---
title: "Cloud server with Harbor"
sidebar_label: "Harbor"
sidebar_position: 5
toc_max_heading_level: 3
description: "How to create a cloud server with a container registry"
---

import Tabs from '@theme/Tabs'
import TabItem from '@theme/TabItem'
import {TabItemLabel} from '@selectel/docux/components'
import {CustomTable} from '@selectel/docux/components'
import Formbricks from '@theme/MDXComponents/Formbricks'
import CopyIcon from '@selectel/docux/icons/copy'
import CreateServer from '@site/i18n/en/docusaurus-plugin-content-docs/current/_partials/cloud-servers/applications/create-server-for-apps.mdx'

# Cloud server with Harbor

Harbor is an open-source registry designed for secure artifact storage and management. Harbor protects artifacts using security policies and Role-Based Access Control (RBAC). It can automatically scan container images for vulnerabilities and sign them as trusted.

The service allows you to centrally, consistently, and securely manage images and other artifacts, for example, within Kubernetes and Docker ecosystems.

You can [create a cloud server with Harbor](#create-cloud-server-with-harbor). In Russia, the application runs on a cloud server with the pre-configured [SelectOS 1 64-bit](https://selectos.selectel.ru/news/mega/) operating system. In other [countries](/infrastructure/locations.mdx#country) — Ubuntu 24.04.

Before creating a cloud server with an application, please review the [software license agreements](https://423.selcdn.ru/kb/license-agreements-for-application-images-LANG.pdf) included in the image.

## Minimum resource requirements \{#minimum-requirements}

<CustomTable>
  <table>
    <thead>
      <th />

      <th>Test environment</th><th>Production environment</th>
    </thead>

    <tbody>
      <tr>
        <th>vCPU count</th><td>2</td><td>4</td>
      </tr>

      <tr>
        <th>RAM</th><td>4 GB</td><td>8 GB</td>
      </tr>

      <tr>
        <th>Boot volume</th><td>40 GB</td><td>160 GB</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## Create a cloud server with Harbor \{#create-cloud-server-with-harbor}

For Harbor to work, the cloud server must be accessible from the internet. To do this, when creating a server, you need to create a private subnet and attach a public floating IP address. To set up Harbor, you must specify user data — custom operating system configuration parameters — when creating the server.

After the server with Harbor is created, a free [TLS certificate from Let’s Encrypt®](/certificates-manager/certificates/lets-encrypt.mdx) will be issued automatically for the domain you specify. To issue the certificate, you must add an A record for the domain and specify the server's public floating IP address as the record value. You can add the domain to [Selectel DNS Hosting (actual](/dns-hosting/)).

1. [Create a public floating IP address](#create-floating-ip).

2. [Add an A record for the domain](#add-a-record).

3. [Create a cloud server with Harbor](#create-harbor-server).

### 1. Create a public floating IP address \{#create-floating-ip}

Create a public floating IP address so that the cloud server with Harbor is accessible from the internet.

Use the [Create a public floating IP address](/cloud-servers/cloud-networks/public-floating-ip-addresses.mdx#create-public-floating-ip) section of the [Public floating IP addresses](/cloud-servers/cloud-networks/public-floating-ip-addresses.mdx) guide.

### 2. Add an A record for the domain \{#add-a-record}

[Add a resource record](/dns-hosting/records/add-record.mdx) to access Harbor by domain.

Specify:

* [resource record type](/dns-hosting/records/add-record.mdx#record-types) in the group — A;
* the record value is the public floating IP address that you [created in step 1](#create-floating-ip).

### 3. Create a server with Harbor \{#create-harbor-server}

<CreateServer AppNameInPanel="Cloud Harbor" MinConfig="2 vCPU, RAM starting from 4 GB and a boot disk size starting from 40 GB" OptionalVolumes="Optional: add an additional" VolumeSize="Specify the size of the network disk in GB or TB" />

<div style={{paddingLeft:'2em'}}>
  ```bash
  #cloud-config
   
  write_files:
  - path: "/opt/gomplate/values/user-values.yaml"
    permissions: "0644"
    content: |
      harborDomain: "<example.com>"
      harborAdminPassword: "<administrator_password>"
      harborPostgresPassword: "<db_administrator_password>"
      harborAcmeEmail: "<root@example.com>"
      useTrivy: <enable_trivy>
  ```

  Specify:

  * `<example.com>` — the domain to access Harbor, which you [added in step 2](#add-a-record);
  * `<administrator_password>` — Harbor administrator password;
  * `<db_administrator_password>` — PostgreSQL database administrator account password;
  * `<root@example.com>` — Harbor administrator email for issuing a Let’s Encrypt® certificate;
  * optional: `<enable_trivy>` — enable the Trivy vulnerability scanner. Possible values: `true` — scanner enabled, `false` or parameter not specified — scanner disabled.
</div>

<Formbricks />
