AWS Batch fails to pull image with latest tag

Viewed 28

In my cloudformation template's AWS::Batch::JobDefinition I have specified the image location as:

Image: !Sub "${FileGenerationImageRepo.RepositoryUri}:latest"

For some reason, this does not work. However, when I specify the actual tag name it works fine

Image: !Sub "${ExportBalancesFileGenerationImageRepo.RepositoryUri}:sometag"

Is there a policy action that I am missing?

Following are my execution role policies

  BatchExecutionRole:
    Type: AWS::IAM::Role
    Properties:
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy
        - arn:aws:iam::aws:policy/AmazonAPIGatewayInvokeFullAccess
        - arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Action:
              - sts:AssumeRole
            Effect: Allow
            Principal:
              Service:
                - ecs-tasks.amazonaws.com
      Policies:
        - PolicyName: BatchExecutionPolicy
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: Allow
                Action:
                  - ecr:GetAuthorizationToken
                  - ecr:BatchCheckLayerAvailability
                  - ecr:GetDownloadUrlForLayer
                  - ecr:BatchGetImage
                  - logs:CreateLogStream
                  - logs:PutLogEvents
                Resource: '*'
0 Answers
Related