Harbor Project Visibility Defaults: API vs UI Discrepancies
0 reputation · 10 Aug 2023, 14:46 UTC
Background
When creating a Harbor project through the REST API, the public field is optional. In v1.x the default was true, while v2.0+ changed the default to false. However, the Helm chart and UI may still apply the legacy default in some minor releases, leading to inconsistent visibility. This ambiguity is critical because anonymous users can pull images and list tags via the Docker Registry HTTP API V2 only when the project is public.
Observed Uncertainty
The /v2/_catalog endpoint returns repositories from all projects the caller can access. For anonymous callers it should list only public projects, but the response can be cached for up to 30 seconds in certain storage backends. Additionally, Harbor 2.10 introduced a global “anonymous access” toggle that can override project‑level public flags. It is unclear how these changes interact when a project is created via the API versus the UI, or when the global toggle is disabled.
Questions
- Does the Harbor API default new projects to public or private in version 2.10?
- How does the
/v2/_catalogendpoint respond to anonymous requests immediately after a project’s visibility is toggled? - Which configuration setting globally overrides project‑level public flags for anonymous pulls in Harbor 2.10+?