如何在Cloud Build中使用存储于Artifact Registry(而非Container Registry)的自定义构建器镜像?
Let’s walk through the common fixes for this scenario—since you’ve confirmed the image exists locally and granted read permissions to the Cloud Build service account, here are the key checks to resolve that manifest not found error:
1. Fix the Image Reference Format (Most Likely Culprit)
Artifact Registry requires a fully qualified image path that includes your GCP project ID. It looks like you’re missing this in your current step.
Your current configuration uses:
name: 'europe-west3-docker.pkg.dev/xxxx/yyyy:latest'
But the correct format should be:
name: 'europe-west3-docker.pkg.dev/YOUR-GCP-PROJECT-ID/xxxx/yyyy:latest'
Where xxxx is your Artifact Registry repository name, and yyyy is your image name. Local pulls might work without the project ID if you’ve tagged the image locally, but Cloud Build needs the full path to resolve the artifact correctly in the registry.
2. Align Cloud Build Region with Artifact Registry Region
Cloud Build workers run in a default region (us-central1) if you don’t specify otherwise. Since your registry is in europe-west3, configure your pipeline to run in the same region to avoid cross-region resolution issues.
Add the region field to your cloudbuild.yaml:
region: europe-west3 steps: - name: 'europe-west3-docker.pkg.dev/YOUR-GCP-PROJECT-ID/xxxx/yyyy:latest' id: install_dependencies entrypoint: pip args: ["install", "-r", "requirements.txt", "--user"]
3. Double-Check Service Account Permissions
Even if you granted read access, confirm you applied it to the correct service account:
- The Cloud Build service account follows this format:
PROJECT-NUMBER@cloudbuild.gserviceaccount.com(not the project ID email). - Verify the account has the
roles/artifactregistry.readerrole on your Artifact Registry repository (project-level permissions work too, but repository-level is more precise). - You can validate permissions with this command (replace placeholders):
gcloud artifacts repositories get-iam-policy xxxx --location europe-west3 --project YOUR-GCP-PROJECT-ID
Look for the Cloud Build service account in the output with the correct reader role.
4. Confirm the latest Tag Exists in the Registry
Double-check that the latest tag is actually pushed to Artifact Registry (sometimes local tags don’t match what’s uploaded):
- Run this command to list all tags for your image:
gcloud artifacts docker images list europe-west3-docker.pkg.dev/YOUR-GCP-PROJECT-ID/xxxx
Ensure yyyy:latest appears in the output. If not, re-push the image with the correct tag.
5. Check for Private Registry/VPC Restrictions
If your Artifact Registry uses private access or VPC peering:
- Make sure Cloud Build is configured with a VPC connector that can reach the registry.
- Verify there are no firewall rules blocking outbound traffic from Cloud Build workers to the Artifact Registry endpoint.
After working through these steps, your Cloud Build pipeline should pull the Artifact Registry image without issues. The missing project ID in the image reference is the most common fix here—easy mistake to make!
内容的提问来源于stack exchange,提问作者thatsmywayjj

