TL;DR: ECR tokens expire every 12 hours; refresh the login with `aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin ACCOUNT.dkr.ecr.us-east-1.amazonaws.com`. Then retry the pull. There is no static ECR password; every 'unauthorized' from ECR means mint a fresh token.

## The error

```text
unauthorized: authentication required (AWS ECR docker pull and push)
```

## Fix it

1. Mint a fresh token and log in (replace region/account):
   `aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin ACCOUNT.dkr.ecr.us-east-1.amazonaws.com`
   Expected: `Login Succeeded`.
2. Retry:
   `docker pull ACCOUNT.dkr.ecr.us-east-1.amazonaws.com/myrepo:tag`
   Expected: succeeds.

## When this applies
- Any ECR pull/push failing with unauthorized
- CI jobs running longer than 12 hours

## When this does NOT apply
- Docker Hub unauthorized (static credentials, separate skill)
- IAM permission errors (those surface as denied with a policy message)

## Versions
All Docker versions; AWS CLI v1/v2.

## Why it happens
ECR issues 12-hour authorization tokens, not passwords. The daemon caches the token in ~/.docker/config.json; once it expires, every registry call 401s until you log in again.

## Edge cases
- In CI, run the get-login-password step at the START of every job, not once per day.
- ECR credential helper (amazon-ecr-credential-helper) automates refresh; configure `"credsStore": "ecr-login"` to stop thinking about it.
- Cross-account: the AWS principal needs ecr:GetAuthorizationToken plus repository permissions; missing repo perms give 'denied', not 'authentication required'.
