ECS task stopped: CannotPullContainerError: pull image manifest has been retried ... / ref pull has been retried
The ECS task couldn’t pull its image — no network route to the registry, missing ECR permissions, or a wrong image tag.
Seen on:
AWS
Meaning
Fargate/EC2 tasks in private subnets need a NAT gateway or VPC endpoints (ecr.api, ecr.dkr, S3 gateway) to reach ECR. The task execution role needs ECR pull permissions, and the tag must exist.
Common causes
- Private subnet without NAT or ECR/S3 VPC endpoints
- assignPublicIp DISABLED in a public subnet
- Task execution role lacks ecr:GetAuthorizationToken/BatchGetImage
- Image tag doesn’t exist
⚡ Quick fix
- Add NAT or VPC endpoints, or enable public IP in public subnets
- Attach AmazonECSTaskExecutionRolePolicy
- Verify the image URI and tag
Detailed fix by platform
AWS CLI
- bash
aws ecs describe-tasks --cluster app --tasks $TASK --query 'tasks[0].stoppedReason' aws ecr describe-images --repository-name web --image-ids imageTag=1.4.2
How to diagnose
- Reason — stoppedReason text
- Network — Route to ECR?
- Role — Execution role policies
- Tag — Exists?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- ACR unauthorized Azure Container Registry: unauthorized: authentication required, visit https://aka.ms/acr/authorization (AKS ErrImagePull 401)
- actively refused it HttpRequestException: No connection could be made because the target machine actively refused it (localhost:5001)
- Container failed to start Cloud Run: The user-provided container failed to start and listen on the port defined provided by the PORT=8080 environment variable
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026