Use AMS Self-Service Provisioning (SSP) mode to access Amazon Elastic Container Registry (Amazon ECR) capabilities directly in your AMS managed account. Amazon Elastic Container Registry is a fully-managed Docker
To learn more, see Amazon Elastic Container Registry
Amazon Elastic Container Registry in AWS Managed Services FAQs
Q: How do I request access to Amazon ECR in my AMS account?
Request access to Amazon ECR by submitting an RFC with the
Management | AWS service | Self-provisioned service | Add (ct-1w8z66n899dct) change type.
This RFC provisions the following IAM role to your account: customer_ecr_console_role
.
Once provisioned in your account, you must onboard the role in your federation solution.
Q: What are the restrictions to using Amazon ECR in my AMS account?
There are restrictions around AMS namespaces for the use of Amazon ECR in your AMS account. Container images may not be prefixed with "AMS-" or "Sentinel-".
Q: What are the prerequisites or dependencies to using Amazon ECR in my AMS account?
There are no prerequisites or dependencies to use Amazon ECR in your AMS account.
Q: Is it possible to have an instance profile with Amazon ECR power user permissions?
Yes, use change type Management | Applications | IAM instance profile | Create (ct-0ixp4ch2tiu04).