aws ecr58 CLI commands available for Amazon ECR.
| Command | API Operation | Sample |
|---|---|---|
batch-check-layer-availabilityChecks the availability of one or more image layers in a repository. When an image is pushed to a repository, each image layer is checked to verify if it has been uploaded before. If it has been uploaded, then the image layer is skipped. This operation is used by the Amazon ECR proxy and is not gen | BatchCheckLayerAvailability | |
batch-delete-imageDeletes a list of specified images within a repository. Images are specified with either an imageTag or imageDigest. You can remove a tag from an image by specifying the image's tag in your request. When you remove the last tag from an image, the image is deleted from your repository. You can comple | BatchDeleteImage | |
batch-get-imageGets detailed information for an image. Images are specified with either an imageTag or imageDigest. When an image is pulled, the BatchGetImage API is called once to retrieve the image manifest. | BatchGetImage | |
batch-get-repository-scanning-configurationGets the scanning configuration for one or more repositories. | BatchGetRepositoryScanningConfiguration | |
complete-layer-uploadInforms Amazon ECR that the image layer upload has completed for a specified registry, repository name, and upload ID. You can optionally provide a sha256 digest of the image layer for data validation purposes. When an image is pushed, the CompleteLayerUpload API is called once per each new image la | CompleteLayerUpload | |
create-pull-through-cache-ruleCreates a pull through cache rule. A pull through cache rule provides a way to cache images from an upstream registry source in your Amazon ECR private registry. For more information, see Using pull through cache rules in the Amazon Elastic Container Registry User Guide. | CreatePullThroughCacheRule | |
create-repositoryCreates a repository. For more information, see Amazon ECR repositories in the Amazon Elastic Container Registry User Guide. | CreateRepository | |
create-repository-creation-templateCreates a repository creation template. This template is used to define the settings for repositories created by Amazon ECR on your behalf. For example, repositories created through pull through cache actions. For more information, see Private repository creation templates in the Amazon Elastic Cont | CreateRepositoryCreationTemplate | |
delete-lifecycle-policyDeletes the lifecycle policy associated with the specified repository. | DeleteLifecyclePolicy | |
delete-pull-through-cache-ruleDeletes a pull through cache rule. | DeletePullThroughCacheRule | |
delete-registry-policyDeletes the registry permissions policy. | DeleteRegistryPolicy | |
delete-repositoryDeletes a repository. If the repository isn't empty, you must either delete the contents of the repository or use the force option to delete the repository and have Amazon ECR delete all of its contents on your behalf. | DeleteRepository | |
delete-repository-creation-templateDeletes a repository creation template. | DeleteRepositoryCreationTemplate | |
delete-repository-policyDeletes the repository policy associated with the specified repository. | DeleteRepositoryPolicy | |
delete-signing-configurationDeletes the registry's signing configuration. Images pushed after deletion of the signing configuration will no longer be automatically signed. For more information, see Managed signing in the Amazon Elastic Container Registry User Guide. Deleting the signing configuration does not affect existing | DeleteSigningConfiguration | |
deregister-pull-time-update-exclusionRemoves a principal from the pull time update exclusion list for a registry. Once removed, Amazon ECR will resume updating the pull time if the specified principal pulls an image. | DeregisterPullTimeUpdateExclusion | |
describe-image-replication-statusReturns the replication status for a specified image. | DescribeImageReplicationStatus | |
describe-image-scan-findingsReturns the scan findings for the specified image. | DescribeImageScanFindings | |
describe-image-signing-statusReturns the signing status for a specified image. If the image matched signing rules that reference different signing profiles, a status is returned for each profile. For more information, see Managed signing in the Amazon Elastic Container Registry User Guide. | DescribeImageSigningStatus | |
describe-imagesReturns metadata about the images in a repository. Starting with Docker version 1.9, the Docker client compresses image layers before pushing them to a V2 Docker registry. The output of the docker images command shows the uncompressed image size. Therefore, Docker might return a larger image than t | DescribeImages | |
describe-pull-through-cache-rulesReturns the pull through cache rules for a registry. | DescribePullThroughCacheRules | |
describe-registryDescribes the settings for a registry. The replication configuration for a repository can be created or updated with the PutReplicationConfiguration API action. | DescribeRegistry | |
describe-repositoriesDescribes image repositories in a registry. | DescribeRepositories | |
describe-repository-creation-templatesReturns details about the repository creation templates in a registry. The prefixes request parameter can be used to return the details for a specific repository creation template. | DescribeRepositoryCreationTemplates | |
get-account-settingRetrieves the account setting value for the specified setting name. | GetAccountSetting | |
get-authorization-tokenRetrieves an authorization token. An authorization token represents your IAM authentication credentials and can be used to access any Amazon ECR registry that your IAM principal has access to. The authorization token is valid for 12 hours. The authorizationToken returned is a base64 encoded string t | GetAuthorizationToken | |
get-download-url-for-layerRetrieves the pre-signed Amazon S3 download URL corresponding to an image layer. You can only get URLs for image layers that are referenced in an image. When an image is pulled, the GetDownloadUrlForLayer API is called once per image layer that is not already cached. This operation is used by the A | GetDownloadUrlForLayer | |
get-lifecycle-policyRetrieves the lifecycle policy for the specified repository. | GetLifecyclePolicy | |
get-lifecycle-policy-previewRetrieves the results of the lifecycle policy preview request for the specified repository. | GetLifecyclePolicyPreview | |
get-registry-policyRetrieves the permissions policy for a registry. | GetRegistryPolicy | |
get-registry-scanning-configurationRetrieves the scanning configuration for a registry. | GetRegistryScanningConfiguration | |
get-repository-policyRetrieves the repository policy for the specified repository. | GetRepositoryPolicy | |
get-signing-configurationRetrieves the registry's signing configuration, which defines rules for automatically signing images using Amazon Web Services Signer. For more information, see Managed signing in the Amazon Elastic Container Registry User Guide. | GetSigningConfiguration | |
initiate-layer-uploadNotifies Amazon ECR that you intend to upload an image layer. When an image is pushed, the InitiateLayerUpload API is called once per image layer that has not already been uploaded. Whether or not an image layer has been uploaded is determined by the BatchCheckLayerAvailability API action. This ope | InitiateLayerUpload | |
list-image-referrersLists the artifacts associated with a specified subject image. The IAM principal invoking this operation must have the ecr:BatchGetImage permission. | ListImageReferrers | |
list-imagesLists all the image IDs for the specified repository. You can filter images based on whether or not they are tagged by using the tagStatus filter and specifying either TAGGED, UNTAGGED or ANY. For example, you can filter your results to return only UNTAGGED images and then pipe that result to a Batc | ListImages | |
list-pull-time-update-exclusionsLists the IAM principals that are excluded from having their image pull times recorded. | ListPullTimeUpdateExclusions | |
list-tags-for-resourceList the tags for an Amazon ECR resource. | ListTagsForResource | |
put-account-settingAllows you to change the basic scan type version or registry policy scope. | PutAccountSetting | |
put-imageCreates or updates the image manifest and tags associated with an image. When an image is pushed and all new image layers have been uploaded, the PutImage API is called once to create or update the image manifest and the tags associated with the image. This operation is used by the Amazon ECR proxy | PutImage | |
put-image-scanning-configurationThe PutImageScanningConfiguration API is being deprecated, in favor of specifying the image scanning configuration at the registry level. For more information, see PutRegistryScanningConfiguration. Updates the image scanning configuration for the specified repository. | PutImageScanningConfiguration | |
put-image-tag-mutabilityUpdates the image tag mutability settings for the specified repository. For more information, see Image tag mutability in the Amazon Elastic Container Registry User Guide. | PutImageTagMutability | |
put-lifecycle-policyCreates or updates the lifecycle policy for the specified repository. For more information, see Lifecycle policy template. | PutLifecyclePolicy | |
put-registry-policyCreates or updates the permissions policy for your registry. A registry policy is used to specify permissions for another Amazon Web Services account and is used when configuring cross-account replication. For more information, see Registry permissions in the Amazon Elastic Container Registry User G | PutRegistryPolicy | |
put-registry-scanning-configurationCreates or updates the scanning configuration for your private registry. | PutRegistryScanningConfiguration | |
put-replication-configurationCreates or updates the replication configuration for a registry. The existing replication configuration for a repository can be retrieved with the DescribeRegistry API action. The first time the PutReplicationConfiguration API is called, a service-linked IAM role is created in your account for the r | PutReplicationConfiguration | |
put-signing-configurationCreates or updates the registry's signing configuration, which defines rules for automatically signing images with Amazon Web Services Signer. For more information, see Managed signing in the Amazon Elastic Container Registry User Guide. To successfully generate a signature, the IAM principal pushi | PutSigningConfiguration | |
register-pull-time-update-exclusionAdds an IAM principal to the pull time update exclusion list for a registry. Amazon ECR will not record the pull time if an excluded principal pulls an image. | RegisterPullTimeUpdateExclusion | |
set-repository-policyApplies a repository policy to the specified repository to control access permissions. For more information, see Amazon ECR Repository policies in the Amazon Elastic Container Registry User Guide. | SetRepositoryPolicy | |
start-image-scanStarts a basic image vulnerability scan. A basic image scan can only be started once per 24 hours on an individual image. This limit includes if an image was scanned on initial push. You can start up to 100,000 basic scans per 24 hours. This limit includes both scans on initial push and scans initi | StartImageScan | |
start-lifecycle-policy-previewStarts a preview of a lifecycle policy for the specified repository. This allows you to see the results before associating the lifecycle policy with the repository. | StartLifecyclePolicyPreview | |
tag-resourceAdds specified tags to a resource with the specified ARN. Existing tags on a resource are not changed if they are not specified in the request parameters. | TagResource | |
untag-resourceDeletes specified tags from a resource. | UntagResource | |
update-image-storage-classTransitions an image between storage classes. You can transition images from Amazon ECR standard storage class to Amazon ECR archival storage class for long-term storage, or restore archived images back to Amazon ECR standard. | UpdateImageStorageClass | |
update-pull-through-cache-ruleUpdates an existing pull through cache rule. | UpdatePullThroughCacheRule | |
update-repository-creation-templateUpdates an existing repository creation template. | UpdateRepositoryCreationTemplate | |
upload-layer-partUploads an image layer part to Amazon ECR. When an image is pushed, each new image layer is uploaded in parts. The maximum size of each image layer part can be 20971520 bytes (or about 20MB). The UploadLayerPart API is called once per each new image layer part. This operation is used by the Amazon | UploadLayerPart | |
validate-pull-through-cache-ruleValidates an existing pull through cache rule for an upstream registry that requires authentication. This will retrieve the contents of the Amazon Web Services Secrets Manager secret, verify the syntax, and then validate that authentication to the upstream registry is successful. | ValidatePullThroughCacheRule |
Our bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to NewsletterOur bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to NewsletterECR