Skip to content
cdkd

Images in cdkd local run-task

cdkd local run-task pulls a public image, logs in to ECR for a private one, and builds a CDK asset image from the cloud assembly. This page covers three cases where the image a container names needs more explanation.

Images that reference the stack

An image taken from an ECR repository in the same stack has no fixed URI in the template:

const repo = new ecr.Repository(this, 'Repo');

taskDef.addContainer('web', {
  image: ecs.ContainerImage.fromEcrRepository(repo, 'latest'),
});

CDK synthesizes the image URI as an Fn::Sub or Fn::GetAtt that refers to the repository, the account and the region. cdkd resolves each part before it fetches the image:

Part of the image URI Resolved from Needs a state flag
${AWS::AccountId}, ${AWS::Region}, ${AWS::Partition}, ${AWS::URLSuffix} STS and the region No
A same-stack AWS::ECR::Repository (${<LogicalId>}, or Fn::GetAtt of Arn | RepositoryUri) The deployed repository name Yes

The repository's name exists only after a deploy, so the stack must have been deployed first. Pass the flag that matches how it was deployed:

# deployed with cdkd deploy
cdkd local run-task MyStack/TaskDef --from-state

# deployed with the AWS CDK CLI
cdkd local run-task MyStack/TaskDef --from-cfn-stack

Without either flag, a reference to a same-stack repository fails with an error that names the two flags.

Which registry hosts are treated as ECR

cdkd must log in before it can pull from a private ECR registry, so it decides from the image's host name whether the registry is ECR. It logs in to the exact host the image names. An image on a FIPS endpoint, a dual-stack endpoint or another account's registry therefore authenticates on its own endpoint.

Host shape Recognized
<account>.dkr.ecr.<region>.<urlSuffix> Yes
<account>.dkr.ecr-fips.<region>.<urlSuffix> In commercial and GovCloud regions
<account>.dkr-ecr[-fips].<region>.on.aws (dual-stack) In commercial and GovCloud regions
A host whose suffix belongs to another region's partition No
A region prefix cdkd does not know yet No

An image whose host has a region prefix cdkd does not know yet is pulled anonymously, and a debug line says that the host looked like ECR.

Letter case in the host is ignored. A host that contains a non-ASCII character is refused.

Partition and URL suffix by region

cdkd derives the partition and the URL suffix from the region. It uses the same mapping wherever it substitutes ${AWS::Partition} and ${AWS::URLSuffix}.

Region prefix Partition URL suffix
us-gov-* aws-us-gov amazonaws.com
cn-* aws-cn amazonaws.com.cn
us-iso-* aws-iso c2s.ic.gov
us-isob-* aws-iso-b sc2s.sgov.gov
eu-isoe-* aws-iso-e cloud.adc-e.uk
us-isof-* aws-iso-f csp.hci.ic.gov
eusc-* aws-eusc amazonaws.eu
everything else aws amazonaws.com

Which images are built as CDK assets

A CDK asset image, such as one from ContainerImage.fromAsset, is built locally from the cloud assembly. cdkd recognizes an asset image by the name of the repository in its URI, which must be a container-assets repository:

Repository Recognized
cdk-<qualifier>-container-assets-<acct>-<region>, any qualifier Always
cdkd-container-assets-<acct>-<region> Always
A custom name from cdkd bootstrap --container-repo <name> Under --from-state, when the region's bootstrap marker can be read

An asset image that cdkd does not recognize is pulled from ECR. The pull is slower than a local build, and the result is otherwise the same.

Last updated: