Zum Hauptinhalt wechseln
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.harbor-c4ca03b8-42c7-4b22-862c-a0e1294cadaf/image3_Azureready.png

Harbor - Hardened Container Registry with Vulnerability Scan

durch Lynxroute

Harbor 2.15.2 - CIS Level 1 hardened container registry on Ubuntu 24.04 LTS, SBOM + CIS

What is Harbor

Harbor is an open-source, CNCF-graduated container registry for storing, scanning and serving OCI container images and Helm charts. On top of the OCI Distribution registry it adds built-in vulnerability scanning with Trivy, content trust and image signing with Cosign, role-based access control with projects and robot accounts, tag retention and immutability rules, storage quotas, webhooks, and pull-through proxy caching plus replication to and from other registries. It runs as a multi-service Docker Compose stack - registry, API core, job service, PostgreSQL, Redis and a bundled Trivy scanner. Images and metadata persist in PostgreSQL and on the local filesystem under /data. Apache-2.0 license, fully auditable, no vendor lock-in.

Why self-host Harbor

Running Harbor on a VM you control keeps your container images, signatures and scan results - which embed proprietary code and build artifacts - inside your own tenant rather than a managed registry service. Self-hosting suits teams with data residency requirements, organisations operating under GDPR, HIPAA or ISO 27001, and any CI/CD pipeline where the registry must stay within your own perimeter with no per-pull or storage fees. Harbor is Apache-2.0, CNCF-governed, fully auditable, with no open-core feature gating and no vendor lock-in.

What this VM image adds

Security hardening:

  • Unique admin password generated per instance at first boot for the built-in admin user, stored in /root/harbor-credentials.txt (mode 0600) - no well-known default password
  • HTTPS enabled automatically at first boot with a self-signed certificate carrying the instance public IP in the SAN, so Docker login, push and pull work immediately
  • Registry, PostgreSQL, Redis and the Trivy adapter behind the host TLS edge - host nginx terminates TLS on 443 and reverse-proxies Harbor; only HTTP/HTTPS are exposed
  • Built-in supply-chain controls - bundled Trivy vulnerability scanning, Cosign image signing and project-based RBAC with robot accounts
  • CVE scan - every image is scanned with Trivy before release
  • UFW firewall - TCP 22 (SSH), 80 (redirects to HTTPS) and 443 only; all other inbound dropped
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
  • Kernel hardening - SYN cookies, ASLR, rp_filter, kexec disabled, IPv6 off
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with Harbor pinned by version, PURL, Apache-2.0 license, supplier and hash
  • CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file at /root/harbor-credentials.txt (mode 0600) with the admin username, password and the portal HTTPS URL

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D4s_v3 recommended)
  2. Open NSG: TCP 443 from your trusted sources and TCP 22 from your management IPs only
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/harbor-credentials.txt for the admin password
  4. Open https://<PUBLIC_IP>/ in your browser, accept the self-signed certificate warning, and log in to the portal as admin
  5. Push an image: docker login <PUBLIC_IP> -u admin, then docker tag and docker push <PUBLIC_IP>/library/your-image:tag

First boot takes a few minutes while the registry, database and Trivy scanner start; the portal shows a loading page until it is ready. To push or pull from a remote client, first trust /etc/nginx/ssl/harbor-selfsigned.crt, or replace the self-signed certificate with a CA-signed one (certbot is pre-installed) for production.

Deutsch (Luxemburg)
Abwahlsymbol „Ihre Datenschutzoptionen“ Ihre Datenschutzoptionen
Verbraucherdatenschutz für Gesundheitsdaten Sitemap Contact Us Privacy & Cookies Terms of Use About our ads Manage cookies