AWS ECR step configuration
Scan container images with AWS ECR.
You can scan your container images and extract scan results from Amazon Elastic Container Registry (ECR).
Important notes for running AWS ECR scans in STO
You can utilize custom STO scan images and pipelines to run scans as a non-root user. For more details, refer Configure your pipeline to use STO images from private registry.
STO supports three different approaches for loading self-signed certificates. For more information, refer Run STO scans with custom SSL certificates.
AWS ECR step settings for STO scans
The recommended workflow is to add an AWS ECR step to a Security or Build stage and then configure it as described below.
Scan
Scan Mode
Scan Configuration
Target
Type
Target and Variant Detection
Name
Variant
Container image
Type (orchestration)
Domain (extraction)
Name
Tag/Digest
Region
Authentication
Access ID (orchestration)
Access Token
Session Token
To enable session-based authentication with AWS, for example, you can pass AWS session token using the key CONTAINER_SESSION_TOKEN with a Harness text secret of your token.
Access Region
The AWS region of the image to scan.
Log Level
Fail on Severity
Additional Configuration
Advanced settings
Proxy settings
Last updated
Was this helpful?