You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jenkins-Docker-AWS CI/CD部署报错:无法拉取ECR容器镜像

Troubleshooting Your ECR Deployment Errors in Jenkins-Docker-AWS CI/CD

Let’s break down the two errors you’re facing and walk through actionable fixes:

1. CannotPullContainerError: API error (404): repository not found

Even though you confirm the ECR repository exists, here are the most likely culprits:

  • Mismatched region: Double-check that your EC2 instance (or Jenkins runner) is either in us-east-2 (same as your ECR repo) or that your deployment script specifies the correct region. ECR repos are region-specific, so a wrong region in your Docker pull command will trigger a 404.
  • Typos in repository URI: Head to the AWS ECR console, copy the exact repository URI, and compare it to what’s in your Jenkins job. Pay attention to account ID, region, and repository name—even a single character mistake (like a missing digit in the account ID) will cause this error.
  • Missing image tag: Ensure the v_50 tag you’re trying to pull actually exists in the ECR repo. You can verify this directly in the ECR console under your repository’s "Images" tab.
  • Permission masking as 404: Oddly enough, IAM permission issues can sometimes return a 404 instead of a 403. So we’ll tackle permissions as part of fixing the second error too.

2. Error response from daemon: Get .../manifests/v_50: no basic auth credentials

This is a clear authentication issue—Docker doesn’t have the necessary credentials to access your private ECR repository. Here’s how to fix it:

Step 1: Assign the right IAM permissions to your EC2 instance

If your Jenkins is running on an EC2 instance, attach an IAM role to the instance with these minimum permissions for pulling ECR images:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ecr:GetDownloadUrlForLayer",
        "ecr:BatchGetImage",
        "ecr:BatchCheckLayerAvailability"
      ],
      "Resource": "arn:aws:ecr:us-east-2:YOUR_ACCOUNT_ID:repository/YOUR_REPO_NAME"
    },
    {
      "Effect": "Allow",
      "Action": "ecr:GetAuthorizationToken",
      "Resource": "*"
    }
  ]
}

You can also use the managed policy AmazonEC2ContainerRegistryReadOnly if you don’t need granular control.

Step 2: Authenticate Docker to ECR

Run this command on your EC2 instance (or in your Jenkins pipeline script) to get a temporary auth token and log Docker into ECR:

aws ecr get-login-password --region us-east-2 | docker login --username AWS --password-stdin YOUR_ACCOUNT_ID.dkr.ecr.us-east-2.amazonaws.com

Make sure to replace YOUR_ACCOUNT_ID and us-east-2 with your actual values. If Jenkins runs as a dedicated user (like jenkins), ensure this user has access to the AWS CLI and the IAM role credentials (no need for static access keys if using an instance role).

Post-Fix Verification

After setting up permissions and authentication, test pulling the image manually from your EC2 instance to confirm:

docker pull YOUR_ACCOUNT_ID.dkr.ecr.us-east-2.amazonaws.com/YOUR_REPO_NAME:v_50

If this works, update your Jenkins deployment script to include the authentication step before pulling the image, and double-check all URIs and regions match exactly.

内容的提问来源于stack exchange,提问作者David M.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 11:08:09