溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊(cè)×
其他方式登錄
點(diǎn)擊 登錄注冊(cè) 即表示同意《億速云用戶服務(wù)條款》

kubernetes中Harbor有什么用

發(fā)布時(shí)間:2021-12-24 16:09:51 來源:億速云 閱讀:294 作者:小新 欄目:大數(shù)據(jù)

這篇文章主要介紹了kubernetes中Harbor有什么用,具有一定借鑒價(jià)值,感興趣的朋友可以參考下,希望大家閱讀完這篇文章之后大有收獲,下面讓小編帶著大家一起了解一下。

一:簡(jiǎn)介

Harbor是一個(gè)用于存儲(chǔ)和分發(fā)Docker鏡像的企業(yè)級(jí)Registry服務(wù)器。

鏡像的存儲(chǔ)harbor使用的是官方的docker registry(v2命名是distribution)服務(wù)去完成。harbor在docker distribution的基礎(chǔ)上增加了一些安全、訪問控制、管理的功能以滿足企業(yè)對(duì)于鏡像倉庫的需求。harbor以docker-compose的規(guī)范形式組織各個(gè)組件,并通過docker-compose工具進(jìn)行啟停。

docker的registry是用本地存儲(chǔ)或者s3都是可以的,harbor的功能是在此之上提供用戶權(quán)限管理、鏡像復(fù)制等功能,提高使用的registry的效率。Harbor的鏡像拷貝功能是通過docker registry的API去拷貝,這種做法屏蔽了繁瑣的底層文件操作、不僅可以利用現(xiàn)有docker registry功能不必重復(fù)造輪子,而且可以解決沖突和一致性的問題。

二:Harbor架構(gòu)
kubernetes中Harbor有什么用

三:主要組件

  • Proxy:對(duì)應(yīng)啟動(dòng)組件nginx。它是一個(gè)nginx反向代理,代理Notary client(鏡像認(rèn)證)、Docker client(鏡像上傳下載等)和瀏覽器的訪問請(qǐng)求(Core Service)給后端的各服務(wù);

  • UI(Core Service):對(duì)應(yīng)啟動(dòng)組件harbor-ui。底層數(shù)據(jù)存儲(chǔ)使用mysql數(shù)據(jù)庫,主要提供了四個(gè)子功能: 

    • UI:一個(gè)web管理頁面ui;

    • API:Harbor暴露的API服務(wù);

    • Auth:用戶認(rèn)證服務(wù),decode后的token中的用戶信息在這里進(jìn)行認(rèn)證;auth后端可以接db、ldap、uaa三種認(rèn)證實(shí)現(xiàn);

    • Token服務(wù)(上圖中未體現(xiàn)):負(fù)責(zé)根據(jù)用戶在每個(gè)project中的role來為每一個(gè)docker push/pull命令issuing一個(gè)token,如果從docker client發(fā)送給registry的請(qǐng)求沒有帶token,registry會(huì)重定向請(qǐng)求到token服務(wù)創(chuàng)建token。

  • Registry:對(duì)應(yīng)啟動(dòng)組件registry。負(fù)責(zé)存儲(chǔ)鏡像文件,和處理鏡像的pull/push命令。Harbor對(duì)鏡像進(jìn)行強(qiáng)制的訪問控制,Registry會(huì)將客戶端的每個(gè)pull、push請(qǐng)求轉(zhuǎn)發(fā)到token服務(wù)來獲取有效的token。

  • Admin Service:對(duì)應(yīng)啟動(dòng)組件harbor-adminserver。是系統(tǒng)的配置管理中心附帶檢查存儲(chǔ)用量,ui和jobserver啟動(dòng)時(shí)候需要加載adminserver的配置;

  • Job Sevice:對(duì)應(yīng)啟動(dòng)組件harbor-jobservice。負(fù)責(zé)鏡像復(fù)制工作的,他和registry通信,從一個(gè)registry pull鏡像然后push到另一個(gè)registry,并記錄job_log;

  • Log Collector:對(duì)應(yīng)啟動(dòng)組件harbor-log。日志匯總組件,通過docker的log-driver把日志匯總到一起;

  • Volnerability Scanning:對(duì)應(yīng)啟動(dòng)組件clair。負(fù)責(zé)鏡像掃描

  • Notary:對(duì)應(yīng)啟動(dòng)組件notary。負(fù)責(zé)鏡像認(rèn)證

  • DB:對(duì)應(yīng)啟動(dòng)組件harbor-db,負(fù)責(zé)存儲(chǔ)project、 user、 role、replication、image_scan、access等的metadata數(shù)據(jù)。

四:安裝

1、安裝python-pip
yum -y install epel-release
yum -y install python-pip

2、安裝docker-compose
pip install docker-compose
待安裝完成后,執(zhí)行查詢版本的命令,即可安裝docker-compose
docker-compose version

3.安裝Harbor
wget https://storage.googleapis.com/harbor-releases/release-1.4.0/harbor-offline-installer-v1.4.0.tgz
tar -zxvf harbor-offline-installer-v1.4.0.tgz

配置文件 harbor.cfg

點(diǎn)擊(此處)折疊或打開

  1. ## Configuration file of Harbor


  2. #The IP address or hostname to access admin UI and registry service.

  3. #DO NOT use localhost or 127.0.0.1, because Harbor needs to be accessed by external clients.

  4. hostname = 120.79.156.135


  5. #The protocol for accessing the UI and token/notification service, by default it is http.

  6. #It can be set to https if ssl is enabled on nginx.

  7. ui_url_protocol = http


  8. #Maximum number of job workers in job service

  9. max_job_workers = 3


  10. #Determine whether or not to generate certificate for the registry's token.

  11. #If the value is on, the prepare script creates new root cert and private key

  12. #for generating token to access the registry. If the value is off the default key/cert will be used.

  13. #This flag also controls the creation of the notary signer's cert.

  14. customize_crt = on


  15. #The path of cert and key files for nginx, they are applied only the protocol is set to https

  16. ssl_cert = /mnt/harbor/cert/server.crt

  17. ssl_cert_key = /mnt/harbor/cert/server.key


  18. #The path of secretkey storage

  19. secretkey_path = /mnt/harbor


  20. #Admiral's url, comment this attribute, or set its value to NA when Harbor is standalone

  21. admiral_url = NA


  22. #Log files are rotated log_rotate_count times before being removed. If count is 0, old versions are removed rather than rotated.

  23. log_rotate_count = 50

  24. #Log files are rotated only if they grow bigger than log_rotate_size bytes. If size is followed by k, the size is assumed to be in kilobytes.

  25. #If the M is used, the size is in megabytes, and if G is used, the size is in gigabytes. So size 100, size 100k, size 100M and size 100G

  26. #are all valid.

  27. log_rotate_size = 200M


  28. #NOTES: The properties between BEGIN INITIAL PROPERTIES and END INITIAL PROPERTIES

  29. #only take effect in the first boot, the subsequent changes of these properties

  30. #should be performed on web ui


  31. #************************BEGIN INITIAL PROPERTIES************************


  32. #Email account settings for sending out password resetting emails.


  33. #Email server uses the given username and password to authenticate on TLS connections to host and act as identity.

  34. #Identity left blank to act as username.

  35. email_identity =


  36. email_server = smtp.mydomain.com

  37. email_server_port = 25

  38. email_username = sample_admin@mydomain.com

  39. email_password = abc

  40. email_from = admin <sample_admin@mydomain.com>

  41. email_ssl = false

  42. email_insecure = false


  43. ##The initial password of Harbor admin, only works for the first time when Harbor starts.

  44. #It has no effect after the first launch of Harbor.

  45. #Change the admin password from UI after launching Harbor.

  46. harbor_admin_password = Weinong$2017


  47. ##By default the auth mode is db_auth, i.e. the credentials are stored in a local database.

  48. #Set it to ldap_auth if you want to verify a user's credentials against an LDAP server.

  49. auth_mode = db_auth


  50. #The url for an ldap endpoint.

  51. ldap_url = ldaps://ldap.mydomain.com


  52. #A user's DN who has the permission to search the LDAP/AD server.

  53. #If your LDAP/AD server does not support anonymous search, you should configure this DN and ldap_search_pwd.

  54. #ldap_searchdn = uid=searchuser,ou=people,dc=mydomain,dc=com


  55. #the password of the ldap_searchdn

  56. #ldap_search_pwd = password


  57. #The base DN from which to look up a user in LDAP/AD

  58. ldap_basedn = ou=people,dc=mydomain,dc=com


  59. #Search filter for LDAP/AD, make sure the syntax of the filter is correct.

  60. #ldap_filter = (objectClass=person)


  61. # The attribute used in a search to match a user, it could be uid, cn, email, sAMAccountName or other attributes depending on your LDAP/AD

  62. ldap_uid = uid


  63. #the scope to search for users, 0-LDAP_SCOPE_BASE, 1-LDAP_SCOPE_ONELEVEL, 2-LDAP_SCOPE_SUBTREE

  64. ldap_scope = 2


  65. #Timeout (in seconds)  when connecting to an LDAP Server. The default value (and most reasonable) is 5 seconds.

  66. ldap_timeout = 5


  67. #Verify certificate from LDAP server

  68. ldap_verify_cert = true


  69. #Turn on or off the self-registration feature

  70. self_registration = on


  71. #The expiration time (in minute) of token created by token service, default is 30 minutes

  72. token_expiration = 30


  73. #The flag to control what users have permission to create projects

  74. #The default value "everyone" allows everyone to creates a project.

  75. #Set to "adminonly" so that only admin user can create project.

  76. project_creation_restriction = everyone


  77. #************************END INITIAL PROPERTIES************************


  78. #######Harbor DB configuration section#######


  79. #The address of the Harbor database. Only need to change when using external db.

  80. db_host = mysql


  81. #The password for the root user of Harbor DB. Change this before any production use.

  82. db_password = Weinong$2017


  83. #The port of Harbor database host

  84. db_port = 3306


  85. #The user name of Harbor database

  86. db_user = root


  87. ##### End of Harbor DB configuration#######


  88. #The redis server address. Only needed in HA installation.

  89. redis_url =


  90. ##########Clair DB configuration############


  91. #Clair DB host address. Only change it when using an exteral DB.

  92. clair_db_host = postgres


  93. #The password of the Clair's postgres database. Only effective when Harbor is deployed with Clair.

  94. #Please update it before deployment. Subsequent update will cause Clair's API server and Harbor unable to access Clair's database.

  95. clair_db_password = password


  96. #Clair DB connect port

  97. clair_db_port = 5432


  98. #Clair DB username

  99. clair_db_username = postgres


  100. #Clair default database

  101. clair_db = postgres


  102. ##########End of Clair DB configuration############


  103. #The following attributes only need to be set when auth mode is uaa_auth

  104. uaa_endpoint = uaa.mydomain.org

  105. uaa_clientid = id

  106. uaa_clientsecret = secret

  107. uaa_verify_cert = true

  108. uaa_ca_cert = /path/to/ca.pem



  109. ### Docker Registry setting ###

  110. #registry_storage_provider can be: filesystem, s3, gcs, azure, etc.

  111. registry_storage_provider_name = filesystem

  112. #registry_storage_provider_config is a comma separated "key: value" pairs, e.g. "key1: value, key2: value2".

  113. #Refer to https://docs.docker.com/registry/configuration/#storage for all available configuration.

  114. registry_storage_provider_config =

配置文件docker-compose.yml

點(diǎn)擊(此處)折疊或打開

  1. version: '2'

  2. services:

  3.   log:

  4.     image: vmware/harbor-log:v1.4.0

  5.     container_name: harbor-log

  6.     restart: always

  7.     volumes:

  8.       - /mnt/harbor/log/:/var/log/docker/:z

  9.       - ./common/config/log/:/etc/logrotate.d/:z

  10.     ports:

  11.       - 127.0.0.1:1514:10514

  12.     networks:

  13.       - harbor

  14.   registry:

  15.     image: vmware/registry-photon:v2.6.2-v1.4.0

  16.     container_name: registry

  17.     restart: always

  18.     volumes:

  19.       - /mnt/harbor/registry:/storage:z

  20.       - ./common/config/registry/:/etc/registry/:z

  21.     networks:

  22.       - harbor

  23.     environment:

  24.       - GODEBUG=netdns=cgo

  25.     command:

  26.       ["serve", "/etc/registry/config.yml"]

  27.     depends_on:

  28.       - log

  29.     logging:

  30.       driver: "syslog"

  31.       options:

  32.         syslog-address: "tcp://127.0.0.1:1514"

  33.         tag: "registry"

  34.   mysql:

  35.     image: vmware/harbor-db:v1.4.0

  36.     container_name: harbor-db

  37.     restart: always

  38.     volumes:

  39.       - /mnt/harbor/database:/var/lib/mysql:z

  40.     networks:

  41.       - harbor

  42.     env_file:

  43.       - ./common/config/db/env

  44.     depends_on:

  45.       - log

  46.     logging:

  47.       driver: "syslog"

  48.       options:

  49.         syslog-address: "tcp://127.0.0.1:1514"

  50.         tag: "mysql"

  51.   adminserver:

  52.     image: vmware/harbor-adminserver:v1.4.0

  53.     container_name: harbor-adminserver

  54.     env_file:

  55.       - ./common/config/adminserver/env

  56.     restart: always

  57.     volumes:

  58.       - /mnt/harbor/config/:/etc/adminserver/config/:z

  59.       - /mnt/harbor/secretkey:/etc/adminserver/key:z

  60.       - /mnt/harbor/:/data/:z

  61.     networks:

  62.       - harbor

  63.     depends_on:

  64.       - log

  65.     logging:

  66.       driver: "syslog"

