1. 说明
1.1. 前置条件
-
Postgres : Harbor 需要 Postgres 数据库才可正常工作
-
LDAP:Harbor 将使用 LDAP 统一管理用户
-
StorageClass: Harbor 需要持久化存储数据
1.2. 依赖镜像
Harbor 需要以下镜像才可运行,离线环境中请将所有镜像导入至所有工作节点。
1
2
3
4
5
6
7
8
9
goharbor/chartmuseum-photon:v2.5.3
goharbor/harbor-core:v2.5.3
goharbor/harbor-exporter:v2.5.3
goharbor/harbor-jobservice:v2.5.3
goharbor/harbor-portal:v2.5.3
goharbor/registry-photon:v2.5.3
goharbor/harbor-registryctl:v2.5.3
goharbor/redis-photon:v2.5.3
goharbor/trivy-adapter-photon:v2.5.3
2. 部署准备
在正式部署前,须对现有环境进行配置以满足最低需求。
2.1. 创建 LDAP Group
连接你的 LDAP 管理器,为其添加如下角色。
1
2
cn=docker,ou=groups,dc=cluster,dc=local
cn=deploy,ou=groups,dc=cluster,dc=local
其中:
-
docker
将具有推送和拉取所有镜像的权限。 -
deploy
将具有拉取所有镜像的权限。
2.2. 准备数据库
连接你的外部 Postgres 数据库,创建如下数据库和用户,并为其创建关联。
-
数据库:
registry
-
数据库用户名:
harbor
-
数据库密码:
harbor_password
如果你使用的是集群内数据库部署的话可使用以下命令快速创建。
使用如下命令连接 Postgres
控制台。
1
kubectl exec -it -n core-middle sts-postgres-0 -- psql -U postgres
连接建立后,执行如下 SQL 语句创建账户和数据库,执行完成后,使用 \q
退出。。
1
2
3
CREATE ROLE harbor with LOGIN CREATEDB PASSWORD 'harbor_password';
CREATE DATABASE registry;
GRANT ALL PRIVILEGES ON DATABASE registry to harbor;
如果要清除旧的数据,可执行以下 SQL 语句,然后再重新创建即可。
1
2
DROP DATABASE registry;
DROP ROLE harbor;
2.3. 创建相关的持久卷
在 Kubernetes 下导入以下配置,创建对应的持久卷。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
namespace: core-app
name: pvc-harbor-chart-museum
labels:
app: harbor
component: chart-museum
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 5Gi
storageClassName: 'sc-nfs-share'
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
namespace: core-app
name: pvc-harbor-job-service-scan-data
labels:
app: harbor
component: job-service
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
storageClassName: 'sc-nfs-share'
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
namespace: core-app
name: pvc-harbor-job-service
labels:
app: harbor
component: job-service
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
storageClassName: 'sc-nfs-share'
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
namespace: core-app
name: pvc-harbor-registry
labels:
app: harbor
component: registry
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 50Gi
storageClassName: 'sc-nfs-share'
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
namespace: core-app
name: pvc-harbor-trivy-data
labels:
app: harbor
component: harbor-trivy
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 5Gi
storageClassName: 'sc-nfs-share'
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
namespace: core-app
name: pvc-harbor-redis-data
labels:
app: harbor
component: harbor-redis
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
storageClassName: 'sc-nfs-share'
3. 部署 Harbor 应用
资源准备完成后,即可开始部署 Harbor 。
3.1. 导入 Harbor 配置
3.1.1. 导入非敏感配置
在 Kubernetes 下导入以下配置,创建 Harbor 自定义配置。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
# Source: harbor/templates/chartmuseum/chartmuseum-cm.yaml
apiVersion: v1
kind: ConfigMap
metadata:
namespace: core-app
name: conf-harbor-chart-museum
data:
PORT: "9999"
CACHE: "redis"
CACHE_REDIS_ADDR: "svc-harbor-redis:6379"
CACHE_REDIS_DB: "3"
BASIC_AUTH_USER: "chart_controller"
DEPTH: "1"
DEBUG: "false"
LOG_JSON: "true"
DISABLE_METRICS: "false"
DISABLE_API: "false"
DISABLE_STATEFILES: "false"
ALLOW_OVERWRITE: "true"
AUTH_ANONYMOUS_GET: "false"
CONTEXT_PATH: ""
INDEX_LIMIT: "0"
MAX_STORAGE_OBJECTS: "0"
MAX_UPLOAD_SIZE: "20971520"
CHART_POST_FORM_FIELD_NAME: "chart"
PROV_POST_FORM_FIELD_NAME: "prov"
STORAGE: "local"
STORAGE_LOCAL_ROOTDIR: "/chart_storage"
STORAGE_TIMESTAMP_TOLERANCE: 1s
---
apiVersion: v1
kind: ConfigMap
metadata:
namespace: core-app
name: conf-harbor-core
data:
app.conf: |+
appname = Harbor
runmode = prod
enablegzip = true
[prod]
httpport = 8080
PORT: "8080"
DATABASE_TYPE: "postgresql"
POSTGRESQL_HOST: "svc-postgres.core-middle.svc.cluster.local"
POSTGRESQL_PORT: "5432"
POSTGRESQL_USERNAME: "harbor"
POSTGRESQL_DATABASE: "registry"
POSTGRESQL_SSLMODE: "disable"
POSTGRESQL_MAX_IDLE_CONNS: "100"
POSTGRESQL_MAX_OPEN_CONNS: "900"
EXT_ENDPOINT: "https://harbor.d7z.net"
CORE_URL: "http://svc-harbor-core:80"
JOBSERVICE_URL: "http://svc-harbor-job-service"
