Medium EC2 Regional

VPCs should be configured with an interface endpoint for ECR API

NIST 800-53

Description

Verifies that VPC interface endpoints are available for the Amazon ECR API.


Remediation

Create a VPC interface endpoint for ECR API to enable private connectivity to Amazon ECR.

Steps

  1. Open the Amazon VPC console.
  2. In the navigation pane, choose 'Endpoints'.
  3. Choose 'Create endpoint'.
  4. Select 'AWS services' as the service category.
  5. Choose 'com.amazonaws.region.ecr.api' as the service.
  6. Select your VPC and subnets.
  7. Choose a security group and policy.
  8. Choose 'Create endpoint'.

Compliance

NIST 800-53