ECR Pull Through Cache and VPC Endpoints for ECS

Answer Correct answer: C, E — Implement ECR pull-through cache for public images and create Interface VPC endpoints for private repositories to allow internal access without internet.

A company is running an internal application in an Amazon Elastic Container Service (Amazon ECS) cluster on Amazon EC2. The ECS cluster instances can connect to the public internet. The ECS tasks that run on the cluster instances are configured to use images from both private Amazon Elastic Container Registry (Amazon ECR) repositories and a public ECR registry repository. A new security policy requires the company to remove the ECS cluster's direct access to the internet. The company must remove any NAT gateways and internet gateways from the VPC that hosts the cluster. A DevOps engineer needs to ensure the ECS cluster can still download images from both the public ECR registry and the private ECR repositories. Images from the public ECR registry must remain up-to-date. New versions of the images must be available to the ECS cluster within 24 hours of publication. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose three.)

  1. Create an AWS CodeBuild project and a new private ECR repository for each image that is downloaded from the public ECR registry. Configure each project to pull the image from the public ECR repository and push the image to the new private ECR repository. Create an Amazon EventBridge rule that invokes the CodeBuild project once every 24 hours. Update each task definition in the ECS cluster to refer to the new private ECR repository.
  2. Create a new Amazon ECR pull through cache rule for each image that is downloaded from the public ECR registry. Create an AWS Lambda function that invokes each pull through cache rule. Create an Amazon EventBridge rule that invokes the Lambda function once every 24 hours. Update each task definition in the ECS cluster to refer to the image from the pull through cache.
  3. Create a new Amazon ECR pull through cache rule for the public ECR registry. Update each task definition in the ECS cluster to refer to the image from the pull through cache. Ensure each public image has been downloaded through the pull through cache at least once before removing internet access from the VPC. Correct Answer
  4. Create an Amazon ECR interface VPC endpoint for the public ECR repositories that are in the VPC.
  5. Create an Amazon ECR interface VPC endpoint for the private ECR repositories that are in the VPC. Correct Answer

Community Insight

The common trap is assuming ECR Public repositories can be accessed via VPC Endpoints; they cannot, requiring a pull-through cache rule instead.

This question tests securing Amazon ECS by using ECR pull-through cache rules to proxy public images and Interface VPC endpoints for private repositories, eliminating the need for NAT or Internet Gateways.

Candidates often select options involving Lambda or CodeBuild for caching (Option B) or assume VPC endpoints work for public registries (Option D), leading to higher operational overhead or technical impossibility.

Community Discussion (5 comments)

Srikantha 👍 1 Selected: CE
C. ECR Pull Through Cache for Public Images This allows public ECR images to be cached in your private ECR. You avoid internet access by referencing the cached copy. Once an image is pulled through the cache, it's stored in private ECR and available for future use even without internet access. Ensures that new versions can still be fetched (within 24h of publication), assuming it's referenced and updated in the cache. Least operational overhead: No need for custom pipelines or daily sync jobs. E. Interface VPC Endpoint for Private ECR Needed to let ECS pull private images without internet or NAT gateway. Interface VPC endpoints connect your VPC to ECR APIs via AWS PrivateLink. F. S3 Gateway Endpoint ECR stores image layers in Amazon S3. When ECS pulls an image, it downloads layers from S3 — so the cluster needs S3 access even if ECR is private. A gateway endpoint provides private S3 access from the VPC.
teo2157 👍 2 Selected: CE
Going with CEF as well
f4b18ba 👍 3 Selected: CE
By using an Amazon ECR pull through cache rule (Option C) and setting up the necessary VPC endpoints for private ECR (Option E) and S3 (Option F), the company can: Eliminate Internet Access: Remove NAT gateways and internet gateways from the VPC. Maintain Image Access: Allow ECS tasks to pull images from both private and public ECR repositories without internet access. Ensure Image Updates: Automatically receive updates to public images within 24 hours via the pull through cache. Minimize Operational Overhead: Avoid complex setups with additional services like CodeBuild, Lambda, or custom scripts.
rainwalker 👍 2
C, E, F https://docs.aws.amazon.com/AmazonECR/latest/userguide/vpc-endpoints.html VPC endpoints currently don't support Amazon ECR Public repositories. Consider using a pull through cache rule to host the public image in a private repository in the same Region as the VPC endpoint. For more information The image metadata and layers in the ECR are stored in Amazon S3. Creating an S3 Gateway endpoint enables the ECS cluster to exchange data between ECR and S3 without the internet.
uncledana 👍 2
By implementing the pull through cache rule and setting up VPC endpoints for both public and private ECR repositories, the ECS cluster can securely access required container images without direct internet access. This approach ensures compliance with the security policy while maintaining operational efficiency and timely updates to images.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To meet the requirements with the least operational overhead while removing internet access, you must address both private and public image sources differently. For private ECR repositories, creating an Amazon ECR Interface VPC endpoint (Option E) allows secure traffic within the VPC without hitting the public internet. For public ECR registry images, since VPC endpoints do not support public registries, you must use an ECR pull-through cache rule (Option C). This caches public images in a private repository within your account, which can then be accessed via the VPC endpoint. Updating task definitions to point to these cached/private sources ensures the cluster functions correctly.

Why the Other Options Are Wrong

Option A involves creating individual CodeBuild projects for each image, which creates significant operational overhead and management complexity compared to a single pull-through cache rule. Option B suggests using Lambda to invoke cache rules, which adds unnecessary complexity and latency; the cache updates automatically on demand or via scheduled tasks if needed, but manual invocation isn't the primary mechanism. Option D is technically incorrect because Amazon ECR Public repositories are global and cannot be accessed via regional VPC endpoints.

Community Comment Notes

Community consensus strongly supports options C, E, and F. Comments highlight that VPC endpoints don't support public ECR, necessitating the pull-through cache. One user noted that S3 Gateway endpoints (Option F in their context, though not listed here as a distinct option in the final three-choice constraint logic usually implies the standard set) are also needed for metadata layers, but based on the provided options, C and E are the critical specific steps for ECR access. Another comment emphasized that the pull-through cache ensures images remain up-to-date and accessible within the VPC.

Official Reference

Exam Strategy

When securing container registries in a restricted VPC, always check if the registry type (Public vs Private) supports VPC endpoints. If it doesn't (like Public ECR), look for 'pull-through cache' as the alternative solution.

Frequently Asked Questions

Can I use a VPC Endpoint for Amazon ECR Public repositories?

No, VPC endpoints do not support ECR Public repositories. You must use a pull-through cache rule to cache public images in a private repository.

Why is Option A not the best choice for caching public images?

Option A requires managing a separate CodeBuild project for each image, creating high operational overhead. The pull-through cache rule automates this efficiently.

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide