apiVersion: data.packaging.carvel.dev/v1alpha1 kind: Package metadata: name: harbor.tanzu.vmware.com.2.8.2+vmware.2-tkg.1 spec: refName: harbor.tanzu.vmware.com version: 2.8.2+vmware.2-tkg.1 releasedAt: "2023-06-08T10:18:00Z" releaseNotes: harbor 2.8.2 https://github.com/goharbor/harbor/releases/tag/v2.8.2 licenses: - 'VMware''s End User License Agreement (Underlying OSS license: Apache License 2.0)' valuesSchema: openAPIv3: title: harbor.tanzu.vmware.com.2.8.2+vmware.2-tkg.1 values schema required: - harborAdminPassword - secretKey properties: namespace: type: string description: The namespace to install Harbor. default: tanzu-system-registry hostname: type: string description: The FQDN for accessing Harbor admin UI and Registry service. default: harbor.yourdomain.com port: type: object description: Port related configuration. properties: https: type: integer description: The network port of the Envoy service in Contour or other Ingress Controller. default: 443 logLevel: type: string description: The log level of core, exporter, jobservice, registry. default: info enum: - debug - info - warning - error - fatal tlsCertificate: type: object description: The tls certificate for the harbor FQDN. required: - tls.crt - tls.key - ca.crt properties: tls.crt: type: string description: The certificate. Note that tls.crt is a key and not nested. tls.key: type: string description: The private key. Note that tls.key is a key and not nested. ca.crt: type: string description: The certificate of CA, this enables the download, link on portal to download the certificate of CA. Note that ca.crt is a key and not nested. tlsSecretLabels: type: object description: the labels you want to add for the harbor-tls secret generated by the tlsCertificate tlsCertificateSecretName: type: string description: The name of the secret if you want to use your own TLS certificate for harbor FQDN, which contains keys named "tls.crt" and "tls.key". enableContourHttpProxy: type: boolean description: Use contour http proxy instead of the ingress when it's true. default: true contourHttpProxy: type: object description: The timeout policy configuration for httpproxy. properties: timeout: type: string description: Timeout for receiving a response from the server after processing a request from client. idleTimeout: type: string description: Timeout for how long the proxy should wait while there is no activity during single request/response (for HTTP/1.1) or stream (for HTTP/2). harborAdminPassword: type: string description: The initial password of Harbor admin. secretKey: type: string description: The secret key used for encryption. Must be a string of 16 chars. database: type: object description: Database component related configuration. required: - password properties: password: type: string description: The initial password of the postgres database. shmSizeLimit: type: integer description: The initial value of shmSizeLimit maxIdleConns: type: integer description: The initial value of maxIdleConns maxOpenConns: type: integer description: The initial value of maxOpenConns exporter: type: object description: The configuration related to exporter. properties: cacheDuration: type: integer description: The initial value of cacheDuration. core: type: object description: Core component related configuration. required: - secret - xsrfKey properties: replicas: type: integer description: The replicas for the core component. default: 1 secret: type: string description: Secret is used when core server communicates with other components. xsrfKey: type: string description: The XSRF key. Must be a string of 32 chars. jobservice: type: object description: Jobservice component related configuration. required: - secret properties: replicas: type: integer description: The replicas for the jobservice component. default: 1 secret: type: string description: Secret is used when job service communicates with other components. registry: type: object description: Registry component related configuration. required: - secret properties: replicas: type: integer description: The replicas for the registry component. default: 1 secret: type: string description: Secret is used to secure the upload state from client and registry storage backend. notary: type: object description: Notary component related configuration. properties: enabled: type: boolean description: Whether to install Notary default: true trivy: type: object description: Trivy component related configuration. properties: enabled: type: boolean description: Whether to install Trivy scanner. default: true replicas: type: integer description: The replicas for the trivy component. default: 1 gitHubToken: type: string description: the GitHub access token to download Trivy DB. default: "" skipUpdate: type: boolean description: The flag to disable Trivy DB downloads from GitHub. default: false offlineScan: type: boolean description: The offlineScan option prevents Trivy from sending API requests to identify dependencies. default: false timeout: type: string description: The timeout set for trivy scanner, it should be a number followed by a letter like "h", "m", "s", or "ms", i.e. 1h, 5m, 60s, 1000ms. default: "" persistence: type: object description: |- The persistence is always enabled and