REGISTRY_URL: "http://svc-harbor-registry:5000"
TOKEN_SERVICE_URL: "http://svc-harbor-core:80/service/token"
WITH_NOTARY: "false"
CORE_LOCAL_URL: "http://127.0.0.1:8080"
WITH_TRIVY: "true"
TRIVY_ADAPTER_URL: "http://svc-harbor-trivy:8080"
REGISTRY_STORAGE_PROVIDER_NAME: "filesystem"
WITH_CHARTMUSEUM: "true"
CHART_REPOSITORY_URL: "http://svc-harbor-chart-museum"
LOG_LEVEL: "info"
CONFIG_PATH: "/etc/core/app.conf"
CHART_CACHE_DRIVER: "redis"
_REDIS_URL_CORE: "redis://svc-harbor-redis:6379/0?idle_timeout_seconds=30"
_REDIS_URL_REG: "redis://svc-harbor-redis:6379/2?idle_timeout_seconds=30"
PORTAL_URL: "http://svc-harbor-portal"
REGISTRY_CONTROLLER_URL: "http://svc-harbor-registry:8080"
REGISTRY_CREDENTIAL_USERNAME: "harbor_registry_user"
HTTP_PROXY: ""
HTTPS_PROXY: ""
NO_PROXY: "svc-harbor-core,svc-harbor-job-service,harbor-database,svc-harbor-chart-museum,svc-harbor-notary-server,svc-harbor-notary-signer,svc-harbor-registry,svc-harbor-portal,svc-harbor-trivy,svc-harbor-exporter,127.0.0.1,localhost,.local,.internal"
PERMITTED_REGISTRY_TYPES_FOR_PROXY_CACHE: "docker-hub,harbor,azure-acr,aws-ecr,google-gcr,quay,docker-registry"
METRIC_ENABLE: "true"
METRIC_PATH: "/metrics"
METRIC_PORT: "8001"
METRIC_NAMESPACE: harbor
METRIC_SUBSYSTEM: core
---
apiVersion: v1
kind: ConfigMap
metadata:
namespace: core-app
name: conf-harbor-exporter-env
data:
HTTP_PROXY: ""
HTTPS_PROXY: ""
NO_PROXY: "svc-harbor-core,svc-harbor-job-service,harbor-database,svc-harbor-chart-museum,svc-harbor-notary-server,svc-harbor-notary-signer,svc-harbor-registry,svc-harbor-portal,svc-harbor-trivy,svc-harbor-exporter,127.0.0.1,localhost,.local,.internal"
LOG_LEVEL: "info"
HARBOR_EXPORTER_PORT: "8001"
HARBOR_EXPORTER_METRICS_PATH: "/metrics"
HARBOR_EXPORTER_METRICS_ENABLED: "true"
HARBOR_EXPORTER_CACHE_TIME: "23"
HARBOR_EXPORTER_CACHE_CLEAN_INTERVAL: "14400"
HARBOR_METRIC_NAMESPACE: harbor
HARBOR_METRIC_SUBSYSTEM: exporter
HARBOR_REDIS_URL: "redis://svc-harbor-redis:6379/1"
HARBOR_REDIS_NAMESPACE: harbor_job_service_namespace
HARBOR_REDIS_TIMEOUT: "3600"
HARBOR_SERVICE_SCHEME: "http"
HARBOR_SERVICE_HOST: "svc-harbor-core"
HARBOR_SERVICE_PORT: "80"
HARBOR_DATABASE_HOST: "svc-postgres.core-middle.svc.cluster.local"
HARBOR_DATABASE_PORT: "5432"
HARBOR_DATABASE_USERNAME: "harbor"
HARBOR_DATABASE_DBNAME: "registry"
HARBOR_DATABASE_SSLMODE: "disable"
HARBOR_DATABASE_MAX_IDLE_CONNS: "100"
HARBOR_DATABASE_MAX_OPEN_CONNS: "900"
---
apiVersion: v1
kind: ConfigMap
metadata:
namespace: core-app
name: conf-harbor-job-service-env
data:
CORE_URL: "http://svc-harbor-core:80"
TOKEN_SERVICE_URL: "http://svc-harbor-core:80/service/token"
REGISTRY_URL: "http://svc-harbor-registry:5000"
REGISTRY_CONTROLLER_URL: "http://svc-harbor-registry:8080"
REGISTRY_CREDENTIAL_USERNAME: "harbor_registry_user"
HTTP_PROXY: ""
HTTPS_PROXY: ""
NO_PROXY: "svc-harbor-core,svc-harbor-job-service,harbor-database,svc-harbor-chart-museum,svc-harbor-notary-server,svc-harbor-notary-signer,svc-harbor-registry,svc-harbor-portal,svc-harbor-trivy,svc-harbor-exporter,127.0.0.1,localhost,.local,.internal"
METRIC_NAMESPACE: harbor
METRIC_SUBSYSTEM: jobservice
---
apiVersion: v1
kind: ConfigMap
metadata:
namespace: core-app
name: harbor-job-service
data:
config.yml: |+
#Server listening port
protocol: "http"
port: 8080
worker_pool:
workers: 10
backend: "redis"
redis_pool:
redis_url: "redis://svc-harbor-redis:6379/1"
namespace: "harbor_job_service_namespace"
idle_timeout_second: 3600
job_loggers:
- name: "FILE"
level: INFO
settings: # Customized settings of logger
base_dir: "/var/log/jobs"
sweeper:
duration: 14 #days
settings: # Customized settings of sweeper
work_dir: "/var/log/jobs"
- name: "STD_OUTPUT"
level: INFO
metric:
enabled: true
path: /metrics
port: 8001
#Loggers for the job service
loggers:
- name: "STD_OUTPUT"
level: INFO
---
apiVersion: v1
kind: ConfigMap
metadata:
namespace: core-app
name: conf-harbor-portal
data:
nginx.conf: |+
worker_processes auto;
pid /tmp/nginx.pid;
events {
worker_connections 1024;
}
http {
client_body_temp_path /tmp/client_body_temp;
proxy_temp_path /tmp/proxy_temp;
