Policy: AWS > ECR > Enabled
Configure whether the AWS ECR service is enabled. This will only affect Guardrails managed User Roles and will allow the Guardrails managed user to access AWS ECR service. - Enabled policy allows Guardrails managed users to perform all the actions for the service - Enabled: Metadata Only policy allows Guardrails managed users to perform only the metadata level actions for the service (like describe*, list*)
Note: - Disabled policy disables the service but does NOT disable the API for Guardrails or SuperUsers - All the resource data stored in the Guardrails CMDB is considered to be metadata - For more information related to permissions and grant levels, please check the documentation
Targets
This policy targets the following resource types:
Controls
Setting this policy configures these controls:
- AWS > ECR > Image > Approved
- AWS > ECR > Public Repository > Approved
- AWS > ECR > Repository > Approved
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/iamPermissions
- tmod:@turbot/aws-ecr#/policy/types/ecrEnabled
- turbot graphql policy-type --id "tmod:@turbot/aws-ecr#/policy/types/ecrEnabled"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/aws-ecr#/policy/types/ecrEnabled"
Get Policy TypeGet Policy Settings