# Ipa Stack Ecr

> Deploy an ECR repository for container image storage.

- Skill: `aws-samples/ipa-stack-ecr` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add aws-samples/ipa-stack-ecr`
- Raw SKILL.md: https://api.skillmd.com/api/skills/aws-samples/ipa-stack-ecr/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: aws-samples (https://skillmd.com/u/aws-samples)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/aws-samples/ipa-stack-ecr

---


# ipa-stack-ecr

Deploy an ECR container image repository. Provides repository URI and ARN outputs for downstream Lambda stacks and security policy scoping.

## Stack Identity

| Property | Value |
|----------|-------|
| Stack name | `{APP_NAMESPACE}-{APP_ENV}-ecr` |
| Template | `infra/cfn/ecr/ecr.yml` |
| Capabilities | none |
| Lifecycle | prepare (prerequisite stack) |
| Tier | ecr |

## Parameters

| Parameter | Type | Default | Validation | Error Message |
|-----------|------|---------|------------|---------------|
| Namespace | String | — | `/^[a-z][a-z0-9-]{0,11}$/` | "Invalid namespace — 1-12 chars, lowercase alphanumeric + hyphens, starts with letter" |
| Environment | String | — | `/^[a-z][a-z0-9-]{0,11}$/` | "Must be 1-12 chars, lowercase letters/digits/hyphens, starts with letter" |

All parameters are **Configuration** type — sourced from `.env` or defaults. No wirable parameters from other stacks.

## Outputs

| Output | Description | Export Convention | Used By |
|--------|-------------|------------------|---------|
| RepositoryUri | ECR repository URI for container images | `{StackName}-RepositoryUri` | ipa.stack.lambda-fn (ImageUri), ipa.stack.lambda-fn-stream (ImageUri) |
| RepositoryArn | ECR repository ARN for security policy scoping | `{StackName}-RepositoryArn` | Security policy scoping |

## Security Summary

**Required IAM actions**: ecr:CreateRepository, DeleteRepository, DescribeRepositories, TagResource — scoped to `arn:aws:ecr:{Region}:{AccountId}:repository/*`. ecr:GetAuthorizationToken on `*` (AWS API limitation — this action does not support resource-level permissions)
**Security controls**: Encryption at rest (AES256), no public access, no automatic deletion on stack removal
**Full advisory**: See [SECURITY.md](SECURITY.md)

## Terraform Module

| Property | Value |
|----------|-------|
| Module path | `infra/tf/ecr/` |
| State key | `{namespace}-{env}/ecr/terraform.tfstate` |
| Required version | `>= 1.5.0` |
| Providers | `hashicorp/aws >= 5.0` |

### Variables

| Variable | Type | Default | Maps to CFN |
|----------|------|---------|-------------|
| namespace | string | — | Namespace |
| environment | string | — | Environment |
| region | string | — | (implicit) |
| state_bucket | string | — | (TF infrastructure) |

### Outputs

| Output | Maps to CFN |
|--------|-------------|
| repository_uri | RepositoryUri |
| repository_arn | RepositoryArn |

