[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-06-16 (世界標準時間)。"],[[["Container Registry uses Cloud Storage to store container images, and Cloud Storage encrypts data server-side by default."],["For compliance, customer-managed encryption keys (CMEK) can be used to encrypt container images stored in Container Registry, allowing control over access by disabling or destroying the key."],["Organization policy constraints, particularly those related to Cloud Storage and Pub/Sub APIs, can affect Container Registry usage, such as preventing image pushes or requiring CMEK for new storage buckets and Pub/Sub topics."],["If `constraints/gcp.restrictNonCmekServices` is enforced, you cannot push images to Container Registry, and Artifact Registry is recommended as an alternative."],["Container Registry can use CMEK by leveraging storage buckets configured with CMEK in Cloud Storage; however, this is impossible if `constraints/gcp.restrictNonCmekServices` is being used."]]],[]]