Artifact Registry Service Agent

Artifact Registry uses a Google-managed service account, called the Artifact Registry Service Agent, to act on your behalf when connecting to other Google Cloud services. You can grant IAM roles to the service agent so that it can integrate with services such as customer-managed encryption keys (CMEK) in Cloud Key Management Service and repository event notifications in Pub/Sub.

Artifact Registry creates the Artifact Registry Service Agent when you create the first Artifact Registry repository in a Google Cloud project. The service agent identifier is:

service-PROJECT-NUMBER@gcp-sa-artifactregistry.iam.gserviceaccount.com

PROJECT-NUMBER is the project number of the Google Cloud project where Artifact Registry is running.

You can manually create the service agent in a project without any repositories with the command:

gcloud beta services identity create \
    --service=artifactregistry.googleapis.com \
    --project=PROJECT-ID

Replace PROJECT-ID with the Google Cloud project ID.

The Artifact Registry Service Agent is granted the Artifact Registry Service Agent role (roles/artifactregistry.serviceAgent) for resources in the project. To enforce the security principle of least privilege, the role only has the minimum required permissions:

  • Publish Pub/Sub topics: pubsub.topics.publish
  • Download artifacts from Artifact Registry repositories: artifactregistry.repositories.downloadArtifacts
  • Read repository metadata: artifactregistry.repositories.get
  • Read artifacts using virtual repositories: artifactregistry.repositories.readViaVirtualRepository
  • Delete artifacts: artifactregistry.versions.delete

What's next

Learn about Artifact Registry roles and configuring access to repositories.