Pipeline fails when using OpenID Connect functionality to pull private images from ECR
Can you share your IAM role's trust relationship definition? Access denied is usually returned by ECR when the conditions in trust relations are not met
@Luiz Rocha thanks for raising the issue. If you have some related logs, please share that, it will help to discover root cause.
Cheers, Galyna
{ "Effect": "Allow", "Principal": { "Federated": "arn:aws:iam::{AWS_ACCOUNT_NUMBER}:oidc-provider/api.bitbucket.org/2.0/workspaces/{WORKSPACE}/pipelines-config/identity/oidc" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringLike": { "api.bitbucket.org/2.0/workspaces/{WORKSPACE}/pipelines-config/identity/oidc:sub": "*:*" } } }
Hi, above is the IAM role trust relationship definitions. This is the instructions I followed: https://support.atlassian.com/bitbucket-cloud/docs/deploy-on-aws-using-bitbucket-pipelines-openid-connect/
oh, it looks like we are referencing the wrong documentation from https://support.atlassian.com/bitbucket-cloud/docs/use-docker-images-as-build-environments/#Private-images-hosted-by-AWS-ECR--EC2-Container-Registry-
it should point to https://support.atlassian.com/bitbucket-cloud/docs/use-aws-ecr-images-in-pipelines-with-openid-connect/ where the relevant IAM role conditions actually allow pulling ECR images
Yes, but I shared the IAM role trust relationship. The IAM permissions already have the required permissions as the documentation as well. I added a wild card to check if there was any missed permissions however the issue still happening.
{ "Sid": "", "Effect": "Allow", "Action": [ "sts:Get*" ], "Resource": "*"},{ "Sid": "", "Effect": "Allow", "Action": "ecr:*", "Resource": "*"}
@mkleint please, can you update the documentation in this link with this information?https://support.atlassian.com/bitbucket-cloud/docs/use-aws-ecr-images-in-pipelines-with-openid-connect/
It looks like you're new here. Sign in or register to get started.