@pypi or @conda into reproducible container images automatically, so your flows deploy and scale without manual image builds. For background on how it works, see Fast, Automatic Containerization of ML and AI Projects with Fast Bakery.
To activate Fast Bakery, run or deploy a flow that uses @pypi or @conda with the --environment=fast-bakery flag:
Using private packages and registries
Out of the box, Fast Bakery resolves publicly available Python packages and can use any public image as a base image. To work with private Python packages, private conda channels, or private container images, create a resource integration that gives Fast Bakery access to your private sources, then register the repository or channel against that integration. The sections below cover the most common scenarios. Each shows a canonical example; for the complete set of options for each command, see Integration types.To run the commands in these sections, you must have:
- The
outerboundsCLI installed and configured. (See Getting started with the platform CLI). - Admin privileges on the platform.
Private container image registries
Fast Bakery builds containers by pulling a base image first. To use a base image hosted in a private registry, create acontainer-registry integration.
For a private registry on Amazon ECR, there are two ways to grant access:
-
Assumed role: Create an IAM role with permissions to pull images from your ECR registry, configured to be assumable by the platform’s task role, then create the integration with the role ARN:
-
Task role: Grant the perimeter’s task IAM role permissions to pull images from your ECR registry, then create the integration with
--use-task-role:After the integration exists, you can use any image in the registry as a base image:
GitLab container registry
For container images in a GitLab container registry, create the integration with username and password credentials:update instead of create and pass the new credentials.
Private PyPI packages
Fast Bakery supports private PyPI repositories by formulatingpip index URLs with credentials for each build. The configuration follows the same pattern for every provider: create an integration for the provider, then register each private repository against it with private-pypi-repositories add.
AWS CodeArtifact
- Create an IAM role with permissions to download packages from your CodeArtifact repositories, configured to be assumable by the platform’s task role.
-
Create a
code-artifactsintegration: -
Register each repository against the integration:
GitLab package registry
- Generate credentials with read permissions for the GitLab package registry, such as a project access token or a personal access token.
-
Create a
gitlab-artifactsintegration: -
Register the repository:
Azure DevOps Artifacts
Azure DevOps Artifacts supports two authentication approaches. With managed identity (recommended), grant the perimeter’s managed identity access to your feed in Azure DevOps, then create the integration without credentials:Artifactory (JFrog)
- Generate credentials for a user with permission to download packages from the PyPI repositories.
-
Create an
artifactoryintegration: -
Register each repository:
PyPI packages from private Git repositories
The@pypi decorator installs packages directly from private Git repositories:
git-pypi-repository integration with credentials that have read access to the repository:
git config URL substitution, so you can scope them at the repository or organization level. This configuration also covers transitive dependencies that reference other private Git URLs.
Private conda packages
Fast Bakery supports packages from private conda channels by formulating channel URLs with static or short-lived credentials for each build request. Artifactory is currently the only supported private conda channel provider.- Generate credentials for a user with permission to download packages from the private conda channels.
-
Create an
artifactoryintegration: -
Register each channel with
private-conda-channels add: