Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Principal ARNs input for ECR Power User #94

Open
ingledl opened this issue Mar 31, 2022 · 0 comments
Open

Principal ARNs input for ECR Power User #94

ingledl opened this issue Mar 31, 2022 · 0 comments

Comments

@ingledl
Copy link

ingledl commented Mar 31, 2022

Describe the Feature

Create an input variable for Principal ARNs to provide power user access to ECR.

Expected Behavior

Principal ARNs will be provided with actions that match the policy AmazonEC2ContainerRegistryPowerUser which provides full access to Amazon EC2 Container Registry repositories, but does not allow repository deletion or policy changes.

Use Case

A centrally managed environment where Principal ARNs are allowed to update images in ECR repos but not alter policies or delete repos. This will add a guardrail to prevent unintentional/intentional deletion of repos containing nonrecoverable container images.

Alternatives Considered

Grant the ability create custom policies to attach to either current Principal ARN input.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant