Skip to main content
Fast Bakery is the platform’s containerization backend. It packages the dependencies you declare with @pypi or @conda into reproducible container images automatically, so your flows deploy and scale without manual image builds. For background on how it works, see Fast, Automatic Containerization of ML and AI Projects with Fast Bakery. To activate Fast Bakery, run or deploy a flow that uses @pypi or @conda with the --environment=fast-bakery flag:

Using private packages and registries

Out of the box, Fast Bakery resolves publicly available Python packages and can use any public image as a base image. To work with private Python packages, private conda channels, or private container images, create a resource integration that gives Fast Bakery access to your private sources, then register the repository or channel against that integration. The sections below cover the most common scenarios. Each shows a canonical example; for the complete set of options for each command, see Integration types.
To run the commands in these sections, you must have:

Private container image registries

Fast Bakery builds containers by pulling a base image first. To use a base image hosted in a private registry, create a container-registry integration. For a private registry on Amazon ECR, there are two ways to grant access:
  1. Assumed role: Create an IAM role with permissions to pull images from your ECR registry, configured to be assumable by the platform’s task role, then create the integration with the role ARN:
  2. Task role: Grant the perimeter’s task IAM role permissions to pull images from your ECR registry, then create the integration with --use-task-role:
    After the integration exists, you can use any image in the registry as a base image:

GitLab container registry

For container images in a GitLab container registry, create the integration with username and password credentials:
To rotate the credentials, run the same command with update instead of create and pass the new credentials.

Private PyPI packages

Fast Bakery supports private PyPI repositories by formulating pip index URLs with credentials for each build. The configuration follows the same pattern for every provider: create an integration for the provider, then register each private repository against it with private-pypi-repositories add.

AWS CodeArtifact

  1. Create an IAM role with permissions to download packages from your CodeArtifact repositories, configured to be assumable by the platform’s task role.
  2. Create a code-artifacts integration:
  3. Register each repository against the integration:

GitLab package registry

  1. Generate credentials with read permissions for the GitLab package registry, such as a project access token or a personal access token.
  2. Create a gitlab-artifacts integration:
  3. Register the repository:

Azure DevOps Artifacts

Azure DevOps Artifacts supports two authentication approaches. With managed identity (recommended), grant the perimeter’s managed identity access to your feed in Azure DevOps, then create the integration without credentials:
With static credentials, pass a personal access token instead:
In both cases, register each feed against the integration:

Artifactory (JFrog)

  1. Generate credentials for a user with permission to download packages from the PyPI repositories.
  2. Create an artifactory integration:
  3. Register each repository:

PyPI packages from private Git repositories

The @pypi decorator installs packages directly from private Git repositories:
To grant Fast Bakery access, create a git-pypi-repository integration with credentials that have read access to the repository:
Fast Bakery applies these credentials as a git config URL substitution, so you can scope them at the repository or organization level. This configuration also covers transitive dependencies that reference other private Git URLs.

Private conda packages

Fast Bakery supports packages from private conda channels by formulating channel URLs with static or short-lived credentials for each build request. Artifactory is currently the only supported private conda channel provider.
  1. Generate credentials for a user with permission to download packages from the private conda channels.
  2. Create an artifactory integration:
  3. Register each channel with private-conda-channels add:
If your use case requires private network connectivity or a provider not covered here, contact Anaconda support.