---
title: "Ensure ECR repositories are encrypted"
canonical: "https://kb.cynergy.app/space/MD/991593141/Ensure%20ECR%20repositories%20are%20encrypted"
format: markdown
---
Cynergy Policy ID: CYN_AWS_GENERAL_53  
Severity: LOW

# Unencrypted ECR repositories

# Description

Encrypting your ECR repositories helps protect your data from unauthorized access or tampering. That way, you can ensure that only authorized users can access and modify the contents of your repositories. Such action can help protect against external threats such as hackers or malware, as well as internal threats such as accidental or unauthorized access.

# Fix - Build time

## Terraform

- **Resource:** aws_ecr_repository
- **Argument:** encryption_configuration.encryption_type

Go

```go
resource "aws_ecr_repository" "example" {
  ...
  name                 = "bar"
+ encryption_configuration {
+   encryption_type = "KMS"
+ }
}

```

## CloudFormation

- **Resource:** AWS::ECR::Repository
- **Argument:** Properties.EncryptionConfiguration.EncryptionType

YAML

```yaml
Resources:
  KMSEncryption:
    Type: AWS::ECR::Repository
    Properties: 
      ...
+     EncryptionConfiguration:
+       EncryptionType: "KMS"
        ...

```