Integrate Harbor
Secure your containerized applications by monitoring Harbor for exposed secrets in container images.
Harbor is a self-hosted, CNCF-graduated container registry. This integration works with any Harbor 2.x instance that exposes its API to GitGuardian, directly or through GitGuardian Bridge.
Why Monitor Harbor?
Harbor is where many organizations keep the container images they ship to production, often behind their own firewall. These images frequently embed database credentials, cloud API keys, and internal service tokens that, when exposed, give an attacker a direct path into production systems and customer data.
Capabilities
| Feature | Support | Details |
|---|---|---|
| Historical Scanning | ✅ (Supported) | Analyze existing images and their layers |
| Incremental Scanning | ✅ (Supported) | Regular scheduled scanning for new content |
| Monitored Perimeter | ✅ (Supported) | Granular monitoring of your repositories |
| Team Perimeter | ✅ (Supported) | Team-based access control |
| Presence Check | ❌ (Not Supported) | All occurrences considered present |
| Source Visibility | ❌ (Not Supported) | All sources are considered as private |
| File Attachments | N/A | Not applicable for container registries |
What we scan:
- All layers of every tagged container image, including each platform of a multi-architecture image
- Dockerfiles and build configurations
- Environment variables in image metadata
What we do not scan:
- Artifacts that are not container images: Helm charts, CNAB bundles, SBOMs, signatures and other accessories
- Untagged images
This integration automatically scans your monitored repositories, downloading container images which may generate bandwidth and compute load on your Harbor instance. To optimize costs and reduce false positives, carefully select the sources to monitor and use our filepath exclusion feature.
Prérequis de plan : Disponible pour le plan GitGuardian Enterprise. Essayez-le gratuitement avec une période d'essai de 30 jours - tous les incidents détectés restent accessibles après la fin de l'essai.
Couverture des détecteurs : Pour minimiser les faux positifs, Generic High Entropy Secret et Generic Password sont désactivés. Tous les autres détecteurs sont activés.
Comprendre les capacités de scan
Scan historique
Découvrez votre dette de secrets : lors de votre première intégration de cette source, GitGuardian effectue un scan complet de l'intégralité de l'historique de votre contenu, en fonction de votre périmètre personnalisé. Cela révèle des secrets qui ont pu être exposés il y a des semaines, des mois, voire des années — vous aidant ainsi à traiter votre dette de sécurité existante.
Comment déclencher un scan historique : rendez-vous sur votre page de périmètre, sélectionnez les sources que vous souhaitez scanner, puis cliquez sur Scan dans la barre d'actions groupées. Consultez Gérer votre périmètre surveillé pour connaître les limites de taille selon votre plan, la gestion des erreurs et tous les détails.
Scan incrémental
Restez protégé grâce à une surveillance régulière : une fois intégrée, GitGuardian assure une protection continue grâce à des scans automatisés planifiés de votre contenu. Le contenu nouveau et modifié est surveillé de manière systématique à intervalles réguliers, garantissant une couverture complète et une détection rapide de toute exposition de secret. Votre source reste sous la protection de GitGuardian, vous donnant l'assurance qu'aucun secret ne passera inaperçu.
Setup your Harbor integration
Prerequisites:
- Owner or Manager account on your GitGuardian Dashboard
- Harbor system administrator permissions to create a system-level robot account
- Connectivité réseau entre GitGuardian et vos services self-hosted. Découvrez GitGuardian Bridge pour permettre des connexions sécurisées entre GitGuardian SaaS et vos services self-hosted dans des réseaux privés.
GitGuardian integrates with Harbor via a robot account with read-only access to your projects.
You can install GitGuardian on multiple Harbor instances to monitor your repositories.
Step 1: Create a robot account in Harbor
A system-level robot account is recommended: it covers every project of the instance, including projects created later. A project-level robot account also works, but GitGuardian will only see that project.
- Log in to your Harbor instance as a system administrator
- Navigate to Administration > Robot Accounts
- Click New Robot Account
- Give it a name (e.g.,
gitguardian). Harbor prefixes the final username withrobot$ - Set the Expiration time. GitGuardian stops scanning when the secret expires, so choose Never expires or plan to update the secret in GitGuardian before it expires
- Under Cover all projects, select the following permissions:
- Repository:
List,Pull - Artifact:
List,Read
- Repository:
- Click Add
- Copy the robot name (e.g.,
robot$gitguardian) and its secret. Harbor shows the secret only once
Step 2: Connect Harbor to GitGuardian
- In the GitGuardian platform, navigate to the Sources integration page
- Click Install next to Harbor in the Container registries section
- Click Install on the Harbor integration page
- Type your Harbor instance URL (e.g.,
https://harbor.example.com) - Type the robot account name, including the
robot$prefix (e.g.,robot$gitguardian) - Paste the robot account secret
- Click Add
- Customize your monitored perimeter:
- Monitor specific Harbor repositories (Recommended)
- No repositories are monitored by default, you will have to select them manually.
- Newly created repositories will not be monitored by default. You can adjust this setting at any time.
- Monitor the entire Harbor instance
- All repositories are monitored by default with a full historical scan automatically triggered.
- Newly created repositories will be monitored by default. You can adjust this setting at any time.
- Monitor specific Harbor repositories (Recommended)
That's it! Your Harbor instance is now installed, and GitGuardian is monitoring all container images of your selected repositories for secrets.
GitGuardian checks the credentials at installation. If the URL does not answer as a Harbor API, or if Harbor rejects the robot account, the error message tells you which one to fix. A frequent cause is a missing robot$ prefix in the username.
Customize your monitored perimeter
GitGuardian lists your Harbor projects, and the repositories inside each project. Repositories whose names contain a / are shown as folders inside their project.
To customize the monitored repositories, navigate to your Harbor settings.
- Select/Unselect projects or repositories to include or exclude them from monitoring
- Confirm by clicking Update monitored perimeter
Automatic repository monitoring
You can enable or disable the automatic addition of newly created repositories to your monitored perimeter by switching the option in your Harbor settings.
Monitoring health
GitGuardian regularly checks that it can still reach your Harbor API and pull from its registry. An installation is flagged as unhealthy when:
- the robot account was disabled, deleted or its secret expired or was rotated
- the Harbor API or the registry behind it is unreachable, for example after a network or proxy change
- the robot account lost its permissions on the projects you monitor
Open the Troubleshoot panel of the installation from your Harbor settings to see the cause. To rotate the secret, use Update credentials: enter the robot name and the new secret, and GitGuardian re-runs the health check right away.
Gérer votre intégration
Surveillance de la santé et maintenance
Si vous devez modifier les paramètres de votre intégration ou résoudre des problèmes de connectivité, accédez à l'interface de gestion via Sources integration.
Désinstaller l'intégration
Bien que notre objectif soit de vous aider à maintenir une couverture de sécurité complète, vous pouvez désinstaller l'intégration chaque fois que nécessaire :
- Naviguez vers Sources integration
- Cliquez sur Edit à côté du nom de l'intégration
- Cliquez sur Configure
- Cliquez sur l'icône delete à côté de votre ressource
- Confirmez la suppression
Note : la suppression de l'intégration préserve votre historique d'incidents, mais arrête les analyses futures et les vérifications de présence pour les intégrations qui le supportent.
