Skip to main content
šŸŽ¤ Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

Harbor Container Registry Guide

Harbor is an open-source container registry with vulnerability scanning, RBAC, image signing, and replication. Learn how to deploy Harbor on Kubernetes.

Luca BertonMarch 1, 20262 min read

Docker Hub rate limits pull requests. Cloud registries (ECR, GCR, ACR) create vendor lock-in. Harbor gives you a self-hosted, CNCF-graduated container registry with enterprise features.

Installation

bash
helm install harbor harbor/harbor \
  --namespace harbor --create-namespace \
  --set expose.type=ingress \
  --set expose.ingress.hosts.core=registry.myorg.com \
  --set expose.tls.certSource=secret \
  --set expose.tls.secret.secretName=harbor-tls \
  --set persistence.persistentVolumeClaim.registry.size=200Gi \
  --set externalURL=https://registry.myorg.com

Push and Pull Images

bash
# Login
docker login registry.myorg.com

# Tag and push
docker tag myapp:latest registry.myorg.com/myproject/myapp:v1.0
docker push registry.myorg.com/myproject/myapp:v1.0

# Pull
docker pull registry.myorg.com/myproject/myapp:v1.0

Projects and RBAC

Harbor organizes images into projects with role-based access:

registry.myorg.com/
ā”œā”€ā”€ platform/          # Platform team images
│   ā”œā”€ā”€ nginx-base
│   └── node-base
ā”œā”€ā”€ commerce/          # Commerce team images  
│   ā”œā”€ā”€ order-api
│   └── payment-service
└── public/            # Public read access
    └── docs-site
RolePullPushManage
Guestāœ“āœ—āœ—
Developerāœ“āœ“āœ—
Maintainerāœ“āœ“Partial
Admināœ“āœ“āœ“
Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

Vulnerability Scanning

Harbor integrates with Trivy for automatic scanning:

# Scan results for myapp:v1.0
Total: 3 vulnerabilities
  Critical: 0
  High: 1 (openssl 3.0.13 → fix: 3.0.14)
  Medium: 2

Configure policies to block vulnerable images:

Project Settings → Policy:
  āœ“ Prevent vulnerable images from being pulled
  Severity threshold: High

Images with High or Critical CVEs cannot be pulled until the vulnerabilities are fixed.

Image Signing

Verify image integrity with Cosign:

bash
# Sign with Cosign
cosign sign registry.myorg.com/commerce/order-api:v1.0

# Harbor shows signature status in the UI
# āœ“ Signed by: build@myorg.com

Combine with Kubernetes admission control to enforce only signed images run in production.

Replication

Mirror images between registries:

yaml
# Harbor replication rule
Source: docker.io/library/nginx
Destination: registry.myorg.com/mirrors/nginx
Trigger: Scheduled (every 6 hours)
Filter: Tag matching "1.2*"

Use cases: - Cache Docker Hub: Avoid rate limits - Multi-region: Replicate to registries in each region - Disaster recovery: Replicate to a backup registry - Air-gapped environments: Pull from Harbor instead of the internet

Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

Proxy Cache

Cache external registries without full replication:

# Configure Docker Hub as a proxy cache
Project: dockerhub-proxy
Type: Proxy Cache
Endpoint: https://hub.docker.com

# Pull through Harbor (cached)
docker pull registry.myorg.com/dockerhub-proxy/library/nginx:1.25

First pull fetches from Docker Hub. Subsequent pulls served from Harbor's cache.

Garbage Collection

Clean up unreferenced blobs:

bash
# Schedule garbage collection
# Harbor Admin → Garbage Collection → Schedule
# Weekly, Sunday at 2 AM

Without GC, deleted tags still consume storage. Schedule it regularly.

Kubernetes Integration

yaml
# Create image pull secret
kubectl create secret docker-registry harbor-creds \
  --docker-server=registry.myorg.com \
  --docker-username=robot-account \
  --docker-password=token

# Use in deployments
spec:
  imagePullSecrets:
    - name: harbor-creds
  containers:
    - image: registry.myorg.com/commerce/order-api:v1.0

For cluster-wide configuration, add the secret to a service account:

bash
kubectl patch serviceaccount default \
  -p '{"imagePullSecrets": [{"name": "harbor-creds"}]}'

Harbor vs Alternatives

FeatureHarborDocker HubECRGHCR
Self-hostedYesNoNoNo
Vulnerability scanningBuilt-in (Trivy)PaidBasicNo
RBACFine-grainedBasicIAMOrg-level
ReplicationMulti-targetNoCross-regionNo
Image signingCosign/NotaryPaidSignerCosign
CostInfrastructure onlyPer-seatPer-GB + transferFree (public)

---

Ready to go deeper? Master container infrastructure with hands-on courses at CopyPasteLearn.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.