1. In IAM, create a role with the policy AmazonEC2ContainerRegistryReadOnly
  2. Add it to the EC2 instance