Overview
The GCP Artifact Registry integration gives Backline read access to the container images your applications run from Google Cloud, so those images are analyzed for vulnerabilities. You supply one Google service account key. Backline uses it for every Google-hosted image address it encounters for your tenant — you do not list your repositories, so images in repositories your teams create later are covered without any change in Backline.This integration is for container images. Private packages hosted on Google Cloud are a separate integration, GCP Package Registry — which was itself named “GCP Artifact Registry” until this release. See Two Google integrations below.
What You Can Do
With the GCP Artifact Registry integration, Backline can:- Analyze image layers for vulnerabilities
- Detect security issues in dependencies
- Track image security across versions
- Monitor compliance with security policies
Covered Image Addresses
Backline treats these as Google-hosted container image addresses and resolves them through this integration:
You do not need to re-tag images that still use a
gcr.io address — both address families are covered by the same connection.
The package address families
<region>-npm.pkg.dev, <region>-python.pkg.dev and <region>-go.pkg.dev are not container image addresses. They belong to the GCP Package Registry integration.Public Images Need No Connection
An image at a Google-hosted address that can be pulled without credentials — such as a public distroless base image — is analyzed whether or not you have this integration connected, and whatever state that connection is in. A publicly pullable Google-hosted image requires the same setup as a publicly pullable Docker Hub image: none. Connect this integration for the images that are private to your Google Cloud projects.Prerequisites
Before connecting GCP Artifact Registry, ensure you have:- A Google Cloud project hosting the container images your applications run
- The Artifact Registry API enabled for that project
- Permissions to create service accounts, assign roles, and create service account keys
Enabling the Artifact Registry API
1
Navigate to the API Library
Go to the Artifact Registry API page in the Google Cloud Console.
2
Select Your Project
Select the project hosting your container images.
3
Enable the API
Click Enable.
Allow a few minutes for Google to propagate the enablement before proceeding.
Creating a Service Account
1
Navigate to Service Accounts
Go to the Service Accounts page in the Google Cloud Console and select your project.
2
Create the Service Account
Click Create service account, give it a unique name and ID, then click Create and Continue.
3
Assign Roles
Grant the service account:
- Artifact Registry Reader — read access to images in Artifact Registry
- Storage Object Viewer — only if you use
gcr.ioaddresses (see below)
4
Generate a JSON Key
- Open the service account you just created
- Go to the Keys tab
- Click Add Key → Create new key
- Select JSON and click Create
Required Permissions
Grant the roles on every project whose images your applications run. One connection covers whatever its key can read, so a key that reaches only one project covers only that project’s images.
Connecting GCP Artifact Registry
1
Go to Integration Hub
In Backline, navigate to Integrations from the main menu.
2
Select GCP Artifact Registry
Find and click on the GCP Artifact Registry integration card, among the container registries.
3
Paste the Service Account JSON
Paste the full contents of the JSON key file into the Service Account JSON field. This is the only field.
4
Test Connection
Click Test Connection to check that the key authenticates with Google.
5
Save
Click Save to complete the integration.
Backline supports one GCP Artifact Registry connection per tenant. To cover images in more than one Google Cloud project, grant that one service account the roles above on each project.
Connection Health
If Google-hosted images stop producing findings, open the integration and click Test Connection. A failed test reports the reason Google gave.After Connection
Once GCP Artifact Registry is connected, Backline will:- Authenticate with the service account key each time it reads one of your Google-hosted images
- Analyze the images your applications reference at the covered addresses
- Report findings, inventory, and base-image attribution for those images
- Suggest a safer base image tag where a newer tag resolves the reported vulnerabilities
Managing the Integration
Rotating the Service Account Key
- Generate a new JSON key in the Google Cloud Console (following the steps above)
- Open the Integration Hub and click on the GCP Artifact Registry integration
- Paste the new key into Service Account JSON, then Test Connection and Save
- Delete the old key from the Google Cloud Console
Disconnecting
- Go to the Integration Hub
- Click on the GCP Artifact Registry integration
- Select Disconnect
- Confirm your choice
Two Google Integrations
Backline has two separate Google Cloud integrations, each with its own credential, status, and lifecycle. You can hold both at once.Troubleshooting
Test Connection Fails
- Verify the JSON key file was pasted in full and is not truncated
- Check that the service account still exists and the key has not been revoked or deleted in the Google Cloud Console
Connected, but Images Produce No Findings
- Verify the service account has Artifact Registry Reader on the project hosting the images
- For
gcr.ioaddresses, verify it also has Storage Object Viewer - Confirm the Artifact Registry API is enabled for the project
- Confirm the image address is one of the covered addresses
- Click Test Connection; if it fails, the reported error names the reason Google gave