Repository access control

Updated at:

Use Resource Access Management (RAM) to grant different levels of image permissions to RAM users, or Security Token Service (STS) to grant temporary image permissions.

Prerequisites

A RAM user has been created by using your Alibaba Cloud account. For more information, see Create a RAM user.

Background information

Resource Access Management (RAM) and Security Token Service (STS) provide flexible, secure access control for image repositories. By default, an Alibaba Cloud account has full permissions on the resources it owns. Use RAM and STS to grant different permissions on image resources to different RAM users and to provide temporary access. Before you configure authorization policies, read .

Important

After you configure authorization policies for a RAM user, use that RAM user to log on to the Container Registry console, create a Personal Edition instance, and set a registry password. You can then view the images that the RAM user has permissions on.

Grant permissions to a RAM user

When granting permissions to a RAM user, follow the principle of least privilege to avoid granting excessive permissions.

Important

If you grant a RAM user the AdministratorAccess permission, which includes management permissions on all Alibaba Cloud resources, the RAM user has all permissions on Container Registry, regardless of any previously granted Container Registry permissions.

Attach system policies to a RAM user

By default, the AliyunContainerRegistryFullAccess and AliyunContainerRegistryReadOnlyAccess policies are created for Container Registry. These policies can be attached directly to a RAM user. The following list describes the system policies:

  • AliyunContainerRegistryFullAccess

    This policy grants a RAM user the same permissions on image resources as the Alibaba Cloud account. The RAM user can perform all operations on image resources.

    {
      "Statement": [
        {
          "Action": "cr:*",
          "Effect": "Allow",
          "Resource": "*"
        }
      ],
      "Version": "1"
    }
                        
  • AliyunContainerRegistryReadOnlyAccess

    This policy grants a RAM user read-only permissions on all image resources. For example, the RAM user can view the repository list and pull images.

    {
      "Statement": [
        {
          "Action": [
            "cr:Get*",
            "cr:List*",
            "cr:PullRepository"
          ],
          "Effect": "Allow",
          "Resource": "*"
        }
      ],
      "Version": "1"
    }
                        

This section describes how to grant the AliyunContainerRegistryReadOnlyAccess policy to a RAM user.

  1. Log on to the RAM console.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, find the RAM user and click Actions in the Attach Policy column.

    Alternatively, you can select multiple RAM users and click Attach Policy at the bottom of the list to grant permissions to them all at once.

  4. Authorize

    1. Select an authorization scope.

      • Account: The permissions apply within the current Alibaba Cloud account.

      • resource: The permissions apply within the specified resource group.

        Note

        To grant permissions at the resource group level, the cloud service must support resource groups. For more information, see Services that support resource groups.

    2. Specify the principal.

      The principal is the user who will receive the permissions. The RAM user you selected is automatically specified as the principal.

    3. In the Policies search box, search for AliyunContainerRegistryReadOnlyAccess, and then click AliyunContainerRegistryReadOnlyAccess in the results list.

    4. Click OK.

  5. Click Off.

Attach custom policies to a RAM user

To enforce fine-grained permission control, create custom policies and attach them to RAM users.

Policy configurations in typical scenarios

The following sections describe how to configure custom policies for typical scenarios:

  • Scenario 1: Grant a RAM user the read permission on a namespace. In this example, the namespace is named juzhong.

    After the RAM user logs on to the Container Registry instance, the RAM user can pull all images in the juzhong namespace. The RAM user can also call API operations to view information about the namespace and all repositories in it.

    {
      "Statement": [
        {
          "Action": [
            "cr:Get*",
            "cr:List*",
            "cr:PullRepository"
          ],
          "Effect": "Allow",
          "Resource": [
            "acs:cr:*:*:repository/juzhong/*"
          ]
        }
      ],
      "Version": "1"
    }
                        
    Important

    If you want to allow the RAM user to view all namespaces in the Container Registry console, add the following authorization configurations. The RAM user can then view all namespaces and repositories, but can pull images only from repositories in the juzhong namespace.

