Skip to main content

Frequently Asked Questions

Why did Google introduce Artifact Registry when Container Registry already existed?

Container Registry only handled Docker images and was backed by GCS buckets with limited access control granularity. Artifact Registry was built as a unified successor supporting container images plus language-specific package formats (npm, Maven, Python, Go modules) in one service, with finer-grained IAM permissions per repository and native vulnerability scanning — consolidating what used to require separate tools into a single artifact management layer.

What's a common mistake teams make with Artifact Registry?

Not configuring cleanup policies, letting every CI build push a new untagged or SHA-tagged image version indefinitely, which quietly accumulates storage costs over months. Setting an automated cleanup policy to remove untagged images past a retention window — while explicitly keeping tagged release versions — keeps storage bounded without risking deletion of anything in use. This is easy to miss because nothing breaks when it happens; the bill just creeps upward until someone audits storage.