- Environment
- Deployment Configuration
- Networking (collapsed)
- Task Overrides (collapsed)
- Container Overrides (collapsed)
- Tags - optional (collapsed)
Sunday, December 18, 2022
AWS Run Task Definition in Cluster
Saturday, December 17, 2022
AWS ECS Task Definition
Now that I have an ECR Image (built locally and pushed up from Docker Desktop) and an ECS Cluster Created, next step is to create a Task Definition.
I provided the Container Port of 8080 (same as the one I exposed in the Dockerfile of the Image).
Note: In order to actually create Task Def and Containers, I had to go back as the Root User and create Inline Policy that contained the following IAM Actions:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"iam:CreateRole",
"iam:AttachRolePolicy"
],
"Resource": "*"
}
]
}
AWS ECS Cluster Creation
Sunday, December 11, 2022
AWS Pushing Docker Image to Elastic Container Registry (ECR)
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ecr:CreateRepository",
"ecr:CompleteLayerUpload",
"ecr:GetAuthorizationToken",
"ecr:UploadLayerPart",
"ecr:InitiateLayerUpload",
"ecr:BatchCheckLayerAvailability",
"ecr:PutImage"
],
"Resource": "*"
}
]
}
C:\>aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin ************.dkr.ecr.us-east-1.amazonaws.com Login Succeeded C:\>docker tag f94c25ad91cd1dabbb0dae012a0da3f50c23e050fdd1916d7bd81d5c9dbec2b9 ************.dkr.ecr.us-east-1.amazonaws.com/java-spring-cloud-demo:v0.0.1 C:\>docker push ************.dkr.ecr.us-east-1.amazonaws.com/java-spring-cloud-demo:v0.0.1 The push refers to repository [************.dkr.ecr.us-east-1.amazonaws.com/java-spring-cloud-demo] e971bfdd6e68: Pushed cb90fdeb280a: Pushed 15b10c92f3b2: Pushed e5e13b0c77cb: Pushed v0.0.1: digest: sha256:6bee10abc02d77bced7593744f31b4d373069042cb45ae4cf4a2648992b5265a size: 1161
AWS IAM User/Group/Policies
Next step in my weekend AWS / Container / Spring Boot experimentation is to try and actually get my Docker Image pushed up to ECR.
It runs fine in my local Docker Desktop, but I want to get it running as a service in AWS ECS.
In following AWS best practices:
"We strongly recommend that you do not use the root user for your everyday tasks, even the administrative ones. Instead, adhere to the best practice of using the root user only to create your first IAM user. Then securely lock away the root user credentials and use them to perform only a few account and service management tasks. To view the tasks that require you to sign in as the root user, see AWS Tasks That Require Root User."
Source: https://docs.aws.amazon.com/IAM/latest/UserGuide/id.html?icmpid=docs_iam_console
I created a new IAM user called java-demo and Policy called ECR-PushImages that should allow this IAM user to push to any ECR Repository.
If I were working in an enterprise environment, I would restrict resources, but since this is home studies, I'm leaving it open.
- AWS Access Key ID: <access key for java-demo IAM user>
- AWS Secret Access Key: <secret access key for java-demo IAM user>
- Default region name: us-east-1
- Default output format: json
C:\>aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin **********.dkr.ecr.us-east-1.amazonaws.com Login Succeeded






