Harbor - Hardened Container Registry with Vulnerability Scan
بواسطة Lynxroute
Harbor 2.15.2 - CIS Level 1 hardened container registry on Ubuntu 24.04 LTS, SBOM + CIS
What is Harbor
Harbor is an open-source, CNCF-graduated container registry for storing, scanning and serving OCI container images and Helm charts. On top of the OCI Distribution registry it adds built-in vulnerability scanning with Trivy, content trust and image signing with Cosign, role-based access control with projects and robot accounts, tag retention and immutability rules, storage quotas, webhooks, and pull-through proxy caching plus replication to and from other registries. It runs as a multi-service Docker Compose stack - registry, API core, job service, PostgreSQL, Redis and a bundled Trivy scanner. Images and metadata persist in PostgreSQL and on the local filesystem under /data. Apache-2.0 license, fully auditable, no vendor lock-in.
Why self-host Harbor
Running Harbor on a VM you control keeps your container images, signatures and scan results - which embed proprietary code and build artifacts - inside your own tenant rather than a managed registry service. Self-hosting suits teams with data residency requirements, organisations operating under GDPR, HIPAA or ISO 27001, and any CI/CD pipeline where the registry must stay within your own perimeter with no per-pull or storage fees. Harbor is Apache-2.0, CNCF-governed, fully auditable, with no open-core feature gating and no vendor lock-in.
What this VM image adds
Security hardening:
- Unique admin password generated per instance at first boot for the built-in admin user, stored in /root/harbor-credentials.txt (mode 0600) - no well-known default password
- HTTPS enabled automatically at first boot with a self-signed certificate carrying the instance public IP in the SAN, so Docker login, push and pull work immediately
- Registry, PostgreSQL, Redis and the Trivy adapter behind the host TLS edge - host nginx terminates TLS on 443 and reverse-proxies Harbor; only HTTP/HTTPS are exposed
- Built-in supply-chain controls - bundled Trivy vulnerability scanning, Cosign image signing and project-based RBAC with robot accounts
- CVE scan - every image is scanned with Trivy before release
- UFW firewall - TCP 22 (SSH), 80 (redirects to HTTPS) and 443 only; all other inbound dropped
- fail2ban - SSH brute-force protection
- AppArmor - mandatory access control
OS hardening (CIS Level 1):
- CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
- auditd - system call auditing for critical paths
- SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
- Kernel hardening - SYN cookies, ASLR, rp_filter, kexec disabled, IPv6 off
- /tmp as tmpfs - nosuid, nodev, noexec
- Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)
Compliance artifacts (inside the VM):
- SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with Harbor pinned by version, PURL, Apache-2.0 license, supplier and hash
- CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
- Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
- Operator credentials file at /root/harbor-credentials.txt (mode 0600) with the admin username, password and the portal HTTPS URL
Quick Start
- Deploy VM from Azure Marketplace (Standard_D4s_v3 recommended)
- Open NSG: TCP 443 from your trusted sources and TCP 22 from your management IPs only
- SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/harbor-credentials.txt for the admin password
- Open https://<PUBLIC_IP>/ in your browser, accept the self-signed certificate warning, and log in to the portal as admin
- Push an image: docker login <PUBLIC_IP> -u admin, then docker tag and docker push <PUBLIC_IP>/library/your-image:tag
First boot takes a few minutes while the registry, database and Trivy scanner start; the portal shows a loading page until it is ready. To push or pull from a remote client, first trust /etc/nginx/ssl/harbor-selfsigned.crt, or replace the self-signed certificate with a CA-signed one (certbot is pre-installed) for production.