Artifact Registry
Artifact Registry stores container images and other packages in repositories inside a Google Cloud project. The GCP Enterprise Baseline keeps every image of the platform in acme-core-artifacts, one repository per image, where a pushed tag can never be moved.
What it does
A repository has a format (here Docker), a region and its own IAM: Reader pulls, Writer pushes. Immutable tags refuse to point an existing tag at a different image. Cleanup policies delete or keep versions by tag prefix, tag state and age, or keep the most recent versions; a KEEP policy wins over a DELETE policy, and a dry run reports what would be deleted without deleting it. Vulnerability scanning by Artifact Analysis inspects images on push.
How BuiltForProd uses it
The artifact-registry unit creates the repositories in the home region; the registry path us-west1-docker.pkg.dev/acme-core-artifacts is published to every stage project as the contract parameter platform--artifact-registry.
| Repository | Image | Pulled by | Pushed by |
|---|---|---|---|
acme-gcp-blueprint-webapp | The web app API | The GKE node account sa-acme-gke-nodes of each stage in webapp_gke_stages | sa-acme-webapp-code-ci |
acme-gcp-blueprint-webapp-frontend | The SPA | The Cloud Run service agent of each plat project | sa-acme-webapp-code-ci |
acme-gcp-blueprint-etl-trigger | The ETL trigger | The Cloud Run service agent of each plat project | sa-acme-etl-code-ci |
acme-github-runner | The self-hosted runner | The runner nodes, when runners are on | sa-acme-baseline-ci |
acme-scc-notifier | The Security Command Center notifier | The Cloud Run service agent of acme-core-security | sa-acme-baseline-ci |
The GKE node readers are listed per stage in webapp_gke_stages of environments/plat/plat.hcl, because the node service accounts are created by the Web App Blueprint and a binding to an account that does not exist yet would fail.
Cleanup. Every repository carries the same four policies:
cleanup_policy_dry_run = var.cleanup_dry_run
cleanup_policies {
id = "keep-releases"
action = "KEEP"
condition {
tag_state = "TAGGED"
tag_prefixes = ["v"]
}
}
# most_recent_versions cannot filter by tag: it keeps the newest versions of every package,
# which in a main-* only repository are the last main builds.
cleanup_policies {
id = "keep-most-recent"
action = "KEEP"
most_recent_versions {
keep_count = var.keep_recent_count
}
}
cleanup_policies {
id = "delete-old-main-builds"
action = "DELETE"
condition {
tag_state = "TAGGED"
tag_prefixes = ["main-"]
older_than = "${var.main_tag_max_age_days * 86400}s"
}
}
cleanup_policies {
id = "delete-untagged"
action = "DELETE"
condition {
tag_state = "UNTAGGED"
older_than = "${var.untagged_max_age_days * 86400}s"
}
}
Release tags (v*) are kept forever and the 30 most recent versions are kept; main-* builds older than 90 days and untagged images older than 14 days are deleted. cleanup_dry_run switches the deletion to a report.
Tags. The code pipelines push each image once as main-<short sha>. A release adds its version tag to that same image with gcloud artifacts docker tags add, a registry-side operation with no pull and no push, and refuses to proceed if the version tag already points at a different image. See Docker for the builds and immutable artifacts for why.
Scanning. With enable_artifact_analysis on in security.hcl (the default, ~$0.26 per image scanned on push), every repository inherits Artifact Analysis scanning. Images use Google-managed encryption.
Terms you will see
| Term | Meaning |
|---|---|
| Immutable tag | A tag that can never be re-pointed once pushed. |
main-<short sha> | The tag every build is pushed with, named after its commit. |
| Release tag | A v* tag added to an existing image; kept forever. |
| Cleanup policy | A rule that keeps or deletes versions by tag, state, age or recency. |
webapp_gke_stages | The stages whose GKE node accounts may pull the API image. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Web App Blueprint overview.
- Artifact Analysis for the vulnerability findings.
- Immutable artifacts for build once, promote everywhere.