#Steps to allow-list the upstream repositories ECR Pull-Through Cache will allow
-
Enable ECR Pull-Through Cache by following https://docs.aws.amazon.com/AmazonECR/latest/userguide/pull-through-cache.html?icmpid=docs_ecr_hp-registry-private (and using the default 'ecr-public' namespace)
-
Create a new Registry Permission with the following, substituting your own AWS account number:
{
"Sid": "RestrictCacheApartFrom",
"Effect": "Deny",