Professional Cloud ArchitectDesign and plan a cloud solution architectureMedium
A software development company uses a CI/CD pipeline to deploy its microservices to Google Kubernetes Engine (GKE). They need to ensure that the images pulled by GKE clusters are always from a trusted source, are scanned for vulnerabilities, and that there's a clear audit trail of who pushed which image. Which Google Cloud service should be integrated into their pipeline to meet these requirements?
- ACloud Build
- BCloud Storage
- CContainer Registry
- DArtifact Registry
Show answer & explanationAnswer & explanation
Correct answer: D. Artifact Registry
Artifact Registry is the recommended, fully managed universal package manager for Google Cloud. It supports Docker images, provides vulnerability scanning (via Security Command Center integration), and offers fine-grained access control and audit logs, ensuring trusted image sources and traceability.
Why the other options are wrong
- A. Cloud Build is a CI/CD service for building and testing, but it needs an artifact repository to store and manage images.
- B. Cloud Storage is object storage, not designed for managing and securing container images in a CI/CD pipeline.
- C. Container Registry is a legacy service for Docker images. While it provides some similar functionality, Artifact Registry is the successor with broader support and enhanced features like vulnerability scanning integration.
Artifact Registry
A fully managed universal package manager on Google Cloud that supports various artifact formats, including Docker images, and integrates with security scanning and access control.
- Universal package manager (Docker, Maven, npm, etc.)
- Vulnerability scanning integration
- Fine-grained access control and audit logs
Memory trick: Artifact Registry is where all your trusted build artifacts live.