# Harbor Container Registry Harbor is deployed at https://harbor.basicstack.de ## Initial Access The initial admin credentials are stored in the `harbor-secrets` sealed secret: - Username: `admin` - Password: Retrieved from secret key `harborAdminPassword` ## OIDC Authentication Setup Harbor requires OIDC to be configured via the web UI or API after initial deployment. The Helm chart does not support OIDC configuration at deployment time. ### Steps to Configure Pocket ID OIDC 1. **Create OIDC Client in Pocket ID** - Navigate to https://auth.basicstack.de - Create a new client with these settings: - Client ID: `harbor` - Redirect URIs: `https://harbor.basicstack.de/c/oidc/callback` - Scopes: `openid`, `profile`, `email`, `groups` - Save the client secret 2. **Configure OIDC in Harbor** - Log in to Harbor as admin: https://harbor.basicstack.de - Navigate to: **Administration** → **Configuration** → **Authentication** - Select **OIDC** as the authentication mode - Fill in the following: - **OIDC Provider Name**: `PocketID` - **OIDC Endpoint**: `https://auth.basicstack.de` - **OIDC Client ID**: `harbor` - **OIDC Client Secret**: (paste the secret from Pocket ID) - **Group Claim Name**: `groups` - **OIDC Admin Group**: `admins` - **OIDC Scope**: `openid,profile,email,groups` - **Verify Certificate**: ✓ (enabled) - **Automatic onboarding**: ✓ (enabled) - **Username Claim**: `email` - Click **Test OIDC Server** to verify connectivity - Click **Save** to apply the configuration 3. **Test OIDC Login** - Log out of Harbor - Return to the Harbor login page - You should now see a "Login via OIDC Provider" button - Click it to authenticate via Pocket ID ### Reference Documentation - Harbor OIDC Configuration: https://goharbor.io/docs/2.12.0/administration/configure-authentication/oidc-auth/ - Pocket ID Harbor Example: https://pocket-id.org/docs/client-examples/harbor ## Storage Harbor uses encrypted Hetzner Cloud volumes for persistence: - Registry data: 50Gi - PostgreSQL database: 10Gi - Redis cache: 5Gi - Trivy vulnerability database: 5Gi - Job service logs: 5Gi All PVCs are configured with `resourcePolicy: keep` to prevent data loss during upgrades. ## Architecture - **Ingress**: Traefik with Let's Encrypt TLS certificates - **Database**: Internal PostgreSQL - **Cache**: Internal Redis - **Vulnerability Scanning**: Trivy enabled - **Authentication**: OIDC via Pocket ID (after manual configuration)