Introduction
Harbor is an open source registry for storing and managing Docker images and Helm charts. Harbor extends Docker Registry by adding functionality such as user management, security scanning, and image replication between registries.
System requirements
- Operating system: Ubuntu 24.04 LTS
- CPU: Minimum 2 cores
- RAM: Minimum 4GB (recommended 8GB)
- Hard drive: Minimum 40GB free space
- Access rights: Root or sudo
Installation steps
Step 1: Update the system
First, update the packages list and upgrade the system:
bash
sudo apt update
sudo apt upgrade -yStep 2: Install Docker
Harbor requires Docker to run. Install Docker using the following commands:
bash
# Cài đặt Docker sudo apt install -y docker.ioKhởi động và kích hoạt Docker
sudo systemctl start docker sudo systemctl enable docker
Kiểm tra phiên bản Docker
docker --version
Step 3: Install Docker Compose
Docker Compose is used to manage Harbor containers:
# Tải Docker Compose sudo curl -L "https://github.com/docker/compose/releases/latest/download/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-composeCấp quyền thực thi
sudo chmod +x /usr/local/bin/docker-compose
Kiểm tra phiên bản
docker-compose --version
Step 4: Download Harbor
Move to folder /opt and download the latest version of Harbor:
# Di chuyển đến thư mục /opt cd /optTải Harbor (phiên bản 2.11.2 - kiểm tra phiên bản mới nhất tại GitHub)
sudo wget https://github.com/goharbor/harbor/releases/download/v2.11.2/harbor-offline-installer-v2.11.2.tgz
Giải nén
sudo tar xzvf harbor-offline-installer-v2.11.2.tgz
Step 5: Configure Harbor
Move into the Harbor folder and create a configuration file:
cd /opt/harbor
sudo cp harbor.yml.tmpl harbor.ymlEdit configuration file harbor.yml:
sudo nano harbor.ymlImportant parameters to configure:
# Hostname - thay bằng IP hoặc domain của bạn hostname: your-domain.com # hoặc IP: 192.168.1.100Giao thức HTTP
http: port: 80
Giao thức HTTPS (tùy chọn - khuyến nghị cho production)
Bỏ comment nếu muốn sử dụng HTTPS
https:
port: 443
certificate: /path/to/cert.crt
private_key: /path/to/cert.key
Mật khẩu admin mặc định (NÊN ĐỔI)
harbor_admin_password: Harbor12345
Cơ sở dữ liệu
database: password: root123 max_idle_conns: 100 max_open_conns: 900
Thư mục lưu trữ data
data_volume: /data
Important note:
- hostname: Must be the domain or IP from which you will access Harbor
- harbor_admin_password: Change the default password for security
- If you only test on the local machine, you can leave it on HTTP. For production, you should use HTTPS
Step 6: Install Harbor
Run the installation script:
# Cài đặt Harbor cơ bản sudo ./install.shHoặc cài đặt với các thành phần bổ sung
sudo ./install.sh --with-trivy --with-chartmuseum
Installation options:
--with-trivy: Enable vulnerability scanning--with-chartmuseum: Enable Helm chart repository support--with-notary: Enable content trust digital signing feature
Step 7: Check status
After installation, check the Harbor containers:
sudo docker-compose psYou will see running containers like:
- harbor-core
- harbor-portal
- harbor-db
- harbor-redis
- nginx
- registry. registry
Step 8: Access Harbor Web UI
Open a browser and access:
http://your-hostname-or-ipDefault login information:
- Username:
admin. admin - Password: The password you configured in
harbor.yml(default:Harbor12345)
Harbor Management
Stop Harbor
cd /opt/harbor
sudo docker-compose stop
Launch Harbor
cd /opt/harbor
sudo docker-compose startRestart Harbor
cd /opt/harbor
sudo docker-compose restartUninstall Harbor
cd /opt/harbor
sudo docker-compose down -vConfigure Docker Client to use Harbor
With HTTP (no SSL)
Add Harbor to the list of insecure registries:
sudo nano /etc/docker/daemon.jsonAdd content:
json
{
"insecure-registries": ["your-harbor-ip:80"]
}Restart Docker:
sudo systemctl restart dockerLogin to Harbor from Docker CLI
docker login your-harbor-ipNhập username: admin
Nhập password: your-password
Push image to Harbor
# Tag imagedocker tag nginx:latest your-harbor-ip/library/nginx:latest
Push image
