Working with Artifact Registry

As the evolution of Container Registry, Artifact Registry is a single place for your organization to manage container images and language packages (such as Maven and npm). It is fully integrated with Google Cloud’s tooling and runtimes and comes with support for native artifact protocols. This makes it simple to integrate it with your CI/CD tooling to set up automated pipelines.

  • Create repositories for Containers and Language Packages
  • Manage container images with Artifact Registry
  • Integrate Artifact Registry with Cloud Code
  • Configure Maven to use Artifact Registry for Java Dependencies

Prepare the lab environment

Set up variables

  • In Cloud Shell, set your project ID and project number. Save them as PROJECT_ID and PROJECT_NUMBER variables:
student_01_0fb7ab211dcf@cloudshell:~ (qwiklabs-gcp-00-1176b71068a0)$ export PROJECT_ID=$(gcloud config get-value project)
export PROJECT_NUMBER=$(gcloud projects describe $PROJECT_ID --format='value(projectNumber)')
export REGION=us-east1
gcloud config set compute/region $REGION
Enable Google services

student_01_0fb7ab211dcf@cloudshell:~ (qwiklabs-gcp-00-1176b71068a0)$ gcloud services enable \ \ \ \ \
Operation "operations/acat.p2-610761045646-51bcfca2-43a2-4c5d-8d1f-8898546f8371" finished successfully.
Get the source code

student_01_0fb7ab211dcf@cloudshell:~ (qwiklabs-gcp-00-1176b71068a0)$ git clone
cd ~/cloud-code-samples
Cloning into 'cloud-code-samples'...
remote: Enumerating objects: 16993, done.
remote: Counting objects: 100% (85/85), done.
remote: Compressing objects: 100% (53/53), done.
remote: Total 16993 (delta 38), reused 74 (delta 32), pack-reused 16908
Receiving objects: 100% (16993/16993), 27.62 MiB | 13.60 MiB/s, done.
Resolving deltas: 100% (10661/10661), done.
Provision the infrastructure

student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples (qwiklabs-gcp-00-1176b71068a0)$ gcloud container clusters create container-dev-cluster --zone=us-east1-d
Default change: VPC-native is the default mode during cluster creation for versions greater than 1.21.0-gke.1500. To create advanced routes based clusters, please pass the `--no-enable-ip-alias` flag
Note: Your Pod address range (`--cluster-ipv4-cidr`) can accommodate at most 1008 node(s).
Creating cluster container-dev-cluster in us-east1-d... Cluster is being health-checked (master is healthy)...done.                                                                
Created [].
To inspect the contents of your cluster, go to:
kubeconfig entry generated for container-dev-cluster.
NAME: container-dev-cluster
LOCATION: us-east1-d
MASTER_VERSION: 1.28.7-gke.1026000
MACHINE_TYPE: e2-medium
NODE_VERSION: 1.28.7-gke.1026000
Working with container images

Create a Docker Repository on Artifact registry

Artifact Registry supports managing container images and language packages. Different artifact types require different specifications. For example, the requests for Maven dependencies are different from requests for Node dependencies.

To support the different API specifications, Artifact Registry needs to know what format you want the API responses to follow. To do this you will create a repository and pass in the --repository-format flag indicating the type of repository desired.

student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples (qwiklabs-gcp-00-1176b71068a0)$ gcloud artifacts repositories create container-dev-repo --repository-format=docker \
  --location=$REGION \
  --description="Docker repository for Container Dev Workshop"
Create request issued for: [container-dev-repo]
Waiting for operation [projects/qwiklabs-gcp-00-1176b71068a0/locations/us-east1/operations/977f0f2c-7897-4348-be27-02e3db83c9d1] to complete...done.                               
Created repository [container-dev-repo].
Configure Docker Authentication to Artifact Registry

When connecting to Artifact Registry credentials are required in order to provide access. Rather than set up separate credentials, Docker can be configured to use your gcloud credentials seamlessly.

student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples (qwiklabs-gcp-00-1176b71068a0)$ gcloud auth configure-docker
WARNING: Your config file at [/home/student_01_0fb7ab211dcf/.docker/config.json] contains these credential helper entries:

Adding credentials for:
gcloud credential helpers already registered correctly.
Explore the sample Application

A sample application is provided in the git repository you cloned.

