Harbor部署教程

Harbor部署教程

安装docker相关依赖

更新 apt 包索引并安装必要的依赖

复制代码
sudo apt-get update -y

sudo apt-get -y install ca-certificates curl gnupg lsb-release  software-properties-common

cd ~

curl -fsSL https://mirrors.aliyun.com/docker-ce/linux/ubuntu/gpg -o docker-gpg.key

cat docker-gpg.key | gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/docker.gpg > /dev/null

sudo chmod 644 /etc/apt/trusted.gpg.d/docker.gpg

add-apt-repository "deb [arch=$(dpkg --print-architecture)] https://mirrors.aliyun.com/docker-ce/linux/ubuntu jammy stable"

安装 Docker Engine

复制代码
sudo apt-get update -y

sudo apt-get install -y docker-ce=5:25.0.0-1~ubuntu.22.04~jammy docker-ce-cli=5:25.0.0-1~ubuntu.22.04~jammy containerd.io docker-compose-plugin

验证 Docker 版本

复制代码
# 验证 Docker 版本
docker --version 
#验证 Docker Compose 版本
docker compose version

编辑配置 文件

复制代码
sudo vi /etc/docker/daemon.json

添加如下内容

复制代码
{
  "registry-mirrors": [
    "https://docker.registry.cyou",
"https://docker-cf.registry.cyou",
"https://dockercf.jsdelivr.fyi",
"https://docker.jsdelivr.fyi",
"https://dockertest.jsdelivr.fyi",
"https://mirror.aliyuncs.com",
"https://dockerproxy.com",
"https://mirror.baidubce.com",
"https://docker.m.daocloud.io",
"https://docker.nju.edu.cn",
"https://docker.mirrors.sjtug.sjtu.edu.cn",
"https://docker.mirrors.ustc.edu.cn",
"https://mirror.iscas.ac.cn",
"https://docker.rainbond.cc"
  ],
 "insecure-registries": ["harborip地址"]
}

重新加载配置docker

复制代码
#重新加载配置
systemctl daemon-reload

#锁定docker
apt-mark hold docker-ce docker-ce-cli containerd.io

#启动docker
systemctl start docker
systemctl enable docker

安装horbor

部署安装horbor

复制代码
sudo mkdir -p /opt/harbor
cd /opt/harbor

# 下载 Harbor v2.10.2 在线安装包
sudo wget https://github.com/goharbor/harbor/releases/download/v2.10.2/harbor-online-installer-v2.10.2.tgz

tar xzf harbor-online-installer-v2.10.2.tgz
cd harbor

sudo cp harbor.yml.tmpl harbor.yml
sudo vim harbor.yml
复制代码
./install.sh 

停止 Harbor 服务
docker compose down

启动 Harbor 服务
docker compose up -d

运行prepare 脚本重新生成配置
./prepare

docker重启,harbor停止运行解决办法

原因分析:Harbor 所有服务都依赖 harbor 自定义桥接网络(networks: harbor),且该网络配置为 external: false(默认私有网络)。Docker 重启时,会先销毁所有容器和非持久化的自定义网络,Harbor 的 harbor 网络会被自动删除,容器重启时因找不到依赖网络而启动失败

方法1:快速恢复(Docker 重启后临时修复)

复制代码
# 1. 进入 Harbor 安装目录
cd /opt/harbor/harbor

# 2. 重新生成 Harbor 配置(可选,若配置未变更可跳过)
./prepare

# 3. 重建 Harbor 网络并启动容器(docker compose 会自动创建缺失的 harbor 网络)
docker compose up -d

方法 2:永久解决(配置自动关联与持久化)

复制代码
# 1. 先停止 Harbor 服务
cd /opt/harbor/harbor
docker compose down

# 2. 删除原有 harbor 私有网络
docker network rm harbor

# 3. 创建持久化的外部桥接网络(命名为 harbor,与原有配置一致)
docker network create --driver bridge --subnet=172.18.0.0/16 --gateway=172.18.0.1 harbor

# 4. 修改 docker-compose.yml 中的网络配置
vim /opt/harbor/harbor/docker-compose.yml

docker-compose.yml修改为如下内容:

复制代码
version: '2.3'
services:
  log:
    image: goharbor/harbor-log:v2.10.2
    container_name: harbor-log
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - DAC_OVERRIDE
      - SETGID
      - SETUID
    volumes:
      - /var/log/harbor/:/var/log/docker/:z
      - type: bind
        source: ./common/config/log/logrotate.conf
        target: /etc/logrotate.d/logrotate.conf
      - type: bind
        source: ./common/config/log/rsyslog_docker.conf
        target: /etc/rsyslog.d/rsyslog_docker.conf
    ports:
      - 127.0.0.1:1514:10514
    networks:
      - harbor
    healthcheck:
      test: ["CMD", "pgrep", "rsyslogd"]
      interval: 5s
      timeout: 3s
      retries: 3
      start_period: 10s
  registry:
    image: goharbor/registry-photon:v2.10.2
    container_name: registry
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - SETGID
      - SETUID
    volumes:
      - /data/registry:/storage:z
      - ./common/config/registry/:/etc/registry/:z
      - type: bind
        source: /data/secret/registry/root.crt
        target: /etc/registry/root.crt
      - type: bind
        source: ./common/config/shared/trust-certificates
        target: /harbor_cust_cert
    networks:
      - harbor
    depends_on:
      log: 
        condition: service_healthy
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "registry"
  registryctl:
    image: goharbor/harbor-registryctl:v2.10.2
    container_name: registryctl
    env_file:
      - ./common/config/registryctl/env
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - SETGID
      - SETUID
    volumes:
      - /data/registry:/storage:z
      - ./common/config/registry/:/etc/registry/:z
      - type: bind
        source: ./common/config/registryctl/config.yml
        target: /etc/registryctl/config.yml
      - type: bind
        source: ./common/config/shared/trust-certificates
        target: /harbor_cust_cert
    networks:
      - harbor
    depends_on:
      - log
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "registryctl"
  postgresql:
    image: goharbor/harbor-db:v2.10.2
    container_name: harbor-db
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - DAC_OVERRIDE
      - SETGID
      - SETUID
    volumes:
      - /data/database:/var/lib/postgresql/data:z
    networks:
      harbor:
    env_file:
      - ./common/config/db/env
    depends_on:
      - log
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "postgresql"
    shm_size: '1gb'
  core:
    image: goharbor/harbor-core:v2.10.2
    container_name: harbor-core
    env_file:
      - ./common/config/core/env
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - SETGID
      - SETUID
    volumes:
      - /data/ca_download/:/etc/core/ca/:z
      - /data/:/data/:z
      - ./common/config/core/certificates/:/etc/core/certificates/:z
      - type: bind
        source: ./common/config/core/app.conf
        target: /etc/core/app.conf
      - type: bind
        source: /data/secret/core/private_key.pem
        target: /etc/core/private_key.pem
      - type: bind
        source: /data/secret/keys/secretkey
        target: /etc/core/key
      - type: bind
        source: ./common/config/shared/trust-certificates
        target: /harbor_cust_cert
    networks:
      harbor:
    depends_on:
      - log
      - registry
      - redis
      - postgresql
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "core"
  portal:
    image: goharbor/harbor-portal:v2.10.2
    container_name: harbor-portal
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - SETGID
      - SETUID
      - NET_BIND_SERVICE
    volumes:
      - type: bind
        source: ./common/config/portal/nginx.conf
        target: /etc/nginx/nginx.conf
    networks:
      - harbor
    depends_on:
      - log
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "portal"

  jobservice:
    image: goharbor/harbor-jobservice:v2.10.2
    container_name: harbor-jobservice
    env_file:
      - ./common/config/jobservice/env
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - SETGID
      - SETUID
    volumes:
      - /data/job_logs:/var/log/jobs:z
      - type: bind
        source: ./common/config/jobservice/config.yml
        target: /etc/jobservice/config.yml
      - type: bind
        source: ./common/config/shared/trust-certificates
        target: /harbor_cust_cert
    networks:
      - harbor
    depends_on:
      - core
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "jobservice"
  redis:
    image: goharbor/redis-photon:v2.10.2
    container_name: redis
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - SETGID
      - SETUID
    volumes:
      - /data/redis:/var/lib/redis
    networks:
      harbor:
    depends_on:
      - log
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "redis"
  proxy:
    image: goharbor/nginx-photon:v2.10.2
    container_name: nginx
    restart: always
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - SETGID
      - SETUID
      - NET_BIND_SERVICE
    volumes:
      - ./common/config/nginx:/etc/nginx:z
      - type: bind
        source: ./common/config/shared/trust-certificates
        target: /harbor_cust_cert
    networks:
      - harbor
    ports:
      - 80:8080
    depends_on:
      - registry
      - core
      - portal
      - log
    logging:
      driver: "syslog"
      options:
        syslog-address: "tcp://localhost:1514"
        tag: "proxy"
networks:
  harbor:
    external: true # 改为 true,使用已创建的外部网络

# 1. 创建 Harbor systemd 服务文件
vim /etc/systemd/system/harbor.service

添加如下内容:

复制代码
[Unit]
Description=Harbor Docker Registry Service
Documentation=https://goharbor.io/
After=docker.service containerd.service  
Requires=docker.service containerd.service

[Service]
Type=oneshot
Environment="PATH=/usr/bin:/usr/local/bin"
WorkingDirectory=/opt/harbor/harbor  
ExecStart=/usr/bin/docker compose up -d
ExecStop=/usr/bin/docker compose down
ExecReload=/usr/bin/docker compose restart
RemainAfterExit=yes

[Install]
WantedBy=multi-user.target

# 1. 重新加载 systemd 配置
systemctl daemon-reload

# 2. 设置 Harbor 开机自启
systemctl enable harbor.servic

# 3. 启动 Harbor 服务(验证配置)
systemctl start harbor.service

# 4. 查看 Harbor 服务状态
systemctl status harbor.service
相关推荐
牛奔14 小时前
Docker Compose 两种安装与使用方式详解(适用于 Docker 19.03 版本)
运维·docker·云原生·容器·eureka
翼龙云_cloud14 小时前
阿里云渠道商:如何手动一键扩缩容ECS实例?
运维·服务器·阿里云·云计算
Sean X14 小时前
Ubuntu24.04安装向日葵
linux·ubuntu
DX_水位流量监测15 小时前
大坝安全监测之渗流渗压位移监测设备技术解析
大数据·运维·服务器·网络·人工智能·安全
电商API&Tina15 小时前
京东 API 数据采集接口接入与行业分析
运维·服务器·网络·数据库·django·php
IT 乔峰15 小时前
脚本部署MHA集群
linux·shell
dz小伟15 小时前
execve() 系统调用深度解析:从用户空间到内核的完整加载过程
linux
Mr_Xuhhh16 小时前
博客标题:深入理解Shell:从进程控制到自主实现一个微型Shell
linux·运维·服务器
JoyCheung-16 小时前
Free底层是怎么释放内存的
linux·c语言