تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.harbor-c4ca03b8-42c7-4b22-862c-a0e1294cadaf/image3_Azureready.png

Harbor - Hardened Container Registry with Vulnerability Scan

بواسطة Lynxroute

Harbor 2.15.2 - CIS Level 1 hardened container registry on Ubuntu 24.04 LTS, SBOM + CIS

What is Harbor

Harbor is an open-source, CNCF-graduated container registry for storing, scanning and serving OCI container images and Helm charts. On top of the OCI Distribution registry it adds built-in vulnerability scanning with Trivy, content trust and image signing with Cosign, role-based access control with projects and robot accounts, tag retention and immutability rules, storage quotas, webhooks, and pull-through proxy caching plus replication to and from other registries. It runs as a multi-service Docker Compose stack - registry, API core, job service, PostgreSQL, Redis and a bundled Trivy scanner. Images and metadata persist in PostgreSQL and on the local filesystem under /data. Apache-2.0 license, fully auditable, no vendor lock-in.

Why self-host Harbor

Running Harbor on a VM you control keeps your container images, signatures and scan results - which embed proprietary code and build artifacts - inside your own tenant rather than a managed registry service. Self-hosting suits teams with data residency requirements, organisations operating under GDPR, HIPAA or ISO 27001, and any CI/CD pipeline where the registry must stay within your own perimeter with no per-pull or storage fees. Harbor is Apache-2.0, CNCF-governed, fully auditable, with no open-core feature gating and no vendor lock-in.

What this VM image adds

Security hardening:

  • Unique admin password generated per instance at first boot for the built-in admin user, stored in /root/harbor-credentials.txt (mode 0600) - no well-known default password
  • HTTPS enabled automatically at first boot with a self-signed certificate carrying the instance public IP in the SAN, so Docker login, push and pull work immediately
  • Registry, PostgreSQL, Redis and the Trivy adapter behind the host TLS edge - host nginx terminates TLS on 443 and reverse-proxies Harbor; only HTTP/HTTPS are exposed
  • Built-in supply-chain controls - bundled Trivy vulnerability scanning, Cosign image signing and project-based RBAC with robot accounts
  • CVE scan - every image is scanned with Trivy before release
  • UFW firewall - TCP 22 (SSH), 80 (redirects to HTTPS) and 443 only; all other inbound dropped
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
  • Kernel hardening - SYN cookies, ASLR, rp_filter, kexec disabled, IPv6 off
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with Harbor pinned by version, PURL, Apache-2.0 license, supplier and hash
  • CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file at /root/harbor-credentials.txt (mode 0600) with the admin username, password and the portal HTTPS URL

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D4s_v3 recommended)
  2. Open NSG: TCP 443 from your trusted sources and TCP 22 from your management IPs only
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/harbor-credentials.txt for the admin password
  4. Open https://<PUBLIC_IP>/ in your browser, accept the self-signed certificate warning, and log in to the portal as admin
  5. Push an image: docker login <PUBLIC_IP> -u admin, then docker tag and docker push <PUBLIC_IP>/library/your-image:tag

First boot takes a few minutes while the registry, database and Trivy scanner start; the portal shows a loading page until it is ready. To push or pull from a remote client, first trust /etc/nginx/ssl/harbor-selfsigned.crt, or replace the self-signed certificate with a CA-signed one (certbot is pre-installed) for production.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط