Leanpub Header

Skip to main content

Harbor in Practice

A Hands-On Lab Guide to Running a Private Container Registry on Virtual Machines and Kubernetes

Harbor in Practice
This book is 100% completeLast updated on 2026-09-14

Twenty-four chapters, twenty-three labs on your own laptop, and several that break Harbor on purpose. Install it on a VM and on Kubernetes, gate deployments on scans and signatures, back it up in an order you can defend — and become the person responsible for the registry, not just the one who installed it.

Minimum price

$14.99

$24.99

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
About

About

About the Book

Installing Harbor takes twenty minutes. Being the person responsible for it does not.

The registry is where an auditor's questions land: what is running, where did it come from, and who could have changed it. Harbor answers all three — once somebody has decided how it authenticates, what it refuses to serve, what deletes things, how it is backed up, and what happens when the backup is needed.

This book is about becoming that somebody. You type.

Twenty-four chapters, twenty-three of them ending in a lab that runs on your laptop. No cloud account, no spare server, no credit card. Build a registry from an empty machine to something you would hand over:

• Install Harbor twice — on a virtual machine and on Kubernetes — then read the chapter that says which one you should actually be running, and why

• Give machines their own identities with robot accounts, and find out what happens when one expires at 3 a.m.

• Refuse a deployment three ways: unscanned, too vulnerable, unsigned

• Sign images with a key that never leaves HashiCorp Vault, and verify them in the cluster

• Write a retention rule, run it as a dry run, and learn why the number it reports is an upper bound rather than a promise

• Delete four hundred artifacts and watch the disk not shrink

• Take a backup in an order you can defend, then restore it and prove it with a digest

• Upgrade a schema that only migrates forwards, and discover that the rollback plan is the restore

Several chapters break things on purpose. You will restore a registry that lists images nobody can pull. You will lose the encryption key that is not in the database and watch every replication fail with an error that points nowhere. You will scale a component to three replicas and find two of them stuck forever.

Every chapter has a Break it on purpose section: the real error text, the cause, the fix. By the end the errors are recognisable rather than alarming.

Every command was run. Every number was checked. The book is pinned to Harbor v2.15.2 and chart v1.19.2, and the companion repository re-checks its claims in CI — including the ones the book makes about Harbor's own behaviour. That discipline found errors in Harbor's documentation while this book was being written, and the book prints them: two configuration paths in the official high-availability guide that Helm accepts and silently ignores; a backup procedure that omits the one file without which the restore is worthless; and read-only mode, which does not stop the garbage collector.

There is no exam. Harbor has no certification, so the book does not pretend otherwise. In its place, Appendix F is a production readiness review: fifty-four items across eight sections, thirty-two of which a script in the repository checks for you. The rest are questions only you can answer, and the appendix says so.

Who this is for: platform engineers, SREs, DevOps and security engineers who will be responsible for a registry — whether they chose it or inherited it. You need to be comfortable in a terminal and to have met a container. You do not need prior Harbor experience.

Includes nine appendices: tool installation for macOS, Linux and Windows, a harbor.yml reference that documents where the VM installer and the Helm chart disagree, an API cookbook whose every path is verified against the 135 the specification defines, ports and volumes, every error message in the book indexed by text, the readiness review, a lab teardown, a migration guide, and a map of the web interface for the four operations that have no API at all.

Share this book

Author

About the Author

Thomas Zachmann

Thomas Zachmann has spent more than twenty years building systems, and the last several of them building Kubernetes platforms for organisations where security and auditability are the requirement rather than the aspiration: on-premises, on bare metal, in air-gapped networks, and in European sovereign clouds — under European regulatory and audit regimes.

His work is the hardening of container platforms and everything that has to hold up when an auditor asks: policy enforcement with Kyverno, identity and access with Keycloak, supply-chain evidence with Harbor, Trivy and Dependency Track — and secrets management with HashiCorp Vault, which he has been deploying and operating since 2017. He works in the public clouds as well, which is what makes the on-premises argument in these books a comparison rather than a preference.

He is a Certified Kubernetes Security Specialist (CKS), Certified Kubernetes Administrator (CKA) and Certified Kubernetes Application Developer (CKAD). Those twenty years began in software engineering — performance and systems programming at SAP in C and C++, database performance analysis at IBM, and Go since. That background is why the automation in his platforms is written rather than bought, and why his books ask you to type rather than to read.

He is based in Hamburg and works across the DACH region.

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub