
The integration with rest of AWS ecosystem is what I like the most. We are running our workloads on ECS and EKS, so having the container registry inside same AWS environment makes everything very smooth. Image pulls are fast, authentication is handled through IAM, no separate login system to manage.
The image vulnerability scanning is something I was not expecting to be so useful but it has become part of our regular workflow now. Every time we push a new image, scan runs automatically and we can see if there are any critical issues before deployment. That has saved us few times from pushing problematic images to production.
UI is simple and straightforward. It is not very fancy but for what we need, finding images, checking tags, reviewing scan results, it gets the job done without confusion. My team members who are not very deep into DevOps side, they can also navigate it without much hand holding.
Private registry with fine grained IAM permissions is also very helpful. We have different teams working on different services and we can control exactly who can push and who can only pull. That level of access control was not possible when we were on DockerHub.
The AI and intelligence side of ECR is honestly not very deep. It is mainly a storage and registry service, so do not expect any smart features out of the box.
Overall the biggest benefit is that ECR just works quietly in background without giving any trouble. In our deployment pipeline it is one less thing to worry about, and for a busy engineering team that peace of mind has real value. Review collected by and hosted on G2.com.
Main frustration is the pricing visibility. Data transfer costs and storage costs are not very straightforward to estimate upfront. Few times our monthly bill came higher than expected and we had to dig through Cost Explorer to understand what exactly happened. A clearer cost breakdown inside ECR console itself would help a lot.
Lifecycle policies are useful but the configuration is not very intuitive. First time setting up automatic cleanup of old images, I had to read documentation multiple times to get it right. For something that should be a basic hygiene feature, it should be much simpler to configure.
The console UI is quite basic. Most operations require going to CLI or writing scripts. For team members who are not very command line comfortable, this creates dependency on DevOps person for even simple tasks like checking image details or manually deleting old tags.
Cross region replication took us lot of trial and error to set up correctly for our multi region deployment. Documentation exists but it does not cover all the edge cases we ran into. Support response was also not very fast when we raised ticket.
Error messages during image push or pull failures are sometimes very vague. It will say authentication failed or access denied but not give enough detail to immediately understand what exactly went wrong. Debugging these issues wastes good amount of time.
Overall ECR is reliable service but these rough edges around cost transparency, usability and error reporting need improvement for it to be truly production team friendly without heavy DevOps involvement. Review collected by and hosted on G2.com.