  • Change into the java directory and review the application code:
student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples (qwiklabs-gcp-00-1176b71068a0)$ cd ~/cloud-code-samples/java/java-hello-world
student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples/java/java-hello-world (qwiklabs-gcp-00-1176b71068a0)$ ls
checkstyle.xml  Dockerfile  img  kubernetes-manifests  pom.xml  skaffold.yaml  src
student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples/java/java-hello-world (qwiklabs-gcp-00-1176b71068a0)$ cat Dockerfile 
# Use maven to compile the java application.
FROM maven:3-jdk-11-slim AS build-env

# Set the working directory to /app

# copy the pom.xml file to download dependencies
COPY pom.xml ./

# download dependencies as specified in pom.xml
# building dependency layer early will speed up compile time when pom is unchanged
RUN mvn verify --fail-never

# Copy the rest of the working directory contents into the container
COPY . ./

# Compile the application.
RUN mvn -Dmaven.test.skip=true package

# Build runtime image.
FROM openjdk:11.0.16-jre-slim

# Copy the compiled files over.
COPY --from=build-env /app/target/ /app/

# Starts java app with debugging server at port 5005.
CMD ["java", "-jar", "/app/hello-world-1.0.0.jar"]
The folder contains an example Java application that renders a simple web page: in addition to various files not relevant for this specific lab, it contains the source code, under the src folder, and a Dockerfile you will use to build a container image locally.

Build the Container Image

Before you can store container images in Artifact Registry you need to create one.

  • Run the following command to build the container image and tag it properly:
student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples/java/java-hello-world (qwiklabs-gcp-00-1176b71068a0)$ docker build -t .
Push the Container Image to Artifact Registry

  • Run the following command to push the container image to the repository you created:
Review the image in Artifact Registry

  1. In Artifact Registry > Repositories, click into container-dev-repo and check that the java-hello-world image is there.
  2. Click on the image and note the image tagged tag1. You can see that Vulnerability Scanning is running or already completed and the number of vulnerabilities detected is visible.

Click on the number of vulnerabilities and you will see the list of vulnerabilities detected in the image, with the CVE bulletin name and the severity. Click VIEW on each listed vulnerability to get more details:

Integration with Cloud Code

In this section you use the Artifact Registry Docker image repository with Cloud Code.

Deploy the Application to GKE Cluster from Cloud Code

  1. From the java-hello-world folder run the following command to open Cloud Shell Editor and add the application folder to this workspace.
cloudshell workspace .

Click on View > Command Palette… and type Run on Kubernetes and select Cloud Code: Run on Kubernetes.

Choose cloud-code-samples/java/java-hello-world/skaffold.yaml and then dockerfile.

Starting to debug the app using configuration 'Kubernetes: Run/Debug' from .vscode/launch.json...
To view more detailed logs, go to Output channel : "Kubernetes: Run/Debug - Detailed"
Input image registry does not match the expected image registry based on the GCP project associated with the current context. Please ensure that the cluster is authorized to pull images from the input registry.

Update initiated
Build started for artifact java-hello-world
Build completed for artifact java-hello-world

Deploy started
Status check started
Resource pod/java-hello-world-79bfd8c959-wsl7p status updated to In Progress
Resource deployment/java-hello-world status updated to In Progress
Resource deployment/java-hello-world status updated to In Progress
Resource deployment/java-hello-world status completed successfully
Status check succeeded

Deploy completed

Forwarded URL from service java-hello-world-external: http://localhost:4503
Debuggable container started pod/java-hello-world-79bfd8c959-wsl7p:server (default)
Update succeeded
Watching for changes...
To disable watch mode for subsequent runs, set watch to false in your launch configuration /home/student_01_0fb7ab211dcf/.vscode/launch.json and relaunch the application.

  1. When you execute Run on Kubernetes for the first time Cloud Code prompts you for the target image repository location. Once provided, the repository url is stored in the file .vscode/launch.json which is created in the application folder.

In the output pane you see that the build starts for the application image java-hello-world, the image is uploaded to the Artifact Registry repository configured previously.

  1. In Artifact Registry > Repositories click into container-dev-repo and check that the java-hello-world image and note a new image tagged latest.

Review the Deployed Application

  1. Go back to Cloud Shell Editor. When deployment is complete Skaffold/Cloud Code will print the exposed url where the service have been forwarded, click on the link - Open Web Preview:

A group celebrating

   It's running!

   Congratulations, you successfully deployed a Kubernetes application with Cloud Code!

Update application code

Now update the application to see the change implemented immediately in the deployment on the cluster:

  1. Open the by clicking on View > Command Palette… and then click one backspace and then enter the path src/main/java/cloudcode/helloworld/web and click the option starting with Hello.. .
  2. Change the text in row 20 from “It’s running!” to “It’s updated!”. You should see the build and deployment process starting immediately.
  3. At the end of the deploy click again on the forwarded url or refresh the browser window with the application to see your change deployed:

It's updated!
Congratulations, you successfully deployed a Kubernetes application with Cloud Code!

In the Cloud console go to Navigation Menu > Artifact Registry > Repositories and click into container-dev-repo to check that the java-hello-world image and note the new image.

Working with language packages

In this section you will set up an Artifact Registry Java repository and upload packages to it, leveraging them in different applications.

Create a Java package repository

student_01_0fb7ab211dcf@cloudshell:~ (qwiklabs-gcp-00-1176b71068a0)$ gcloud artifacts repositories create container-dev-java-repo \
    --repository-format=maven \
    --location=us-east1 \
    --description="Java package repository for Container Dev Workshop"
Create request issued for: [container-dev-java-repo]
Waiting for operation [projects/qwiklabs-gcp-00-1176b71068a0/locations/us-east1/operations/55a307df-d054-43ae-b4c1-2e6b3eed4ef3] to complete...done.                               
Created repository [container-dev-java-repo].
In the Cloud console go to Artifact Registry > Repositories and notice your newly created Maven repository named container-dev-java-repo, if you click on it you can see that it’s empty at the moment.

Set up authentication to Artifact Repository

  • Use the following command to update the well-known location for Application Default Credentials (ADC) with your user account credentials so that the Artifact Registry credential helper can authenticate using them when connecting with repositories:
student_01_0fb7ab211dcf@cloudshell:~ (qwiklabs-gcp-00-1176b71068a0)$ gcloud auth login --update-adc

Configure Maven for Artifact Registry

  1. Run the following command to print the repository configuration to add to your Java project:
student_01_0fb7ab211dcf@cloudshell:~ (qwiklabs-gcp-00-1176b71068a0)$ gcloud artifacts print-settings mvn \
    --repository=container-dev-java-repo \
<!-- Insert following snippet into your pom.xml -->




student_01_0fb7ab211dcf@cloudshell:~ (qwiklabs-gcp-00-1176b71068a0)$ 

Open the pom.xml in Cloud Shell Editor and add the returned settings to the appropriate sections in the file:

<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="" xmlns:xsi=""

 <name>Cloud Code Hello World</name>
 <description>Getting started with Cloud Code</description>





 <!-- The Spring Cloud GCP BOM will manage spring-cloud-gcp version numbers for you. -->










Upload your Java package to Artifact Registry

With Artifact Registry configured in Maven, you can now use Artifact Registry to store Java Jars for use by other projects in your organization.

  • Run the following command to upload your Java package to Artifact Registry:
student_01_0fb7ab211dcf@cloudshell:~/cloud-code-samples/java/java-hello-world (qwiklabs-gcp-00-1176b71068a0)$ mvn deploy

[INFO] --- deploy:2.8.2:deploy (default-deploy) @ hello-world ---
Uploading to artifact-registry: artifactregistry://
[INFO] ArtifactRegistry Maven Wagon: Retrieving credentials...
[INFO] Trying Application Default Credentials...
[INFO] Using Application Default Credentials.
Uploaded to artifact-registry: artifactregistry:// (44 MB at 6.3 MB/s)
Uploading to artifact-registry: artifactregistry://
Uploaded to artifact-registry: artifactregistry:// (3.6 kB at 1.9 kB/s)
Downloading from artifact-registry: artifactregistry://
Uploading to artifact-registry: artifactregistry://
Uploaded to artifact-registry: artifactregistry:// (315 B at 173 B/s)
[INFO] ------------------------------------------------------------------------
[INFO] ------------------------------------------------------------------------
[INFO] Total time:  01:25 min
[INFO] Finished at: 2024-05-09T16:17:50Z
[INFO] ------------------------------------------------------------------------
Check the Java package in Artifact Registry

In the Cloud console go to Artifact Registry > Repositories and click into container-dev-java-repo to check that the hello-world binary artifact is there:

Congratulations! In this lab you learned about some of the features available in Artifact Registry. You first created repositories for containers and language packages. You then managed container images with Artifact Registry and integrated it with Cloud Code. Finally, you configured Maven to use Artifact Registry for Java dependencies. You now have a solid understanding of features available in Artifact Registry.




