public-cloud-roadmap icon indicating copy to clipboard operation
public-cloud-roadmap copied to clipboard

Managed Registry allow to plug external authentication

Open tanandy opened this issue 3 years ago • 8 comments

As a MPR administrator I want to plug Harbor to an external authentication (LDAP, OIDC...) So that I can control identity and authentication in a common tool and better handle key/access rotation

tanandy avatar Mar 31 '21 14:03 tanandy

Hi @tanandy Indeed this is part of our mid term roadmap. I had it to the public backlog

mhurtrel avatar Mar 31 '21 14:03 mhurtrel

Plugging OVH Harbor to our Active Directory would bring value. HA with SLA is the key feature of a Managed Registry but authentication should follow, knowing that it's available in Harbor. However let's be aware of this constraint which make a migration arduous : https://goharbor.io/docs/2.1.0/administration/configure-authentication/ldap-auth/

scndel avatar Jun 10 '21 14:06 scndel

@scndel We have this in mind and will allow a "reset to classic authentification with admin password" from OVHcloud API in case anything goes wrong ;)

mhurtrel avatar Jun 16 '21 08:06 mhurtrel

Good any ETA for this feature ?

tanandy avatar Jun 16 '21 08:06 tanandy

No fotmal eta at thid stage but py cutrent view on the roadmap and staffing gives me an informed guess between october and end of year holidays.

mhurtrel avatar Jun 16 '21 09:06 mhurtrel

Hello ! Just confirming we still plan to offer this feature, after we cwill have open canadian and german regions. This should be done this summer. sorry for the delay.

mhurtrel avatar Mar 30 '23 07:03 mhurtrel

You can now use this feature following that documentation : https://help.ovhcloud.com/csm/en-gb-public-cloud-private-registry-configure-oidc-provider-authentication?id=kb_article_view&sysparm_article=KB0059382

Integration to OVHcloud control panel (UI also known as "Manager") will be done in the next few months.

mhurtrel avatar Aug 30 '23 12:08 mhurtrel

docker login validation is missing in the documentation. I consider it is mandatory to let a user be sure she/he well followed each step of the doc.