a default StorageClass is needed in the k8s cluster to provision volumes dynamically. Specify another StorageClass in the "storageClass" or set "existingClaim" if you have already existing persistent volumes to use For storing images and charts, you can also use "azure", "gcs", "s3", "swift" or "oss". Set it in the "imageChartStorage" section properties: persistentVolumeClaim: type: object description: PersistentVolumeClaim related configuration. properties: registry: type: object description: PersistentVolumeClaim related configuration for registry component. properties: existingClaim: type: string description: |- Use the existing PVC which must be created manually before bound, and specify the "subPath" if the PVC is shared with other components default: "" storageClass: type: string description: |- Specify the "storageClass" used to provision the volume. Or the default StorageClass will be used(the default). Set it to "-" to disable dynamic provisioning default: "" subPath: type: string description: The "subPath" if the PVC is shared with other components. default: "" accessMode: type: string description: Access mode of the PVC. default: ReadWriteOnce size: type: string description: Size of the PVC. default: 10Gi jobservice: type: object description: PersistentVolumeClaim related configuration for jobservice component. properties: jobLog: type: object description: PersistentVolumeClaim for jobservice log properties: existingClaim: type: string description: |- Use the existing PVC which must be created manually before bound, and specify the "subPath" if the PVC is shared with other components default: "" storageClass: type: string description: |- Specify the "storageClass" used to provision the volume. Or the default StorageClass will be used(the default). Set it to "-" to disable dynamic provisioning default: "" subPath: type: string description: The "subPath" if the PVC is shared with other components. default: "" accessMode: type: string description: Access mode of the PVC. default: ReadWriteOnce size: type: string description: Size of the PVC. default: 1Gi database: type: object description: PersistentVolumeClaim related configuration for database component. properties: existingClaim: type: string description: |- Use the existing PVC which must be created manually before bound, and specify the "subPath" if the PVC is shared with other components default: "" storageClass: type: string description: |- Specify the "storageClass" used to provision the volume. Or the default StorageClass will be used(the default). Set it to "-" to disable dynamic provisioning default: "" subPath: type: string description: The "subPath" if the PVC is shared with other components. default: "" accessMode: type: string description: Access mode of the PVC. default: ReadWriteOnce size: type: string description: Size of the PVC. default: 1Gi redis: type: object description: PersistentVolumeClaim related configuration for redis component. properties: existingClaim: type: string description: |- Use the existing PVC which must be created manually before bound, and specify the "subPath" if the PVC is shared with other components default: "" storageClass: type: string description: |- Specify the "storageClass" used to provision the volume. Or the default StorageClass will be used(the default). Set it to "-" to disable dynamic provisioning default: "" subPath: type: string description: The "subPath" if the PVC is shared with other components. default: "" accessMode: type: string description: Access mode of the PVC. default: ReadWriteOnce size: type: string description: Size of the PVC. default: 1Gi trivy: type: object description: PersistentVolumeClaim related configuration for redis component. properties: existingClaim: type: string description: |- Use the existing PVC which must be created manually before bound, and specify the "subPath" if the PVC is shared with other components default: "" storageClass: type: string description: |- Specify the "storageClass" used to provision the volume. Or the default StorageClass will be used(the default). Set it to "-" to disable dynamic provisioning default: "" subPath: type: string description: The "subPath" if the PVC is shared with other components. default: "" accessMode: type: string description: Access mode of the PVC. default: ReadWriteOnce size: type: string description: Size of the PVC. default: 5Gi imageChartStorage: type: object description: |- Define which storage backend is used for registry and chartmuseum to store images and charts. Refer to https://github.com/docker/distribution/blob/master/docs/configuration.md#storage for the detail. properties: disableredirect: type: boolean description: |- Specify whether to disable `redirect` for images and chart storage, for backends which not supported it (such as using minio for `s3` storage type), please disable it. To disable redirects, simply set `disableredirect` to `true` instead. Refer to https://github.com/docker/distribution/blob/master/docs/configuration.md#redirect for the detail. default: false type: type: string description: |- Specify the type of storage: "filesystem", "azure", "gcs", "s3", "swift", "oss" and fill the information needed in the corresponding section. The type must be "filesystem" if you want to use persistent volumes for registry and chartmuseum default: filesystem filesystem: type: object description: Filesystem storage related configuration. properties: rootdirectory: type: string description: The rootdirectory in filesystem. default: /storage azure: type: object description: Azure storage related configuration. required: - accountname - accountkey - container properties: accountname: type: string description: Account name of azure storage. default: accountname accountkey: type: string description: Account key of azure storage. default: base64encodedaccountkey container: type: string description: Container name of azure storage. default: containername realm: type: string description: Realm for azure storage. default: core.windows.net gcs: type: object required: - bucket - encodedkey properties: bucket: type: string description: Bucket name of gcs. default: bucketname encodedkey: type: string description: The base64 encoded json file which contains the key default: base64-encoded-json-key-file rootdirectory: type: string description: The rootdirectory in gcs. default: null chunksize: type: integer description: Check size for gcs. default: 5242880 s3: type: object required: - region - bucket properties: region: type: string description: Region of s3. default: us-west-1 bucket: type: string description: Bucket name of s3. default: bucketname accesskey: type: string description: Access key of s3. default: null secretkey: type: string description: Secret key of s3. default: null regionendpoint: type: string description: Region endpoint of s3, eg http://myobjects.local default: null encrypt: type: boolean description: Encrypt for s3. default: false keyid: type: string description: Keyid of s3. default: null secure: type: boolean description: Secure for s3. default: true skipverify: type: boolean description: skipverify for s3. default: false v4auth: type: boolean description: Use v4auth for s3 when it's true. default: true chunksize: type: integer description: Check size for s3. default: null rootdirectory: type: string description: The rootdirectory in s3. default: null storageclass: type: string description: Storage class of s3. default: STANDARD multipartcopychunksize: type: integer description: multi part copy chunk size of s3. default: null multipartcopymaxconcurrency: type: integer description: multi part copy max concurrency of s3. default: null multipartcopythresholdsize: type: integer description: multi part copy threshold size of s3. default: null swift: type: object description: Swift storage related configuration. required: - authurl - username - password - container properties: authurl: type: string description: Auth url of swift. default: https://storage.myprovider.com/v3/auth username: type: string description: Username of swift. default: username password: type: string description: Password of swift. default: password container: type: string description: Container of swift. default: containername region: type: string description: Region of swift. default: null tenant: type: string description: Tenant of swift. default: null tenantid: type: string description: Tenant id of swift. default: null domain: type: string description: Domain of swift. default: null domainid: type: string description: Domain id of swift. default: null trustid: type: string description: Trust id of swift. default: null insecureskipverify: type: boolean description: Ignore the cert verify when it's true. default: null chunksize: type: string description: Check size of swift, eg 5M. default: null prefix: type: string description: Prefix path of swift. default: null secretkey: type: string description: Secret key of swift. default: null accesskey: type: string description: Access key of swift. default: null authversion: type: string description: Auth version of swift. default: null endpointtype: type: string description: Endpoint type of swift, eg public. default: null tempurlcontainerkey: type: boolean description: Use temp url container key of swift when it's true. default: null tempurlmethods: type: string description: Temp url methods of swift. default: null oss: type: object description: OSS storage related configuration. required: - accesskeyid - accesskeysecret - region - bucket properties: accesskeyid: type: string description: Access key id of oss. default: accesskeyid accesskeysecret: type: string description: Access key secert of oss. default: accesskeysecret region: type: string description: Region of oss. default: regionname bucket: type: string description: Bucket name of oss. default: bucketname endpoint: type: string description: Endpoint of oss. default: null internal: type: boolean description: Use the internal endpoint when it's true. default: null encrypt: type: boolean description: Encrypt of oss. default: null secure: type: boolean description: Secure of oss. default: null chunksize: type: string description: Chunk size for the oss, eg 10M. default: null rootdirectory: type: string description: The rootdirectory in oss. default: null proxy: type: object description: The proxy related configuration. properties: httpProxy: type: string description: HTTP proxy URL. default: "" httpsProxy: type: string description: HTTPS proxy URL. default: "" noProxy: type: string description: Ignore proxy for the domains. default: 127.0.0.1,localhost,.local,.internal pspNames: type: string description: The PSP names used by Harbor pods. The names are separated by ','. 'null' means all PSP can be used. default: "null" caBundleSecretName: type: string description: The custom ca bundle secret, the secret must contain key named "ca.crt", which will be injected into the trust store for core, jobservice, registry, trivy components metrics: type: object description: The metrics used by core, registry and exporter properties: enabled: type: boolean description: Enable the metrics when it's true default: false core: type: object description: The core component related configuration. properties: path: type: string description: The path of the metrics. default: /metrics port: type: integer description: The port of the metrics. default: 8001 registry: type: object description: The registry component related configuration. properties: path: type: string description: The path of the metrics. default: /metrics port: type: integer description: The port of the metrics. default: 8001 jobservice: type: object description: The jobservice component related configuration. properties: path: type: string description: The path of the metrics. default: /metrics port: type: integer description: The port of the metrics. default: 8001 exporter: type: object description: The exporter component related configuration. properties: path: type: string description: The path of the metrics. default: /metrics port: type: integer description: The port of the metrics. default: 8001 network: type: object description: The network related configuration. properties: ipFamilies: type: array description: The array of network ipFamilies. Default [] is equivalent to have both ["IPv4","IPv6"]. Or you can choose one of ["IPv4"] or ["IPv6"] default: [] trace: type: object description: The tracing configuration for Harbor. properties: enabled: type: boolean description: Enable tracing for Harbor. default: false provider: type: string description: The provider type of tracing, jaeger or otel. default: jaeger sample_rate: type: number description: Set sample_rate to 1 if you wanna sampling 100% of trace data; set 0.5 if you wanna sampling 50% of trace data, and so forth. default: 1 namespace: type: string description: The namespace used to differentiate different harbor services. attributes: type: object description: The attributes is a key value dict contains user defined attributes used to initialize trace provider. jaeger: type: object description: Jaeger provider for Harbor tracing, it support two modes - collector mode & agent mode. properties: endpoint: type: string description: The endpoint of jaeger. default: http://hostname:14268/api/traces username: type: string description: The username of jaeger in collector mode. password: type: string description: The password of jaeger in collector mode. agent_host: type: string description: The agent_host of jaeger in agent mode. agent_port: type: integer description: The agent_port of jaeger in agent mode. otel: type: object description: Otel provider for Harbor tracing. properties: endpoint: type: string description: The endpoint of otel. default: hostname:4318 url_path: type: string description: The url path of tracing with Otel. default: /v1/traces compression: type: boolean description: Whether to set compression when enabling tracing with Otel. default: false insecure: type: boolean description: Whether to connect the collector insecurely. default: true timeout: type: integer description: The max waiting time for the backend to process each spans batch, in seconds. default: 10 cache: type: object description: The cache layer configurations for Harbor. properties: enabled: type: boolean description: Enable cache for Harbor. default: false expireHours: type: integer description: The expire hour of cache. default: 24 template: spec: fetch: - imgpkgBundle: image: projects.registry.vmware.com/tkg/packages/standard/harbor:v2.8.2_vmware.2-tkg.1 template: - ytt: paths: - config/ ignoreUnknownComments: true inline: paths: "config/networkpolicy.yaml": | #@ load("@ytt:data", "data") --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: harbor-app-network-policy namespace: #@ data.values.namespace spec: podSelector: matchLabels: app: harbor ingress: - {} - kbld: paths: - '-' - .imgpkg/images.yml deploy: - kapp: rawOptions: - --wait-timeout=5m - --kube-api-qps=20 - --kube-api-burst=30 --- apiVersion: data.packaging.carvel.dev/v1alpha1 kind: PackageMetadata metadata: name: harbor.tanzu.vmware.com spec: displayName: harbor iconSVGBase64:  longDescription: Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Harbor extends the open source Docker Distribution by adding the functionalities usually required by users such as security, identity and management. shortDescription: OCI Registry providerName: VMware maintainers: - name: Miner Yang - name: Daojun Zhang - name: Shengwen Yu categories: - OCI registry supportDescription: Support provided by VMware for deployment on Tanzu clusters. Best-effort support for deployment on any conformant Kubernetes cluster. Contact support by opening a support request via VMware Cloud Services or my.vmware.com.