<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>harbor Archives - OVHcloud Blog</title>
	<atom:link href="https://blog.ovhcloud.com/tag/harbor/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.ovhcloud.com/tag/harbor/</link>
	<description>Innovation for Freedom</description>
	<lastBuildDate>Tue, 23 Jun 2020 16:17:36 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://blog.ovhcloud.com/wp-content/uploads/2019/07/cropped-cropped-nouveau-logo-ovh-rebranding-32x32.gif</url>
	<title>harbor Archives - OVHcloud Blog</title>
	<link>https://blog.ovhcloud.com/tag/harbor/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Celebrating Harbor joining the restricted list of CNCF Graduated projects</title>
		<link>https://blog.ovhcloud.com/celebrating-harbor-joining-the-restricted-list-of-cncf-graduated-projects/</link>
		
		<dc:creator><![CDATA[Maxime Hurtrel]]></dc:creator>
		<pubDate>Tue, 23 Jun 2020 16:17:35 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cloud-native]]></category>
		<category><![CDATA[CNCF]]></category>
		<category><![CDATA[harbor]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Public Cloud]]></category>
		<category><![CDATA[registry]]></category>
		<guid isPermaLink="false">https://www.ovh.com/blog/?p=18582</guid>

					<description><![CDATA[A couple of months ago, one year after the general availability of our Managed Kubernetes Service, we launched Managed Private Registry service. We shared in a previous blog post why we chose to base it on the CNCF Harbor project . Two OVHcloud employees became project maintainers. We now have a new event to celebrate: [&#8230;]<img src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2Fcelebrating-harbor-joining-the-restricted-list-of-cncf-graduated-projects%2F&amp;action_name=Celebrating%20Harbor%20joining%20the%20restricted%20list%20of%20CNCF%20Graduated%20projects&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-image"><figure class="aligncenter size-large"><img fetchpriority="high" decoding="async" width="1024" height="537" src="https://www.ovh.com/blog/wp-content/uploads/2020/06/ABB4DF92-271C-4A3A-A0C8-5AB4C03EAA2C-1024x537.jpeg" alt="Celebrating Harbor joining the restricted list of CNCF Graduated projects" class="wp-image-18590" srcset="https://blog.ovhcloud.com/wp-content/uploads/2020/06/ABB4DF92-271C-4A3A-A0C8-5AB4C03EAA2C-1024x537.jpeg 1024w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/ABB4DF92-271C-4A3A-A0C8-5AB4C03EAA2C-300x157.jpeg 300w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/ABB4DF92-271C-4A3A-A0C8-5AB4C03EAA2C-768x403.jpeg 768w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/ABB4DF92-271C-4A3A-A0C8-5AB4C03EAA2C.jpeg 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>A couple of months ago, one year after the general availability of our Managed Kubernetes Service, we launched <a href="https://www.ovh.com/blog/managing-harbor-at-cloud-scale-the-story-behind-harbor-kubernetes-operator/" data-wpel-link="exclude">Managed Private Registry service</a>. We shared in a <a href="https://www.ovh.com/blog/managing-harbor-at-cloud-scale-the-story-behind-harbor-kubernetes-operator/" data-wpel-link="exclude">previous blog post why we chose to base it on the CNCF Harbor project</a> . Two OVHcloud employees became project maintainers. We now have a new event to celebrate: the Cloud-Native Computing Foundation just announced that Harbor joined the very restricted list of &#8220;Graduated&#8221; projects.</p>



<h2 class="wp-block-heading">CNCF Graduation : The Ultimate Maturity Level</h2>



<p>The CNCF hosts a few dozen open-source projects and does an excellent job offering those projects support for growth, both in terms of infrastructure and tools, but also community and awareness. However most of these projects are living in &#8220;the CNCF Sandbox&#8221; or the &#8220;Incubating&#8221; stage. There are currently only 11 projects that have &#8220;graduated&#8221;, including Kubernetes, Prometheus and Helm. Harbor is now the latest one to receive this great badge of recognition.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" width="1024" height="330" src="https://www.ovh.com/blog/wp-content/uploads/2020/06/F5E8A3FA-29D3-475D-9E92-30A0A0B586D7-e1592925697272-1024x330.jpeg" alt="CNCF" class="wp-image-18592" srcset="https://blog.ovhcloud.com/wp-content/uploads/2020/06/F5E8A3FA-29D3-475D-9E92-30A0A0B586D7-e1592925697272-1024x330.jpeg 1024w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/F5E8A3FA-29D3-475D-9E92-30A0A0B586D7-e1592925697272-300x97.jpeg 300w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/F5E8A3FA-29D3-475D-9E92-30A0A0B586D7-e1592925697272-768x248.jpeg 768w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/F5E8A3FA-29D3-475D-9E92-30A0A0B586D7-e1592925697272.jpeg 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>Each level reflects the completion of very specific maturity characteristics<a href="https://www.cncf.io/projects/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">, </a>enforced and validated by the CNCF Technical Oversight Committee. To graduate, Harbor for example has demonstrated that it has active committers from multiple organizations. It went through exhaustive and independent security audits and has fully transparent governance. Harbor also received a<a href="https://bestpractices.coreinfrastructure.org/fr/projects?q=harbor" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer"> CII best practices badge</a>.</p>



<h2 class="wp-block-heading">OVHcloud Proudly Democratizing Harbor</h2>



<p>Many enterprise-grade organizations already adopted Harbor as a part of commercial containerization platforms. They usually deploy and operate it on premise or in the cloud. If skeptics wanted a last sign to adopt Harbor, it has come&#8230; and OVHcloud is very proud to help make Harbor even simpler!</p>



<p>With our totally <a href="https://www.ovhcloud.com/en-ie/public-cloud/managed-private-registry/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">managed service</a>, any OVHcloud user can benefit from a dedicated, highly available and full-featured Harbor. We offer totally predictable costs and enterprise-grade features that many cloud registries on the market lack. Those not yet ready to embrace the cloud will also benefit from our donation of <a href="https://goharbor.io/blog/introducing-the-harbor-operator/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">what became the official Harbor Kubernetes operator </a>to facilitate self-deployment and lifecycle in specific environments.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" width="1024" height="637" src="https://www.ovh.com/blog/wp-content/uploads/2020/06/54D0BF0A-0044-4374-8263-9EA95A2A2447-1024x637.jpeg" alt="" class="wp-image-18596" srcset="https://blog.ovhcloud.com/wp-content/uploads/2020/06/54D0BF0A-0044-4374-8263-9EA95A2A2447-1024x637.jpeg 1024w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/54D0BF0A-0044-4374-8263-9EA95A2A2447-300x187.jpeg 300w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/54D0BF0A-0044-4374-8263-9EA95A2A2447-768x478.jpeg 768w, https://blog.ovhcloud.com/wp-content/uploads/2020/06/54D0BF0A-0044-4374-8263-9EA95A2A2447.jpeg 1177w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<h2 class="wp-block-heading">More for our current and future managed registry users!</h2>



<p>Because we want you to celebrate with us, we are announcing today even more generous plans for our Managed Private Registry:</p>



<ul class="wp-block-list"><li>the &#8220;M&#8221; plan, ideal for medium-sized software companies or business units in large organizations; now includes vulnerability scanning</li><li>the &#8220;L&#8221; plan can now host up to 5 TB of your artifacts (container layers, Helm charts, etc.)</li></ul>



<p>Prices and other characteristics are unchanged, making the service one of the most interesting enterprise-grade registry services on the market. All existing and future customers automatically benefit from these improvements. The public pricing page will be updated soon. Of course, as with most OVHcloud products, the ingress and egress traffic remain unlimited and at no charge.</p>



<p><a href="https://www.ovhcloud.com/en-ie/public-cloud/managed-private-registry/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Currently exposing the very stable Harbor 1.10</a>, our container team already has plans to move to Harbor 2.0.</p>



<p>See you at the Kubecon Europe and OVHcloud summit later this year!</p>
<img loading="lazy" decoding="async" src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2Fcelebrating-harbor-joining-the-restricted-list-of-cncf-graduated-projects%2F&amp;action_name=Celebrating%20Harbor%20joining%20the%20restricted%20list%20of%20CNCF%20Graduated%20projects&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Managing Harbor at cloud scale : The story behind Harbor Kubernetes Operator</title>
		<link>https://blog.ovhcloud.com/managing-harbor-at-cloud-scale-the-story-behind-harbor-kubernetes-operator/</link>
		
		<dc:creator><![CDATA[Maxime Hurtrel]]></dc:creator>
		<pubDate>Tue, 17 Mar 2020 15:18:11 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CNCF]]></category>
		<category><![CDATA[containers]]></category>
		<category><![CDATA[Docker]]></category>
		<category><![CDATA[harbor]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Public Cloud]]></category>
		<category><![CDATA[registry]]></category>
		<guid isPermaLink="false">https://www.ovh.com/blog/?p=17509</guid>

					<description><![CDATA[Recently, our container platforms team made our &#8220;Private Managed Registry&#8221; service generally available. In this blog post, we will explain why OVHcloud chose to base this service on the Harbor project, built a Kubernetes operator for it, and open sourced it under the CNCF goharbor project. The need for a S.M.A.R.T private registry After our [&#8230;]<img src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2Fmanaging-harbor-at-cloud-scale-the-story-behind-harbor-kubernetes-operator%2F&amp;action_name=Managing%20Harbor%20at%20cloud%20scale%20%3A%20The%20story%20behind%20Harbor%20Kubernetes%20Operator&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></description>
										<content:encoded><![CDATA[
<p>Recently, our container platforms team made our <a href="https://www.ovhcloud.com/en-ie/public-cloud/managed-private-registry/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer"> &#8220;Private Managed Registry&#8221; service </a> generally available. In this blog post, we will explain why OVHcloud chose to base this service on the Harbor project, built a Kubernetes operator for it, and open sourced it under the CNCF goharbor project.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.ovh.com/blog/wp-content/uploads/2020/03/7E235649-EEE8-4D3A-ABF7-0A1D6D93942F-1024x537.png" alt="" class="wp-image-17604" width="512" height="269" srcset="https://blog.ovhcloud.com/wp-content/uploads/2020/03/7E235649-EEE8-4D3A-ABF7-0A1D6D93942F-1024x537.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2020/03/7E235649-EEE8-4D3A-ABF7-0A1D6D93942F-300x157.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2020/03/7E235649-EEE8-4D3A-ABF7-0A1D6D93942F-768x403.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2020/03/7E235649-EEE8-4D3A-ABF7-0A1D6D93942F.png 1200w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure></div>



<h2 class="wp-block-heading"><strong>The need for a</strong><a href="https://www.ovhcloud.com/en-ie/about-us/who-are/#text-media-4-2" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer"><strong> </strong><strong>S.M.A.R.T</strong></a><strong> </strong><strong>private registry</strong></h2>



<p>After our<a href="https://www.ovhcloud.com/en-ie/public-cloud/kubernetes/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer"> Managed Kubernetes Service release</a>, we received many requests&nbsp; for a fully managed private container registry.</p>



<p>Though a container registry for hosting images may sound quite trivial to deploy, our users mentioned a production-grade registry solution was a critical part of the software delivery supply chain and was actually quite difficult to maintain.</p>



<p>Our customers were asking for an enterprise-grade solution, offering advanced role-based-access-control and security by design, as concerns around vulnerabilities within the publicly available images increased and requirements for content-trust became a necessity.</p>



<p>Users were regularly praising the user interface of services such as the Docker Hub, but at the same time requested a service with high availability and backed by SLA.</p>



<h2 class="wp-block-heading"><strong>The perfect mix of open source and enterprise-grade feature set</strong></h2>



<p>After surveying prospects to fine tune our feature set and pricing model, we searched for the best existing technologies to back it and landed on the<a href="http://goharbor.io" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer"> CNCF incubating project Harbor</a> (donated to the CNCF by VMWare). In addition to Harbor being one of the few projects to reach CNCF incubation state, thus confirming the strong commitment from the community, it has as well become a key part of several commercial enterprise containerization solutions. We also appreciated the approach taken by Harbor of not re-inventing the wheel but gluing best-of-breed technologies for components such as vulnerability scanning, content trust and many others. It leverages CNCF’s strong network of open source projects and ensures great UX quality levels.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="537" height="188" src="https://www.ovh.com/blog/wp-content/uploads/2020/03/B2CA67EE-44B7-4B1A-BA6E-EB3D328F96B2.png" alt="" class="wp-image-17601" srcset="https://blog.ovhcloud.com/wp-content/uploads/2020/03/B2CA67EE-44B7-4B1A-BA6E-EB3D328F96B2.png 537w, https://blog.ovhcloud.com/wp-content/uploads/2020/03/B2CA67EE-44B7-4B1A-BA6E-EB3D328F96B2-300x105.png 300w" sizes="auto, (max-width: 537px) 100vw, 537px" /></figure></div>



<p>It was now the time to take this 10k-GitHub-stars technology and adapt it to our specific case : managing tens of thousands of registries for our users, each of them having specific volume of container images and usage patterns.</p>



<p>Of course high-availability (customers&#8217;s software integration and deployment rely on this service) but also data durability were non-negotiable for us.</p>



<p>In addition, Kubernetes to ensure stateless services HA and object storage (based on Openstack Swift and<a href="https://www.ovh.com/blog/ovhcloud-object-storage-clusters-support-s3-api/" data-wpel-link="exclude"> compatible with the S3 API</a>) were evident choices to check those requirements.</p>



<h2 class="wp-block-heading"><strong>Addressing&nbsp; operational challenges at the cloud-provider scale</strong></h2>



<p>Within a few weeks, we opened the service in public beta, quickly attracting hundreds of active users. But with this surge in traffic, we naturally hit our first bottlenecks and performance challenges.</p>



<p>We approached the Harbor user group and team who kindly pointed us to potential solutions, and after some small but key changes to how Harbor handles database connections our issues were resolved. This reinforced our beliefs that the Harbor community is strong and committed to the health of the project and the requirements of its users.</p>



<p>As our service flourished there was no real tooling available to easily accommodate the life-cycle of Harbor instances. Our commitment to the Kubernetes ecosystem made the concept of a Harbor operator for Kubernetes an interesting approach.</p>



<p>We discussed with the Harbor maintainers and they warmly welcomed our idea to develop it, and open source it as the official Harbor Kubernetes Operator. OVHcloud is very proud to have the project now available in the <a href="https://goharbor.io/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">goharbor</a> GitHub project under Apache 2 licensing. This project is another example of our strong commitment towards open source and our willingness to contribute our efforts back to the projects that we love.</p>



<h2 class="wp-block-heading"><strong>A versatile operator designed to accommodate any Harbor deployment</strong></h2>



<p>Readers familiar with the Harbor project may wonder what value this operator brings to the current catalogue of deployments including the Helm Chart version maintained by the project.</p>



<p>The operator design pattern is quickly catching on and mimics an application-centric controller that extends Kubernetes to manage more complex, stateful apps.&nbsp; Simply put, It addresses different use-cases than those of Helm. Whereas the Helm chart offers an all-in-one installer that would also deploy the different dependencies of Harbor (database, cache, etc) from open source Docker images,other enterprises, service operators and cloud providers like us will want to pick-and-choose the service or technology behind those components.</p>



<p>We also aim at extending the current v0.5&nbsp; operator to manage the full life-cycle of Harbor, from deployment to deletion, including scaling, updates, upgrades, and backup management.</p>



<p>This will help production users reach their target SLO, benefit from managed solutions or from existing databases clusters they already maintain for example.</p>



<p>We designed the operator (leveraging the OperatorSDK framework) so that both Harbor optional modules (Helm Chart store, vulnerability scanner etc) and dependencies (registry storage backend, relation and non relational databases, etc) can easily match your specific use case.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="887" src="https://www.ovh.com/blog/wp-content/uploads/2020/03/69A12D7F-A2B3-45B3-87DB-3A942BC529E4-1024x887.png" alt="" class="wp-image-17611" srcset="https://blog.ovhcloud.com/wp-content/uploads/2020/03/69A12D7F-A2B3-45B3-87DB-3A942BC529E4-1024x887.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2020/03/69A12D7F-A2B3-45B3-87DB-3A942BC529E4-300x260.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2020/03/69A12D7F-A2B3-45B3-87DB-3A942BC529E4-768x665.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2020/03/69A12D7F-A2B3-45B3-87DB-3A942BC529E4.png 1495w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption> Simplified architecture behind OVHcloud&#8217;d Managed Private Registry service </figcaption></figure></div>



<h2 class="wp-block-heading"><strong>Contributing to Harbor and the operator project</strong></h2>



<p>We already have a roadmap planned with the Harbor maintainers to further enrich the operator to accommodate more than the deployment and destruction phases (for example making Harbor version upgrades more elegant). We look forward to being an integral part of the project and will continue investing in Harbor.</p>



<p>To that end, Jérémie Monsinjon and Pierre Peronnet have also been invited to be&nbsp; maintainers of the Harbor project focusing on <a href="https://github.com/goharbor/harbor-operator" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">goharbor/operator</a> .</p>



<p>In addition to regular contributions to multiple projects we use within OVHcloud, the container-platform team is also working on other major open sources releases, like an official OVHcloud cloud controller for self-managed Kubernetes we plan to deliver in late 2020.</p>



<p></p>



<p>Download Harbor or the Harbor Operator :<a href="http://www.github.com/goharbor" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer"> Official Harbor Github repo</a></p>



<p>Learn more about Harbor : <a href="http://goharbor.io" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer"> Official Harbor website</a></p>
<img loading="lazy" decoding="async" src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2Fmanaging-harbor-at-cloud-scale-the-story-behind-harbor-kubernetes-operator%2F&amp;action_name=Managing%20Harbor%20at%20cloud%20scale%20%3A%20The%20story%20behind%20Harbor%20Kubernetes%20Operator&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
