更新 AWS ECR permission policy

import sys
import boto3
reponame=sys.argv[1]
client = boto3.client('ecr')
response = client.set_repository_policy(
    registryId='123455667789',
    repositoryName="abcd/"+reponame,
    policyText="{\n  \"Version\" : \"2008-10-17\",\n  \"Statement\" : [ {\n    \"Sid\" : \"For ECR PPE/Prod account\",\n    \"Effect\" : \"Allow\",\n    \"Principal\" : {\n      \"AWS\" : [ \"arn:aws:iam::234556677899:root\", \"arn:aws:iam::3535346457578:root\" ]\n    },\n    \"Action\" : [ \"ecr:GetDownloadUrlForLayer\", \"ecr:BatchGetImage\", \"ecr:BatchCheckLayerAvailability\", \"ecr:ListImages\" ]\n  } ]\n}",
   force=False
)ip

相關文章
相關標籤/搜索