fastcgi_temp_path /tmp/fastcgi_temp;
uwsgi_temp_path /tmp/uwsgi_temp;
scgi_temp_path /tmp/scgi_temp;
server {
listen 8080;
listen [::]:8080;
server_name localhost;
root /usr/share/nginx/html;
index index.html index.htm;
include /etc/nginx/mime.types;
gzip on;
gzip_min_length 1000;
gzip_proxied expired no-cache no-store private auth;
gzip_types text/plain text/css application/json application/javascript application/x-javascript text/xml application/xml application/xml+rss text/javascript;
location / {
try_files $uri $uri/ /index.html;
}
location = /index.html {
add_header Cache-Control "no-store, no-cache, must-revalidate";
}
}
}
---
apiVersion: v1
kind: ConfigMap
metadata:
namespace: core-app
name: conf-harbor-registry
data:
config.yml: |+
version: 0.1
log:
level: info
fields:
service: registry
storage:
filesystem:
rootdirectory: /storage
cache:
layerinfo: redis
maintenance:
uploadpurging:
enabled: true
age: 168h
interval: 24h
dryrun: false
delete:
enabled: true
redirect:
disable: false
redis:
addr: svc-harbor-redis:6379
db: 2
readtimeout: 10s
writetimeout: 10s
dialtimeout: 10s
pool:
maxidle: 100
maxactive: 500
idletimeout: 60s
http:
addr: :5000
relativeurls: false
# set via environment variable
# secret: placeholder
debug:
addr: :8001
prometheus:
enabled: true
path: /metrics
auth:
htpasswd:
realm: harbor-registry-basic-realm
path: /etc/registry/passwd
validation:
disabled: true
compatibility:
schema1:
enabled: true
ctl-config.yml: |+
---
protocol: "http"
port: 8080
log_level: info
registry_config: "/etc/registry/config.yml"
3.1.2. 导入敏感配置
在 Kubernetes 下导入以下配置,创建 Harbor 账户密码相关配置。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
---
apiVersion: v1
kind: Secret
metadata:
namespace: core-app
name: secret-harbor-chart-museum
type: Opaque
stringData:
CACHE_REDIS_PASSWORD: ""
---
apiVersion: v1
kind: Secret
metadata:
namespace: core-app
name: secret-harbor-internal-tls
type: Opaque
data:
tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUUwekNDQXJ1Z0F3SUJBZ0lKQVBZL096TE1lVnEyTUEwR0NTcUdTSWIzRFFFQkN3VUFNQUF3SGhjTk1Ua3cKTkRFNE1ESXlOek0zV2hjTk1qa3dOREUxTURJeU56TTNXakFBTUlJQ0lqQU5CZ2txaGtpRzl3MEJBUUVGQUFPQwpBZzhBTUlJQ0NnS0NBZ0VBM3hsVUpzMmIvYUkyTkxveTRPSVErZG4veU1iL085OWlLRFJ5WktwSDhyU09tUytvCkY5dW5tU0F6TDY1WEEvdjZuWTBPTEkvZEFTRGprcWtCcElkVEd6b2dSNWY4VWlCNm9zdUVZN1Y3MVhaZHpXTHIKUGpuSnE2WkxBYW9LbXdHODBXNStXZDZWOFB5Z094NTJta3IxdzdJV0t6KzFaTEk1aXpicHBvbjdYVkdWUmFBVApSdk5aRGlKNkNlSnBjSjVINzIzbGtmNVJ2SldhdFpMQ1lJWURiUmZUaUtzeVEvU2xSY3Y1QlZmSGcvTEpTSDlRCkxHUmhQTUFSbGRsOXd5WkN3WlpESHhoZUk0YSsyNmFhOE1ZM3U5c3QvbDAvT282VkNUR3BNaUVoaUdGMkxWanAKVVdxLytCUDRTRkV2SmZxL0R1aW5JMTM5Vy81YVpaNy9Id1JQbG1ZVTZwWFRSTHlJZzdqZCsxOWZKd1I3WDM3cQp3MG84dDA2RmhqbXJDemFZQ1Vqb1JlcURtSGFObVpOL2Rkdkc3alpXQnUrak5oMFlhdnN5UXlDSVZtdjZ5cVNjCmpQaUQ5dWl2eHFUd2pKaWRJQlJmdVVyejNhRVJRN2NRZ2YwcWhxakl6Zmx6SGJGS2hJTG9jQldxN3p5Tmw5aHIKdlVHVC9XWmN3MHQvT3RNNzJTUGFwbG1UZ1ZiYlFSeGYyVkh6eXB0R0l2dHlkbFhLOHRoeE9NcFhvNGUrU2w4ZAoxZ2RRY0M0b2lzTjlGMjlvTnM4UDV5RlFQLy94WXV2OEM2MDduQ2oxRHpySWQ1YXZHL05WZktCL2ZiREtFRmdOCjJXaEhJblR6UExFY2pGNGZFcmNVQUV1V1cwYnVYLzZGSENHM2lUdHJxeUQ5MktUVkRmTjFKNTZycmNzQ0F3RUEKQWFOUU1FNHdIUVlEVlIwT0JCWUVGRmhOaFRvNFVBQzJQVXNmOGpZYVdqMTYwdkdFTUI4R0ExVWRJd1FZTUJhQQpGRmhOaFRvNFVBQzJQVXNmOGpZYVdqMTYwdkdFTUF3R0ExVWRFd1FGTUFNQkFmOHdEUVlKS29aSWh2Y05BUUVMCkJRQURnZ0lCQU1Bc0V0VmxFTE13ZHRjaWZIZU9UMGtPbWY1d285SW4vZUZTZ3NjQ3pCTURhUngyQjNxMzZBb1MKSWw3WFdBWnBldmFSN1c3eWVBUkthQXNoQkxoeWdVcUxEMHpXYktsU045SHByZDF3ZHBNMGZmeVBwTjVkeE9ZQQplcjA0eTEyR1JuQ2JNWXFpNGN2enRQNFRpblhxcTJ5SFNZaExiTzlxa0k1Z2JXVnhrUnVJY01Ldml4ZGRsbE5ZClEzb2JKYURESG1vdk0zK2cvRysxWUZndDRxRVMzOFhuSjdCclNzaEhubjVFSVFoMjg2eGZKcml5cksyaEhiTEoKcXowWXVGNkczRFhQZVdHZ1h2ajBIaXBjMGY4VURaa0tray9lR0VJNnZFa3l0eXZvZXBvWkkyWGJBZi9aTXk1bgpLd3VoRW40aGhrRk13V2FTV3AvaDBRZE1DYXhrNEJWU09xbU5WYUxTQjcrRmpzSWo0Q2FzRm90WWl5SjJncFJCCk5mOFFhUzRiejBUbjFlQmJDOGtzaitlM1pXZVgyYjV3Vk1qcWw5alR0MlgxSUNzOEtLZTN2RUJranFUMkFVaTIKNTJUdEt6bTczYVdyei9HUHkvUTJMQ29yM0ZoOUZHVlNCT0JCRFhHeTZNSnBOSEpuWVZIOUVFTkZHT2g4NW9sMQoycEFET0JCNXZBVS9rTEI1TEhQajJrdWUvRk1pSGFObnJTWUlHck1sQlNYMmpqOUVZYTF1dVVIK3BkNE1CajFGCjV1SDhPUmlhUTZodDIrV0hrbHhpYzFSajV5VFlRd1ZsSDcwQ0JPbitxVkVkbzYzeVF3ekFNSktGSXdsR1VRRVgKamlsamdjODZxNGNadFVURnJjd01pZGJrKzhRNitKYkRWZzdIVi8rcG5DK3dudjE5N2t3ZQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlKS1FJQkFBS0NBZ0VBM3hsVUpzMmIvYUkyTkxveTRPSVErZG4veU1iL085OWlLRFJ5WktwSDhyU09tUytvCkY5dW5tU0F6TDY1WEEvdjZuWTBPTEkvZEFTRGprcWtCcElkVEd6b2dSNWY4VWlCNm9zdUVZN1Y3MVhaZHpXTHIKUGpuSnE2WkxBYW9LbXdHODBXNStXZDZWOFB5Z094NTJta3IxdzdJV0t6KzFaTEk1aXpicHBvbjdYVkdWUmFBVApSdk5aRGlKNkNlSnBjSjVINzIzbGtmNVJ2SldhdFpMQ1lJWURiUmZUaUtzeVEvU2xSY3Y1QlZmSGcvTEpTSDlRCkxHUmhQTUFSbGRsOXd5WkN3WlpESHhoZUk0YSsyNmFhOE1ZM3U5c3QvbDAvT282VkNUR3BNaUVoaUdGMkxWanAKVVdxLytCUDRTRkV2SmZxL0R1aW5JMTM5Vy81YVpaNy9Id1JQbG1ZVTZwWFRSTHlJZzdqZCsxOWZKd1I3WDM3cQp3MG84dDA2RmhqbXJDemFZQ1Vqb1JlcURtSGFObVpOL2Rkdkc3alpXQnUrak5oMFlhdnN5UXlDSVZtdjZ5cVNjCmpQaUQ5dWl2eHFUd2pKaWRJQlJmdVVyejNhRVJRN2NRZ2YwcWhxakl6Zmx6SGJGS2hJTG9jQldxN3p5Tmw5aHIKdlVHVC9XWmN3MHQvT3RNNzJTUGFwbG1UZ1ZiYlFSeGYyVkh6eXB0R0l2dHlkbFhLOHRoeE9NcFhvNGUrU2w4ZAoxZ2RRY0M0b2lzTjlGMjlvTnM4UDV5RlFQLy94WXV2OEM2MDduQ2oxRHpySWQ1YXZHL05WZktCL2ZiREtFRmdOCjJXaEhJblR6UExFY2pGNGZFcmNVQUV1V1cwYnVYLzZGSENHM2lUdHJxeUQ5MktUVkRmTjFKNTZycmNzQ0F3RUEKQVFLQ0FnRUFrOHE4czRQcnZZYnk3OVVWbFdKTktxY2V5a3dCa3hFMWZqcllPUldRMmhpQWlyeEdWNSs4bERULwprNnVqbTFFV3diNUswSHh4UktrYitQRWExSHFOTkhFNkp4TnBKS0s5ZXhEbFlBUSt4N2RGQnFWci8ybmF6bW80Ck1COE1MWWxtSXp0V1dvU1l3ZThvMm1FZzRxK2J4WXM1SW1kdTdBa2hFN2RKNjNobTIzZ0xNZmVNTGFsUnFvcHUKWEJQd0U1blhQNmFHdVVOSHRHMUs4dFFKRGxaWStMRWJBZU9mUmVOUWhUOU5kUnVrWVNXNTc5dmZLYmxKclN2egp1bGc4OXNWbTNjV0VLNXBCNnJqOXdKYks5NHZvS2Z0VnFiYnVCd1dqZDFhOXBpYktod1ZCZTJMMkZXaHBTWmM1CkYvY29DN25qVGFZVDZ0cjkxeTVWaGhKaElaUUNmL3Z2NFpsNVhoRkhzNVZUWk5iTS9PZnF5RlFMWVhWSk80OEsKRjd0bWF6QUVRUUJRd1ZacUg5QzlOUWR6UEhXbWMzOE9raHRjMXd6YXFuL3JnOSsxc2dBTUQ4aFdDdFFKVWU5NwpiOXltaDVBMFo0UVhLcHlGVDBiK3BYY0QxalJoYTA3VXRrWCsvekxKOUhwQVhjVW16a0crajVDWE5wbnhzSXE1CmZKRmVxM2hCajl3Nm40aCs1ME00VzBGc2U1WW9FVXNjM0IwZno4QmxRQmIrWUpMRkxOSDM0TUg4cDFsMFpEWUoKeWFlMHBzeGxCaWpnNE9QWitXQ0JhK2p0Rlc0TGlXZ0VjeHdnejh3K2hFT0FRcjJhMURjN3c4amQrWTRJSzhVbQpsVFZzNWRicDRtT21QTWxSdi9HTTdrRHVkRnFiTWczWUZ3WGczUWJxdVZxTFp6RXpqVmtDZ2dFQkFQSktaYkNXCllmTGVqa1MvZmtSeVYzVkliNTRtS3dRSG9NV3ViODh0UGdHdVh6anNKeWQ1UVRRNThQcFVqWHJMSG1uOGxTMisKdmlFOEdKeWxLd04xeU1sWnc0MCtrWmhwSFVwQ1d4LzJaS2pBcXZxQTlPT0tvMmZ2NkhkL3dPQW5VNEN0aW9DMQpwcmk3bEtGWVhvUDhEdFFWd0hZdkl6Q1JxRG5oYzRtd0pEcXpUQzl4ZHVJK3N2eHpsNHhIODJmeDBqclBpRlkrCi93T2RYanlmSVBqeWhIQzRqUFRXYmFpcndYUzlkQmpTbDEyOGFJUlQ1ODAveVhFL1NZQXVnZzA1akt0ZzV6UUEKU28xM01UZXpYUkhYZE8wZGkzdEVNSEdSRUVrRnBlVm5uUFF2Q0NlZEswRFYzNmlOd2lXYzhwd2RmTE1WbmVUdApES3daZWRDeCtvLzdldjBDZ2dFQkFPdTQ4REdFSkpKekh4VlI1bVkxSzJBbFp5WXRwVE9XZWhLMXpYNzRKdk0zCll4TjRuZCtaeDVuOXVTUG1tS3pxRjNUVSs0NFJWdGRKSzZlam9GRThkTURUTldhU0xXL1pEbU4xblQwbmp2T24KSVdKbjU5eW5PQ2hXV0taZ1haLzlVcUdSN1B0Nk94U2trZXg5Yy9mWUJzTVgveHVzZFhRaWdlb2dsMGlPWVZGVwpnWElpaUxSTEhwSEpzSy91TnhJaXpqMGhUWVluN3VEN1BSRU53RlJjQ1lmOEoxZVVGYmQ2RHVDVldlUUNLV2dmCk5kMnRTV29pMFZ5bGo0dVVYOEl3MHRqTE5NRDVDUkVKRWs0R1N2NEVEU212VWR2MUxpQktKQ0wybEVjZ29QZUMKb09EMmlDYzVLcWdubVFyYVJpbEZGazhSVlhBOVBXWkdZM0MwYjZUVm1tY0NnZ0VBTlpPMkFPS0FMbENBYlR0YgpGSStrUDA4UlA0dDVINThBTWpac2l3ZWFHbzBRaVduUERxK0ZkNk1JWXBLbjVtdGNBbHZVTVJWb3ZiaW9TSnROCmM2cHNCL3BOZjhKQ044Mm1xSEViN1dseXdNNDZBTUxiWkNXWUZMZThWQkJ2K2lFNEdkQkdQRWZ1NGhLNHZ5VG4KWVpBdlJ6NjRIR280QWRsenRiamc3NlYvbld0Z2dXMDV1TFhjcG01NUtKQVFodisyV1VMakJ3OVBIT0dEb1N3ZgpBbTIrVTU2N3JMaHQ3MHByc1FEajEwbGFKMlF1U0hTMVlYR2xmZUZjdzNlRlVwOVROK0pwdmRvQ29sMmxDSWdsCklIamdaajZPUldmQ3Zwb3hXN1JnQnVadWtxQ0QwUjYwSGRZdGF2eE4zanRpZXBzYXBBODNweE8wSmFwTWdaV1oKcnBVUmtRS0NBUUJPY0V2OUxpdTlUL0dYOXBqa2llelZJWjBoWnk4QjY2RFRlUXZZcEZyUnRDeVQzaDhxdU5GaQp2THRPNXYwSERSNmhFZjVqV0FHOXdldDA3VTM3dWxKZmwraTlLUWRWb0xUWkE5bys3MXJ5V1RzU3MrREQzQ0VqCnl4ZlV4VnhpVUxtZWFpQ2h6aHE2MDhoN0dZUHRoVVU2eGxGdHRBV2hqNW9MZnF6WXlBZzZPTDc2YStOeG0wMmcKMWF5bDNtOFU2ZUFYRjIza3BvVW0rSE5wcVZuR3VKbXpWb1VBNzVZS1orTnJlRWRoU0JiZlB3TjlzSnd0WlVpbAp1N0g0a0hjTTk1SXg4ZXlzQ2pLcUtJcWV6QmxJVGJEVG5qTnZMamNiSjVDKzBhNmx2SVhUMXZRUjUvZUdsYzlNCkJXRTM2MHBOa1YvTEQ4bU9mOUplcGkyUTQzb0RMOUVoQW9JQkFRRFRXSW1meTBLOWdHekEyclB5MTY5bVdZUUsKT2xjbkQzK2hRcTZ4NTFabjFlL3RleEZlVmxoSG40cnJuUmRDRk9BcDQ3dUZrSjJtNzJHQ1ZENzRFd1F1Y0s5eQpBRDVqb3JxZ1ZIcUNLWmRrSGpiMlY2ME16bTZnM3J0TDlXSlhGVkx2TkJiL1FHQjJ2Z0hWT08wenFpcUdaajRlCkV4N2wybS8vNVNFNERMdG43MEo5Q2dHMUh0WENTOGRXckdQTDFwekRuazhWWHRub1h6YjBMQ2hMVUZFZ1pSbWgKY1Y2QUZIRUsySDh3Qkh2aU55ZWhzUlFpRGtsMkFpV09jSk52a3pXNjhjazJuSmpSV3lQWUsxSkwzTkNLcEIzUQpPb2hyUDBmSGNXQVhNVzk3d0ZYWmhSZm5RZkR4eElPbGozTWNZVDBBbGFuWGQwRjROR2MyTnZtcGh4MDQKLS0tLS1FTkQgUlNBIFBSSVZBVEUgS0VZLS0tLS0K
