It is possible to allow pulling from but not pushing to the Docker API VPC Endpoint (com.amazonaws.<region>.ecr.dkr
) in its attached policy?
I can't find a reference for any supported actions other than "*"
, is there a way to specify pull only? Or something via a condition?