Skip to main content

Integrate Harbor

Secure your containerized applications by monitoring Harbor for exposed secrets in container images.

tip

Harbor is a self-hosted, CNCF-graduated container registry. This integration works with any Harbor 2.x instance that exposes its API to GitGuardian, directly or through GitGuardian Bridge.

Why Monitor Harbor?​

Harbor is where many organizations keep the container images they ship to production, often behind their own firewall. These images frequently embed database credentials, cloud API keys, and internal service tokens that, when exposed, give an attacker a direct path into production systems and customer data.

Capabilities​

FeatureSupportDetails
Historical Scanning✅ (Supported)Analyze existing images and their layers
Incremental Scanning✅ (Supported)Regular scheduled scanning for new content
Monitored Perimeter✅ (Supported)Granular monitoring of your repositories
Team Perimeter✅ (Supported)Team-based access control
Presence Check❌ (Not Supported)All occurrences considered present
Source Visibility❌ (Not Supported)All sources are considered as private
File AttachmentsN/ANot applicable for container registries

What we scan:

  • All layers of every tagged container image, including each platform of a multi-architecture image
  • Dockerfiles and build configurations
  • Environment variables in image metadata

What we do not scan:

  • Artifacts that are not container images: Helm charts, CNAB bundles, SBOMs, signatures and other accessories
  • Untagged images
info

This integration automatically scans your monitored repositories, downloading container images which may generate bandwidth and compute load on your Harbor instance. To optimize costs and reduce false positives, carefully select the sources to monitor and use our filepath exclusion feature.

info

Plan requirements: Available for GitGuardian Enterprise plan. Try it for free with a 30-day trial - any detected incidents remain accessible after the trial ends.
Detector coverage: To minimize false positives, Generic High Entropy Secret and Generic Password are disabled. All other detectors are enabled.

Understanding scanning capabilities​

Historical scanning​

Uncover your secret debt: When you first integrate this source, GitGuardian performs a comprehensive scan of your entire content history, based on your customized perimeter. This reveals secrets that may have been exposed weeks, months, or even years ago - helping you address your existing security debt.

How to trigger a historical scan: Go to your perimeter page, select the sources you want to scan, and click Scan in the bulk actions bar. See Manage your monitored perimeter for plan-based size limits, error handling, and full details.

Incremental scanning​

Stay protected with regular monitoring: Once integrated, GitGuardian provides ongoing protection through scheduled automated scans of your content. New and modified content is systematically monitored at regular intervals, ensuring comprehensive coverage and timely detection of any secret exposures. Your source remains under GitGuardian's protection, giving you confidence that secrets won't go unnoticed.

Setup your Harbor integration​

Prerequisites:

  • Owner or Manager account on your GitGuardian Dashboard
  • Harbor system administrator permissions to create a system-level robot account
  • Network connectivity between GitGuardian and your self-hosted services. Check out GitGuardian Bridge to enable secure connections between GitGuardian SaaS and your self-hosted services in private networks.

GitGuardian integrates with Harbor via a robot account with read-only access to your projects.

You can install GitGuardian on multiple Harbor instances to monitor your repositories.

Step 1: Create a robot account in Harbor​

A system-level robot account is recommended: it covers every project of the instance, including projects created later. A project-level robot account also works, but GitGuardian will only see that project.

  1. Log in to your Harbor instance as a system administrator
  2. Navigate to Administration > Robot Accounts
  3. Click New Robot Account
  4. Give it a name (e.g., gitguardian). Harbor prefixes the final username with robot$
  5. Set the Expiration time. GitGuardian stops scanning when the secret expires, so choose Never expires or plan to update the secret in GitGuardian before it expires
  6. Under Cover all projects, select the following permissions:
    • Repository: List, Pull
    • Artifact: List, Read
  7. Click Add
  8. Copy the robot name (e.g., robot$gitguardian) and its secret. Harbor shows the secret only once

Step 2: Connect Harbor to GitGuardian​

  1. In the GitGuardian platform, navigate to the Sources integration page
  2. Click Install next to Harbor in the Container registries section
  3. Click Install on the Harbor integration page
  4. Type your Harbor instance URL (e.g., https://harbor.example.com)
  5. Type the robot account name, including the robot$ prefix (e.g., robot$gitguardian)
  6. Paste the robot account secret
  7. Click Add
  8. Customize your monitored perimeter:
    • Monitor specific Harbor repositories (Recommended)
      • No repositories are monitored by default, you will have to select them manually.
      • Newly created repositories will not be monitored by default. You can adjust this setting at any time.
    • Monitor the entire Harbor instance
      • All repositories are monitored by default with a full historical scan automatically triggered.
      • Newly created repositories will be monitored by default. You can adjust this setting at any time.

That's it! Your Harbor instance is now installed, and GitGuardian is monitoring all container images of your selected repositories for secrets.

GitGuardian checks the credentials at installation. If the URL does not answer as a Harbor API, or if Harbor rejects the robot account, the error message tells you which one to fix. A frequent cause is a missing robot$ prefix in the username.

Customize your monitored perimeter​

GitGuardian lists your Harbor projects, and the repositories inside each project. Repositories whose names contain a / are shown as folders inside their project.

To customize the monitored repositories, navigate to your Harbor settings.

  1. Select/Unselect projects or repositories to include or exclude them from monitoring
  2. Confirm by clicking Update monitored perimeter

Automatic repository monitoring​

You can enable or disable the automatic addition of newly created repositories to your monitored perimeter by switching the option in your Harbor settings.

