# AWS ECR Authentication issue

**URL:** <https://forums.suse.com/t/aws-ecr-authentication-issue/10660>\
**Category:** SUSE Rancher Prime\
**Created:** [June 4, 2018, 5:56pm UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660 "2018-06-04T17:56:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rsareth](https://avatars.discourse-cdn.com/v4/letter/r/ea5d25/32.png) [@rsareth](https://forums.suse.com/u/rsareth)\
**Post date:** [June 4, 2018, 5:56pm UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/1 "2018-06-04T17:56:54Z")

</div>

Hello everybody,

I’m facing a big issue on **pulling my own docker images from our own aws ecr registry**. I’m using **rancher-v2.0.2**

The rancher and k8s documentations about the IAM profile are not clear at all.

So, I have these questions:

- **how do I create the IAM profile instance?** I create a IAM Role named **kubernetes** with that:

> ```
> {
> "Version": "2012-10-17",
> "Statement": [
> {
> "Effect": "Allow",
> "Action": [
> "ecr:*",
> "cloudtrail:LookupEvents"
> ],
> "Resource": "*"
> }
> ]
> }
> 
> ```

- **Creating this IAM Role is the right ressource for my issue?**

I think I searched everywhere stackoverflow/github/google and I didn’t find anything clear. I’m completely lost.

Is there someone who found a solution for this?

Thank you by advance

Rasmey

---

<div class="post-metadata">

**Author:** ![francesco2013](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/francesco2013/32/4611_2.png) [@francesco2013](https://forums.suse.com/u/francesco2013)\
**Post date:** [November 9, 2018, 9:31am UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/2 "2018-11-09T09:31:22Z")

</div>

I have the same problem. I find it shocking after such a long time there is no answer.  
Could someone be so nice to please post a step by step working howto on how to use ECR on Rancher 2.0 ?  
I have tried basically everything I could find but nothing seems to work. I am using Rancher 2.0 with kubelet 1.20.

---

<div class="post-metadata">

**Author:** ![Travis\_Burrell](https://avatars.discourse-cdn.com/v4/letter/t/e56c9b/32.png) [@Travis\_Burrell](https://forums.suse.com/u/Travis_Burrell)\
**Post date:** [November 14, 2018, 6:08pm UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/3 "2018-11-14T18:08:30Z")

</div>

I’m guessing you guys have [seen this](https://rancher.com/using-amazon-container-registry-service/)? I’m still researching how to get the token into Rancher, but it seems they have a solution for it. I’d be curious to see what you both ended up doing.

---

<div class="post-metadata">

**Author:** ![shuckepco](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/shuckepco/32/4610_2.png) [@shuckepco](https://forums.suse.com/u/shuckepco)\
**Post date:** [November 15, 2018, 8:18am UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/4 "2018-11-15T08:18:09Z")

</div>

Sorry to say that, but that blog post was written in March 2016. 🙂 Hence, it is not about Rancher 2.x.

I summarized our solution and the current status in [ECR Credentials](http://forums.suse.com/t/ecr-credentials/10050).

Sadly, there is a confusing amount of forum threads and Github issues regarding this topic…

---

<div class="post-metadata">

**Author:** ![rsareth](https://avatars.discourse-cdn.com/v4/letter/r/ea5d25/32.png) [@rsareth](https://forums.suse.com/u/rsareth)\
**Post date:** [November 15, 2018, 9:11am UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/5 "2018-11-15T09:11:20Z")

</div>

Hi,

The main issue is you split the documentation. For example, some documentation for the version 1.6 are still relevant in the 2.x. I don’t remember exactly but there is no explicit reference for that.

I read the documentation for the version 1.6.

I suggest you to “copy/paste/adapt” the doc when you create a new version of rancher.

Le jeu. 15 nov. 2018 à 09:28, Sebastian Hucke [rancher@discoursemail.com](mailto:rancher@discoursemail.com) a écrit :

---

<div class="post-metadata">

**Author:** ![shuckepco](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/shuckepco/32/4610_2.png) [@shuckepco](https://forums.suse.com/u/shuckepco)\
**Post date:** [November 15, 2018, 11:43am UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/6 "2018-11-15T11:43:58Z")

</div>

There is a slight misunderstanding:  
I am _not_ a Rancher employee / project member. 😉 I am just a user who wrote down his solution in a forum to give some help back to the community.

That fact aside, there are tons of possible tools out there you can possibly integrate Rancher / Kubernetes with. And there are even more solutions you can deploy on such a platform. The question is: Is a project’s documentation the right place for all that stuff? IMHO, no. That is the reason why there are so many people out there, describing _their_ solutions in blog posts, forums, stackoverflow questions etc. The question on how to use an AWS ECR registry within Kubernetes is such a specific case - this is totally independent of Rancher.

By the way, if you feel something is missing in the docs: it is up to you to write some texts and start a pull request @ [https://github.com/rancher/docs](https://github.com/rancher/docs). 😉 Don’t forget: You get something for free here. And you are also free to participate, if you like.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [November 15, 2018, 4:07pm UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/7 "2018-11-15T16:07:32Z")

</div>

> [@rsareth](#):
>
> For example, some documentation for the version 1.6 are still relevant in the 2.x.

This is just not true, there is virtually nothing in 1.x docs relevant to 2.x, other then things that are just about k8s in general.

1.x had an ECR updater we maintained because we had our own orchestration system and had to. We do not have one for 2.x, because Kubernetes has built-in support for ECR when running in AWS. For the minority using ECR in clusters outside of AWS, there are third-party scripts other people maintain.

---

<div class="post-metadata">

**Author:** ![francesco2013](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/francesco2013/32/4611_2.png) [@francesco2013](https://forums.suse.com/u/francesco2013)\
**Post date:** [November 16, 2018, 7:44am UTC](https://forums.suse.com/t/aws-ecr-authentication-issue/10660/8 "2018-11-16T07:44:07Z")

</div>

Hello Rsareth,

I have finally made it work using a role with the following permissions for ECR:

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "ecr:CreateRepository",
                "ecr:GetAuthorizationToken"
            ],
            "Resource": "*"
        },
        {
            "Sid": "VisualEditor1",
            "Effect": "Allow",
            "Action": "ecr:*",
            "Resource": "arn:aws:ecr:*:*:repository/*"
        }
    ]
}

```

Hope this will help you 🙂
