Harbor and S3 Object Storage: Redirect Behavior with External URLs
0 reputation · 29 Oct 2021, 07:57 UTC
A common production deployment pattern for Harbor involves transitioning from the default local filesystem to S3-compatible object storage to support high availability across multiple nodes. This shift changes how the registry handles image layers, as the registry component must provide the client with a redirect URL to the object storage bucket.
When the external_url in harbor.yml is configured, the system uses this value to generate the redirection targets for image pulls. In environments where a load balancer or reverse proxy handles TLS termination, there is often a discrepancy between the internal registry protocol and the external URL presented to the client.
If the internal communication remains HTTP while the external_url is HTTPS, the registry may generate redirects that the client cannot resolve or that the load balancer rejects.
- How does Harbor ensure the
external_urlis consistently applied across all redirect headers when using S3 storage in a multi-node production cluster? - What is the expected behavior when the internal registry port differs from the external port defined in the configuration?