Chuyển đến nội dung chính

Install Harbor on Ubuntu 24.04

Duy Tran10 min
Install Harbor on Ubuntu 24.04

Introduction

Harbor is an open source registry for storing and managing Docker images and Helm charts. Harbor extends Docker Registry by adding functionality such as user management, security scanning, and image replication between registries.

System requirements

  • Operating system: Ubuntu 24.04 LTS
  • CPU: Minimum 2 cores
  • RAM: Minimum 4GB (recommended 8GB)
  • Hard drive: Minimum 40GB free space
  • Access rights: Root or sudo

Installation steps

Step 1: Update the system

First, update the packages list and upgrade the system:

bash

sudo apt update
sudo apt upgrade -y

Step 2: Install Docker

Harbor requires Docker to run. Install Docker using the following commands:

bash

# Cài đặt Docker
sudo apt install -y docker.io

Khởi động và kích hoạt Docker

sudo systemctl start docker sudo systemctl enable docker

Kiểm tra phiên bản Docker

docker --version

Step 3: Install Docker Compose

Docker Compose is used to manage Harbor containers:

# Tải Docker Compose
sudo curl -L "https://github.com/docker/compose/releases/latest/download/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose

Cấp quyền thực thi

sudo chmod +x /usr/local/bin/docker-compose

Kiểm tra phiên bản

docker-compose --version

Step 4: Download Harbor

Move to folder /opt and download the latest version of Harbor:

# Di chuyển đến thư mục /opt
cd /opt

Tải Harbor (phiên bản 2.11.2 - kiểm tra phiên bản mới nhất tại GitHub)

sudo wget https://github.com/goharbor/harbor/releases/download/v2.11.2/harbor-offline-installer-v2.11.2.tgz

Giải nén

sudo tar xzvf harbor-offline-installer-v2.11.2.tgz

Step 5: Configure Harbor

Move into the Harbor folder and create a configuration file:

cd /opt/harbor
sudo cp harbor.yml.tmpl harbor.yml

Edit configuration file harbor.yml:

sudo nano harbor.yml

Important parameters to configure:

# Hostname - thay bằng IP hoặc domain của bạn
hostname: your-domain.com  # hoặc IP: 192.168.1.100

Giao thức HTTP

http: port: 80

Giao thức HTTPS (tùy chọn - khuyến nghị cho production)

Bỏ comment nếu muốn sử dụng HTTPS

https:

port: 443

certificate: /path/to/cert.crt

private_key: /path/to/cert.key

Mật khẩu admin mặc định (NÊN ĐỔI)

harbor_admin_password: Harbor12345

Cơ sở dữ liệu

database: password: root123 max_idle_conns: 100 max_open_conns: 900

Thư mục lưu trữ data

data_volume: /data

Important note:

  1. hostname: Must be the domain or IP from which you will access Harbor
  2. harbor_admin_password: Change the default password for security
  3. If you only test on the local machine, you can leave it on HTTP. For production, you should use HTTPS

Step 6: Install Harbor

Run the installation script:

# Cài đặt Harbor cơ bản
sudo ./install.sh

Hoặc cài đặt với các thành phần bổ sung

sudo ./install.sh --with-trivy --with-chartmuseum

Installation options:

  • --with-trivy: Enable vulnerability scanning
  • --with-chartmuseum: Enable Helm chart repository support
  • --with-notary: Enable content trust digital signing feature

Step 7: Check status

After installation, check the Harbor containers:

sudo docker-compose ps

You will see running containers like:

  • harbor-core
  • harbor-portal
  • harbor-db
  • harbor-redis
  • nginx
  • registry. registry

Step 8: Access Harbor Web UI

Open a browser and access:

http://your-hostname-or-ip

Default login information:

  • Username: admin. admin
  • Password: The password you configured in harbor.yml (default: Harbor12345)

Harbor Management

Stop Harbor

cd /opt/harbor

sudo docker-compose stop

Launch Harbor

cd /opt/harbor
sudo docker-compose start

Restart Harbor

cd /opt/harbor
sudo docker-compose restart

Uninstall Harbor

cd /opt/harbor
sudo docker-compose down -v

Configure Docker Client to use Harbor

With HTTP (no SSL)

Add Harbor to the list of insecure registries:

sudo nano /etc/docker/daemon.json

Add content:

json

{
"insecure-registries": ["your-harbor-ip:80"]
}

Restart Docker:

sudo systemctl restart docker

Login to Harbor from Docker CLI

docker login your-harbor-ip

Nhập username: admin

Nhập password: your-password

Push image to Harbor

# Tag image

docker tag nginx:latest your-harbor-ip/library/nginx:latest

Push image

docker push your-harbor-ip/library/nginx:latest

Pull image from Harbor

docker pull your-harbor-ip/library/nginx:latest

Configuring HTTPS for Harbor (Production)

1. Create self-signed certificate (for testing)

# Tạo thư mục chứa certificate
sudo mkdir -p /opt/harbor/certs
cd /opt/harbor/certs

Tạo private key

sudo openssl genrsa -out harbor.key 4096

Tạo certificate signing request

sudo openssl req -new -key harbor.key -out harbor.csr

Tạo self-signed certificate

sudo openssl x509 -req -days 365 -in harbor.csr -signkey harbor.key -out harbor.crt

2. Update Harbor configuration

Edit /opt/harbor/harbor.yml:

https:
port: 443
certificate: /opt/harbor/certs/harbor.crt
private_key: /opt/harbor/certs/harbor.key

3. Reinstall Harbor

cd /opt/harbor
sudo ./prepare
sudo docker-compose down -v
sudo docker-compose up -d

Backup and Restore

Backup Harbor

# Backup cơ sở dữ liệu và cấu hình
cd /opt/harbor
sudo docker-compose stop

Backup data directory

sudo tar -czf harbor-backup-$(date +%Y%m%d).tar.gz /data /opt/harbor/harbor.yml

sudo docker-compose start

Restore Harbor

# Stop Harbor
cd /opt/harbor
sudo docker-compose down

Restore data

sudo tar -xzf harbor-backup-YYYYMMDD.tar.gz -C /

Start Harbor

sudo docker-compose up -d

Troubleshoot common problems

1. Harbor fails to start

Check logs:

cd /opt/harbor
sudo docker-compose logs

2. Cannot push/pull images

  • Check configuration insecure-registries in /etc/docker/daemon.json
  • Make sure you're logged in: docker login your-harbor-ip
  • Check the firewall: sudo ufw status

3. Error "x509: certificate signed by unknown authority"

If using a self-signed certificate, you need to add the certificate to Docker:

sudo mkdir -p /etc/docker/certs.d/your-harbor-ip
sudo cp /opt/harbor/certs/harbor.crt /etc/docker/certs.d/your-harbor-ip/ca.crt
sudo systemctl restart docker

4. Port is already in use

Check the port being used:

sudo netstat -tulpn | grep :80

Change internal port harbor.yml if needed.

Advanced features

1. Scan for security vulnerabilities with Trivy

After installing with --with-trivy, you can:

  • Scan images automatically when pushed
  • View vulnerability reports in Web UI
  • Block pulling images with serious vulnerabilities

2. Replication

Harbor supports copying images between registries:

  • Access Administration → Replications
  • Create destination endpoint
  • Create replication rule

3. User management and authorization

  • Create separate projects for each team
  • Permissions: Project Admin, Developer, Guest
  • Integrate LDAP/AD for authentication

4. Webhooks

Configure webhooks to receive notifications when:

  • Image is pushed
  • Image is pulled
  • Security scan completed

Harbor Security

Best Practices

  1. Change the default admin password immediately after installation
  2. Use HTTPS for production environments
  3. Enable vulnerability scanning with Trivy
  4. Access restrictions by firewall
  5. Periodic backups data and configuration
  6. Harbor Update often
  7. Use RBAC to manage access rights
  8. Turn on audit log to track activity

Firewall configuration

# Cho phép HTTP (port 80)
sudo ufw allow 80/tcp

Cho phép HTTPS (port 443)

sudo ufw allow 443/tcp

Cho phép SSH

sudo ufw allow 22/tcp

Kích hoạt firewall

sudo ufw enable

Conclusion

You have completed installing Harbor on Ubuntu 24.04. Harbor can now be used as a private Docker registry for your organization with full management, security, and replication features.

Reference resources

Useful commands

# Kiểm tra phiên bản Harbor
docker exec harbor-core harbor version

Xem logs của tất cả services

docker-compose logs -f

Xem logs của một service cụ thể

docker-compose logs -f harbor-core

Kiểm tra disk usage

df -h /data

Clean up unused images (giải phóng dung lượng)

docker system prune -a


Note: This guide applies to Harbor v2.11.2 on Ubuntu 24.04. Some details may vary depending on the version of Harbor you use.