Chemins exclus
GitGuardian exclut automatiquement les fichiers de l'analyse si leurs chemins contiennent l'une de ces expressions régulières :
/__pypackages__/
/\.venv/
/\.tox/
/site-packages/
/venv/
distutils/command/register\.py
python.*/awscli/examples/
python.*/dulwich/(tests|contrib/test_)
python.*/hgext/bugzilla\.py
python.*/mercurial/util\.py
python.*/test/certdata/
python.*/urllib/request\.py
python.*/pygments/lexers/
/cryptography.+/tests/.+(fixtures|test)_.+\.py
/python.+pygpgme.+/tests/
botocore/data/.+/(examples|service)-.+\.json
usr(/local)?/lib/python.+/dist-packages
/libevent.+/info/test/test/
/conda-.+-py.+/info/test/tests.+/test_.+\.py
/python[^/]+/test/
/man/man5/kdc\.conf\.5
erlang.*(inets|ssl).*/examples/
/gems/.*httpclient.*/(test|sample)/
/gems/.*faraday.*/
/vendor/bundle/
/\.gem/
ruby-[^/]+/test/openssl/
/(g|G)o/src/cmd/go/internal/.*_test\.go
/(g|G)o/src/cmd/go/internal/.*/testdata/
/(g|G)o/src/cmd/go/testdata/
/(g|G)o/src/crypto/x509/platform_root_key\.pem
/(G|g)o/src/crypto/(tls|x509)/.*_test\.go
/(g|G)o/src/net/(url|http)/.*_test\.go
src/github.com/DataDog/datadog-agent/.*test.*\.go
google/internal/.*_test\.go
golang.org.*oauth2@.*/.*\.go
/flutter/.*/packages/flutter_tools/test/data/
/flutter/.*/examples/image_list/lib
/\.pub-cache
etc/ssl/private/ssl-cert-snakeoil\.key
perl.*Cwd\.pm
ansible/.*/tests/(integration|unit)/
ansible/.*/test/awx
ansible/collections/ansible_collections/.*/plugins/
/curl/.*/(tests|docs|lib/url\.c)
/doc/wget.+/NEWS
dist/awscli/examples/
usr(/local)?/lib/aws-cli/examples/
/google-cloud-sdk/(lib|platform)/
\.git/modules/third[-_]?party/
\.git/modules/external/
/\.npm/_cacache
/node_modules/
/\.parcel-cache/
/\.yarn/cache/
/\.m2/
/\.ivy2/cache/
/\.mix/
/\.hex/
/composer/cache/
/\.nuget/packages/
/libgpg-error/errorref\.txt
/Homebrew/Library/Taps/
/tcl[^/]+/http-.+\.tm
/tcl[^/]+/[^/]+/http-.+\.tm
usr/share/lua/[^/]+/posix/init\.lua
openssl/openssl-[^/]+/test/recipes/
usr/share/doc/libssl-doc/demos/
boringssl/src/third_party/[^/]+test[^/]+/[^/]+_test\.json
Additional Self-Hosted considerations
For GitGuardian Self-Hosted instances, scan frequency can be configured in the Admin Area:
- Time interval unit: seconds
- Default value: 172800 (2 days)
- Minimum value: 1800 (30 minutes)
Privacy and compliance
Gestion des données
GitGuardian traite vos données uniquement pour détecter les secrets exposés :
- Accès en lecture seule : nous ne demandons jamais l'accès en écriture sauf s'il est limité à la création de webhooks pour recevoir et traiter les événements en temps réel
- Rétention minimale des données : nous ne stockons que les données et métadonnées nécessaires à la gestion des incidents
- Chiffrement : toutes les données en transit et au repos sont chiffrées
- Conformité : nous suivons les mêmes standards de protection des données que nos autres intégrations
Considérations régionales
GitGuardian héberge ses services dans deux régions AWS : eu-central-1 (Francfort) et us-west-2 (Oregon). Assurez-vous que votre région de déploiement GitGuardian s'aligne avec vos exigences de résidence des données. Contactez le support si vous avez besoin de conseils sur la conformité aux réglementations locales.
User notification
Country-specific laws and regulations may require you to inform your users that your repositories are being scanned for secrets. Here is a suggestion for a message you may want to use:
As part of our internal information security process, the company scans its repositories for potential secrets leaks using GitGuardian. All data collected will be processed for the purpose of detecting potential leaks. To find out more about how we manage your personal data and to exercise your rights, please refer to our employee/partner privacy notice.
Please note that only repositories relating to the company's activity and business may be monitored and that users shall refrain from sharing personal or sensitive data not relevant to the repository's purpose.