---
apiVersion: v1
kind: Secret
metadata:
namespace: core-app
name: secret-harbor-core
type: Opaque
stringData:
secretKey: "not-a-secure-key"
secret: "please_replace_this_to_random_data"
HARBOR_ADMIN_PASSWORD: "harbor-admin-password"
POSTGRESQL_PASSWORD: "harbor_password"
HARBOR_DATABASE_PASSWORD: "harbor_password"
REGISTRY_CREDENTIAL_PASSWORD: "harbor_registry_password"
CSRF_KEY: "please_replace_this_to_random_data"
---
apiVersion: v1
kind: Secret
metadata:
namespace: core-app
name: secret-harbor-job-service
type: Opaque
stringData:
JOBSERVICE_SECRET: "please_replace_this_to_random_data"
REGISTRY_CREDENTIAL_PASSWORD: "harbor_registry_password"
---
apiVersion: v1
kind: Secret
metadata:
namespace: core-app
name: secret-harbor-registry
type: Opaque
stringData:
REGISTRY_REDIS_PASSWORD: ""
REGISTRY_HTTP_SECRET: "please_replace_this_to_random_data"
REGISTRY_HTPASSWD: "harbor_registry_user:$2a$10$WktPbZNT.O/vjv/Y0k.UbuLwxsvddxai/qGu7Kw2TawemGkG2l4H6"
---
apiVersion: v1
kind: Secret
metadata:
namespace: core-app
name: secret-harbor-trivy
type: Opaque
stringData:
redisURL: redis://svc-harbor-redis:6379/5?idle_timeout_seconds=30
gitHubToken: ""
---
3.2. 创建 Service
配置导入完成后,创建相关的 Service 配置。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-chart-museum
labels:
app: harbor
spec:
ports:
- port: 80
targetPort: 9999
selector:
app: harbor
component: chart-museum
---
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-core
labels:
app: harbor
spec:
ports:
- name: http-web
port: 80
targetPort: 8080
- name: http-metrics
port: 8001
selector:
app: harbor
component: core
---
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-exporter
labels:
app: harbor
spec:
ports:
- name: http-metrics
port: 8001
selector:
app: harbor
component: exporter
---
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-job-service
labels:
app: harbor
spec:
ports:
- name: http-jobservice
port: 80
targetPort: 8080
- name: http-metrics
port: 8001
selector:
app: harbor
component: job-service
---
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-portal
labels:
app: harbor
spec:
ports:
- port: 80
targetPort: 8080
selector:
app: harbor
component: portal
---
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-redis
labels:
app: harbor
spec:
ports:
- port: 6379
selector:
app: harbor
component: redis
---
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-registry
labels:
app: harbor
spec:
ports:
- name: http-registry
port: 5000
- name: http-controller
port: 8080
- name: http-metrics
port: 8001
selector:
app: harbor
component: registry
---
apiVersion: v1
kind: Service
metadata:
namespace: core-app
name: svc-harbor-trivy
labels:
app: harbor
spec:
ports:
- name: http-trivy
protocol: TCP
port: 8080
selector:
app: harbor
component: trivy
3.3. 创建 Pod
Service 创建完成后,在 Kubernetes 下导入以下配置来创建 Harbor 启动配置。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: core-app
name: deploy-harbor-chart-museum
labels:
app: harbor
component: chart-museum
spec:
replicas: 1
revisionHistoryLimit: 10
strategy:
type: RollingUpdate
selector:
matchLabels:
app: harbor
component: chart-museum
template:
metadata:
labels:
app: harbor
component: chart-museum
spec:
securityContext:
runAsUser: 10000
fsGroup: 10000
automountServiceAccountToken: false
containers:
- name: chart-museum
image: goharbor/chartmuseum-photon:v2.5.3
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /health
scheme: HTTP
port: 9999
initialDelaySeconds: 300
periodSeconds: 10
readinessProbe:
httpGet:
path: /health
scheme: HTTP
port: 9999
initialDelaySeconds: 1
periodSeconds: 10
envFrom:
- configMapRef:
name: conf-harbor-chart-museum
- secretRef:
name: secret-harbor-chart-museum
env:
- name: BASIC_AUTH_PASS
valueFrom:
secretKeyRef:
name: secret-harbor-core
