Lesson 408 · AWS Learning Path

AWS 408: ECR lifecycle, vulnerability scanning, image promotion, and deployment admission

· Published · 4 min read

Labelled process diagram for AWS 408: Versioned intent to Automated validation to Controlled AWS change to Observed result and retained evidence, with decision, proof and rejection evidence.

Why this lesson matters

Amazon ECR stores images, but a secure release also needs immutable identity, trusted producers, vulnerability intelligence, controlled promotion, deployment admission, retention and evidence. A tag can move, a scan can age, and replication can copy an artifact without approving it.

Repository and image identity

Design repositories by ownership, trust boundary, environment and retention rather than creating one shared registry. Repository policies control cross-account pull/push; IAM controls callers; KMS controls encrypted data; network endpoint policies may narrow access further. Separate build push, security inspection, promotion and runtime pull roles.

OCI image content is identified by digest. Tags are human references and may be mutable unless repository policy prevents replacement. Use immutable tags where appropriate, but record and deploy the digest. Multi-architecture image indexes have their own digest and reference platform manifests; verify the digest consumed by each runtime architecture.

StageIdentity/controlRequired evidence
BuildSource, workflow and image digestReproducible manifest/provenance
CandidateRestricted repository and tag policyPush identity and checksum
InspectScan coverage and timestampFindings tied to exact digest
ApprovePolicy, exception and signatureDecision owner and expiry
PromoteCopy same digestSource/destination digest match
DeployAdmission plus runtime pull roleDeployed task/pod digest
RetireLifecycle/retention ruleNo active or rollback dependency

Scanning and finding decisions

Basic scanning and enhanced scanning have different engines, coverage and update behavior. Enhanced scanning integrates with Amazon Inspector and can provide continuous updates for supported operating-system and programming-language package vulnerabilities. Confirm current registry scan configuration, filters, scan frequency and Inspector coverage rather than assuming every image is continuously rescanned.

Severity is a starting point. A decision also needs package reachability/use, runtime exposure, exploit intelligence, image age, compensating controls, environment and business impact. Never suppress a vulnerability only because no patch exists. Record an exception owner, rationale, scope, expiry and replacement plan. Re-evaluate when vulnerability intelligence or the image changes.

Scan status such as complete does not mean safe, and zero findings can mean unsupported/failed coverage. Gate on successful coverage plus policy. Preserve the raw finding identity, package/version/fixed version, observed time, digest and policy result. Compare findings at build and before deployment because databases evolve.

Promotion, replication and admission

Build once and promote the same digest across accounts/Regions. A destination copy or ECR replication needs destination repository policy, KMS and monitoring. Replication is availability/distribution, not approval, and can lag or fail. Reconcile source/destination digest and required metadata/signatures before release.

The admission decision verifies repository/account allowlist, immutable digest, signature/provenance policy, scan coverage/freshness, vulnerability threshold, exception validity and environment approval. Then runtime definitions reference the approved digest. An admission controller or pipeline gate must fail closed when evidence is missing or its dependencies are unavailable, with a tightly governed emergency process.

For ECS inspect task definition image and resolved deployment/task evidence. For EKS use admission policy and inspect Pod image IDs because a manifest tag may resolve differently over time. Keep deploy authority separate from policy/signature administration so one compromised role cannot approve its own image.

Lifecycle and operations

Lifecycle policies select images by rule priority, tag status/prefix/pattern, count or age. Preview before applying. Rules can delete candidate or rollback images if naming assumptions are wrong; preserve every deployed digest, rollback set, investigation hold and associated signature/provenance/SBOM. Deleting a tag does not necessarily delete referenced content, and storage accounting requires observation.

Monitor unauthorized push/delete/policy change, tag overwrite attempts, scan coverage/errors, critical finding age, exception expiry, replication lag/failure, pull denials and runtime digest drift. Recovery must rebuild registry access and prove the restored image digest and evidence, not simply repush a familiar tag.

~~~bash aws ecr describe-registry aws ecr describe-repositories --repository-names app aws ecr describe-images --repository-name app --image-ids imageTag=candidate aws ecr describe-image-scan-findings --repository-name app --image-id imageDigest=sha256:DIGEST aws ecr get-lifecycle-policy-preview --repository-name app ~~~

Workshop and failure analysis

Given twelve manifests and finding sets, resolve tags to digests, identify unsupported/failed scans, apply a policy with expiring exceptions, prove cross-account promotion and choose admitted deployments. Preview a lifecycle policy against active, rollback, quarantined and expired images. Design ECS and EKS runtime verification.

Test 22 failures: shared push role, mutable release tag, tag deployed instead of digest, index/platform mismatch, scan never enabled, scan failed interpreted clean, stale findings, unsupported package ignored, severity alone decides, exception has no expiry, signing role compromised, replication assumed approval, replica lag, destination KMS denial, cross-account pull too broad, admission fails open, admission checks tag only, runtime digest differs, lifecycle priority misunderstood, rollback image deleted, evidence detached, and registry recovery repushes different bytes.

Cost and acceptance

Price storage, data transfer, replication, KMS, basic/enhanced scanning and Inspector coverage, logs and retained versions. This lesson creates nothing. Submit repository/role design, image ledger, scan decisions, promotion proof, admission policy, lifecycle preview, recovery test and all diagnoses. Pass requires digest-based identity, verified scan coverage, separated approval and fail-closed admission.

Official sources

Advertisement