In my cloudformation template's AWS::Batch::JobDefinition I have specified the image location as:
Image: !Sub "${FileGenerationImageRepo.RepositoryUri}:latest"
For some reason, this does not work. However, when I specify the actual tag name it works fine
Image: !Sub "${ExportBalancesFileGenerationImageRepo.RepositoryUri}:sometag"
Is there a policy action that I am missing?
Following are my execution role policies
BatchExecutionRole:
Type: AWS::IAM::Role
Properties:
ManagedPolicyArns:
- arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy
- arn:aws:iam::aws:policy/AmazonAPIGatewayInvokeFullAccess
- arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly
AssumeRolePolicyDocument:
Version: '2012-10-17'
Statement:
- Action:
- sts:AssumeRole
Effect: Allow
Principal:
Service:
- ecs-tasks.amazonaws.com
Policies:
- PolicyName: BatchExecutionPolicy
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- ecr:GetAuthorizationToken
- ecr:BatchCheckLayerAvailability
- ecr:GetDownloadUrlForLayer
- ecr:BatchGetImage
- logs:CreateLogStream
- logs:PutLogEvents
Resource: '*'