docker push your-harbor-ip/library/nginx:latest
Pull image from Harbor
docker pull your-harbor-ip/library/nginx:latestConfiguring HTTPS for Harbor (Production)
1. Create self-signed certificate (for testing)
# Tạo thư mục chứa certificate sudo mkdir -p /opt/harbor/certs cd /opt/harbor/certsTạo private key
sudo openssl genrsa -out harbor.key 4096
Tạo certificate signing request
sudo openssl req -new -key harbor.key -out harbor.csr
Tạo self-signed certificate
sudo openssl x509 -req -days 365 -in harbor.csr -signkey harbor.key -out harbor.crt
2. Update Harbor configuration
Edit /opt/harbor/harbor.yml:
https:
port: 443
certificate: /opt/harbor/certs/harbor.crt
private_key: /opt/harbor/certs/harbor.key3. Reinstall Harbor
cd /opt/harbor
sudo ./prepare
sudo docker-compose down -v
sudo docker-compose up -dBackup and Restore
Backup Harbor
# Backup cơ sở dữ liệu và cấu hình cd /opt/harbor sudo docker-compose stopBackup data directory
sudo tar -czf harbor-backup-$(date +%Y%m%d).tar.gz /data /opt/harbor/harbor.yml
sudo docker-compose start
Restore Harbor
# Stop Harbor cd /opt/harbor sudo docker-compose downRestore data
sudo tar -xzf harbor-backup-YYYYMMDD.tar.gz -C /
Start Harbor
sudo docker-compose up -d
Troubleshoot common problems
1. Harbor fails to start
Check logs:
cd /opt/harbor
sudo docker-compose logs2. Cannot push/pull images
- Check configuration
insecure-registriesin/etc/docker/daemon.json - Make sure you're logged in:
docker login your-harbor-ip - Check the firewall:
sudo ufw status
3. Error "x509: certificate signed by unknown authority"
If using a self-signed certificate, you need to add the certificate to Docker:
sudo mkdir -p /etc/docker/certs.d/your-harbor-ip
sudo cp /opt/harbor/certs/harbor.crt /etc/docker/certs.d/your-harbor-ip/ca.crt
sudo systemctl restart docker4. Port is already in use
Check the port being used:
sudo netstat -tulpn | grep :80Change internal port harbor.yml if needed.
Advanced features
1. Scan for security vulnerabilities with Trivy
After installing with --with-trivy, you can:
- Scan images automatically when pushed
- View vulnerability reports in Web UI
- Block pulling images with serious vulnerabilities
2. Replication
Harbor supports copying images between registries:
- Access Administration → Replications
- Create destination endpoint
- Create replication rule
3. User management and authorization
- Create separate projects for each team
- Permissions: Project Admin, Developer, Guest
- Integrate LDAP/AD for authentication
4. Webhooks
Configure webhooks to receive notifications when:
- Image is pushed
- Image is pulled
- Security scan completed
Harbor Security
Best Practices
- Change the default admin password immediately after installation
- Use HTTPS for production environments
- Enable vulnerability scanning with Trivy
- Access restrictions by firewall
- Periodic backups data and configuration
- Harbor Update often
- Use RBAC to manage access rights
- Turn on audit log to track activity
Firewall configuration
# Cho phép HTTP (port 80) sudo ufw allow 80/tcpCho phép HTTPS (port 443)
sudo ufw allow 443/tcp
Cho phép SSH
sudo ufw allow 22/tcp
Kích hoạt firewall
sudo ufw enable
Conclusion
You have completed installing Harbor on Ubuntu 24.04. Harbor can now be used as a private Docker registry for your organization with full management, security, and replication features.
Reference resources
- Harbor Official Documentation: https://goharbor.io/docs/
- GitHub Repository: https://github.com/goharbor/harbor
- Community Forum: https://github.com/goharbor/harbor/discussions
Useful commands
# Kiểm tra phiên bản Harbor docker exec harbor-core harbor versionXem logs của tất cả services
docker-compose logs -f
Xem logs của một service cụ thể
docker-compose logs -f harbor-core
Kiểm tra disk usage
df -h /data
Clean up unused images (giải phóng dung lượng)
docker system prune -a
Note: This guide applies to Harbor v2.11.2 on Ubuntu 24.04. Some details may vary depending on the version of Harbor you use.
