Google Artifact Registry for MIZOKI SDKs
This Terraform module creates and configures Google Artifact Registry repositories for the MIZOKI SRPVDAL Python and TypeScript SDKs.
Features
- Creates PyPI repository for Python SDK
- Creates npm repository for TypeScript SDK
- Configures IAM permissions for publishing (CI/CD)
- Configures IAM permissions for consumers
- Sets up retention policies to keep recent versions
- Provides authentication instructions
Usage
1. Initialize Terraform
cd deployment/terraform/artifact_registry
terraform init
2. Configure Variables
Copy and edit the example configuration:
cp terraform.tfvars.example terraform.tfvars
# Edit terraform.tfvars with your values
3. Apply Configuration
terraform plan
terraform apply
4. Create Repositories via Makefile (Alternative)
If you prefer using the Makefile instead of Terraform:
# From project root
make sdk-gar-create-repos
Publishing SDKs
Manual Publishing
# Publish Python SDK to GAR
make sdk-python-publish-gar
# Publish TypeScript SDK to GAR
make sdk-ts-publish-gar
CI/CD Publishing
The GitHub Actions workflow .github/workflows/sdk-publish-gar.yml automatically publishes when you push version tags:
# Tag and release Python SDK
git tag python-sdk-v1.0.1
git push origin python-sdk-v1.0.1
# Tag and release TypeScript SDK
git tag ts-sdk-v1.0.1
git push origin ts-sdk-v1.0.1
Consuming SDKs
Python SDK
# Configure authentication
gcloud auth application-default login
# Install from GAR
pip install --index-url https://us-central1-python.pkg.dev/PROJECT/mizoki-python/simple \
mizoki-srpvdal-client==1.0.0
# Or configure pip.conf globally
cat >> ~/.pip/pip.conf <<EOF
[global]
index-url = https://us-central1-python.pkg.dev/PROJECT/mizoki-python/simple
EOF
TypeScript SDK
# Configure authentication
gcloud auth application-default login
TOKEN=$(gcloud auth print-access-token)
# Configure npm for this project
cat > .npmrc <<EOF
registry=https://us-central1-npm.pkg.dev/PROJECT/mizoki-npm/
always-auth=true
//us-central1-npm.pkg.dev/PROJECT/mizoki-npm/:_authToken=${TOKEN}
EOF
# Install package
npm install @mizoki/srpvdal-client@1.0.0
IAM Requirements
Publisher (CI/CD)
The service account used for publishing needs:
- roles/artifactregistry.writer on both repositories
Consumers
Service accounts or users consuming the SDKs need:
- roles/artifactregistry.reader on the respective repository
Workload Identity Federation Setup
For GitHub Actions without service account keys:
- Create a Workload Identity Pool:
gcloud iam workload-identity-pools create github-pool \
--location=global \
--display-name="GitHub Actions Pool"
- Create a provider:
gcloud iam workload-identity-pools providers create-oidc github-provider \
--location=global \
--workload-identity-pool=github-pool \
--issuer-uri="https://token.actions.githubusercontent.com" \
--attribute-mapping="google.subject=assertion.sub,attribute.repository=assertion.repository"
- Grant IAM binding:
gcloud iam service-accounts add-iam-policy-binding \
github-actions-sa@PROJECT.iam.gserviceaccount.com \
--role=roles/iam.workloadIdentityUser \
--member="principalSet://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/github-pool/attribute.repository/mediaintelligence/MIZOKICloudRun"
- Set GitHub secrets:
-
GCP_WIF_PROVIDER: projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/github-pool/providers/github-provider -GCP_WIF_SA_EMAIL: github-actions-sa@PROJECT.iam.gserviceaccount.com
Cleanup Policies
Both repositories are configured to keep the 10 most recent versions. Older versions are automatically deleted to manage storage costs.
Outputs
After applying Terraform, you'll get: - Repository URLs for publishing - Index URLs for package installation - Authentication configuration commands