Harbor私有镜像仓库部署指南

张开发
2026/4/3 23:39:53 15 分钟阅读
Harbor私有镜像仓库部署指南
Harbor镜像仓库部署下面一步需要翻墙用的1.8.0版本的harbor[rootkub-k8s-master ~]# wget https://storage.googleapis.com/harbor-releases/release-1.8.0/harbor-offline-installer-v1.8.0.tgz[rootkub-k8s-master ~]# curl -L https://github.com/docker/compose/releases/download/1.22.0/docker-compose-uname -s-uname -m -o /usr/local/bin/docker-compose我们选择了上传这两个软件包所以要更改名称移动路径[rootk8s-master ~]# mv docker-compose-Linux-x86_64 /usr/local/bin/docker-compose[rootkub-k8s-master ~]# chmod x /usr/local/bin/docker-compose[rootkub-k8s-master ~]# tar xf harbor-offline-installer-v1.8.0.tgz[rootkub-k8s-master ~]# cd harborhttp访问方式的配置[rootkub-k8s-master harbor]# vim harbor.yml #主机名要可以解析(需要部署dns服务器用/etc/hosts文件没有用)如果不可以解析可以使用IP地址,需要修改的内容如下hostname:192.168.246.166[rootkub-k8s-master harbor]# ./install.sh #需要等待下载镜像如果安装失败重启docker服务重新安装即可浏览器访问测试 http://192.168.246.166配置https访问[rootkub-k8s-master ~]# mkdir -p /data/cert/[rootkub-k8s-master ~]# cd /data/cert[rootkub-k8s-master cert]# openssl genrsa -out /data/cert/server.key 2048Generating RSA private key,2048bit long modulus........................................................ e is65537(0x10001)[rootkub-k8s-master cert]# openssl req -x509 -new -nodes -key /data/cert/server.key -subj /CN192.168.246.166 -days 3650 -out /data/cert/server.crt[rootkub-k8s-master ~]# ll -a /data/cert[rootkub-k8s-master ~]# cd /root/harbor[rootkub-k8s-master harbor]# vim harbor.yml #编辑如下重启[rootkub-k8s-master harbor]# ./prepareprepare basedirissetto /root/harbor Clearing the configuration file: /config/log/logrotate.conf Clearing the configuration file: /config/nginx/nginx.conf Clearing the configuration file: /config/core/env Clearing the configuration file: /config/core/app.conf Clearing the configuration file: /config/registry/config.yml Clearing the configuration file: /config/registry/root.crt Clearing the configuration file: /config/registryctl/env Clearing the configuration file: /config/registryctl/config.yml Clearing the configuration file: /config/db/env Clearing the configuration file: /config/jobservice/env Clearing the configuration file: /config/jobservice/config.yml Generated configuration file: /config/log/logrotate.conf Generated configuration file: /config/nginx/nginx.conf Generated configuration file: /config/core/env Generated configuration file: /config/core/app.conf Generated configuration file: /config/registry/config.yml Generated configuration file: /config/registryctl/env Generated configuration file: /config/db/env Generated configuration file: /config/jobservice/env Generated configuration file: /config/jobservice/config.yml loaded secret from file: /secret/keys/secretkey Generated configuration file: /compose_location/docker-compose.yml Clean up the inputdir如果出错重启Docker服务再次执行./prepare[rootkub-k8s-master harbor]# docker-compose downStopping nginx...doneStopping harbor-portal...doneStopping harbor-jobservice...doneStopping harbor-core...doneStopping harbor-db...doneStopping redis...doneStopping registryctl...doneStopping registry...doneStopping harbor-log...doneRemoving nginx...doneRemoving harbor-portal...doneRemoving harbor-jobservice...doneRemoving harbor-core...doneRemoving harbor-db...doneRemoving redis...doneRemoving registryctl...doneRemoving registry...doneRemoving harbor-log...doneRemoving network harbor_harbor[rootkub-k8s-master harbor]# docker-compose up -d #放后台访问客户端配置(每个访问harbor的机器上都要配置)在client上面操作[rootkub-k8s-node1 ~]# vim /etc/docker/daemon.json #编辑文件{insecure-registries:[192.168.246.166]#该ip为部署仓库机器的ip}[rootkub-k8s-node1 ~]# systemctl restart docker创建项目创建账号换gebeier用户登录查看项目授权再次使用gebeier用户登录测试1.登录[rootkub-k8s-node1 ~]# docker login 192.168.246.166Username: gebeier Password: Login Succeeded2.下载一个测试的镜像[rootkub-k8s-node1 ~]# docker pull daocloud.io/library/centos:73.查看[rootkub-k8s-node1 ~]# docker imagesREPOSITORY TAG IMAGE ID CREATED SIZE daocloud.io/library/centos798ebf73aba753months ago 109MB4.打个tag[rootkub-k8s-node1 ~]# docker tag daocloud.io/library/centos:7 192.168.91.140/centos/centos:7.45.上传到仓库[rootkub-k8s-node1 ~]# docker push 192.168.91.140/centos/centos:7.4在web界面中查看镜像是否被上传到仓库中拉取测试来到node2[rootk8s-node2 ~]# cat /etc/docker/daemon.json{insecure-registries:[192.168.246.166]}[rootk8s-node2 ~]# systemctl restart docker[rootk8s-node2 ~]# docker login 192.168.246.166 --usernamegebeier --password***[rootk8s-node2 ~]# 192.168.91.140/centos/centos:7.4ker login 192.168.246.166 --username‘gebeier’ --password‘***’[外链图片转存中...(img-fhDq6fLR-1775092352362)] shell [rootk8s-node2 ~]# 192.168.91.140/centos/centos:7.4

更多文章