Professional Cloud ArchitectDesign and plan a cloud solution architectureMedium

A software development company uses a CI/CD pipeline to deploy its microservices to Google Kubernetes Engine (GKE). They need to ensure that the images pulled by GKE clusters are always from a trusted source, are scanned for vulnerabilities, and that there's a clear audit trail of who pushed which image. Which Google Cloud service should be integrated into their pipeline to meet these requirements?

  1. ACloud Build
  2. BCloud Storage
  3. CContainer Registry
  4. DArtifact Registry
Show answer & explanation

Correct answer: D. Artifact Registry

Artifact Registry is the recommended, fully managed universal package manager for Google Cloud. It supports Docker images, provides vulnerability scanning (via Security Command Center integration), and offers fine-grained access control and audit logs, ensuring trusted image sources and traceability.

Why the other options are wrong

  • A. Cloud Build is a CI/CD service for building and testing, but it needs an artifact repository to store and manage images.
  • B. Cloud Storage is object storage, not designed for managing and securing container images in a CI/CD pipeline.
  • C. Container Registry is a legacy service for Docker images. While it provides some similar functionality, Artifact Registry is the successor with broader support and enhanced features like vulnerability scanning integration.

Artifact Registry

A fully managed universal package manager on Google Cloud that supports various artifact formats, including Docker images, and integrates with security scanning and access control.

  • Universal package manager (Docker, Maven, npm, etc.)
  • Vulnerability scanning integration
  • Fine-grained access control and audit logs

Memory trick: Artifact Registry is where all your trusted build artifacts live.

More Design and plan a cloud solution architecture questions