Cloud Cost Sense
Google Artifact Registry Cost: Storage, Egress, and Cleanup
Estimate Google Artifact Registry cost from stored image layers, repository location, downloads, vulnerability scanning, and cleanup policies.
Estimate stored layers and version growth
Artifact Registry storage is based on artifacts at rest, so start with the compressed size of container layers or packages and the number of versions retained. Shared container layers can reduce the physical growth compared with multiplying every image size by every tag, while frequent base-image updates can create new layers. Measure repository storage over a release cycle instead of estimating from source code size.
Standard and remote repositories store artifacts; virtual repositories route requests to upstream repositories rather than storing their own copies. The storage allowance is evaluated across the billing account, not independently for every project. Use the current official pricing page for the applicable allowance and rate rather than embedding a price that can change.
Map every download from repository to consumer
Data transfer depends on the repository location and where each artifact is delivered. Pulls into the same location can avoid transfer charges, while cross-region, cross-continent, Internet, or on-premises downloads can follow different rates. Record the locations of Cloud Run services, GKE nodes, Compute Engine VMs, CI runners, and developer machines that pull from each repository.
Estimate transferred bytes as image or package bytes pulled per deployment multiplied by deployments, cold nodes, environments, and destinations. Layer caches can reduce repeat downloads, but autoscaling, ephemeral CI workers, and frequent base-image changes can weaken that saving. Co-locate repositories with their main runtimes when latency, resilience, and data residency requirements allow.
Include scanning, then clean up safely
Vulnerability scanning is a separate cost when the relevant scanning API and supported feature are enabled. Inventory which repositories and artifact types are scanned, how often new images are pushed, and whether on-demand scans also run in CI. Confirm current Artifact Analysis pricing and your Security Command Center tier before treating every scan as the same charge.
Use cleanup policies to delete versions you no longer need and keep production releases or a recent version count. Test a policy in dry-run mode, inspect the matches, and protect rollback artifacts before enabling deletion; active cleanup runs asynchronously and is not an immediate storage reset. Compare a normal release month with a high-frequency build month, then monitor storage and transfer billing after rollout.
Estimate the Cloud Build minutes that create these artifacts