赞
踩
平时经常用Docker来部署各种环境,发现从DockerHub上下载镜像有时候比较慢。第三方的镜像还可以使用一些国内的镜像仓库来加速,如果我们自己构建的镜像那就不行了。这时候搭建一个私有的镜像仓库很有必要,最近发现Harbor这个企业级镜像仓库,非常好用且功能强大,推荐给大家!
Harbor是一款开源的Docker镜像仓库服务,在Github上目前有13.4k+Star。提供了基于角色的镜像访问机制,可以保护你的镜像安全。
学习开源项目的第一步,一般都是把它运行起来,我们先来把Harbor运行起来吧!
tar xvf harbor-offline-installer-v1.10.6.tgz复制代码
[root@linux-local harbor]# lltotal 700260drwxr-xr-x. 3 root root 20 Dec 2 11:18 common-rw-r--r--. 1 root root 3398 Nov 17 11:58 common.sh-rw-r--r--. 1 root root 5348 Dec 2 14:41 docker-compose.yml-rw-r--r--. 1 root root 717021676 Nov 17 11:59 harbor.v1.10.6.tar.gz-rw-r--r--. 1 root root 5882 Dec 2 11:21 harbor.yml-rwxr-xr-x. 1 root root 2284 Nov 17 11:58 install.sh-rw-r--r--. 1 root root 11347 Nov 17 11:58 LICENSE-rwxr-xr-x. 1 root root 1749 Nov 17 11:58 prepare复制代码
# 指定Harbor的管理界面及镜像仓库访问地址hostname: 192.168.3.101# http相关配置http: # http端口,如果配置了https,默认使用https port: 80# https相关配置#https:# # https端口# port: 443# # 指定Habor中Nginx的https的证书和私钥地址# certificate: /your/certificate/path# private_key: /your/private/key/path# Harbor默认管理员账号admin的密码harbor_admin_password: Harbor12345# Harbor内置PostgreSQL数据库配置database: # root用户密码 password: root123 # 最大空闲连接数,小于等于0表示无空闲连接 max_idle_conns: 50 # 最大连接数,小于等于0表示无限制 max_open_conns: 100# 默认数据目录data_volume: /data# Clair configurationclair: # The interval of clair updaters, the unit is hour, set to 0 to disable the updaters. updaters_interval: 12jobservice: # Maximum number of job workers in job service max_job_workers: 10notification: # Maximum retry count for webhook job webhook_job_max_retry: 10chart: # Change the value of absolute_url to enabled can enable absolute url in chart absolute_url: disabled# 日志配置log: # 日志级别配置: debug, info, warning, error, fatal level: info # 日志本地存储策略 local: # 日志文件滚动数量,超过该数量会删除日志文件 rotate_count: 50 # 日志滚动大小,超过该大小会生成新的日志文件 rotate_size: 200M # 日志存储路径 location: /var/log/harbor# This attribute is for migrator to detect the version of the .cfg file, DO NOT MODIFY!_version: 1.10.0# Configure proxies to be used by Clair, the replication jobservice, and Harbor. Leave blank if no proxies are required.proxy: http_proxy: https_proxy: # no_proxy endpoints will appended to 127.0.0.1,localhost,.local,.internal,log,db,redis,nginx,core,portal,postgresql,jobservice,registry,registryctl,clair,chartmuseum,notary-server no_proxy: components: - core - jobservice - clair复制代码
./install.sh复制代码
[Step 0]: checking if docker is installed ...Note: docker version: 19.03.5[Step 1]: checking docker-compose is installed ...Note: docker-compose version: 1.24.0[Step 2]: loading Harbor images ...Loaded image: goharbor/harbor-migrator:v1.10.6Loaded image: goharbor/harbor-core:v1.10.6Loaded image: goharbor/harbor-db:v1.10.6Loaded image: goharbor/harbor-registryctl:v1.10.6Loaded image: goharbor/nginx-photon:v1.10.6Loaded image: goharbor/clair-photon:v1.10.6Loaded image: goharbor/clair-adapter-photon:v1.10.6Loaded image: goharbor/harbor-portal:v1.10.6Loaded image: goharbor/harbor-log:v1.10.6Loaded image: goharbor/registry-photon:v1.10.6Loaded image: goharbor/notary-signer-photon:v1.10.6Loaded image: goharbor/harbor-jobservice:v1.10.6Loaded image: goharbor/redis-photon:v1.10.6Loaded image: goharbor/prepare:v1.10.6Loaded image: goharbor/notary-server-photon:v1.10.6Loaded image: goharbor/chartmuseum-photon:v1.10.6[Step 3]: preparing environment ...[Step 4]: preparing harbor configs ...prepare base dir is set to /mydata/harbor/harborWARNING:root:WARNING: HTTP protocol is insecure. Harbor will deprecate http protocol in the future. Please make sure to upgrade to httpsClearing the configuration file: /config/log/logrotate.confClearing the configuration file: /config/log/rsyslog_docker.confClearing the configuration file: /config/nginx/nginx.confClearing the configuration file: /config/core/envClearing the configuration file: /config/core/app.confClearing the configuration file: /config/registry/config.ymlClearing the configuration file: /config/registry/root.crtClearing the configuration file: /config/registryctl/envClearing the configuration file: /config/registryctl/config.ymlClearing the configuration file: /config/db/envClearing the configuration file: /config/jobservice/envClearing the configuration file: /config/jobservice/config.ymlGenerated configuration file: /config/log/logrotate.confGenerated configuration file: /config/log/rsyslog_docker.confGenerated configuration file: /config/nginx/nginx.confGenerated configuration file: /config/core/envGenerated configuration file: /config/core/app.confGenerated configuration file: /config/registry/config.ymlGenerated configuration file: /config/registryctl/envGenerated configuration file: /config/db/envGenerated configuration file: /config/jobservice/envGenerated configuration file: /config/jobservice/config.ymlloaded secret from file: /secret/keys/secretkeyGenerated configuration file: /compose_location/docker-compose.ymlClean up the input dirNote: stopping existing Harbor instance ...Stopping harbor-jobservice ... doneStopping harbor-core ... doneStopping redis ... doneStopping registryctl ... doneStopping registry ... doneStopping harbor-db ... doneStopping harbor-portal ... doneStopping harbor-log ... doneRemoving harbor-jobservice ... doneRemoving harbor-core ... doneRemoving redis ... doneRemoving registryctl ... doneRemoving registry ... doneRemoving harbor-db ... doneRemoving harbor-portal ... doneRemoving harbor-log ... doneRemoving network harbor_harbor[Step 5]: starting Harbor ...Creating network "harbor_harbor" with the default driverCreating harbor-log ... doneCreating harbor-portal ... doneCreating registry ... doneCreating harbor-db ... doneCreating registryctl ... doneCreating redis ... doneCreating harbor-core ... doneCreating harbor-jobservice ... doneCreating nginx ... done✔ ----Harbor has been installed and started successfully.----复制代码
REPOSITORY TAG IMAGE ID CREATED SIZE latest dc3bacd8b5ea 8 days ago 1.23MBgoharbor/chartmuseum-photon v1.10.6 01b70eccaf71 2 weeks ago 178MBgoharbor/harbor-migrator v1.10.6 a5d4a4ee44e4 2 weeks ago 356MBgoharbor/redis-photon v1.10.6 99e25b65195c 2 weeks ago 132MBgoharbor/clair-adapter-photon v1.10.6 aa72598ecc12 2 weeks ago 61.3MBgoharbor/clair-photon v1.10.6 da1b03030e34 2 weeks ago 171MBgoharbor/notary-server-photon v1.10.6 37c8bed3e255 2 weeks ago 142MBgoharbor/notary-signer-photon v1.10.6 c56d82220929 2 weeks ago 139MBgoharbor/harbor-registryctl v1.10.6 1d3986d90c65 2 weeks ago 101MBgoharbor/registry-photon v1.10.6 3e669c8204ed 2 weeks ago 83.7MBgoharbor/nginx-photon v1.10.6 a39d8dd46060 2 weeks ago 43.7MBgoharbor/harbor-log v1.10.6 1085d3865a57 2 weeks ago 106MBgoharbor/harbor-jobservice v1.10.6 aa05538acecf 2 weeks ago 143MBgoharbor/harbor-core v1.10.6 193e76e6be5d 2 weeks ago 129MBgoharbor/harbor-portal v1.10.6 942a9c448850 2 weeks ago 51.8MBgoharbor/harbor-db v1.10.6 37da2e5414ae 2 weeks ago 170MBgoharbor/prepare v1.10.6 35f073e33ec5 2 weeks ago 177MB复制代码
接下来我们就可以使用Harbor来管理我们的镜像了。
vi /etc/docker/daemon.json复制代码
{ "registry-mirrors":["https://xxx.aliyuncs.com"], "insecure-registries":["192.168.3.101:80"]}复制代码
systemctl restart docker复制代码
./install.sh复制代码
[root@linux-local harbor]# docker login 192.168.3.101:80Username: adminPassword: WARNING! Your password will be stored unencrypted in /root/.docker/config.json.Configure a credential helper to remove this warning. Seehttps://docs.docker.com/engine/reference/commandline/login/#credentials-storeLogin Succeeded复制代码
FROM busybox:latest复制代码
docker build -t 192.168.3.101:80/test/busybox .复制代码
docker push 192.168.3.101:80/test/busybox复制代码
# 停止Harbordocker-compose stop# 启动Harbordocker-compose start复制代码
这里使用之前的mall-tiny-fabric项目来演示下,如何使用Maven插件一键打包并推送到Harbor镜像仓库。
io.fabric8 docker-maven-plugin 0.33.0build-imagepackagebuildhttp://192.168.3.101:2375http://192.168.3.101:80adminHarbor12345192.168.3.101:80/mall-tiny/${project.name}:${project.version}java:8${project.build.finalName}.jar/artifact["java", "-jar","/${project.build.finalName}.jar"]macrozheng${project.artifactId}8080:8080mysql:db /etc/localtime:/etc/localtime/mydata/app/${project.artifactId}/logs:/var/logs复制代码
[INFO] Scanning for projects...[INFO] [INFO] ------------------------------------------------------------------------[INFO] Building mall-tiny-fabric 0.0.1-SNAPSHOT[INFO] ------------------------------------------------------------------------[INFO] [INFO] --- docker-maven-plugin:0.33.0:push (default-cli) @ mall-tiny-fabric ---[INFO] DOCKER> The push refers to repository [192.168.3.101:80/mall-tiny/mall-tiny-fabric]###############[INFO] DOCKER> 0.0.1-SNAPSHOT: digest: sha256:3a54682fd3b04526f6da0916e98f3d0d5ba4193a8ad6aafbe6c05a1badf6c13b size: 2212[INFO] DOCKER> Temporary image tag skipped. Target image '192.168.3.101:80/mall-tiny/mall-tiny-fabric:0.0.1-SNAPSHOT' already has registry set or no registry is available[INFO] DOCKER> Pushed 192.168.3.101:80/mall-tiny/mall-tiny-fabric:0.0.1-SNAPSHOT in 2 minutes and 8 seconds [INFO] ------------------------------------------------------------------------[INFO] BUILD SUCCESS[INFO] ------------------------------------------------------------------------[INFO] Total time: 02:11 min[INFO] Finished at: 2020-12-02T15:11:10+08:00[INFO] Final Memory: 19M/219M[INFO] ------------------------------------------------------------------------Process finished with exit code 0复制代码
Harbor提供了管理界面让我们可以更方便地管理Docker镜像,同时添加了基于角色的权限管理功能来保护镜像的安全。之前我们为了安全地使用镜像,需要使用繁琐的TLS来控制远程Docker服务打包镜像,具体参考《Docker服务开放了这个端口,服务器分分钟变肉机!》。现在我们只要搭建一个Harbor镜像仓库,然后本地打包好镜像上传到Harbor,需要使用镜像的时候直接从Harbor下载即可!
作者:MacroZheng
链接:https://juejin.cn/post/6907022706689245198
来源:掘金
著作权归作者所有。商业转载请联系作者获得授权,非商业转载请注明出处。
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。