key: secret
- # Needed to make AWS' client connect correctly (see https://github.com/helm/chartmuseum/issues/280)
name: AWS_SDK_LOAD_CONFIG
value: "1"
ports:
- containerPort: 9999
volumeMounts:
- name: chart-museum-data
mountPath: /chart_storage
volumes:
- name: chart-museum-data
persistentVolumeClaim:
claimName: pvc-harbor-chart-museum
---
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: core-app
name: deploy-harbor-core
labels:
app: harbor
component: core
spec:
replicas: 1
revisionHistoryLimit: 10
selector:
matchLabels:
app: harbor
component: core
template:
metadata:
labels:
app: harbor
component: core
spec:
securityContext:
runAsUser: 10000
fsGroup: 10000
automountServiceAccountToken: false
terminationGracePeriodSeconds: 120
containers:
- name: core
image: goharbor/harbor-core:v2.5.3
imagePullPolicy: IfNotPresent
startupProbe:
httpGet:
path: /api/v2.0/ping
scheme: HTTP
port: 8080
failureThreshold: 360
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /api/v2.0/ping
scheme: HTTP
port: 8080
failureThreshold: 2
periodSeconds: 10
readinessProbe:
httpGet:
path: /api/v2.0/ping
scheme: HTTP
port: 8080
failureThreshold: 2
periodSeconds: 10
envFrom:
- configMapRef:
name: conf-harbor-core
- secretRef:
name: secret-harbor-core
- secretRef:
name: secret-harbor-internal-tls
env:
- name: CORE_SECRET
valueFrom:
secretKeyRef:
name: secret-harbor-core
key: secret
- name: JOBSERVICE_SECRET
valueFrom:
secretKeyRef:
name: secret-harbor-job-service
key: JOBSERVICE_SECRET
ports:
- containerPort: 8080
volumeMounts:
- name: config
mountPath: /etc/core/app.conf
subPath: app.conf
- name: secret-key
mountPath: /etc/core/key
subPath: key
- name: token-service-private-key
mountPath: /etc/core/private_key.pem
subPath: tls.key
- name: psc
mountPath: /etc/core/token
volumes:
- name: config
configMap:
name: conf-harbor-core
items:
- key: app.conf
path: app.conf
- name: secret-key
secret:
secretName: secret-harbor-core
items:
- key: secretKey
path: key
- name: token-service-private-key
secret:
secretName: secret-harbor-internal-tls
- name: psc
emptyDir: { }
---
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: core-app
name: deploy-harbor-exporter
labels:
app: harbor
component: exporter
spec:
replicas: 1
revisionHistoryLimit: 10
selector:
matchLabels:
app: harbor
component: exporter
template:
metadata:
labels:
app: harbor
component: exporter
spec:
securityContext:
runAsUser: 10000
fsGroup: 10000
automountServiceAccountToken: false
containers:
- name: exporter
image: goharbor/harbor-exporter:v2.5.3
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /
port: 8001
initialDelaySeconds: 300
periodSeconds: 10
readinessProbe:
httpGet:
path: /
port: 8001
initialDelaySeconds: 30
periodSeconds: 10
args: [ "-log-level", "info" ]
envFrom:
- configMapRef:
name: conf-harbor-exporter-env
- secretRef:
name: secret-harbor-core
- secretRef:
name: secret-harbor-internal-tls
ports:
- containerPort: 8080
---
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: core-app
name: deploy-harbor-job-service
labels:
app: harbor
component: job-service
spec:
replicas: 1
revisionHistoryLimit: 10
strategy:
type: RollingUpdate
selector:
matchLabels:
app: harbor
component: job-service
template:
metadata:
labels:
app: harbor
component: job-service
spec:
securityContext:
runAsUser: 10000
fsGroup: 10000
automountServiceAccountToken: false
terminationGracePeriodSeconds: 120
containers:
- name: job-service
image: goharbor/harbor-jobservice:v2.5.3
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /api/v1/stats
scheme: HTTP
port: 8080
initialDelaySeconds: 300
periodSeconds: 10
readinessProbe:
httpGet:
path: /api/v1/stats
scheme: HTTP
port: 8080
initialDelaySeconds: 20
periodSeconds: 10
env:
- name: CORE_SECRET
valueFrom:
secretKeyRef:
name: secret-harbor-core
key: secret
envFrom:
- configMapRef:
name: conf-harbor-job-service-env
- secretRef:
name: secret-harbor-job-service
ports:
- containerPort: 8080
volumeMounts:
- name: job-service-config
mountPath: /etc/jobservice/config.yml
subPath: config.yml
- name: job-logs
mountPath: /var/log/jobs
- name: job-scan-data-exports
