# ecr — ECR repository > **Module kind:** L1 primitive | **Version:** 1.0.0 A single ECR repository that hosts the container image for the ECS task. The simplest container-registry module — one resource, two inputs, two outputs. ## Resources | Resource | Type | Purpose | |----------|------|---------| | repository | `aws_ecr_repository` | The ECR repository | ## Inputs | Name | Type | Required | Default | Description | |------|------|----------|---------|-------------| | `name` | string | yes | — | The ECR repository name | | `region` | string | yes | — | AWS region the repository is created in | ## Outputs | Name | Type | Description | |------|------|-------------| | `repository_url` | string | The ECR repository URL | | `repository_arn` | arn | The ECR repository ARN | ## Usage ```json { "id": "ecr", "type": "aws:ecr:repository", "module": "ecr@1.0.0", "inputs": { "name": "acdl-microservice", "region": "us-east-1" } } ``` The `repository_url` output is used to build the `image` input for `ecs-service` (e.g. `:latest`). ## Compliance extension points - **Image scanning** — add `image_scanning_configuration { scan_on_push = true }` for vulnerability scanning (SOC2 CC7.6, DORA ICT risk testing, HIPAA security monitoring). - **Encryption** — add `encryption_configuration { encryption_type = "KMS", kms_key = ... }` with a customer-managed key (SOC2 CC6.1, HIPAA §164.312(a)(2)(iv), GDPR Art.32). - **Image tag immutability** — add `image_tag_mutability = "IMMUTABLE"` to prevent tag overwriting (SOX §802, SOC2 CC6.1 integrity, DORA audit integrity). - **Lifecycle policy** — add `aws_ecr_lifecycle_policy` to enforce image retention / cleanup (GDPR Art.5(2) data minimization, SOC2 CC5.2). - **Access policy** — add a repository policy restricting pull/push to known roles (SOC2 CC6.1, HIPAA §164.308(a)(4)). ## Versioning `1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.