Container Supply Chain: ECR Scan on Push and Lifecycle Policies
Keep container registries safe and tidy. You enable scan on push, build and push several image versions from CodeBuild, read the vulnerability findings, and add a lifecycle policy that keeps only the latest releases.
Level: Advanced · Time: about 50 minutes · Region: us-east-1
AWS services you'll use
- ECR
- CodeBuild
What you'll do in this lab
- Create the repository
- Build and push images from CodeBuild
- Review scan findings
- Keep the registry tidy
- Verify the solution end to end
Each task is checked against your live AWS account. Step-by-step instructions, hints and verification unlock when you start the lab.
Before you start
- Associate-level experience with CI/CD, IAM roles and CloudFormation
- Comfortable with CloudShell, git-less zip workflows and YAML
How the lab works
- Get a real, temporary AWS account locked to one region. No AWS account of your own needed.
- Build in the real AWS console with a guide beside it, and hints when you are stuck.
- Verify every task: we check the resources in your live account.
- Automatic cleanup: everything is deleted when you stop, and nothing is billed to you.
Questions about this lab
Do I need my own AWS account?
No. When you start the lab, Cloud Arena gives you a real, temporary AWS account with its own login, locked to one region. You work in the real AWS Management Console, not a simulator.
Will AWS charge me anything?
No. Cloud Arena pays for the AWS resources, and everything you create is deleted automatically when you stop the lab or the session ends. Nothing is billed to you by AWS.
How long does the Container Supply Chain: ECR Scan on Push and Lifecycle Policies lab take?
Plan for about 50 minutes. The session timer is shown on screen, and every task is checked against your live AWS account when you click Verify.
How do I get access to this lab?
It is included in the AWS Certified DevOps Engineer – Professional plan: a one-time payment for every lab in the path, 2 attempts per lab and a 7-day money-back guarantee. You can also start with the 5 free labs.
Does this lab help with the DevOps Engineer – Professional (DOP-C02) exam?
Yes. It is part of the AWS Certified DevOps Engineer – Professional path, which covers the hands-on skills behind the exam. Doing the task in a real account is what makes the questions easier to reason about.
Related AWS labs
- Chaos Engineering with AWS FIS: Prove the Web Tier Survives Instance Loss
- CodeDeploy In-Place Deployments to EC2 with AppSpec Lifecycle Hooks
- Continuous Integration with CodePipeline and CodeBuild: Tests and Reports
- Safe Lambda Releases: SAM Canary Deployments with Alarm-Based Rollback
- Stream Logs in Real Time: CloudWatch Logs Subscription to Kinesis and Lambda
- CodeBuild: Secrets from Parameter Store and Secrets Manager, and Build Caching