aws ecr get-login --region us-east-1 comnand失败。

时间:2018-12-28 11:29:28

标签: amazon-web-services

调用GetAuthorizationToken操作时发生错误(AccessDeniedException):用户:arn:aws:iam :: 325699294512:user / s3-imports无权执行:ecr:资源上的GetAuthorizationToken:*

1 个答案:

答案 0 :(得分:1)

您必须向用户添加“ s3-imports”,至少要具有ecr的只读访问权限。

{
"Version": "2012-10-17",
"Statement": [{
    "Effect": "Allow",
    "Action": [
        "ecr:GetAuthorizationToken",
        "ecr:BatchCheckLayerAvailability",
        "ecr:GetDownloadUrlForLayer",
        "ecr:GetRepositoryPolicy",
        "ecr:DescribeRepositories",
        "ecr:ListImages",
        "ecr:DescribeImages",
        "ecr:BatchGetImage"
    ],
    "Resource": "*"
}]
}