# Issue with Docker update module and AWS ECR credential helper

**URL:** <https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793>\
**Category:** General Discussions\
**Tags:** docker, aws\
**Created:** [June 25, 2021, 12:26am UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793 "2021-06-25T00:26:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![agrue](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@agrue](https://hub.mender.io/u/agrue)\
**Post date:** [June 25, 2021, 12:26am UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793/1 "2021-06-25T00:26:49Z")

</div>

Hello,

I am trying to manage a docker image hosted on AWS Elastic Container Registry using the docker update module.

AWS ECR uses [AWS ECR Credential Helper](https://github.com/awslabs/amazon-ecr-credential-helper) to manage authentication.

Everything works great until the ArtifactInstall phase when the docker daemon errors out unauthorized, as it would if the cred helper was not installed or the pull was attempted for some other private repo.

I’m able to pull the image listed in the mender artifact manifest without issue, and there’s only a root user configured on this install (aws cred store is configured for the user running mender daemon).

Is there maybe an environment issue I’m missing here? Thanks!

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [June 25, 2021, 1:20pm UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793/2 "2021-06-25T13:20:33Z")

</div>

Is there maybe some environment variable setup or some such you need to access the credential helper?

---

<div class="post-metadata">

**Author:** ![agrue](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@agrue](https://hub.mender.io/u/agrue)\
**Post date:** [June 25, 2021, 2:31pm UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793/3 "2021-06-25T14:31:26Z")

</div>

The binary just needs to be available on the path, `/usr/sbin` in my case.

After that, [credential helpers for docker](https://docs.docker.com/engine/reference/commandline/login/#credential-helpers) are defined in `~/.docker/config.json`:

```auto
{
        "credHelpers": {
                "reponumber.ecr.us-east-1.amazonaws.com": "ecr-login"
        }
}

```

Which should look for `docker-credential-ecr-login` on the path when dealing with `reponumber.ecr.us-east-1.amazonaws.com`. The ecr helper looks for some config in `~/.aws`, specifically a region and set of creds.

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [June 25, 2021, 3:39pm UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793/4 "2021-06-25T15:39:16Z")

</div>

@Alan @lramirez any ideas?

---

<div class="post-metadata">

**Author:** ![agrue](https://avatars.discourse-cdn.com/v4/letter/a/3ec8ea/32.png) [@agrue](https://hub.mender.io/u/agrue)\
**Post date:** [July 2, 2021, 11:09pm UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793/5 "2021-07-02T23:09:46Z")

</div>

Turns out the `HOME` env variable when running the update module was set to `/root`, a nonexistent directory on my install. Correcting it to `/home/root` brought things in line.

Not sure if there’s some logic behind this but it feels like a bug? Maybe `HOME` should either be inherited or match the user running mender daemon.

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [July 6, 2021, 2:48pm UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793/6 "2021-07-06T14:48:16Z")

</div>

That’s interesting. I definitely think it can be fixed. @Alan do you want to take a look?

---

<div class="post-metadata">

**Author:** ![tbraunjones](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tbraunjones/32/2169_2.png) [@tbraunjones](https://hub.mender.io/u/tbraunjones)\
**Post date:** [May 6, 2024, 5:14pm UTC](https://hub.mender.io/t/issue-with-docker-update-module-and-aws-ecr-credential-helper/3793/7 "2024-05-06T17:14:54Z")

</div>

Any update on this? It still seems to be an issue. I had to do:

```auto
ln -s /home/root /root

```

To get the docker update module to work.
