Kaizen

Container Registry

A private ECR repository that scans every pushed image and expires old ones.

GovCloudCMKView source
Module
ecr
Layer
Compute
Interface
7 inputs, 3 outputs
Used by
14 Kaizen apps

Why it matters

Every deploy starts from a container image, and that image has to live somewhere private. This repository scans each image for known vulnerabilities as soon as it is pushed and deletes stale images on a schedule, so storage costs stay flat. Federal stacks pass a customer managed key to encrypt the images.

Use it when

  • An app builds its own image in CI and deploys it with ecs-service.

Reach for something else when

  • The app runs a public or vendor image, such as a Chainguard image from cgr.dev. Point container_image at that registry instead. Use ecs-service.

What it creates

  • aws_ecr_repository (scan on push, AES256 or KMS encryption)
  • aws_ecr_lifecycle_policy (expire untagged images, keep the last N tagged images per prefix)

Secure by default

  • Every pushed image is scanned (scan_on_push = true, not configurable).
  • Images are encrypted at rest with AES256 when no key is given.
  • Untagged images expire after 7 days, and only the last 10 tagged images per prefix are kept.

Commercial and GovCloud

main.tf
module "ecr" {
  source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//ecr?ref=v1.7.0"

  repo_name = local.app_name
  app_name  = local.app_name

  tags = local.tags
}
SettingCommercial defaultFederal settingNote
kms_key_arnnull (AES256)customer managed KMS key ARNFedRAMP SC-13.

How it connects

Inputs

NameTypeDefaultRequiredDescription
app_namestringyesApplication name used in tagging
repo_namestringyesECR repository name (e.g. my-app)
image_tag_mutabilitystring"MUTABLE"noImage tag mutability (MUTABLE or IMMUTABLE)
kms_key_arnstringnullnoCustomer-managed KMS key ARN for repository encryption. Null falls back to AES256 (AWS-managed). Federal posture (FedRAMP SC-13) requires a customer-managed key.
tagged_count_to_keepnumber10noNumber of tagged images to keep per prefix
tagsmap(string){}noTags to apply to all resources
untagged_expiry_daysnumber7noDays before untagged images are expired

Outputs

NameDescription
repository_arnValue: aws_ecr_repository.this.arn
repository_nameValue: aws_ecr_repository.this.name
repository_urlValue: aws_ecr_repository.this.repository_url

Used by

AppPinned ref
BidBuddyv1.0.0
castlev1.6.0
dustv1.1.0
evergreenv1.0.0
foragerv1.1.0
ginkgov1.3.0
juniperv1.1.0
magnoliav1.1.0
meridianv1.0.0
oakv1.1.0
poppyv1.1.0
saplingsv1.3.0
skeddyv1.6.0
test-health-dashboardv1.4.0

On this page