Skip to main content

Overview

The GCP Artifact Registry integration gives Backline read access to the container images your applications run from Google Cloud, so those images are analyzed for vulnerabilities. You supply one Google service account key. Backline uses it for every Google-hosted image address it encounters for your tenant — you do not list your repositories, so images in repositories your teams create later are covered without any change in Backline.
This integration is for container images. Private packages hosted on Google Cloud are a separate integration, GCP Package Registry — which was itself named “GCP Artifact Registry” until this release. See Two Google integrations below.

What You Can Do

With the GCP Artifact Registry integration, Backline can:
  • Analyze image layers for vulnerabilities
  • Detect security issues in dependencies
  • Track image security across versions
  • Monitor compliance with security policies
Where an image carries no source provenance, Backline asks you to map it to its repository and Dockerfile once. See Image to Code Mapping.

Covered Image Addresses

Backline treats these as Google-hosted container image addresses and resolves them through this integration: You do not need to re-tag images that still use a gcr.io address — both address families are covered by the same connection.
The package address families <region>-npm.pkg.dev, <region>-python.pkg.dev and <region>-go.pkg.dev are not container image addresses. They belong to the GCP Package Registry integration.

Public Images Need No Connection

An image at a Google-hosted address that can be pulled without credentials — such as a public distroless base image — is analyzed whether or not you have this integration connected, and whatever state that connection is in. A publicly pullable Google-hosted image requires the same setup as a publicly pullable Docker Hub image: none. Connect this integration for the images that are private to your Google Cloud projects.

Prerequisites

Before connecting GCP Artifact Registry, ensure you have:
  • A Google Cloud project hosting the container images your applications run
  • The Artifact Registry API enabled for that project
  • Permissions to create service accounts, assign roles, and create service account keys

Enabling the Artifact Registry API

1

Navigate to the API Library

Go to the Artifact Registry API page in the Google Cloud Console.
2

Select Your Project

Select the project hosting your container images.
3

Enable the API

Click Enable.
Allow a few minutes for Google to propagate the enablement before proceeding.

Creating a Service Account

1

Navigate to Service Accounts

Go to the Service Accounts page in the Google Cloud Console and select your project.
2

Create the Service Account

Click Create service account, give it a unique name and ID, then click Create and Continue.
3

Assign Roles

Grant the service account:
  1. Artifact Registry Reader — read access to images in Artifact Registry
  2. Storage Object Viewer — only if you use gcr.io addresses (see below)
Click Continue, then Done.
4

Generate a JSON Key

  1. Open the service account you just created
  2. Go to the Keys tab
  3. Click Add Key → Create new key
  4. Select JSON and click Create
The JSON key file downloads automatically.
Store the JSON key securely. It grants read access to the container images in the projects where you granted it roles.

Required Permissions

If every image you run is at a <region>-docker.pkg.dev address, Artifact Registry Reader alone is enough. Add Storage Object Viewer if any of your image references still use a gcr.io host.
Grant the roles on every project whose images your applications run. One connection covers whatever its key can read, so a key that reaches only one project covers only that project’s images.

Connecting GCP Artifact Registry

1

Go to Integration Hub

In Backline, navigate to Integrations from the main menu.
2

Select GCP Artifact Registry

Find and click on the GCP Artifact Registry integration card, among the container registries.
3

Paste the Service Account JSON

Paste the full contents of the JSON key file into the Service Account JSON field. This is the only field.
4

Test Connection

Click Test Connection to check that the key authenticates with Google.
5

Save

Click Save to complete the integration.
Backline supports one GCP Artifact Registry connection per tenant. To cover images in more than one Google Cloud project, grant that one service account the roles above on each project.

Connection Health

If Google-hosted images stop producing findings, open the integration and click Test Connection. A failed test reports the reason Google gave.

After Connection

Once GCP Artifact Registry is connected, Backline will:
  1. Authenticate with the service account key each time it reads one of your Google-hosted images
  2. Analyze the images your applications reference at the covered addresses
  3. Report findings, inventory, and base-image attribution for those images
  4. Suggest a safer base image tag where a newer tag resolves the reported vulnerabilities

Managing the Integration

Rotating the Service Account Key

  1. Generate a new JSON key in the Google Cloud Console (following the steps above)
  2. Open the Integration Hub and click on the GCP Artifact Registry integration
  3. Paste the new key into Service Account JSON, then Test Connection and Save
  4. Delete the old key from the Google Cloud Console
Regularly rotating service account keys is a security best practice.

Disconnecting

  1. Go to the Integration Hub
  2. Click on the GCP Artifact Registry integration
  3. Select Disconnect
  4. Confirm your choice
Disconnecting stops Backline from reading private images in your Google Cloud projects, so those images will no longer produce findings. Publicly pullable Google-hosted images are unaffected.

Two Google Integrations

Backline has two separate Google Cloud integrations, each with its own credential, status, and lifecycle. You can hold both at once.

Troubleshooting

Test Connection Fails

  • Verify the JSON key file was pasted in full and is not truncated
  • Check that the service account still exists and the key has not been revoked or deleted in the Google Cloud Console

Connected, but Images Produce No Findings

  • Verify the service account has Artifact Registry Reader on the project hosting the images
  • For gcr.io addresses, verify it also has Storage Object Viewer
  • Confirm the Artifact Registry API is enabled for the project
  • Confirm the image address is one of the covered addresses
  • Click Test Connection; if it fails, the reported error names the reason Google gave