Skip to main content

Artifact Registry

Artifact Registry stores container images and other packages in repositories inside a Google Cloud project. The GCP Enterprise Baseline keeps every image of the platform in acme-core-artifacts, one repository per image, where a pushed tag can never be moved.

What it does​

A repository has a format (here Docker), a region and its own IAM: Reader pulls, Writer pushes. Immutable tags refuse to point an existing tag at a different image. Cleanup policies delete or keep versions by tag prefix, tag state and age, or keep the most recent versions; a KEEP policy wins over a DELETE policy, and a dry run reports what would be deleted without deleting it. Vulnerability scanning by Artifact Analysis inspects images on push.

How BuiltForProd uses it​

The artifact-registry unit creates the repositories in the home region; the registry path us-west1-docker.pkg.dev/acme-core-artifacts is published to every stage project as the contract parameter platform--artifact-registry.

RepositoryImagePulled byPushed by
acme-gcp-blueprint-webappThe web app APIThe GKE node account sa-acme-gke-nodes of each stage in webapp_gke_stagessa-acme-webapp-code-ci
acme-gcp-blueprint-webapp-frontendThe SPAThe Cloud Run service agent of each plat projectsa-acme-webapp-code-ci
acme-gcp-blueprint-etl-triggerThe ETL triggerThe Cloud Run service agent of each plat projectsa-acme-etl-code-ci
acme-github-runnerThe self-hosted runnerThe runner nodes, when runners are onsa-acme-baseline-ci
acme-scc-notifierThe Security Command Center notifierThe Cloud Run service agent of acme-core-securitysa-acme-baseline-ci

The GKE node readers are listed per stage in webapp_gke_stages of environments/plat/plat.hcl, because the node service accounts are created by the Web App Blueprint and a binding to an account that does not exist yet would fail.

Cleanup. Every repository carries the same four policies:

GCP/acme-gcp-platform-baseline/modules/artifact-registry/main.tf (lines 44-82)
cleanup_policy_dry_run = var.cleanup_dry_run

cleanup_policies {
id = "keep-releases"
action = "KEEP"
condition {
tag_state = "TAGGED"
tag_prefixes = ["v"]
}
}

# most_recent_versions cannot filter by tag: it keeps the newest versions of every package,
# which in a main-* only repository are the last main builds.
cleanup_policies {
id = "keep-most-recent"
action = "KEEP"
most_recent_versions {
keep_count = var.keep_recent_count
}
}

cleanup_policies {
id = "delete-old-main-builds"
action = "DELETE"
condition {
tag_state = "TAGGED"
tag_prefixes = ["main-"]
older_than = "${var.main_tag_max_age_days * 86400}s"
}
}

cleanup_policies {
id = "delete-untagged"
action = "DELETE"
condition {
tag_state = "UNTAGGED"
older_than = "${var.untagged_max_age_days * 86400}s"
}
}

Release tags (v*) are kept forever and the 30 most recent versions are kept; main-* builds older than 90 days and untagged images older than 14 days are deleted. cleanup_dry_run switches the deletion to a report.

Tags. The code pipelines push each image once as main-<short sha>. A release adds its version tag to that same image with gcloud artifacts docker tags add, a registry-side operation with no pull and no push, and refuses to proceed if the version tag already points at a different image. See Docker for the builds and immutable artifacts for why.

Scanning. With enable_artifact_analysis on in security.hcl (the default, ~$0.26 per image scanned on push), every repository inherits Artifact Analysis scanning. Images use Google-managed encryption.

Terms you will see​

TermMeaning
Immutable tagA tag that can never be re-pointed once pushed.
main-<short sha>The tag every build is pushed with, named after its commit.
Release tagA v* tag added to an existing image; kept forever.
Cleanup policyA rule that keeps or deletes versions by tag, state, age or recency.
webapp_gke_stagesThe stages whose GKE node accounts may pull the API image.

Where to read more​