Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

  • Global
  • Personal

Recognition

  • Give kudos
  • Received
  • Given

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Private pipeline image - AWS ECR and cross-account role assumption

It seems possible to pull private images from ECR, but only with credentials stored in the same AWS account as the ECR registry.

My case and infosec setup is such that accounts and authentication aren't in the same AWS account as the ECR, and I'm using role assumption, a standard AWS feature that's been there for years.

Is there any way to convince Bitbucket Pipelines to authenticate with the provided keys, then assume a role, and only then fetch the ECR image?

Current Bitbucket Pipelines way of using private images:

image:
  name: <aws_ECRREPO_account>.dkr.ecr.<region>.amazonaws.com/<image>:<tag>
  aws: 
    access-key: $AWS_ACCESS_KEY
    secret-key: $AWS_SECRET_KEY

What I would like to be able to do:

image:
  name: <aws_ECRREPO_account>.dkr.ecr.<region>.amazonaws.com/<image>:<tag>
  aws: 
access-key: $AWS_ACCESS_KEY secret-key: $AWS_SECRET_KEY
    assume-role: arn:aws:iam::<aws_ECRREPO_account>:role/ECRPowerUser

Where the AWS access/secret keys are those of a user in a _different_ AWS account (an InfoSec AWS account, which has permission to assume cross-account role into the ECR-hosting AWS account).

Hope this makes sense.

Thanks.

1 answer

We are facing the same situation.

 

Would be great have the 'assume-role' option  

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Jira

Announcing the waitlist for Jira Work Management

Hey there Cloud Community members! We’re excited to give you the first glimpse of the new home for business teams on Jira — Jira Work Management. Jira Work Management is the next generation of J...

644 views 10 16
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you