Harbor

Harbor

CNCF-graduated container registry that stores, scans and signs OCI images. RBAC, replication and audit logging ship in the free Apache core with no paid tier. Runs as a multi-service stack, so weigh the operational weight.

🩺 Vitals

What do these metrics mean?
  • Last active: when code was last pushed, as of our last check. The dot is green when that was recent, grey otherwise. A long gap can mean a tool is finished and stable, not only unmaintained.
  • Latest release: the most recent tagged, packaged version the maintainers published. Not every healthy project tags releases.
  • Open issues: unresolved reports and requests. A high number is normal for a popular project and is not a warning on its own.
  • Stars: how many people bookmarked the project on its forge. A rough popularity signal, not a measure of quality.

πŸ—οΈ Profile

1. The Executive Summary

What is it? Harbor is a self-hosted registry for container images and OCI artifacts that adds the governance layer a bare registry lacks: role-based access control, vulnerability scanning, image signing, replication and audit logging. Any OCI-compatible client pushes images to Harbor, which stores, scans and signs them before they reach production. As a CNCF Graduated project under the Linux Foundation, it is vendor-neutral, and every one of those capabilities ships in the free Apache-licensed core with no enterprise edition to buy.

The Strategic Verdict:

2. The "Hidden" Costs (TCO Analysis)

Cost Component JFrog Artifactory (Commercial) Harbor (Self-Hosted)
Licensing Per-tier enterprise subscription None (Apache 2.0)
Scanning & Signing Higher-tier feature Included (Trivy, Cosign/Notation)
SSO, RBAC & Replication Enterprise tier Included

3. The "Day 2" Reality Check

πŸš€ Deployment & Operations

πŸ›‘οΈ Security & Governance (Risk Assessment)

4. Market Landscape

🏒 Proprietary Incumbents

🀝 Open Source Ecosystem