It seems possible to pull private images from ECR, but only with credentials stored in the same AWS account as the ECR registry.
My case and infosec setup is such that accounts and authentication aren't in the same AWS account as the ECR, and I'm using role assumption, a standard AWS feature that's been there for years.
Is there any way to convince Bitbucket Pipelines to authenticate with the provided keys, then assume a role, and only then fetch the ECR image?
Current Bitbucket Pipelines way of using private images:
image:
name: <aws_ECRREPO_account>.dkr.ecr.<region>.amazonaws.com/<image>:<tag>
aws:
access-key: $AWS_ACCESS_KEY
secret-key: $AWS_SECRET_KEY
What I would like to be able to do:
image:
name: <aws_ECRREPO_account>.dkr.ecr.<region>.amazonaws.com/<image>:<tag>
aws: <br> access-key: $AWS_ACCESS_KEY
secret-key: $AWS_SECRET_KEY<br> assume-role: arn:aws:iam::<aws_ECRREPO_account>:role/ECRPowerUser
Where the AWS access/secret keys are those of a user in a _different_ AWS account (an InfoSec AWS account, which has permission to assume cross-account role into the ECR-hosting AWS account).
Hope this makes sense.
Thanks.