Skip to content

Configurable ECR tag TTLs with branch- default - #57

Closed
kosanna wants to merge 36 commits into
masterfrom
adjust-branch-ttl
Closed

kosanna wants to merge 36 commits into
masterfrom
adjust-branch-ttl

Conversation

@kosanna

@kosanna kosanna commented Apr 13, 2026 •

Copy link
Copy Markdown
Collaborator

Support branch-specific image retention policies in ECR

With container scanning enabled, temporary branch images can accumulate in repositories and create noise/cost + keep vulerabilities "stuck" in teams dashboards for up to 30 days (current default), even if fixed.

Ideally, users would need to have a way to aggressively clean up branch images while maintaining longer retention for primary/master images to enable fast deployments.

This PR adds support for configurable, tag-based lifecycle policies in ECR. Allows users to specify a TTL specifically for images tagged with desired patterns, while keeping other images under the original max-age-days default policy.

Changes

  • Add new default for branch- tags (gantry standard) to 1 day
  • Add pattern + ttl configuration option to override 30 days default for custom patterns. Can specify up to 8 rules (because we have limit of 10 total and 2 defaults already)

Expected benefits:

  • Reduces noise from branch image CVE findings
  • Lowers storage costs by preventing branch image accumulation
  • Provides leverage for teams to do more fine-grained customisation on ttls

@kosanna
kosanna marked this pull request as ready for review April 14, 2026 02:22
@kosanna
kosanna requested a review from Copilot April 14, 2026 02:23
@kosanna
kosanna marked this pull request as draft April 14, 2026 02:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds configurable, tag-prefix-based ECR lifecycle rules so branch images can expire much sooner than long-lived tags, reducing storage and scan noise while keeping a longer catch-all retention.

Changes:

  • Introduces tag-ttl configuration to set per-tag-prefix TTLs for ECR lifecycle policies.
  • Adds a default TTL of 1 day for branch--prefixed tags.
  • Updates documentation to describe new retention behavior and configuration.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.

File Description
plugin.yml Adds tag-ttl configuration schema entry.
hooks/lib/ecr-registry-provider.bash Builds multi-rule ECR lifecycle policy using tag-prefix TTL mappings + catch-all max age.
README.md Documents default branch retention and new tag-ttl configuration.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread README.md Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread tests/tag-ttl.bats Outdated
Comment thread tests/gcr-registry-provider.bats
Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread README.md Outdated
kosanna and others added 6 commits April 14, 2026 15:35
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread README.md Outdated
Comment thread tests/tag-ttl.bats Outdated
Comment thread hooks/lib/ecr-registry-provider.bash
Comment thread README.md

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 3 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread README.md
Comment thread hooks/lib/ecr-registry-provider.bash Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 3 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread README.md Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread hooks/lib/ecr-registry-provider.bash

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread hooks/lib/ecr-registry-provider.bash Outdated
Comment thread tests/tag-ttl.bats Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 3 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread hooks/lib/tag-ttl-validation.bash Outdated
@@ -0,0 +1,58 @@
validate_tag_ttl_env_vars() {
local base_var='BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_'
declare -A prefix_indices ttl_indices

Copilot AI Apr 15, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This validator uses declare -A associative arrays, which requires Bash 4+. Since the hooks run under #!/usr/bin/env bash (and macOS agents commonly provide Bash 3.2), this will hard-fail with a syntax error on those environments. Consider rewriting this without associative arrays (e.g., collect indices in regular arrays / strings and check membership), or explicitly documenting/enforcing a Bash 4+ requirement for the plugin.

Copilot uses AI. Check for mistakes.
Comment thread hooks/lib/tag-ttl-validation.bash Outdated
Comment thread hooks/lib/tag-ttl-validation.bash Outdated
Comment on lines +25 to +31
log_fatal "tag-ttl entry ${idx} has TTL but no PREFIX; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1
fi
done

for idx in "${!prefix_indices[@]}"; do
if [[ -z "${ttl_indices[$idx]:-}" ]]; then
log_fatal "tag-ttl entry ${idx} has PREFIX but no TTL; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1

Copilot AI Apr 15, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same issue here: the message mentions TAG_TTL_${idx}_PREFIX / TAG_TTL_${idx}_TTL, but those env vars don’t exist. Please update the error to reference BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_PREFIX and ..._${idx}_TTL (or the corresponding tag-ttl[${idx}] config keys) so users can fix the right setting.

Suggested change
log_fatal "tag-ttl entry ${idx} has TTL but no PREFIX; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1
fi
done
for idx in "${!prefix_indices[@]}"; do
if [[ -z "${ttl_indices[$idx]:-}" ]]; then
log_fatal "tag-ttl entry ${idx} has PREFIX but no TTL; both TAG_TTL_${idx}_PREFIX and TAG_TTL_${idx}_TTL must be configured" 1
log_fatal "tag-ttl entry ${idx} has TTL but no PREFIX; both BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_PREFIX and BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_TTL must be configured (or the corresponding tag-ttl[${idx}].prefix and tag-ttl[${idx}].ttl config keys)" 1
fi
done
for idx in "${!prefix_indices[@]}"; do
if [[ -z "${ttl_indices[$idx]:-}" ]]; then
log_fatal "tag-ttl entry ${idx} has PREFIX but no TTL; both BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_PREFIX and BUILDKITE_PLUGIN_DOCKER_ECR_CACHE_TAG_TTL_${idx}_TTL must be configured (or the corresponding tag-ttl[${idx}].prefix and tag-ttl[${idx}].ttl config keys)" 1

Copilot uses AI. Check for mistakes.
kosanna and others added 3 commits April 17, 2026 10:24
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@kosanna kosanna closed this Apr 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants