Amazon ECR
You can scan Amazon ECR using our Docker integration. The recommended setup is to run the Enterprise scanner on an AWS host with an attached IAM role for ECR access. Keeping docker login and the scan on the same host is the simplest, most reliable configuration.
Important
- No auto-enumeration of images.
- Every image URI must be explicitly listed.
- ECR Tokens expire approximately every 12 hours.
- Consider creating a cron for docker login for recurring scans to refresh the authentication token.
Walkthrough
1. Create the scanner in the dashboard and download the config.yml to your host.
2. Create an AWS IAM User Group with the pre-defined policyAmazonEC2ContainerRegistryReadOnly
3. Add a user to the AWS IAM User Group.
4. Authenticate to ECR. AWS ECR's docker login always uses the literal username AWS, which is used below. Confirm you have the correct docker container repo address (e.g. 123456789012.dkr.ecr.us-east-1.amazonaws.com/your-repo)
Example
Note: This stores the credential in ~/.docker/config.json of the user who ran it (e.g. /root/.docker/config.json or /home/ec2-user/.docker/config.json), base64-encoded.
5. Add the Docker source to config.yml
No username/password in the YAML. dockerKeychain: true reads the credential from step 3. The full registry hostname in each image URI tells the scanner which ECR registry to pull from.
5. Run the scan
./scanner scan --config=config.yaml Validate first if needed: ./scanner validate --config=config.yaml --debug
Important Points
- Self-hosted scanner only: ECR scanning cannot be performed on the hosted scanner.
- Run as the same user: The scanner must be run by the same user that executed docker login because it reads the keychain from that specific user's home directory.
- No auto-enumeration: Every image URI must be explicitly listed.
- Only linux/amd64 images are scanned: Images for arm64 or multi-arch architectures are skipped.
- ECR token expiration: Tokens expire approximately every 12 hours; docker login should be scheduled via cron for recurring scans.
- Full egress recommended: Partial allowlists can degrade results as the scanner verifies secrets against over 800 endpoints.