Back to Artifact Registries

Harbor

Open-source cloud-native registry for storing, signing, and scanning container images.

Free and open-source (Apache 2.0)

Harbor is a CNCF graduated open-source container registry that stores, signs, and scans container images. Features: vulnerability scanning (Trivy), RBAC, image replication, OIDC/LDAP authentication, notary-based image signing, and audit logging. Self-hosted for teams needing full control over their artifact registry. Supports Helm charts and OCI artifacts.

  • Best for: Artifact Registries
  • Pricing: Free and open-source (Apache 2.0)

Disclosure: We may earn a commission if you click this link and make a purchase, at no additional cost to you.

Visit Harbor

Features

✓

Access Control

Fine-grained permissions for artifact access

RBAC with LDAP/OIDC integration

✓

Container Images

Store and distribute Docker/OCI container images

Docker and OCI container image storage

✓

High Availability

Redundancy and failover for artifact storage

Self-hosted with HA support

✓

Image Signing

Cryptographic signing of artifacts for integrity

Notary-based image signing

✓

Lifecycle Policies

Automated cleanup of old or unused artifacts

Tag retention and garbage collection

✓

Multi-Format Support

Support for Docker, Maven, npm, PyPI, Helm, and more

Docker, Helm charts, OCI artifacts

✓

OCI Support

Open Container Initiative artifact format

OCI distribution spec compliant

✗

Pull-Through Cache

Cache upstream registry artifacts locally

No built-in pull-through cache

✓

Replication

Mirror artifacts across registries and regions

Cross-registry replication

✓

Vulnerability Scanning

Scan artifacts for known vulnerabilities

Trivy integration for vulnerability scanning

Best For

Find the right DevOps tools for your specific needs. Harbor is featured in these buying guides:

Related Links