ResourceInitializationError ☁️ AWS

ECS: ResourceInitializationError: unable to pull secrets or registry auth

Fargate couldn’t fetch the task’s secrets (Secrets Manager/SSM) or registry credentials before starting containers.

Seen on: AWS

Meaning

The task execution role needs permission to read referenced secrets (and kms:Decrypt for customer keys), and the task needs a network path to Secrets Manager/SSM (NAT or VPC endpoints).

Common causes

  • Execution role lacks secretsmanager:GetSecretValue / ssm:GetParameters
  • Customer-managed KMS key not allowed
  • No route to Secrets Manager/SSM from private subnets
  • Secret ARN/name wrong

⚡ Quick fix

  1. Grant the execution role read access to those secrets (and KMS)
  2. Add VPC endpoints or NAT
  3. Check the secret ARN in the task definition

Detailed fix by platform

IAM

  1. { "Effect": "Allow", "Action": ["secretsmanager:GetSecretValue", "ssm:GetParameters", "kms:Decrypt"], "Resource": ["arn:aws:secretsmanager:eu-west-1:123456789012:secret:app/*"] }

How to diagnose

  1. Role — Execution role (not task role) policies
  2. Network — Endpoints/NAT
  3. ARN — Correct secret reference

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.