An open source trusted cloud native registry project that stores, signs, and scans content.
Go to file
He Weiwei 385aaac00d
Merge pull request #11620 from heww/fix-issue-11524
feat(scanner): make Clair and Trivy as reserved name for scanners
2020-04-15 15:21:35 +08:00
.github Make sure codecov reports are merged 2020-04-11 12:00:07 +08:00
api Add version API to swagger 2020-04-09 11:03:42 +08:00
contrib Update config file names 2019-09-02 18:19:06 +08:00
docs Add Multi-Scanner test file 2020-04-08 16:26:31 +08:00
make Merge pull request #11620 from heww/fix-issue-11524 2020-04-15 15:21:35 +08:00
src Merge pull request #11620 from heww/fix-issue-11524 2020-04-15 15:21:35 +08:00
tests Merge pull request #11616 from jwangyangls/fix-bug-case 2020-04-14 21:41:47 +08:00
tools Remove migrator container 2020-04-01 12:16:53 +08:00
.dockerignore Add dockerignore file to prevent local node_modules to be copied into the portal image 2019-05-18 09:11:35 +02:00
.drone.yml There is a new commit in harbor-e2e-engine:1.42, which is upgrade docker to the latest version, so drone.yml should be update to the new one. 2019-11-19 15:03:04 +08:00
.gitignore update chart sdk to support helm v3 2020-03-02 11:39:09 +08:00
.gitmessage Update README and .gitmessage 2018-07-17 16:42:03 +08:00
ADOPTERS.md Fix docs links and images for adopters 2020-02-04 21:59:39 -05:00
CHANGELOG.md Update CHANGELOG.md for v1.8.0 2019-06-04 11:20:28 +01:00
codecov.yml Make sure codecov reports are merged 2020-04-11 12:00:07 +08:00
CONTRIBUTING.md upgrade golang version to v1.13.8 (#11006) 2020-03-11 12:20:06 +08:00
gskey.sh.enc Enable travis to update logs to GSR (#5949) 2018-09-27 08:54:56 +08:00
LICENSE Replacing copyright notices with "Copyright Project Harbor Authors". 2018-09-19 16:59:36 +00:00
Makefile chore(trivy): Bump up trivy to 0.5.4 2020-04-09 18:02:18 +02:00
OWNERS.md Update OWNERS.md 2019-10-21 02:34:09 -05:00
README.md Update the link of CI badge 2020-04-09 16:31:31 +08:00
RELEASES.md Update the support matrix 2020-02-27 19:59:39 +08:00
ROADMAP.md Update ROADMAP.md 2019-10-22 11:16:09 -07:00
SECURITY.md Document the versioning and release process, also updating the SECURITY.md 2019-10-18 14:24:42 +08:00
VERSION Bump up base version to v2.0.0 2020-03-09 12:36:22 +08:00

Harbor

CI Coverage Status Go Report Card CII Best Practices Codacy Badge Nightly Status


notificationCommunity Meeting
The Harbor Project holds bi-weekly community calls in two different timezones. To join the community calls or to watch previous meeting notes and recordings, please visit the meeting schedule.



Note: The master branch may be in an unstable or even broken state during development. Please use releases instead of the master branch in order to get a stable set of binaries.

Harbor

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Harbor extends the open source Docker Distribution by adding the functionalities usually required by users such as security, identity and management. Having a registry closer to the build and run environment can improve the image transfer efficiency. Harbor supports replication of images between registries, and also offers advanced security features such as user management, access control and activity auditing.

Harbor is hosted by the Cloud Native Computing Foundation (CNCF). If you are an organization that wants to help shape the evolution of cloud native technologies, consider joining the CNCF. For details about who's involved and how Harbor plays a role, read the CNCF announcement.

Features

  • Cloud native registry: With support for both container images and Helm charts, Harbor serves as registry for cloud native environments like container runtimes and orchestration platforms.
  • Role based access control: Users access different repositories through 'projects' and a user can have different permission for images or Helm charts under a project.
  • Policy based replication: Images and charts can be replicated (synchronized) between multiple registry instances based on policies with using filters (repository, tag and label). Harbor automatically retries a replication if it encounters any errors. This can be used to assist loadbalancing, achieve high availabiliy, and faciliate multi-datacenter deployments in hybrid and multi-cloud scenarios.
  • Vulnerability Scanning: Harbor scans images regularly for vulnerabilities and has policy checks to prevent vulnerable images from being deployed.
  • LDAP/AD support: Harbor integrates with existing enterprise LDAP/AD for user authentication and management, and supports importing LDAP groups into Harbor that can then be given permissions to specific projects.
  • OIDC support: Harbor leverages OpenID Connect (OIDC) to verify the identity of users authenticated by an external authorization server or identity provider. Single sign-on can be enabled to log into the Harbor portal.
  • Image deletion & garbage collection: System admin can run garbage collection jobs so that images(dangling manifests and unreferenced blobs) can be deleted and their space can be freed up periodically.
  • Notary: Support signing container images using Docker Content Trust (leveraing Notary) for guaranteeing authenticity and provenance. In additon, policies that prevent unsigned images from being deployed can also be activated.
  • Graphical user portal: User can easily browse, search repositories and manage projects.
  • Auditing: All the operations to the repositories are tracked through logs.
  • RESTful API: RESTful APIs are provided to facilitate administrative operations, and are easy to use for integration with external systems. An embedded Swagger UI is available for exploring and testing the API.
  • Easy deployment: Harbor can be deployed via Docker compose as well Helm Chart. A Harbor Operator was added recently as well - https://goharbor.io/docs/1.10/build-customize-contribute/e2e_api_python_based_scripting_guide/

API

  • Harbor RESTful API: The APIs for most administrative operations of Harbor and can be used to perform integrations with Harbor programmatically.
    • Spec validation status:

Compatibility

The compatibility list document provides compatibility information for the Harbor components.

Install & Run

System requirements:

On a Linux host: docker 17.06.0-ce+ and docker-compose 1.18.0+ .

Download binaries of Harbor release and follow Installation & Configuration Guide to install Harbor.

If you want to deploy Harbor on Kubernetes, please use the Harbor chart.

Refer to User Guide for more details on how to use Harbor.

Community

Additional Tools

Tools layered on top of Harbor and contributed by community.

  • Harbor.Tagd
    • Automates the process of cleaning up old tags from your Harbor container registries.
    • Lead by @nlowe from HylandSoftware.

Demos

  • Live Demo - A demo environment with the latest Harbor stable build installed. For additional information please refer to this page.
  • Video Demos - Demos for Harbor features and continuously updated.

Partners and Users

For a list of users, please refer to ADOPTERS.md.

Security

Security Audit

A third party security audit was performed by Cure53 in October of 2019. You can see the full report here.

Reporting security vulnerabilities

If you've found a security related issue, a vulnerability, or a potential vulnerability in Harbor please let the Harbor Security Team know with the details of the vulnerability. We'll send a confirmation email to acknowledge your report, and we'll send an additional email when we've identified the issue positively or negatively.

For further details please see our complete security release process.

License

Harbor is available under the Apache 2 license.

This project uses open source components which have additional licensing terms. The official docker images and licensing terms for these open source components can be found at the following locations: