Implement per-pod image pull permissions with ECR repository policies on Amazon EKS
Containers Blog
This article explains how to implement per-pod Amazon ECR image pull permissions on Amazon EKS using Kubernetes Enhancement Proposal (KEP) 4412 and ECR repository policies for multi-tenant clusters.
- KEP 4412 enables per-pod credential support for kubelet image pulls using projected service account tokens
- Each team gets a dedicated IAM role scoped to their namespace via OIDC trust policy
- ECR repository policies enforce access control by allowing or denying specific team IAM roles
- Pods annotated with ecr-role-arn assume their team's IAM role; unannotated pods fall back to node role
- Requires EKS v1.35 or later and RBAC audience permissions configured before nodes join
- Walkthrough demonstrates setup with Terraform, including cluster creation, IAM roles, ECR repositories, and sample deployments
- Two-layer enforcement: team IAM role scopes pod identity, ECR policy controls repository access
This solution provides native AWS controls for granular tenant isolation in multi-tenant EKS clusters without custom admission controllers or policy engines.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.