Skip to content

CodeArtifact/ECR: pull-through cache for public Docker #1252

Description

@gangster

Part of #1249 (ADR-098, D2).

Enable ECR pull-through cache rules so public base/tooling images are lazily mirrored into our account and served with IAM auth.

Scope:

  • PTC rules for docker.io, ghcr.io, quay.io, registry.k8s.io
  • Docker Hub upstream credentials in Secrets Manager (avoid anonymous rate limits)
  • Extend the ecr module/unit (or a sibling) as appropriate
  • Confirm node/pod pull path resolves cached images; document the <acct>.dkr.ecr…/docker.io/library/... reference form

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/infraGeneral IaC / AWS platform infrastructurearea/supply-chaincosign, SLSA, CI provenance, image signingenhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions