> ## Documentation Index
> Fetch the complete documentation index at: https://anaconda.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Fast Bakery

export const Comments = ({children}) => {
  return <div class="my-4 px-5 py-4 overflow-hidden rounded-2xl flex gap-3 border border-zinc-500/20 bg-zinc-50/50 dark:border-zinc-500/30 dark:bg-zinc-500/10" data-callout-type="comments">
      <div class="w-4">
        <svg width="14" height="14" viewBox="0 0 640 640" fill="currentColor" xmlns="http://www.w3.org/2000/svg" class="w-5 h-5" aria-label="Comments">
            <path d="M320 112C434.9 112 528 205.1 528 320C528 434.9 434.9 528 320 528C205.1 528 112 434.9 112 320C112 205.1 205.1 112 320 112zM320 576C461.4 576 576 461.4 576 320C576 178.6 461.4 64 320 64C178.6 64 64 178.6 64 320C64 461.4 178.6 576 320 576zM280 400C266.7 400 256 410.7 256 424C256 437.3 266.7 448 280 448L360 448C373.3 448 384 437.3 384 424C384 410.7 373.3 400 360 400L352 400L352 312C352 298.7 341.3 288 328 288L280 288C266.7 288 256 298.7 256 312C256 325.3 266.7 336 280 336L304 336L304 400L280 400zM320 256C337.7 256 352 241.7 352 224C352 206.3 337.7 192 320 192C302.3 192 288 206.3 288 224C288 241.7 302.3 256 320 256z" />
        </svg>
      </div>
      <div class="text-sm prose min-w-0 w-full">
        {children}
      </div>
    </div>;
};

Fast Bakery is the platform's containerization backend. It packages the dependencies you declare with `@pypi` or `@conda` into reproducible container images automatically, so your flows deploy and scale without manual image builds. For background on how it works, see [Fast, Automatic Containerization of ML and AI Projects with Fast Bakery](https://www.anaconda.com/blog/containerize-with-fast-bakery).

To activate Fast Bakery, run or deploy a flow that uses `@pypi` or `@conda` with the `--environment=fast-bakery` flag:

```sh theme={null}
# For local Kubernetes runs
python flow.py --environment=fast-bakery run --with kubernetes

# For Argo Workflows
python flow.py --environment=fast-bakery argo-workflows create
python flow.py argo-workflows trigger
```

## Using private packages and registries

Out of the box, Fast Bakery resolves publicly available Python packages and can use any public image as a base image. To work with private Python packages, private conda channels, or private container images, create a resource integration that gives Fast Bakery access to your private sources, then register the repository or channel against that integration.

The sections below cover the most common scenarios. Each shows a canonical example; for the complete set of options for each command, see [Integration types](/docs/platform/cli/integrations/integration-types).

<Note>
  To run the commands in these sections, you must have:

  * The `outerbounds` CLI installed and configured. (See [Getting started with the platform CLI](/docs/platform/cli)).
  * Admin privileges on the platform.
</Note>

### Private container image registries

Fast Bakery builds containers by pulling a base image first. To use a base image hosted in a private registry, create a `container-registry` integration.

For a private registry on Amazon ECR, there are two ways to grant access:

1. **Assumed role**: Create an IAM role with permissions to pull images from your ECR registry, configured to be assumable by the platform's task role, then create the integration with the role ARN:

   ```sh theme={null}
   outerbounds integrations container-registry create <INTEGRATION_NAME> \
     --description "<DESCRIPTION>" \
     --registry-domain <REGISTRY_DOMAIN> \
     --target-role-arn <ROLE_ARN>
   ```

   <Comments>
     Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
     Replace \<DESCRIPTION> with a short description of the registry.<br />
     Replace \<REGISTRY\_DOMAIN> with your ECR registry domain, (Example: `123456789012.dkr.ecr.us-west-2.amazonaws.com/`).<br />
     Replace \<ROLE\_ARN> with the ARN of the IAM role that can pull images from the registry.
   </Comments>

2. **Task role**: Grant the perimeter's task IAM role permissions to pull images from your ECR registry, then create the integration with `--use-task-role`:

   ```sh theme={null}
   outerbounds integrations container-registry create <INTEGRATION_NAME> \
     --description "<DESCRIPTION>" \
     --registry-domain <REGISTRY_DOMAIN> \
     --use-task-role
   ```

   <Comments>
     Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
     Replace \<DESCRIPTION> with a short description of the registry.<br />
     Replace \<REGISTRY\_DOMAIN> with your ECR registry domain.
   </Comments>

   After the integration exists, you can use any image in the registry as a base image:

```python theme={null}
@kubernetes(image="<REGISTRY_DOMAIN>/myimage:v0.1.0")
@pypi(
    packages={
        "pandas": "2.3.3",
        "scikit-learn": "1.7.2",
    },
    python="3.12",
)
```

#### GitLab container registry

For container images in a GitLab container registry, create the integration with username and password credentials:

```sh theme={null}
outerbounds integrations container-registry create <INTEGRATION_NAME> \
  --description "<DESCRIPTION>" \
  --registry-domain <REGISTRY_DOMAIN> \
  --username <USERNAME> \
  --password <PASSWORD>
```

<Comments>
  Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
  Replace \<DESCRIPTION> with a short description of the registry.<br />
  Replace \<REGISTRY\_DOMAIN> with the registry domain, for example `registry.gitlab.com/myorg/mygroup`.<br />
  Replace \<USERNAME> and \<PASSWORD> with credentials that have read access to the registry, such as a project access token or a personal access token.
</Comments>

To rotate the credentials, run the same command with `update` instead of `create` and pass the new credentials.

### Private PyPI packages

Fast Bakery supports private PyPI repositories by formulating `pip` index URLs with credentials for each build. The configuration follows the same pattern for every provider: create an integration for the provider, then register each private repository against it with `private-pypi-repositories add`.

#### AWS CodeArtifact

1. Create an IAM role with permissions to download packages from your CodeArtifact repositories, configured to be assumable by the platform's task role.

2. Create a `code-artifacts` integration:

   ```sh theme={null}
   outerbounds integrations code-artifacts create <INTEGRATION_NAME> \
     --description "<DESCRIPTION>" \
     --domain <DOMAIN> \
     --domain-owner <AWS_ACCOUNT_ID> \
     --aws-region <REGION> \
     --target-role <ROLE_ARN>
   ```

   <Comments>
     Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
     Replace \<DESCRIPTION> with a short description of the integration.<br />
     Replace \<DOMAIN> with your CodeArtifact domain.<br />
     Replace \<AWS\_ACCOUNT\_ID> with the AWS account ID that owns the domain.<br />
     Replace \<REGION> with the AWS region of the repositories.<br />
     Replace \<ROLE\_ARN> with the ARN of the IAM role from step 1.
   </Comments>

3. Register each repository against the integration:

   ```sh theme={null}
   outerbounds integrations private-pypi-repositories add \
     --repository-name <REPOSITORY_NAME> \
     --repository-host-integration-name <INTEGRATION_NAME>
   ```

   <Comments>
     Replace \<REPOSITORY\_NAME> with the name of the CodeArtifact repository.<br />
     Replace \<INTEGRATION\_NAME> with the name of the integration from step 2.
   </Comments>

#### GitLab package registry

1. Generate credentials with read permissions for the GitLab package registry, such as a project access token or a personal access token.

2. Create a `gitlab-artifacts` integration:

   ```sh theme={null}
   outerbounds integrations gitlab-artifacts create <INTEGRATION_NAME> \
     --description "<DESCRIPTION>" \
     --gitlab-url <GITLAB_URL> \
     --project-id <PROJECT_ID> \
     --username <USERNAME> \
     --password <PASSWORD>
   ```

   <Comments>
     Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
     Replace \<DESCRIPTION> with a short description of the integration.<br />
     Replace \<GITLAB\_URL> with your GitLab instance URL. Defaults to `gitlab.com`.<br />
     Replace \<PROJECT\_ID> with the numeric ID of the GitLab project that hosts the packages.<br />
     Replace \<USERNAME> and \<PASSWORD> with the credentials from step 1.
   </Comments>

3. Register the repository:

   ```sh theme={null}
   outerbounds integrations private-pypi-repositories add \
     --repository-name <REPOSITORY_NAME> \
     --repository-host-integration-name <INTEGRATION_NAME>
   ```

   <Comments>
     Replace \<REPOSITORY\_NAME> with the repository name to register.<br />
     Replace \<INTEGRATION\_NAME> with the name of the integration from step 2.
   </Comments>

#### Azure DevOps Artifacts

Azure DevOps Artifacts supports two authentication approaches. With managed identity (recommended), grant the perimeter's managed identity access to your feed in Azure DevOps, then create the integration without credentials:

```sh theme={null}
outerbounds integrations azure-artifacts create <INTEGRATION_NAME> \
  --description "<DESCRIPTION>" \
  --organization <ORGANIZATION> \
  --project-name <PROJECT_NAME>
```

<Comments>
  Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
  Replace \<DESCRIPTION> with a short description of the integration.<br />
  Replace \<ORGANIZATION> with your Azure DevOps organization.<br />
  Replace \<PROJECT\_NAME> with the Azure DevOps project that hosts the feed.
</Comments>

With static credentials, pass a personal access token instead:

```sh theme={null}
outerbounds integrations azure-artifacts create <INTEGRATION_NAME> \
  --description "<DESCRIPTION>" \
  --organization <ORGANIZATION> \
  --project-name <PROJECT_NAME> \
  --username <USERNAME> \
  --password <PASSWORD>
```

<Comments>
  Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
  Replace \<DESCRIPTION> with a short description of the integration.<br />
  Replace \<ORGANIZATION> with your Azure DevOps organization.<br />
  Replace \<PROJECT\_NAME> with the Azure DevOps project that hosts the feed.<br />
  Replace \<USERNAME> and \<PASSWORD> with a personal access token that has read access to the feed.
</Comments>

In both cases, register each feed against the integration:

```sh theme={null}
outerbounds integrations private-pypi-repositories add \
  --repository-name <REPOSITORY_NAME> \
  --repository-host-integration-name <INTEGRATION_NAME>
```

<Comments>
  Replace \<REPOSITORY\_NAME> with the name of the feed.<br />
  Replace \<INTEGRATION\_NAME> with the name of the integration.
</Comments>

#### Artifactory (JFrog)

1. Generate credentials for a user with permission to download packages from the PyPI repositories.

2. Create an `artifactory` integration:

   ```sh theme={null}
   outerbounds integrations artifactory create <INTEGRATION_NAME> \
     --description "<DESCRIPTION>" \
     --domain <DOMAIN> \
     --username <USERNAME> \
     --password <PASSWORD>
   ```

   <Comments>
     Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
     Replace \<DESCRIPTION> with a short description of the integration.<br />
     Replace \<DOMAIN> with your Artifactory domain, for example `mycompany.jfrog.io`.<br />
     Replace \<USERNAME> and \<PASSWORD> with the credentials from step 1.
   </Comments>

3. Register each repository:

   ```sh theme={null}
   outerbounds integrations private-pypi-repositories add \
     --repository-name <REPOSITORY_NAME> \
     --repository-host-integration-name <INTEGRATION_NAME>
   ```

   <Comments>
     Replace \<REPOSITORY\_NAME> with the repository name to register.<br />
     Replace \<INTEGRATION\_NAME> with the name of the integration from step 2.
   </Comments>

### PyPI packages from private Git repositories

The `@pypi` decorator installs packages directly from private Git repositories:

```python theme={null}
@pypi(
    packages={
        "git+https://github.com/<ORG>/<REPO>.git@main": ""
    },
    python="3.12",
)
```

<Comments>
  Replace \<ORG> and \<REPO> with the GitHub organization and repository that host the package.
</Comments>

To grant Fast Bakery access, create a `git-pypi-repository` integration with credentials that have read access to the repository:

```sh theme={null}
outerbounds integrations git-pypi-repository create <INTEGRATION_NAME> \
  --description "<DESCRIPTION>" \
  --repository-url <REPOSITORY_URL> \
  --username <USERNAME> \
  --password <PASSWORD>
```

<Comments>
  Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
  Replace \<DESCRIPTION> with a short description of the integration.<br />
  Replace \<REPOSITORY\_URL> with the repository or organization URL, for example `https://github.com/myorg`.<br />
  Replace \<USERNAME> and \<PASSWORD> with credentials that have read access to the repository.
</Comments>

Fast Bakery applies these credentials as a `git config` URL substitution, so you can scope them at the repository or organization level. This configuration also covers transitive dependencies that reference other private Git URLs.

### Private conda packages

Fast Bakery supports packages from private conda channels by formulating channel URLs with static or short-lived credentials for each build request. Artifactory is currently the only supported private conda channel provider.

1. Generate credentials for a user with permission to download packages from the private conda channels.

2. Create an `artifactory` integration:

   ```sh theme={null}
   outerbounds integrations artifactory create <INTEGRATION_NAME> \
     --description "<DESCRIPTION>" \
     --domain <DOMAIN> \
     --username <USERNAME> \
     --password <PASSWORD>
   ```

   <Comments>
     Replace \<INTEGRATION\_NAME> with a name for the integration.<br />
     Replace \<DESCRIPTION> with a short description of the integration.<br />
     Replace \<DOMAIN> with your Artifactory domain.<br />
     Replace \<USERNAME> and \<PASSWORD> with the credentials from step 1.
   </Comments>

3. Register each channel with `private-conda-channels add`:

   ```sh theme={null}
   outerbounds integrations private-conda-channels add \
     --repository-name <CHANNEL_NAME> \
     --repository-host-integration-name <INTEGRATION_NAME>
   ```

   <Comments>
     Replace \<CHANNEL\_NAME> with the name of the conda channel.<br />
     Replace \<INTEGRATION\_NAME> with the name of the integration from step 2.
   </Comments>

If your use case requires private network connectivity or a provider not covered here, contact Anaconda support.
