Skip to content

Commit a20fb54

Browse files
authored
feat: add permissions for ECR Public container pulls to Auto Mode NodeRole (#8698)
feat: ECR Public authenticated pulls Update the default EKS Auto Mode Node Role to allow authenticated pulls from ECR public. This ensures that container pulls are not unnecessarily throttled due to unauthenticated pulls.
1 parent a11df6a commit a20fb54

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

pkg/cfn/builder/roles/auto-mode-node-role.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ Resources:
1818
- sts:AssumeRole
1919
ManagedPolicyArns:
2020
- !Sub "arn:${AWS::Partition}:iam::aws:policy/AmazonEC2ContainerRegistryPullOnly"
21+
- !Sub "arn:${AWS::Partition}:iam::aws:policy/AmazonElasticContainerRegistryPublicReadOnly"
2122
- !Sub "arn:${AWS::Partition}:iam::aws:policy/AmazonEKSWorkerNodeMinimalPolicy"
2223

2324
Outputs:

0 commit comments

Comments
 (0)