Home icon

Implement per-pod image pull permissions with ECR repository policies on Amazon EKS

Containers Blog



This article explains how to implement per-pod Amazon ECR image pull permissions on Amazon EKS using Kubernetes Enhancement Proposal (KEP) 4412 and ECR repository policies for multi-tenant clusters.

  • KEP 4412 enables per-pod credential support for kubelet image pulls using projected service account tokens
  • Each team gets a dedicated IAM role scoped to their namespace via OIDC trust policy
  • ECR repository policies enforce access control by allowing or denying specific team IAM roles
  • Pods annotated with ecr-role-arn assume their team's IAM role; unannotated pods fall back to node role
  • Requires EKS v1.35 or later and RBAC audience permissions configured before nodes join
  • Walkthrough demonstrates setup with Terraform, including cluster creation, IAM roles, ECR repositories, and sample deployments
  • Two-layer enforcement: team IAM role scopes pod identity, ECR policy controls repository access

This solution provides native AWS controls for granular tenant isolation in multi-tenant EKS clusters without custom admission controllers or policy engines.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Apr 17
2024
Dynamically create repositories upon image push to Amazon ECR
Sep 23
2026
Amazon EMR on EKS now supports IPv6 Amazon EKS clusters
Sep 25
2026
One Amazon EKS, many edges: How to choose your edge container strategy on AWS
Aug 5
2025
Amazon ECR now supports 100,000 images per repository

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.