Add argocd.argoproj.io/compare-options: IgnoreExtraneous annotation to harbor-secrets sealed secret template to prevent ArgoCD from seeing the unsealed secret (created by sealed-secrets controller) as extraneous. This is the same fix applied in DEV-377 for Directus and previously in DEV-289, DEV-290 for other services. Resolves: DEV-378 Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|---|---|---|
| .. | ||
| Chart.yaml | ||
| harbor-secrets-sealed.yaml | ||
| README.md | ||
| values.yaml | ||
Harbor Container Registry
Harbor is deployed at https://harbor.basicstack.de
Initial Access
The initial admin credentials are stored in the harbor-secrets sealed secret:
- Username:
admin - Password: Retrieved from secret key
harborAdminPassword
OIDC Authentication Setup
Harbor requires OIDC to be configured via the web UI or API after initial deployment. The Helm chart does not support OIDC configuration at deployment time.
Steps to Configure Pocket ID OIDC
-
Create OIDC Client in Pocket ID
- Navigate to https://auth.basicstack.de
- Create a new client with these settings:
- Client ID:
harbor - Redirect URIs:
https://harbor.basicstack.de/c/oidc/callback - Scopes:
openid,profile,email,groups
- Client ID:
- Save the client secret
-
Configure OIDC in Harbor
- Log in to Harbor as admin: https://harbor.basicstack.de
- Navigate to: Administration → Configuration → Authentication
- Select OIDC as the authentication mode
- Fill in the following:
- OIDC Provider Name:
PocketID - OIDC Endpoint:
https://auth.basicstack.de - OIDC Client ID:
harbor - OIDC Client Secret: (paste the secret from Pocket ID)
- Group Claim Name:
groups - OIDC Admin Group:
admins - OIDC Scope:
openid,profile,email,groups - Verify Certificate: ✓ (enabled)
- Automatic onboarding: ✓ (enabled)
- Username Claim:
email
- OIDC Provider Name:
- Click Test OIDC Server to verify connectivity
- Click Save to apply the configuration
-
Test OIDC Login
- Log out of Harbor
- Return to the Harbor login page
- You should now see a "Login via OIDC Provider" button
- Click it to authenticate via Pocket ID
Reference Documentation
- Harbor OIDC Configuration: https://goharbor.io/docs/2.12.0/administration/configure-authentication/oidc-auth/
- Pocket ID Harbor Example: https://pocket-id.org/docs/client-examples/harbor
Storage
Harbor uses encrypted Hetzner Cloud volumes for persistence:
- Registry data: 50Gi
- PostgreSQL database: 10Gi
- Redis cache: 5Gi
- Trivy vulnerability database: 5Gi
- Job service logs: 5Gi
All PVCs are configured with resourcePolicy: keep to prevent data loss during upgrades.
Architecture
- Ingress: Traefik with Let's Encrypt TLS certificates
- Database: Internal PostgreSQL
- Cache: Internal Redis
- Vulnerability Scanning: Trivy enabled
- Authentication: OIDC via Pocket ID (after manual configuration)