetAuthorizationToken on resource: * because no identity-based policy allows the ecr:GetAuthorizationToken action
问题根源
你的IAM策略将ecr:GetAuthorizationToken与其他ECR仓库级操作绑定在同一个Statement中,并指定了具体ECR仓库ARN作为Resource。但ecr:GetAuthorizationToken属于账户级操作,不支持绑定单个仓库资源,必须将Resource设置为*才能生效。
修正后的IAM策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ecr:GetAuthorizationToken", "Resource": "*" }, { "Effect": "Allow", "Action": [ "ecr:GetDownloadUrlForLayer", "ecr:BatchCheckLayerAvailability", "ecr:BatchGetImage", "ecr:CompleteLayerUpload", "ecr:InitiateLayerUpload", "ecr:PutImage", "ecr:UploadLayerPart", "iam:PassRole" ], "Resource": "arn:aws:ecr:us-east-1:12243*****:repository/d***testecr" } ] }
说明
- 拆分两个Statement:第一个单独配置账户级的
GetAuthorizationToken操作,资源设为*;第二个保留原有的仓库级操作及对应仓库ARN。 - 调整后,EC2实例可正常获取授权令牌,同时拥有指定仓库的操作权限。
内容的提问来源于stack exchange,提问作者Desh Deepak Dhobi
相关产品推荐
相关产品推荐