mountPath: /var/scandata_exports
volumes:
- name: job-service-config
configMap:
name: harbor-job-service
- name: job-logs
persistentVolumeClaim:
claimName: pvc-harbor-job-service
- name: job-scan-data-exports
persistentVolumeClaim:
claimName: pvc-harbor-job-service-scan-data
---
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: core-app
name: deploy-harbor-portal
labels:
app: harbor
component: portal
spec:
replicas: 1
revisionHistoryLimit: 10
selector:
matchLabels:
app: harbor
component: portal
template:
metadata:
labels:
app: harbor
component: portal
spec:
securityContext:
runAsUser: 10000
fsGroup: 10000
automountServiceAccountToken: false
containers:
- name: portal
image: goharbor/harbor-portal:v2.5.3
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /
scheme: HTTP
port: 8080
initialDelaySeconds: 300
periodSeconds: 10
readinessProbe:
httpGet:
path: /
scheme: HTTP
port: 8080
initialDelaySeconds: 1
periodSeconds: 10
ports:
- containerPort: 8080
volumeMounts:
- name: portal-config
mountPath: /etc/nginx/nginx.conf
subPath: nginx.conf
volumes:
- name: portal-config
configMap:
name: conf-harbor-portal
---
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: core-app
name: deploy-harbor-registry
labels:
app: harbor
component: registry
spec:
replicas: 1
revisionHistoryLimit: 10
strategy:
type: RollingUpdate
selector:
matchLabels:
app: harbor
component: registry
template:
metadata:
labels:
app: harbor
component: registry
spec:
securityContext:
runAsUser: 10000
fsGroup: 10000
fsGroupChangePolicy: OnRootMismatch
automountServiceAccountToken: false
terminationGracePeriodSeconds: 120
containers:
- name: registry
image: goharbor/registry-photon:v2.5.3
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /
scheme: HTTP
port: 5000
initialDelaySeconds: 300
periodSeconds: 10
readinessProbe:
httpGet:
path: /
scheme: HTTP
port: 5000
initialDelaySeconds: 1
periodSeconds: 10
args: [ "serve", "/etc/registry/config.yml" ]
envFrom:
- secretRef:
name: secret-harbor-registry
ports:
- containerPort: 5000
- containerPort: 5001
volumeMounts:
- name: registry-data
mountPath: /storage
- name: registry-htpasswd
mountPath: /etc/registry/passwd
subPath: passwd
- name: registry-config
mountPath: /etc/registry/config.yml
subPath: config.yml
- name: registryctl
image: goharbor/harbor-registryctl:v2.5.3
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /api/health
scheme: HTTP
port: 8080
initialDelaySeconds: 300
periodSeconds: 10
readinessProbe:
httpGet:
path: /api/health
scheme: HTTP
port: 8080
initialDelaySeconds: 1
periodSeconds: 10
envFrom:
- secretRef:
name: secret-harbor-registry
env:
- name: CORE_SECRET
valueFrom:
secretKeyRef:
name: secret-harbor-core
key: secret
- name: JOBSERVICE_SECRET
valueFrom:
secretKeyRef:
name: secret-harbor-job-service
key: JOBSERVICE_SECRET
ports:
- containerPort: 8080
volumeMounts:
- name: registry-data
mountPath: /storage
- name: registry-config
mountPath: /etc/registry/config.yml
subPath: config.yml
- name: registry-config
mountPath: /etc/registryctl/config.yml
subPath: ctl-config.yml
volumes:
- name: registry-htpasswd
secret:
secretName: secret-harbor-registry
items:
- key: REGISTRY_HTPASSWD
path: passwd
- name: registry-config
configMap:
name: conf-harbor-registry
- name: registry-data
persistentVolumeClaim:
claimName: pvc-harbor-registry
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
namespace: core-app
name: sts-harbor-redis
labels:
app: harbor
component: redis
spec:
replicas: 1
serviceName: svc-harbor-redis
selector:
matchLabels:
app: harbor
component: redis
template:
metadata:
labels:
app: harbor
component: redis
spec:
securityContext:
runAsUser: 999
fsGroup: 999
automountServiceAccountToken: false
terminationGracePeriodSeconds: 120
containers:
- name: redis
image: goharbor/redis-photon:v2.5.3
imagePullPolicy: IfNotPresent
livenessProbe:
tcpSocket:
port: 6379
initialDelaySeconds: 300
periodSeconds: 10
readinessProbe:
tcpSocket:
port: 6379
initialDelaySeconds: 1
periodSeconds: 10
volumeMounts:
- name: redis-data
mountPath: /var/lib/redis
volumes:
- name: redis-data
persistentVolumeClaim:
claimName: pvc-harbor-redis-data
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
namespace: core-app
name: sts-harbor-trivy
labels:
app: harbor
component: trivy
spec:
replicas: 1
serviceName: svc-harbor-trivy
selector:
matchLabels:
app: harbor
component: trivy
template:
metadata:
labels:
app: harbor
component: trivy
spec:
securityContext:
runAsUser: 10000
fsGroup: 10000
automountServiceAccountToken: false
containers:
- name: trivy
image: goharbor/trivy-adapter-photon:v2.5.3
imagePullPolicy: IfNotPresent
securityContext:
privileged: false
allowPrivilegeEscalation: false
env:
- name: HTTP_PROXY
value: ""
- name: HTTPS_PROXY
value: ""
- name: NO_PROXY
value: "svc-harbor-core,svc-harbor-job-service,harbor-database,svc-harbor-chart-museum,svc-harbor-notary-server,svc-harbor-notary-signer,svc-harbor-registry,svc-harbor-portal,svc-harbor-trivy,svc-harbor-exporter,127.0.0.1,localhost,.local,.internal"
- name: "SCANNER_LOG_LEVEL"
value: "info"
- name: "SCANNER_TRIVY_CACHE_DIR"
value: "/home/scanner/.cache/trivy"
- name: "SCANNER_TRIVY_REPORTS_DIR"
value: "/home/scanner/.cache/reports"
- name: "SCANNER_TRIVY_DEBUG_MODE"
value: "false"
- name: "SCANNER_TRIVY_VULN_TYPE"
value: "os,library"
- name: "SCANNER_TRIVY_TIMEOUT"
value: "5m0s"
- name: "SCANNER_TRIVY_GITHUB_TOKEN"
valueFrom:
secretKeyRef:
name: secret-harbor-trivy
key: gitHubToken
- name: "SCANNER_TRIVY_SEVERITY"
value: "UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL"
- name: "SCANNER_TRIVY_IGNORE_UNFIXED"
value: "false"
- name: "SCANNER_TRIVY_SKIP_UPDATE"
value: "false"
- name: "SCANNER_TRIVY_OFFLINE_SCAN"
value: "false"
- name: "SCANNER_TRIVY_INSECURE"
value: "false"
- name: SCANNER_API_SERVER_ADDR
value: ":8080"
- name: "SCANNER_REDIS_URL"
valueFrom:
secretKeyRef:
name: secret-harbor-trivy
key: redisURL
- name: "SCANNER_STORE_REDIS_URL"
valueFrom:
secretKeyRef:
name: secret-harbor-trivy
key: redisURL
- name: "SCANNER_JOB_QUEUE_REDIS_URL"
valueFrom:
secretKeyRef:
name: secret-harbor-trivy
key: redisURL
ports:
- name: api-server
containerPort: 8080
volumeMounts:
- name: cache-data
mountPath: /home/scanner/.cache
readOnly: false
livenessProbe:
httpGet:
scheme: HTTP
path: /probe/healthy
port: api-server
initialDelaySeconds: 5
periodSeconds: 10
successThreshold: 1
failureThreshold: 10
readinessProbe:
httpGet:
scheme: HTTP
path: /probe/ready
port: api-server
initialDelaySeconds: 5
periodSeconds: 10
successThreshold: 1
failureThreshold: 3
volumes:
- name: cache-data
persistentVolumeClaim:
claimName: pvc-harbor-trivy-data
3.4. 创建 Ingress
Deployment 创建完成后,将 Service 通过 Ingress 暴露到外部地址。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
namespace: core-app
name: ingress-harbor
labels:
app: harbor
annotations:
nginx.ingress.kubernetes.io/proxy-body-size: "0"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
ingressClassName: nginx-public
tls:
- secretName: 'tls-pub-d7z'
hosts:
- harbor.d7z.net
rules:
- http:
paths:
- path: /api/
pathType: Prefix
backend:
service:
name: svc-harbor-core
port:
number: 80
- path: /service/
pathType: Prefix
backend:
service:
name: svc-harbor-core
port:
number: 80
- path: /v2/
pathType: Prefix
backend:
service:
name: svc-harbor-core
port:
number: 80
- path: /chartrepo/
pathType: Prefix
backend:
service:
name: svc-harbor-core
port:
number: 80
- path: /c/
pathType: Prefix
backend:
service:
name: svc-harbor-core
port:
number: 80
- path: /
pathType: Prefix
backend:
service:
name: svc-harbor-portal
port:
number: 80
host: harbor.d7z.net
3.5. 获取部署状态
使用以下命令获取部署状态。
1
kubectl get pods,pvc,svc,ingress -n core-app -l app=harbor
4. 配置 Harbor
部署完成后,访问 https://harbor.d7z.net/
, 使用用户名 admin
和配置的密码 harbor-admin-password
登陆 Harbor 。
4.1. 配置 LDAP 管理器
访问 https://harbor.d7z.net/harbor/configs/auth
,切换验证模式为 LDAP,按下图填入内容。
LDAP 过滤器内容如下:
1
(|(memberOf=cn=admin,ou=groups,dc=cluster,dc=local)(memberOf=cn=docker,ou=groups,dc=cluster,dc=local)(memberOf=cn=deploy,ou=groups,dc=cluster,dc=local))
LDAP 组过滤器内容如下:
1
(|(cn=admin)(cn=deploy)(cn=docker))
编辑完成后,点击 测试LDAP服务器
,如一切无误,点击保存即可。
4.2. 测试镜像推送
使用如下命令登陆 Harbor,输入具有写入权限的账户和密码,如一切无误,则登陆成功
1
docker login harbor.d7z.net