# ECR Credentials

**URL:** <https://forums.suse.com/t/ecr-credentials/10050>\
**Category:** Rancher 2.0 Tech Preview\
**Created:** [April 11, 2018, 7:06pm UTC](https://forums.suse.com/t/ecr-credentials/10050 "2018-04-11T19:06:00Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![shuckepco](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/shuckepco/32/4610_2.png) [@shuckepco](https://forums.suse.com/u/shuckepco)\
**Post date:** [November 12, 2018, 9:37am UTC](https://forums.suse.com/t/ecr-credentials/10050/10 "2018-11-12T09:37:52Z")

</div>

You can spin up a special container that handles the updates of your ECR session tokens:

> **[GitHub - trondhindenes/ecr-updater: Allows use of AWS ECR registries with...](https://github.com/trondhindenes/ecr-updater)**
>
> Allows use of AWS ECR registries with Kubernetes no matter where your cluster is running. - GitHub - trondhindenes/ecr-updater: Allows use of AWS ECR registries with Kubernetes no matter where your...

Here is a version with some tweaks, too:  
[GitHub - sehucke/ecr-updater: Allows use of AWS ECR registries with Kubernetes no matter where your cluster is running.](https://github.com/sehucke/ecr-updater). Minor tweaks aside, most important change was to use a kubectl-proxy implementation that is more open sourced and has a credible author (Lachlan Evenson / lachie83 @ Github). But this is up to you. 🙂

See as well: [How to refresh ECR credentials in a non-AWS Rancher 2.x installation · Issue #14907 · rancher/rancher · GitHub](https://github.com/rancher/rancher/issues/14907)

The above mentioned solution works pretty well to keep your ECR login token valid. But currently there are some obstacles to work around to successfully deploy using your ECR registry.

1. See [Private registry not working](http://forums.suse.com/t/private-registry-not-working/10535) → You have to manually alter the yaml file of your workloads to include this:

2. And a minor one: You have to specify the full URI to your ECR registry when you deploy a workload. It is not possible to choose a registry to pull from and just type `myimage:stable` as you are used to when pulling from Docker Hub.

---

_[View the full topic](https://forums.suse.com/t/ecr-credentials/10050)._
