
Harbor
Trusted cloud native registry for storing, signing, and scanning artifacts
29k stars 5.3k forks last commit first released Apache-2.0
Actively maintained
Last commit 28 Jul 2026.

Harbor is a CNCF Graduated cloud native registry for managing container images and related artifacts with security and governance controls. It extends the OCI/Docker registry model with enterprise features like policy enforcement, vulnerability scanning, and image signing to support secure supply chains.
Key Features
- Stores and manages container images and other cloud native artifacts, including Helm charts
- Role-based access control using projects for multi-tenant repository management
- Policy-based replication between registries for hybrid and multi-cloud deployments
- Built-in vulnerability scanning with policies to block deployment of vulnerable artifacts
- Image signing support and validation for provenance and integrity (including Notary-based workflows)
- Authentication integrations including LDAP/AD and OpenID Connect for SSO
- Audit logs for repository and administrative operations
- REST API with Swagger/OpenAPI interface for automation and integrations
Use Cases
- Run a private, policy-controlled registry for Kubernetes and Docker environments
- Enforce artifact security (scan/sign) as part of CI/CD and release workflows
- Replicate images across regions or datacenters for performance and availability
Limitations and Considerations
- Full feature set and integrations typically require multiple supporting components (scanner, signing, auth provider) and careful operational configuration
Harbor is a strong fit for teams that need a secure, compliant artifact registry with enterprise access control and automation capabilities. It is widely adopted in cloud native environments and integrates well with Kubernetes-centric workflows.
Categories:
Tags:
Tech Stack:
Similar to Harbor

RepoFlow
Simple, scalable package management for private and public repositories.
RepoFlow is a self-hosted package management platform supporting Docker, NPM, PyPI, Maven, and more, with CVE scanning, smart search, and access controls.


Gitea
Self-hosted Git hosting with code review, issues, and CI/CD
Gitea is a lightweight, self-hosted Git service with repositories, pull requests, issues, wiki, packages, and built-in CI/CD via Actions and runners.

Bytebase
Database DevSecOps platform for schema change and access governance
Open-source database DevSecOps tool for managing schema migrations, SQL review, audit logging, access control, and data masking across multiple databases.
Databasus
Web-based scheduled backup management for databases
Open-source database backup tool for PostgreSQL, MySQL/MariaDB, and MongoDB with scheduling, encrypted archives, multiple storage backends, and notifications.

Zot
OCI-native container and artifact registry (OCI Distribution compliant)
Open-source, production-ready OCI-native container image and artifact registry with single-binary deployment, S3/local storage, web UI and CLI.

Squidex
Open-source headless CMS with API-first content management
Squidex is an open-source headless CMS and content hub with REST and GraphQL APIs, workflows, versioning, and integrations for delivering content to any app or site.





