Jenkins-Docker-AWS CI/CD部署报错:无法拉取ECR容器镜像
Let’s break down the two errors you’re facing and walk through actionable fixes:
1. CannotPullContainerError: API error (404): repository not found
Even though you confirm the ECR repository exists, here are the most likely culprits:
- Mismatched region: Double-check that your EC2 instance (or Jenkins runner) is either in
us-east-2(same as your ECR repo) or that your deployment script specifies the correct region. ECR repos are region-specific, so a wrong region in your Docker pull command will trigger a 404. - Typos in repository URI: Head to the AWS ECR console, copy the exact repository URI, and compare it to what’s in your Jenkins job. Pay attention to account ID, region, and repository name—even a single character mistake (like a missing digit in the account ID) will cause this error.
- Missing image tag: Ensure the
v_50tag you’re trying to pull actually exists in the ECR repo. You can verify this directly in the ECR console under your repository’s "Images" tab. - Permission masking as 404: Oddly enough, IAM permission issues can sometimes return a 404 instead of a 403. So we’ll tackle permissions as part of fixing the second error too.
2. Error response from daemon: Get .../manifests/v_50: no basic auth credentials
This is a clear authentication issue—Docker doesn’t have the necessary credentials to access your private ECR repository. Here’s how to fix it:
Step 1: Assign the right IAM permissions to your EC2 instance
If your Jenkins is running on an EC2 instance, attach an IAM role to the instance with these minimum permissions for pulling ECR images:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ecr:GetDownloadUrlForLayer", "ecr:BatchGetImage", "ecr:BatchCheckLayerAvailability" ], "Resource": "arn:aws:ecr:us-east-2:YOUR_ACCOUNT_ID:repository/YOUR_REPO_NAME" }, { "Effect": "Allow", "Action": "ecr:GetAuthorizationToken", "Resource": "*" } ] }
You can also use the managed policy AmazonEC2ContainerRegistryReadOnly if you don’t need granular control.
Step 2: Authenticate Docker to ECR
Run this command on your EC2 instance (or in your Jenkins pipeline script) to get a temporary auth token and log Docker into ECR:
aws ecr get-login-password --region us-east-2 | docker login --username AWS --password-stdin YOUR_ACCOUNT_ID.dkr.ecr.us-east-2.amazonaws.com
Make sure to replace YOUR_ACCOUNT_ID and us-east-2 with your actual values. If Jenkins runs as a dedicated user (like jenkins), ensure this user has access to the AWS CLI and the IAM role credentials (no need for static access keys if using an instance role).
Post-Fix Verification
After setting up permissions and authentication, test pulling the image manually from your EC2 instance to confirm:
docker pull YOUR_ACCOUNT_ID.dkr.ecr.us-east-2.amazonaws.com/YOUR_REPO_NAME:v_50
If this works, update your Jenkins deployment script to include the authentication step before pulling the image, and double-check all URIs and regions match exactly.
内容的提问来源于stack exchange,提问作者David M.