  67.       options:

  68.         syslog-address: "tcp://127.0.0.1:1514"

  69.         tag: "adminserver"

  70.   ui:

  71.     image: vmware/harbor-ui:v1.4.0

  72.     container_name: harbor-ui

  73.     env_file:

  74.       - ./common/config/ui/env

  75.     restart: always

  76.     volumes:

  77.       - ./common/config/ui/app.conf:/etc/ui/app.conf:z

  78.       - ./common/config/ui/private_key.pem:/etc/ui/private_key.pem:z

  79.       - ./common/config/ui/certificates/:/etc/ui/certificates/:z

  80.       - /mnt/harbor/secretkey:/etc/ui/key:z

  81.       - /mnt/harbor/ca_download/:/etc/ui/ca/:z

  82.       - /mnt/harbor/psc/:/etc/ui/token/:z

  83.     networks:

  84.       - harbor

  85.     depends_on:

  86.       - log

  87.       - adminserver

  88.       - registry

  89.     logging:

  90.       driver: "syslog"

  91.       options:

  92.         syslog-address: "tcp://127.0.0.1:1514"

  93.         tag: "ui"

  94.   jobservice:

  95.     image: vmware/harbor-jobservice:v1.4.0

  96.     container_name: harbor-jobservice

  97.     env_file:

  98.       - ./common/config/jobservice/env

  99.     restart: always

  100.     volumes:

  101.       - /mnt/harbor/job_logs:/var/log/jobs:z

  102.       - ./common/config/jobservice/app.conf:/etc/jobservice/app.conf:z

  103.       - /mnt/harbor/secretkey:/etc/jobservice/key:z

  104.     networks:

  105.       - harbor

  106.     depends_on:

  107.       - ui

  108.       - adminserver

  109.     logging:

  110.       driver: "syslog"

  111.       options:

  112.         syslog-address: "tcp://127.0.0.1:1514"

  113.         tag: "jobservice"

  114.   proxy:

  115.     image: vmware/nginx-photon:v1.4.0

  116.     container_name: nginx

  117.     restart: always

  118.     volumes:

  119.       - ./common/config/nginx:/etc/nginx:z

  120.     networks:

  121.       - harbor

  122.     ports:

  123.       - 80:80

  124.       - 443:443

  125.       - 4443:4443

  126.     depends_on:

  127.       - mysql

  128.       - registry

  129.       - ui

  130.       - log

  131.     logging:

  132.       driver: "syslog"

  133.       options:

  134.         syslog-address: "tcp://127.0.0.1:1514"

  135.         tag: "proxy"

  136. networks:

  137.   harbor:

  138.     external: false

安裝Harbor
./install.sh

可以使用docker-compose來管理Harbor的生命周期。 一些有用的命令列出如下:
docker-compose ps  查看
kubernetes中Harbor有什么用

docker-compose stop  停止
docker-compose start 啟動(dòng)
docker-compose down  刪除,利用./install.sh可以重新安裝

五:驗(yàn)證

1.碰到的問題

a. 錯(cuò)誤提示

點(diǎn)擊(此處)折疊或打開

  1. /usr/lib/python2.7/site-packages/requests/__init__.py:80: RequestsDependencyWarning: urllib3 (1.21.1) or chardet (2.2.1) doesn

原因:python庫中urllib3 (1.21.1) or chardet (2.2.1) 的版本不兼容
解決辦法:
pip uninstall urllib3
pip uninstall  chardet
pip install requests

b.錯(cuò)誤提示:“harbor failed to initialize the system: read /etc/adminserver/key: is a directory”
原因:harbor.cfg中的secretkey_path和docker-compose.yml中的設(shè)置不一致

2.ui 界面
kubernetes中Harbor有什么用

感謝你能夠認(rèn)真閱讀完這篇文章,希望小編分享的“kubernetes中Harbor有什么用”這篇文章對(duì)大家有幫助,同時(shí)也希望大家多多支持億速云,關(guān)注億速云行業(yè)資訊頻道,更多相關(guān)知識(shí)等著你來學(xué)習(xí)!

向AI問一下細(xì)節(jié)

免責(zé)聲明:本站發(fā)布的內(nèi)容(圖片、視頻和文字)以原創(chuàng)、轉(zhuǎn)載和分享為主,文章觀點(diǎn)不代表本網(wǎng)站立場(chǎng),如果涉及侵權(quán)請(qǐng)聯(lián)系站長(zhǎng)郵箱:is@yisu.com進(jìn)行舉報(bào),并提供相關(guān)證據(jù),一經(jīng)查實(shí),將立刻刪除涉嫌侵權(quán)內(nèi)容。

AI