You probably need to add some policies to your node role, such as
arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly
This article goes through the whole setup.