ECS: ResourceInitializationError: unable to pull secrets or registry auth
Fargate couldn’t fetch the task’s secrets (Secrets Manager/SSM) or registry credentials before starting containers.
Seen on:
AWS
Meaning
The task execution role needs permission to read referenced secrets (and kms:Decrypt for customer keys), and the task needs a network path to Secrets Manager/SSM (NAT or VPC endpoints).
Common causes
- Execution role lacks secretsmanager:GetSecretValue / ssm:GetParameters
- Customer-managed KMS key not allowed
- No route to Secrets Manager/SSM from private subnets
- Secret ARN/name wrong
⚡ Quick fix
- Grant the execution role read access to those secrets (and KMS)
- Add VPC endpoints or NAT
- Check the secret ARN in the task definition
Detailed fix by platform
IAM
{ "Effect": "Allow", "Action": ["secretsmanager:GetSecretValue", "ssm:GetParameters", "kms:Decrypt"], "Resource": ["arn:aws:secretsmanager:eu-west-1:123456789012:secret:app/*"] }
How to diagnose
- Role — Execution role (not task role) policies
- Network — Endpoints/NAT
- ARN — Correct secret reference
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026