Back to Artifact Registries

Harbor

Open-source cloud-native registry for storing, signing, and scanning container images.

Free and open-source (Apache 2.0)

Harbor is a CNCF graduated open-source container registry that stores, signs, and scans container images. Features: vulnerability scanning (Trivy), RBAC, image replication, OIDC/LDAP authentication, notary-based image signing, and audit logging. Self-hosted for teams needing full control over their artifact registry. Supports Helm charts and OCI artifacts.

  • Best for: Artifact Registries
  • Pricing: Free and open-source (Apache 2.0)

Disclosure: We may earn a commission if you click this link and make a purchase, at no additional cost to you.

Visit Harbor

Features

Access Control

Fine-grained permissions for artifact access

RBAC with LDAP/OIDC integration

Container Images

Store and distribute Docker/OCI container images

Docker and OCI container image storage

High Availability

Redundancy and failover for artifact storage

Self-hosted with HA support

Image Signing

Cryptographic signing of artifacts for integrity

Notary-based image signing

Lifecycle Policies

Automated cleanup of old or unused artifacts

Tag retention and garbage collection

Multi-Format Support

Support for Docker, Maven, npm, PyPI, Helm, and more

Docker, Helm charts, OCI artifacts

OCI Support

Open Container Initiative artifact format

OCI distribution spec compliant

Pull-Through Cache

Cache upstream registry artifacts locally

No built-in pull-through cache

Replication

Mirror artifacts across registries and regions

Cross-registry replication

Vulnerability Scanning

Scan artifacts for known vulnerabilities

Trivy integration for vulnerability scanning

Best For

Find the right DevOps tools for your specific needs. Harbor is featured in these buying guides:

Related Links