harbor/docs/user_guide.md

112 lines
4.8 KiB
Markdown
Raw Normal View History

2016-03-07 10:39:36 +01:00
#User Guide
##Overview
This guide takes you through the fundamentals of using Harbor. You'll learn how to use Harbor to:
2016-03-08 08:11:39 +01:00
* Manage your projects.
* Manage members of a project.
* Search projects and repositories.
* Manage Harbor system if you are the system administrator.
* Pull and push images using Docker client.
2016-03-07 10:39:36 +01:00
##Role Based Access Control
RBAC (Role Based Access Control) is provided in Harbor and there are four roles with different privileges:
* **Guest**: Guest has read-only privilege for a specified project.
* **Developer**: Developer has read and write privileges for a project.
2016-03-08 04:58:48 +01:00
* **ProjectAdmin**: When creating a new project, you will be assigned the "ProjectAdmin" role to the project. Besides read-write privileges, the "ProjectAdmin" also has some management privileges, such as adding and removing members.
2016-03-07 10:39:36 +01:00
* **SysAdmin**: "SysAdmin" has the most privileges. In addition to the privileges mentioned above, "SysAdmin" can also list all projects, set an ordinary user as administrator and delete users. The public project "library" is also owned by the administrator.
2016-03-08 06:54:53 +01:00
* **Anonymous**: When a user is not logged in, the user is considered as an "anonymous" user. An anonymous user has no access to private projects and has read-only access to public projects.
2016-03-07 10:39:36 +01:00
2016-03-08 06:54:53 +01:00
##User account
As a new user, you can sign up an account by going through the self-registration process. The username and email must be unique in the Harbor system. The password must contain at least 7 characters with 1 lowercase letter, 1 uppercase letter and 1 numeric character.
If the administrator has configured LDAP/AD as authentication source, no sign-up is required. The LDAP/AD user id can be used directly to log in to Harbor.
2016-03-08 04:58:48 +01:00
2016-03-08 06:54:53 +01:00
When you forgot your password, you can follow the below steps to reset the password:
2016-03-08 04:58:48 +01:00
1. Click the link "forgot password" in the sign in page.
2016-03-08 06:54:53 +01:00
2. Input the email used when you signed up, an email will be sent out to you.
3. After receiving the email, click on the link in the email which directs you to a password reset web page.
2016-03-08 04:58:48 +01:00
4. Input your new password and click "Submit".
2016-03-07 10:39:36 +01:00
##Managing projects
2016-03-08 04:58:48 +01:00
A project in Harbor contains all repositories of an application. RBAC is applied to a project. There are two types of projects in Harbor:
2016-03-07 10:39:36 +01:00
* **Public**: All users have the read privilege to a public project, it's convenient for you to share some repositories with others in this way.
2016-03-08 06:54:53 +01:00
* **Private**: A private project can only be accessed by users with proper privileges.
2016-03-07 10:39:36 +01:00
2016-03-08 06:54:53 +01:00
You can create a project after you signed in. Enabling the "Public project" checkbox will make this project public.
2016-03-07 10:39:36 +01:00
![create project](img/create_project.png)
2016-03-08 04:58:48 +01:00
After the project is created, you can browse repositories, users and access logs using the navigation column on the left.
2016-03-07 10:39:36 +01:00
![browse project](img/browse_project.png)
2016-03-08 06:54:53 +01:00
All access logs can be listed by clicking "Logs". You can apply a filter by username, or operations and dates under "Advanced Search".
2016-03-08 04:58:48 +01:00
2016-03-07 10:39:36 +01:00
![browse project](img/project_log.png)
2016-03-08 04:58:48 +01:00
##Managing members of a project
2016-03-07 10:39:36 +01:00
###Adding members
You can add members with different roles to an existing project.
![browse project](img/add_member.png)
###Updating and removing members
2016-03-08 04:58:48 +01:00
You can update or remove a member by clicking the icon on the right.
2016-03-07 10:39:36 +01:00
![browse project](img/remove_update_member.png)
##Searching projects and repositories
2016-03-08 04:58:48 +01:00
Entering a keyword in the search field at the top lists all matching projects and repos. The search result includes public repos and private repos you have access privilege to.
2016-03-07 10:39:36 +01:00
![browse project](img/search.png)
##Administrator options
###Setting administrator and deleting user
2016-03-08 06:54:53 +01:00
Administrator can add "SysAdmin" role to an ordinary user by toggling the switch under "System Admin". To delete a user, click on the recycle bin icon.
2016-03-07 10:39:36 +01:00
![browse project](img/set_admin_remove_user.png)
##Pulling and pushing images using Docker client
2016-03-08 04:58:48 +01:00
**NOTE: Harbor only supports Registry V2 API. You need to use Docker client 1.6.0 or higher.**
2016-03-07 10:39:36 +01:00
###Pulling images
2016-03-08 04:58:48 +01:00
If the project that the image belongs to is private, you should sign in first:
2016-03-07 10:39:36 +01:00
```sh
$ docker login 10.117.169.182
```
2016-03-08 04:58:48 +01:00
You can now pull the image:
2016-03-07 10:39:36 +01:00
```sh
$ docker pull 10.117.169.182/library/ubuntu:14.04
```
2016-03-08 04:58:48 +01:00
**Note: Replace "10.117.169.182" with the IP address or domain name of your Harbor node.**
2016-03-07 10:39:36 +01:00
###Pushing images
2016-03-08 04:58:48 +01:00
Before pushing an image, you must create a corresponding project on Harbor web UI.
2016-03-07 10:39:36 +01:00
2016-03-08 04:58:48 +01:00
First, log in from Docker client:
2016-03-07 10:39:36 +01:00
```sh
$ docker login 10.117.169.182
```
2016-03-08 04:58:48 +01:00
Tag the image:
2016-03-07 10:39:36 +01:00
```sh
$ docker tag ubuntu:14.04 10.117.169.182/demo/ubuntu:14.04
```
2016-03-08 04:58:48 +01:00
Push the image:
2016-03-07 10:39:36 +01:00
```sh
$ docker push 10.117.169.182/demo/ubuntu:14.04
```
2016-03-08 04:58:48 +01:00
**Note: Replace "10.117.169.182" with the IP address or domain name of your Harbor node.**