Q: Your CodeBuild job is failing with a permissions error when trying to push to ECR. What do you check?
CodeBuild uses a service role. That role needs ECR permissions:
#AWS #CI/CD on AWS #L2 #Cloud #Infrastructure
🎙️ Candidate Opening & Architectural Context
""When an interviewer asks how I troubleshoot this in AWS, I frame it through my hands-on production experience. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
CodeBuild uses a service role. That role needs ECR permissions:
ecr:GetAuthorizationToken— to authenticate with ECR.ecr:BatchCheckLayerAvailability,ecr:PutImage,ecr:InitiateLayerUpload, etc. — to push layers.
2️⃣
Remediation & Permanent Safeguards
In the CodeBuild buildspec.yml, the login command: This requires ecr:GetAuthorizationToken at minimum. Check the service role policy. Also check: ECR repository policy — cross-account pushes need a resource policy on the ECR repo too. --- ## 🟠 Cost & Architecture
aws ecr get-login-password | docker login --username AWS --password-stdin <account>.dkr.ecr.<region>.amazonaws.com
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: ecr:GetAuthorizationToken — to authenticate with ECR.."
⚡ 60-Second Elevator Pitch Talking Points
- ecr:GetAuthorizationToken — to authenticate with ECR.
- ecr:BatchCheckLayerAvailability, ecr:PutImage, ecr:InitiateLayerUpload, etc. — to push layers.
Advertisement