Container Registry
A private ECR repository that scans every pushed image and expires old ones.
GovCloudCMKView source
- Module
- ecr
- Layer
- Compute
- Interface
- 7 inputs, 3 outputs
- Used by
- 14 Kaizen apps
Why it matters
Every deploy starts from a container image, and that image has to live somewhere private. This repository scans each image for known vulnerabilities as soon as it is pushed and deletes stale images on a schedule, so storage costs stay flat. Federal stacks pass a customer managed key to encrypt the images.
Use it when
- An app builds its own image in CI and deploys it with ecs-service.
Reach for something else when
- The app runs a public or vendor image, such as a Chainguard image from cgr.dev. Point container_image at that registry instead. Use ecs-service.
What it creates
aws_ecr_repository(scan on push, AES256 or KMS encryption)aws_ecr_lifecycle_policy(expire untagged images, keep the last N tagged images per prefix)
Secure by default
- Every pushed image is scanned (scan_on_push = true, not configurable).
- Images are encrypted at rest with AES256 when no key is given.
- Untagged images expire after 7 days, and only the last 10 tagged images per prefix are kept.
Commercial and GovCloud
module "ecr" {
source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//ecr?ref=v1.7.0"
repo_name = local.app_name
app_name = local.app_name
tags = local.tags
}| Setting | Commercial default | Federal setting | Note |
|---|---|---|---|
kms_key_arn | null (AES256) | customer managed KMS key ARN | FedRAMP SC-13. |
How it connects
- To ecs-service: repository_url (as container_image)
Inputs
| Name | Type | Default | Required | Description |
|---|---|---|---|---|
app_name | string | yes | Application name used in tagging | |
repo_name | string | yes | ECR repository name (e.g. my-app) | |
image_tag_mutability | string | "MUTABLE" | no | Image tag mutability (MUTABLE or IMMUTABLE) |
kms_key_arn | string | null | no | Customer-managed KMS key ARN for repository encryption. Null falls back to AES256 (AWS-managed). Federal posture (FedRAMP SC-13) requires a customer-managed key. |
tagged_count_to_keep | number | 10 | no | Number of tagged images to keep per prefix |
tags | map(string) | {} | no | Tags to apply to all resources |
untagged_expiry_days | number | 7 | no | Days before untagged images are expired |
Outputs
| Name | Description |
|---|---|
repository_arn | Value: aws_ecr_repository.this.arn |
repository_name | Value: aws_ecr_repository.this.name |
repository_url | Value: aws_ecr_repository.this.repository_url |
Used by
| App | Pinned ref |
|---|---|
| BidBuddy | v1.0.0 |
| castle | v1.6.0 |
| dust | v1.1.0 |
| evergreen | v1.0.0 |
| forager | v1.1.0 |
| ginkgo | v1.3.0 |
| juniper | v1.1.0 |
| magnolia | v1.1.0 |
| meridian | v1.0.0 |
| oak | v1.1.0 |
| poppy | v1.1.0 |
| saplings | v1.3.0 |
| skeddy | v1.6.0 |
| test-health-dashboard | v1.4.0 |