- 23 Dec 2024
- Print
- DarkLight
- PDF
Container Registry
- Updated On 23 Dec 2024
- Print
- DarkLight
- PDF
Overview
Container registry is a repository for storing and accessing container images, supporting container-based application development, often as part of DevOps workflows.
Dataloop integrates with Google Container Registry (GCR), a GCP service for storing private container images. While GCR offers robust features, Artifact Registry is the recommended GCP service for managing container images and other artifacts. Learn more
To integrate Google Container Registry (GCR) with the Dataloop platform, follow these steps:
Create and Configure a GCP Google Container Registry
Step 1: Set Up a GCP Project
If you don’t have an existing project:
- Go to the Project Selector.
- Click New Project.
- Provide a Project Name and select the Billing Account.
- Click Create.
- Set the project as active:
gcloud config set project [PROJECT_ID]
Step 2: Enable the Google Container Registry API
- Go to the GCP Console: https://console.cloud.google.com/.
- Navigate to APIs & Services > Library.
- Search for Google Container Registry API.
- Click Enable.
- Enable billing for your GCP project by following the necessary steps.
Step 3: Configure Docker Authentication
- Install the Google Cloud CLI if you haven't already.
- Download gcloud CLI.
- Authenticate and configure Docker:
gcloud auth login
gcloud auth configure-docker
Step 4: Create and Push a Container Image
- Tag your Docker image:
docker tag [IMAGE_NAME] gcr.io/[PROJECT_ID]/[IMAGE_NAME]:[TAG]
- Push the image to GCR:
docker push gcr.io/[PROJECT_ID]/[IMAGE_NAME]:[TAG]
- Verify the image:
- Navigate to Container Registry in the GCP Console: https://console.cloud.google.com/gcr.
- Confirm that the image is visible in the registry.
Configure GCR for Use with Dataloop Platform
Step 1: Provide Access to Dataloop
- In GCP, go to IAM & Admin > IAM.
- Add the Dataloop service account (provided in Dataloop documentation or platform settings) as a member:
- Assign roles:
- Container Registry Viewer (to view and pull images).
- Storage Object Viewer (to access image layers).
- Assign roles:
- If the Dataloop service account details are unclear: Check Dataloop's documentation or contact their support team for the correct service account information.
Step 2: Generate a Service Account Key
- Create a service account:
- Navigate to IAM & Admin > Service Accounts.
- Click Create Service Account.
- Provide a Name (e.g., dataloop-access) and click Create.
- Assign the following roles:
- Storage Object Viewer.
- Container Registry Viewer.
- Click Done.
- Generate a key for the service account:
- Find your service account in the list.
- Click the three-dot menu and select Manage Keys.
- Click Add Key > Create New Key.
- Select JSON and click Create
- Save the JSON key file securely.
Step 3: Upload the Service Account Key to Dataloop
- Log in to your Dataloop Platform.
- Navigate to the Data Governance page.
- Click Create Integration.
- Name: Provide a name for the integration.
- Provider: Select GCP from the list.
- Integration Type: Select Private Container Registry from the list.
- Registry Name: Select Google Container Registry (GCP) from the list.
- Password: Provide the JSON key (base64).
base64
The password is in base64
and can be downloaded using the following JSON file:
{
"type": "service_account",
"project_id": "",
"private_key_id": "",
"private_key": "",
"client_email": "",
"client_id": "",
"auth_uri": "",
"token_uri": "",
"auth_provider_x509_cert_url": "",
"client_x509_cert_url": ""
}
Step 4: Test the Configuration
- In the Dataloop platform, try pulling or referencing a Docker image hosted in your GCR.
- Ensure the integration is working without any errors.