You download the Harbor installers from the official releases page. Download either the online installer or the offline installer.

  • Online installer: The online installer downloads the Harbor images from Docker hub. For this reason, the installer is very small in size.

  • Offline installer: Use the offline installer if the host to which are are deploying Harbor does not have a connection to the Internet. The offline installer contains pre-built images, so it is larger than the online installer.

The installation processes are almost the same for both the online and offline installers.

Download and Unpack the Installer

  1. Go to the Harbor releases page.

  2. Download either the online or offline installer for the version you want to install.

  3. Optionally download the corresponding *.asc file to verify that the package is genuine.

    The *.asc file is an OpenPGP key file. Perform the following steps to verify that the downloaded bundle is genuine.

    1. Obtain the public key for the *.asc file.

      1. gpg --keyserver hkps://keyserver.ubuntu.com --receive-keys 644FF454C0B4115C

      You should see the message public key "Harbor-sign (The key for signing Harbor build) <jiangd@vmware.com>" imported

    2. Verify that the package is genuine by running one of the following commands.

      • Online installer:

        1. gpg -v keyserver hkps://keyserver.ubuntu.com –verify harbor-online-installer-version.tgz.asc
      • Offline installer:

        1. gpg -v keyserver hkps://keyserver.ubuntu.com –verify harbor-offline-installer-version.tgz.asc

      The gpg command verifies that the signature of the bundle matches that of the *.asc key file. You should see confirmation that the signature is correct.

      1. gpg: armor header: Version: GnuPG v1
      2. gpg: assuming signed data in 'harbor-online-installer-v2.0.2.tgz'
      3. gpg: Signature made Tue Jul 28 09:49:20 2020 UTC
      4. gpg: using RSA key 644FF454C0B4115C
      5. gpg: using pgp trust model
      6. gpg: Good signature from "Harbor-sign (The key for signing Harbor build) <jiangd@vmware.com>" [unknown]
      7. gpg: WARNING: This key is not certified with a trusted signature!
      8. gpg: There is no indication that the signature belongs to the owner.
      9. Primary key fingerprint: 7722 D168 DAEC 4578 06C9 6FF9 644F F454 C0B4 115C
      10. gpg: binary signature, digest algorithm SHA1, key algorithm rsa4096
  4. Use tar to extract the installer package:

    • Online installer:

      1. bash $ tar xvf harbor-online-installer-version.tgz
    • Offline installer:

      1. bash $ tar xvf harbor-offline-installer-version.tgz

Next Steps