How do I get AWS Batch to run jobs using private repository?

Viewed 458

I'm trying to run a batch job on a container with AWS Batch using Fargate spot instances. What I have accomplished so far:

  • Upload image to ECR via CI pipeline into a private repository
  • Successfully ran job on ECS Fargate cluster
    • Created proper ECSTaskExecutionRole (as described in AWS docs)
    • Did not enable private repository authentication (the ECSTaskExecutionRole has "ecr:GetAuthorizationToken"... in my mind that suffices to fetch a token and pull the image. I also don't see the reason to store secrets somewhere when I can handle everything with IAM permissions... am I wrong?)
    • I ran the cluster in a
      • dedicated VPC with 2 public subnets
      • an IGW (Outbound allow all, inbound allow HTTP, HTTPS and SSH)
      • enabled auto-assign public IPv4 and DNS

Now I am actually trying to run the job with AWS Batch on Fargate spot instances. So I basically use the same setup but with a different compute environment (can't use my default one for some reason). And what I'm seeing is this error:

ResourceInitializationError: unable to pull secrets or registry auth: execution resource retrieval failed: unable to retrieve ecr registry auth: service call has been retried 1 time(s): InvalidParameterException: Invalid parameter at 'registryIds' fail...

Now, I also tried to run a generic Hello World job created with the AWS Batch Wizard which results in this error:

CannotPullContainerError: inspect image has been retried 5 time(s): failed to resolve ref "docker.io/library/amazonlinux:latest": failed to do request: Head https://registry-1.docker.io/v2/library/amazonlinux/manifests/latest: dial tcp 18.214.230.110:4...

I tried to identify the differences between the task created in the ECS console and the task created in the Batch console. The only difference I could find was that the latter uses the "com.amazonaws.ecs.capability.docker-remote-api.1.22" next to 1.18 and 1.19. The task created with ECS is not using 1.22 ...

I already checked out the other answers regarding that topic, but couldn't solve the issue so far...

0 Answers
Related