AWS 408: ECR lifecycle, vulnerability scanning, image promotion, and deployment admission
Why this lesson matters
Amazon ECR stores images, but a secure release also needs immutable identity, trusted producers, vulnerability intelligence, controlled promotion, deployment admission, retention and evidence. A tag can move, a scan can age, and replication can copy an artifact without approving it.
Repository and image identity
Design repositories by ownership, trust boundary, environment and retention rather than creating one shared registry. Repository policies control cross-account pull/push; IAM controls callers; KMS controls encrypted data; network endpoint policies may narrow access further. Separate build push, security inspection, promotion and runtime pull roles.
OCI image content is identified by digest. Tags are human references and may be mutable unless repository policy prevents replacement. Use immutable tags where appropriate, but record and deploy the digest. Multi-architecture image indexes have their own digest and reference platform manifests; verify the digest consumed by each runtime architecture.
| Stage | Identity/control | Required evidence |
|---|---|---|
| Build | Source, workflow and image digest | Reproducible manifest/provenance |
| Candidate | Restricted repository and tag policy | Push identity and checksum |
| Inspect | Scan coverage and timestamp | Findings tied to exact digest |
| Approve | Policy, exception and signature | Decision owner and expiry |
| Promote | Copy same digest | Source/destination digest match |
| Deploy | Admission plus runtime pull role | Deployed task/pod digest |
| Retire | Lifecycle/retention rule | No active or rollback dependency |
Scanning and finding decisions
Basic scanning and enhanced scanning have different engines, coverage and update behavior. Enhanced scanning integrates with Amazon Inspector and can provide continuous updates for supported operating-system and programming-language package vulnerabilities. Confirm current registry scan configuration, filters, scan frequency and Inspector coverage rather than assuming every image is continuously rescanned.
Severity is a starting point. A decision also needs package reachability/use, runtime exposure, exploit intelligence, image age, compensating controls, environment and business impact. Never suppress a vulnerability only because no patch exists. Record an exception owner, rationale, scope, expiry and replacement plan. Re-evaluate when vulnerability intelligence or the image changes.
Scan status such as complete does not mean safe, and zero findings can mean unsupported/failed coverage. Gate on successful coverage plus policy. Preserve the raw finding identity, package/version/fixed version, observed time, digest and policy result. Compare findings at build and before deployment because databases evolve.
Promotion, replication and admission
Build once and promote the same digest across accounts/Regions. A destination copy or ECR replication needs destination repository policy, KMS and monitoring. Replication is availability/distribution, not approval, and can lag or fail. Reconcile source/destination digest and required metadata/signatures before release.
The admission decision verifies repository/account allowlist, immutable digest, signature/provenance policy, scan coverage/freshness, vulnerability threshold, exception validity and environment approval. Then runtime definitions reference the approved digest. An admission controller or pipeline gate must fail closed when evidence is missing or its dependencies are unavailable, with a tightly governed emergency process.
For ECS inspect task definition image and resolved deployment/task evidence. For EKS use admission policy and inspect Pod image IDs because a manifest tag may resolve differently over time. Keep deploy authority separate from policy/signature administration so one compromised role cannot approve its own image.
Lifecycle and operations
Lifecycle policies select images by rule priority, tag status/prefix/pattern, count or age. Preview before applying. Rules can delete candidate or rollback images if naming assumptions are wrong; preserve every deployed digest, rollback set, investigation hold and associated signature/provenance/SBOM. Deleting a tag does not necessarily delete referenced content, and storage accounting requires observation.
Monitor unauthorized push/delete/policy change, tag overwrite attempts, scan coverage/errors, critical finding age, exception expiry, replication lag/failure, pull denials and runtime digest drift. Recovery must rebuild registry access and prove the restored image digest and evidence, not simply repush a familiar tag.
~~~bash aws ecr describe-registry aws ecr describe-repositories --repository-names app aws ecr describe-images --repository-name app --image-ids imageTag=candidate aws ecr describe-image-scan-findings --repository-name app --image-id imageDigest=sha256:DIGEST aws ecr get-lifecycle-policy-preview --repository-name app ~~~
Workshop and failure analysis
Given twelve manifests and finding sets, resolve tags to digests, identify unsupported/failed scans, apply a policy with expiring exceptions, prove cross-account promotion and choose admitted deployments. Preview a lifecycle policy against active, rollback, quarantined and expired images. Design ECS and EKS runtime verification.
Test 22 failures: shared push role, mutable release tag, tag deployed instead of digest, index/platform mismatch, scan never enabled, scan failed interpreted clean, stale findings, unsupported package ignored, severity alone decides, exception has no expiry, signing role compromised, replication assumed approval, replica lag, destination KMS denial, cross-account pull too broad, admission fails open, admission checks tag only, runtime digest differs, lifecycle priority misunderstood, rollback image deleted, evidence detached, and registry recovery repushes different bytes.
Cost and acceptance
Price storage, data transfer, replication, KMS, basic/enhanced scanning and Inspector coverage, logs and retained versions. This lesson creates nothing. Submit repository/role design, image ledger, scan decisions, promotion proof, admission policy, lifecycle preview, recovery test and all diagnoses. Pass requires digest-based identity, verified scan coverage, separated approval and fail-closed admission.