Google Artifact Registry for MIZOKI SDKs

This Terraform module creates and configures Google Artifact Registry repositories for the MIZOKI SRPVDAL Python and TypeScript SDKs.

Features

Usage

1. Initialize Terraform

cd deployment/terraform/artifact_registry
terraform init

2. Configure Variables

Copy and edit the example configuration:

cp terraform.tfvars.example terraform.tfvars
# Edit terraform.tfvars with your values

3. Apply Configuration

terraform plan
terraform apply

4. Create Repositories via Makefile (Alternative)

If you prefer using the Makefile instead of Terraform:

# From project root
make sdk-gar-create-repos

Publishing SDKs

Manual Publishing

# Publish Python SDK to GAR
make sdk-python-publish-gar

# Publish TypeScript SDK to GAR
make sdk-ts-publish-gar

CI/CD Publishing

The GitHub Actions workflow .github/workflows/sdk-publish-gar.yml automatically publishes when you push version tags:

# Tag and release Python SDK
git tag python-sdk-v1.0.1
git push origin python-sdk-v1.0.1

# Tag and release TypeScript SDK
git tag ts-sdk-v1.0.1
git push origin ts-sdk-v1.0.1

Consuming SDKs

Python SDK

# Configure authentication
gcloud auth application-default login

# Install from GAR
pip install --index-url https://us-central1-python.pkg.dev/PROJECT/mizoki-python/simple \
  mizoki-srpvdal-client==1.0.0

# Or configure pip.conf globally
cat >> ~/.pip/pip.conf <<EOF
[global]
index-url = https://us-central1-python.pkg.dev/PROJECT/mizoki-python/simple
EOF

TypeScript SDK

# Configure authentication
gcloud auth application-default login
TOKEN=$(gcloud auth print-access-token)

# Configure npm for this project
cat > .npmrc <<EOF
registry=https://us-central1-npm.pkg.dev/PROJECT/mizoki-npm/
always-auth=true
//us-central1-npm.pkg.dev/PROJECT/mizoki-npm/:_authToken=${TOKEN}
EOF

# Install package
npm install @mizoki/srpvdal-client@1.0.0

IAM Requirements

Publisher (CI/CD)

The service account used for publishing needs: - roles/artifactregistry.writer on both repositories

Consumers

Service accounts or users consuming the SDKs need: - roles/artifactregistry.reader on the respective repository

Workload Identity Federation Setup

For GitHub Actions without service account keys:

  1. Create a Workload Identity Pool:
gcloud iam workload-identity-pools create github-pool \
  --location=global \
  --display-name="GitHub Actions Pool"
  1. Create a provider:
gcloud iam workload-identity-pools providers create-oidc github-provider \
  --location=global \
  --workload-identity-pool=github-pool \
  --issuer-uri="https://token.actions.githubusercontent.com" \
  --attribute-mapping="google.subject=assertion.sub,attribute.repository=assertion.repository"
  1. Grant IAM binding:
gcloud iam service-accounts add-iam-policy-binding \
  github-actions-sa@PROJECT.iam.gserviceaccount.com \
  --role=roles/iam.workloadIdentityUser \
  --member="principalSet://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/github-pool/attribute.repository/mediaintelligence/MIZOKICloudRun"
  1. Set GitHub secrets: - GCP_WIF_PROVIDER: projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/github-pool/providers/github-provider - GCP_WIF_SA_EMAIL: github-actions-sa@PROJECT.iam.gserviceaccount.com

Cleanup Policies

Both repositories are configured to keep the 10 most recent versions. Older versions are automatically deleted to manage storage costs.

Outputs

After applying Terraform, you'll get: - Repository URLs for publishing - Index URLs for package installation - Authentication configuration commands

← All docsView source on GitHub →