[ECR] [request]: Sync (pull) Docker containers from extern source as a service into ECR
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
What do you want us to build?
Extend ECR functionality that enables us to pull external public Docker container images from remote repos, as well allow to authenticate to external repos (e. g. Quay.io, Docker Hub, Azure ACR) in order to pull private images into ECR. I imagine the syncing functionality can be once off or scheduled. Synced images could be set to be scanned when pulled in, as well reject, if they do not qualify minimum configures vulnerability scanning (user can define the threshold of critical, high, medium or low classified CVEs).
**Which service(s) is this request for?**
ECR
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
Lower custom solutions built by every company in order to pull/sync external images and scan them for CVEs. This should really be out of the box as a synchronisation job.
**Are you currently working around this issue?**
How are you currently solving this problem?
Custom pipelines executed.
**Additional context**
Anything else we should know?
As for credentials to external private Docker image repos, the interface should offer to store the secrets in AWS secure storage (e. g. SSM Parameter store encrypted at rest)
**Attachments**
If you think you might have additional information that you'd like to include via an attachment, please do - we'll take a look. (Remember to remove any personally-identifiable information.)
Contributor guide
Research direction
No repository files, tests, or entry points are named. Start by reviewing the ECR scope and the requested external repositories, authentication, scheduling, vulnerability thresholds, and secure credential storage; done would require an agreed design for these capabilities.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, docker
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100