Using private dependencies with Cloud Run functions

Artifact Registry lets you store private npm and Python packages that you can include as dependencies in a Cloud Run function. You can use default permissions in the same project or grant roles to the Cloud Build service account for cross-project builds.

Required permissions

Cloud Run functions uses the Cloud Build service account in the same Google Cloud project to build and deploy your function.

  • If Cloud Run functions and Artifact Registry are in the same Google Cloud project, the service account has the necessary permissions to download from repositories.
  • If Cloud Run functions and Artifact Registry are in different projects, you must grant repository access to the Cloud Build service account.
    • To provide read-only access for downloading dependencies, grant the Artifact Registry Reader role.
    • If you also use Cloud Build to upload artifacts to repositories, grant the Artifact Registry Writer role.

Configuring access to dependencies

See the Cloud Run functions documentation for npm and Python configuration instructions.