    {
      "Statement": [
        {
          "Action": [
            "cr:Get*",
            "cr:List*",
            "cr:PullRepository"
          ],
          "Effect": "Allow",
          "Resource": [
            "acs:cr:*:*:repository/juzhong/*"
          ]
        },
        {
          "Action": [
            "cr:ListNamespace",
            "cr:ListRepository"
          ],
          "Effect": "Allow",
          "Resource": [
            "*"
          ]
        }
      ],
      "Version": "1"
    }
                        
  • Scenario 2: Grant a RAM user all permissions on a repository. In this example, the repository is named nginx, belongs to the juzhong namespace, and is located in the China (Hangzhou) region.

    Important

    If you want to allow the RAM user to manage repositories in the Container Registry console, add the configurations described in scenario 1.

    {
      "Statement": [
        {
          "Action": [
            "cr:*"
          ],
          "Effect": "Allow",
          "Resource": [
            "acs:cr:cn-hangzhou:*:repository/juzhong/nginx"
          ]
        },
        {
          "Action": [
            "cr:Get*",
            "cr:List*"
          ],
          "Effect": "Allow",
          "Resource": [
            "acs:cr:*:*:repository/juzhong"
          ]
        }
      ],
      "Version": "1"
    }
                        
  • Scenario 3: Allow a RAM user to only push images to a specific repository.

    The following policy allows a RAM user to only push images to the specified repository:

    {
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "cr:PushRepository",
            "cr:GetAuthorizationToken"
          ],
          "Resource": [
            "acs:cr:*:*:repository/<namespace>/<repository>"
          ]
        }
      ],
      "Version": "1"
    }
                        

    cr:GetAuthorizationToken is used by docker login to obtain an access credential, which is required before you can push images. Replace <namespace> and <repository> with actual values. To grant push permissions on all repositories in a namespace, use acs:cr:*:*:repository/<namespace>/*.

  • Scenario 4: Grant all permissions on a namespace to a RAM user.

    Important

    This scenario is supported only through API calls. If you want to allow the user to view all repositories in the Container Registry console, add the configurations described in scenario 1.

    {
        "Statement": [
            {
                "Action": [
                    "cr:*"
                ],
                "Effect": "Allow",
                "Resource": [
                    "acs:cr:cn-hangzhou:*:repository/juzhong",
                    "acs:cr:cn-hangzhou:*:repository/juzhong/*"
                ]
            }
        ],
        "Version": "1"
    }

Create a custom policy using one of the preceding scripts, then attach it to the RAM user as follows:

  1. Create a custom policy.

    1. Log on to the RAM console by using your Alibaba Cloud account.

    2. In the left-side navigation pane, choose Permissions > Policies.

    3. On the Policies page, click Create Policy.

    4. On the Create Policy page, click the JSON Editor tab and edit the policy document in the code editor. For more information about the policy syntax, see Policy structure and syntax.

      For more information about configuring the Action and Resource parameters in the policy document, see Authentication rules for Container Registry.
    5. Click Confirm. In the Create Policy dialog box, configure the Policy Name and Notes parameters.

  2. Attach the custom policy to a RAM user.

    1. Log on to the RAM console by using your Alibaba Cloud account.

    2. In the left-side navigation pane, choose Identities > Users.

    3. On the User page, find the RAM user to which you want to attach the custom policy, and click Add Permission in the Actions column.

    4. In the Authorize panel, grant permissions to the RAM user.

      1. Select the authorization scope.

        • Account: The permissions apply within the current Alibaba Cloud account.

        • resource: The permissions apply within the specified resource group.

          If you select ResourceGroup for the Resource Scope parameter, make sure that the cloud service supports resource groups. For more information, see Services that work with Resource Group.
      2. Specify a principal.

        The principal is the RAM user to which you want to grant permissions. By default, the current RAM user is specified. You can also specify another RAM user.

      3. Click Custom Policy below All Types from the drop-down list, enter a custom policy name in the search box to search for the custom policy, and then click the name of the custom policy.

      4. Click OK.

    5. Click Off.

Authentication rules for Container Registry

The following table describes the Alibaba Cloud Resource Name (ARN) format in an authorization policy when you use RAM to grant permissions to users.

Resource

ARN format

repository

acs:cr:$regionid:$accountid:repository/$namespacename/$repositoryname

The following table describes the parameters in the ARN format.

Parameter

Description

regionid

The region ID. Use an asterisk (*) to specify all regions.

accountid

The numeric ID of the Alibaba Cloud account. Use an asterisk (*) to specify all accounts.

namespacename

The name of the namespace.

repositoryname

The name of the image repository.