Monitoring health​

GitGuardian regularly checks that it can still reach your Harbor API and pull from its registry. An installation is flagged as unhealthy when:

  • the robot account was disabled, deleted or its secret expired or was rotated
  • the Harbor API or the registry behind it is unreachable, for example after a network or proxy change
  • the robot account lost its permissions on the projects you monitor

Open the Troubleshoot panel of the installation from your Harbor settings to see the cause. To rotate the secret, use Update credentials: enter the robot name and the new secret, and GitGuardian re-runs the health check right away.

Managing your integration​

Monitoring health and Maintenance​

If you need to modify your integration settings or troubleshoot connectivity issues, access the management interface through Sources integration.

Uninstalling the integration​

While our goal is to help you maintain comprehensive security coverage, you may uninstall the integration whenever necessary:

  1. Navigate to Sources integration
  2. Click Edit next to the integration name
  3. Click Configure
  4. Click the delete icon next to your resource
  5. Confirm the removal

Note: Removing the integration preserves your incident history, but stops future scanning and presence checks for the integrations that support it.

Excluded paths​

GitGuardian automatically excludes files from scanning if their paths contain any of these regular expressions:

/__pypackages__/
/\.venv/
/\.tox/
/site-packages/
/venv/
distutils/command/register\.py
python.*/awscli/examples/
python.*/dulwich/(tests|contrib/test_)
python.*/hgext/bugzilla\.py
python.*/mercurial/util\.py
python.*/test/certdata/
python.*/urllib/request\.py
python.*/pygments/lexers/
/cryptography.+/tests/.+(fixtures|test)_.+\.py
/python.+pygpgme.+/tests/
botocore/data/.+/(examples|service)-.+\.json
usr(/local)?/lib/python.+/dist-packages
/libevent.+/info/test/test/
/conda-.+-py.+/info/test/tests.+/test_.+\.py
/python[^/]+/test/
/man/man5/kdc\.conf\.5
erlang.*(inets|ssl).*/examples/
/gems/.*httpclient.*/(test|sample)/
/gems/.*faraday.*/
/vendor/bundle/
/\.gem/
ruby-[^/]+/test/openssl/
/(g|G)o/src/cmd/go/internal/.*_test\.go
/(g|G)o/src/cmd/go/internal/.*/testdata/
/(g|G)o/src/cmd/go/testdata/
/(g|G)o/src/crypto/x509/platform_root_key\.pem
/(G|g)o/src/crypto/(tls|x509)/.*_test\.go
/(g|G)o/src/net/(url|http)/.*_test\.go
src/github.com/DataDog/datadog-agent/.*test.*\.go
google/internal/.*_test\.go
golang.org.*oauth2@.*/.*\.go
/flutter/.*/packages/flutter_tools/test/data/
/flutter/.*/examples/image_list/lib
/\.pub-cache
etc/ssl/private/ssl-cert-snakeoil\.key
perl.*Cwd\.pm
ansible/.*/tests/(integration|unit)/
ansible/.*/test/awx
ansible/collections/ansible_collections/.*/plugins/
/curl/.*/(tests|docs|lib/url\.c)
/doc/wget.+/NEWS
dist/awscli/examples/
usr(/local)?/lib/aws-cli/examples/
/google-cloud-sdk/(lib|platform)/
\.git/modules/third[-_]?party/
\.git/modules/external/
/\.npm/_cacache
/node_modules/
/\.parcel-cache/
/\.yarn/cache/
/\.m2/
/\.ivy2/cache/
/\.mix/
/\.hex/
/composer/cache/
/\.nuget/packages/
/libgpg-error/errorref\.txt
/Homebrew/Library/Taps/
/tcl[^/]+/http-.+\.tm
/tcl[^/]+/[^/]+/http-.+\.tm
usr/share/lua/[^/]+/posix/init\.lua
openssl/openssl-[^/]+/test/recipes/
usr/share/doc/libssl-doc/demos/
boringssl/src/third_party/[^/]+test[^/]+/[^/]+_test\.json

Additional Self-Hosted considerations​

For GitGuardian Self-Hosted instances, scan frequency can be configured in the Admin Area:

  • Time interval unit: seconds
  • Default value: 172800 (2 days)
  • Minimum value: 1800 (30 minutes)

Privacy and compliance​

Data handling​

GitGuardian processes your data solely to detect exposed secrets:

  • Read-only access: We never require write access unless scoped to creating webhooks to receive and process real-time events
  • Minimal data retention: We store only data and metadata necessary for incident management
  • Encryption: All data in transit and at rest is encrypted
  • Compliance: We follow the same data protection standards as our other integrations

Regional considerations​

GitGuardian hosts its services in two AWS regions: eu-central-1 (Frankfurt) and us-west-2 (Oregon). Ensure your GitGuardian deployment region aligns with your data residency requirements. Contact support if you need guidance on compliance with local regulations.

User notification​

Country-specific laws and regulations may require you to inform your users that your repositories are being scanned for secrets. Here is a suggestion for a message you may want to use:

As part of our internal information security process, the company scans its repositories for potential secrets leaks using GitGuardian. All data collected will be processed for the purpose of detecting potential leaks. To find out more about how we manage your personal data and to exercise your rights, please refer to our employee/partner privacy notice.

Please note that only repositories relating to the company's activity and business may be monitored and that users shall refrain from sharing personal or sensitive data not relevant to the repository's purpose.