I'm trying to set up CI/CD with CircleCI and I'd like the base image of my pipelines to be a custom made CI/CD image which lives in Artifact Registry. I'm having trouble figuring out how to properly authenticate CircleCI when pulling the base image for a job.
I've looked at both the CirlceCI docs for authenticated pulls and the Artifact Registry docs for authentication and I can't figure out how to put the two puzzle pieces together. It seems CircleCI requires some sort of password or access-key while Artifact Registry requires either glcoud for direct docker configuration (gcloud auth configure-docker) access token generation OR interactive docker logins (cat KEY-FILE | docker login -u KEY-TYPE --password-stdin \ https://LOCATION-docker.pkg.dev).
How can I use a private docker image in Artifact Registry as the base for a job in CircleCI?