Docker Hub rate limits pull requests. Cloud registries (ECR, GCR, ACR) create vendor lock-in. Harbor gives you a self-hosted, CNCF-graduated container registry with enterprise features.
Installation
helm install harbor harbor/harbor \
--namespace harbor --create-namespace \
--set expose.type=ingress \
--set expose.ingress.hosts.core=registry.myorg.com \
--set expose.tls.certSource=secret \
--set expose.tls.secret.secretName=harbor-tls \
--set persistence.persistentVolumeClaim.registry.size=200Gi \
--set externalURL=https://registry.myorg.comPush and Pull Images
# Login
docker login registry.myorg.com
# Tag and push
docker tag myapp:latest registry.myorg.com/myproject/myapp:v1.0
docker push registry.myorg.com/myproject/myapp:v1.0
# Pull
docker pull registry.myorg.com/myproject/myapp:v1.0Projects and RBAC
Harbor organizes images into projects with role-based access:
registry.myorg.com/
āāā platform/ # Platform team images
ā āāā nginx-base
ā āāā node-base
āāā commerce/ # Commerce team images
ā āāā order-api
ā āāā payment-service
āāā public/ # Public read access
āāā docs-site| Role | Pull | Push | Manage |
|---|---|---|---|
| Guest | ā | ā | ā |
| Developer | ā | ā | ā |
| Maintainer | ā | ā | Partial |
| Admin | ā | ā | ā |
Master this topic with hands-on labs
Go beyond reading ā build real projects in sandboxed environments with expert video guidance.
Browse Courses āVulnerability Scanning
Harbor integrates with Trivy for automatic scanning:
# Scan results for myapp:v1.0
Total: 3 vulnerabilities
Critical: 0
High: 1 (openssl 3.0.13 ā fix: 3.0.14)
Medium: 2Configure policies to block vulnerable images:
Project Settings ā Policy:
ā Prevent vulnerable images from being pulled
Severity threshold: HighImages with High or Critical CVEs cannot be pulled until the vulnerabilities are fixed.
Image Signing
Verify image integrity with Cosign:
# Sign with Cosign
cosign sign registry.myorg.com/commerce/order-api:v1.0
# Harbor shows signature status in the UI
# ā Signed by: build@myorg.comCombine with Kubernetes admission control to enforce only signed images run in production.
Replication
Mirror images between registries:
# Harbor replication rule
Source: docker.io/library/nginx
Destination: registry.myorg.com/mirrors/nginx
Trigger: Scheduled (every 6 hours)
Filter: Tag matching "1.2*"Use cases: - Cache Docker Hub: Avoid rate limits - Multi-region: Replicate to registries in each region - Disaster recovery: Replicate to a backup registry - Air-gapped environments: Pull from Harbor instead of the internet
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps ā curated insights delivered to your inbox. No spam.
Subscribe Free āProxy Cache
Cache external registries without full replication:
# Configure Docker Hub as a proxy cache
Project: dockerhub-proxy
Type: Proxy Cache
Endpoint: https://hub.docker.com
# Pull through Harbor (cached)
docker pull registry.myorg.com/dockerhub-proxy/library/nginx:1.25First pull fetches from Docker Hub. Subsequent pulls served from Harbor's cache.
Garbage Collection
Clean up unreferenced blobs:
# Schedule garbage collection
# Harbor Admin ā Garbage Collection ā Schedule
# Weekly, Sunday at 2 AMWithout GC, deleted tags still consume storage. Schedule it regularly.
Kubernetes Integration
# Create image pull secret
kubectl create secret docker-registry harbor-creds \
--docker-server=registry.myorg.com \
--docker-username=robot-account \
--docker-password=token
# Use in deployments
spec:
imagePullSecrets:
- name: harbor-creds
containers:
- image: registry.myorg.com/commerce/order-api:v1.0For cluster-wide configuration, add the secret to a service account:
kubectl patch serviceaccount default \
-p '{"imagePullSecrets": [{"name": "harbor-creds"}]}'Harbor vs Alternatives
| Feature | Harbor | Docker Hub | ECR | GHCR |
|---|---|---|---|---|
| Self-hosted | Yes | No | No | No |
| Vulnerability scanning | Built-in (Trivy) | Paid | Basic | No |
| RBAC | Fine-grained | Basic | IAM | Org-level |
| Replication | Multi-target | No | Cross-region | No |
| Image signing | Cosign/Notary | Paid | Signer | Cosign |
| Cost | Infrastructure only | Per-seat | Per-GB + transfer | Free (public) |
---
Ready to go deeper? Master container infrastructure with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials ā start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Kaniko Rootless Container Builds
Kaniko builds container images inside Kubernetes without Docker daemon or root access. Learn how to use Kaniko in CI/CD pipelines, Tekton, and GitHub Actions.
Container Security Best Practices
Secure containers in production. Image scanning, rootless, read-only filesystems, secrets management, and runtime security.
Podman vs Docker in 2026
Podman and Docker both run containers but differ in architecture. Compare rootless containers, daemon requirements, Compose support, and Kubernetes.
Headlamp Kubernetes Dashboard Guide
Headlamp is a modern Kubernetes dashboard that replaces the official Kubernetes Dashboard. Learn how to install Headlamp, manage clusters, and extend it.
Helm Charts Beginner Tutorial
Get started with Helm charts for Kubernetes. Install community charts, create custom charts, manage values files, and handle releases.
Hyperparameter Tuning with MLflow
Combine scikit-learn's RandomizedSearchCV with MLflow tracking to find optimal model parameters and compare results visually.
Explore topics
Browse more articles on the topics covered here.