Move Helm chart configuration from inline values in app-harbor.yaml to separate files in apps/harbor/ subdirectory, following the same pattern as forgejo and other apps. Changes: - Create apps/harbor/Chart.yaml defining dependency on Harbor Helm chart - Create apps/harbor/values.yaml with all Helm values configuration - Update app-harbor.yaml to use git path source instead of direct Helm chart - Add apps/harbor/README.md documenting OIDC setup procedure OIDC authentication must be configured via Harbor UI after deployment, as the Helm chart does not support OIDC configuration at deployment time. The README provides step-by-step instructions for Pocket ID integration. Co-Authored-By: Paperclip <noreply@paperclip.ing>
71 lines
2.5 KiB
Markdown
71 lines
2.5 KiB
Markdown
# Harbor Container Registry
|
|
|
|
Harbor is deployed at https://harbor.basicstack.de
|
|
|
|
## Initial Access
|
|
|
|
The initial admin credentials are stored in the `harbor-secrets` sealed secret:
|
|
- Username: `admin`
|
|
- Password: Retrieved from secret key `harborAdminPassword`
|
|
|
|
## OIDC Authentication Setup
|
|
|
|
Harbor requires OIDC to be configured via the web UI or API after initial deployment. The Helm chart does not support OIDC configuration at deployment time.
|
|
|
|
### Steps to Configure Pocket ID OIDC
|
|
|
|
1. **Create OIDC Client in Pocket ID**
|
|
- Navigate to https://auth.basicstack.de
|
|
- Create a new client with these settings:
|
|
- Client ID: `harbor`
|
|
- Redirect URIs: `https://harbor.basicstack.de/c/oidc/callback`
|
|
- Scopes: `openid`, `profile`, `email`, `groups`
|
|
- Save the client secret
|
|
|
|
2. **Configure OIDC in Harbor**
|
|
- Log in to Harbor as admin: https://harbor.basicstack.de
|
|
- Navigate to: **Administration** → **Configuration** → **Authentication**
|
|
- Select **OIDC** as the authentication mode
|
|
- Fill in the following:
|
|
- **OIDC Provider Name**: `PocketID`
|
|
- **OIDC Endpoint**: `https://auth.basicstack.de`
|
|
- **OIDC Client ID**: `harbor`
|
|
- **OIDC Client Secret**: (paste the secret from Pocket ID)
|
|
- **Group Claim Name**: `groups`
|
|
- **OIDC Admin Group**: `admins`
|
|
- **OIDC Scope**: `openid,profile,email,groups`
|
|
- **Verify Certificate**: ✓ (enabled)
|
|
- **Automatic onboarding**: ✓ (enabled)
|
|
- **Username Claim**: `email`
|
|
- Click **Test OIDC Server** to verify connectivity
|
|
- Click **Save** to apply the configuration
|
|
|
|
3. **Test OIDC Login**
|
|
- Log out of Harbor
|
|
- Return to the Harbor login page
|
|
- You should now see a "Login via OIDC Provider" button
|
|
- Click it to authenticate via Pocket ID
|
|
|
|
### Reference Documentation
|
|
|
|
- Harbor OIDC Configuration: https://goharbor.io/docs/2.12.0/administration/configure-authentication/oidc-auth/
|
|
- Pocket ID Harbor Example: https://pocket-id.org/docs/client-examples/harbor
|
|
|
|
## Storage
|
|
|
|
Harbor uses encrypted Hetzner Cloud volumes for persistence:
|
|
- Registry data: 50Gi
|
|
- PostgreSQL database: 10Gi
|
|
- Redis cache: 5Gi
|
|
- Trivy vulnerability database: 5Gi
|
|
- Job service logs: 5Gi
|
|
|
|
All PVCs are configured with `resourcePolicy: keep` to prevent data loss during upgrades.
|
|
|
|
## Architecture
|
|
|
|
- **Ingress**: Traefik with Let's Encrypt TLS certificates
|
|
- **Database**: Internal PostgreSQL
|
|
- **Cache**: Internal Redis
|
|
- **Vulnerability Scanning**: Trivy enabled
|
|
- **Authentication**: OIDC via Pocket ID (after manual configuration)
|