TECHNOLOGIES: HARBOR

Harbor Security Review

A public Harbor project or an over-permissioned robot account can leak the images your Kubernetes clusters pull into production. We test project visibility, RBAC roles and robot accounts on your registry. CREST-certified testers, fixed price from £3,740 for a 3-day single-registry scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Harbor Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
30

Harbor’s own robot account tokens expire after 30 days by default, but any individual robot can be set to Never Expired instead.

A Harbor registry is only as tightly scoped as the projects, roles and robot accounts your team configured

Harbor documents five project-level roles, from Limited Guest up to Project Admin, and each one maps to a different set of push, pull and management capabilities, so a Limited Guest can pull an image but cannot even see the other members of the project it came from. Every project is also set to public or private, and Harbor’s own documentation confirms a public project lets any user pull its images while an anonymous, unauthenticated caller still gets read-only access to it, and a project can be toggled between the two at any point after it is created. We test which role every member actually holds in every project, and whether a project holding anything sensitive is still set to public from an earlier integration.

Harbor separates project-scoped robot accounts, limited to a single project, from system-wide robot accounts an administrator can create with permissions spanning multiple projects at once, and neither type can log into the Harbor interface itself. Robot account tokens expire after 30 days by default, but the system-wide expiry period can be changed and any individual robot can instead be marked Never Expired, so a CI credential built for one migration can keep working long after the migration is done. Authentication itself runs through a local database, LDAP or Active Directory, or an external OIDC provider, and Harbor’s documentation is explicit that once you create local user accounts in database mode, the instance is locked into that mode and cannot switch to LDAP or OIDC afterwards. We test which robot accounts exist, their real scope and expiry, and which authentication backend is actually controlling who can sign in.

Harbor supports content trust through Cosign and Notation, a project admin can require every artifact to be signed before it can be pulled, and a separate deployment security policy can block a pull outright once a vulnerability above a chosen severity is found by the project’s scanner. We review the projects, roles, robot accounts, signing and scanning policy on your own Harbor instance, the same way we review a client’s own workload configuration on a Kubernetes cluster pulling from it, rather than testing Harbor’s own open-source codebase.

SCOPE

What we review in a Harbor registry

HB-01

Project Visibility and Anonymous Pull Access

Every Harbor project is set to public or private, and Harbor’s own documentation confirms a public project lets any user pull its images while a private project restricts pulls to its actual members, with an anonymous, unauthenticated caller getting read-only access to a public project and no access at all to a private one. A project can also be toggled between public and private at any point after it is created, so a project made public for a short-lived integration can stay that way long after the reason for it has gone. We test the visibility setting on every project against what it actually stores, and check whether an anonymous, unauthenticated caller can reach and pull from a project that should require an account.

HB-02

Project Roles and RBAC Bindings

Harbor defines five project-level roles, Limited Guest, Guest, Developer, Maintainer and Project Admin, and each maps to a different set of capabilities: a Limited Guest can pull images but cannot push, see logs or see other members, while a Maintainer can scan images, view replication jobs and delete images and Helm charts on top of a Developer’s read-write access. Whichever role a member actually holds decides what they can push into a project, and those pushed images are exactly what a downstream Kubernetes or OpenShift cluster later pulls into a running workload. We test the actual role bound to every member and group in every project against what that role is meant to be used for.

HB-03

System Administrator Role and Global Settings

The Harbor system administrator role sits above every project role, able to list every project on the instance, promote another user to administrator, delete user accounts and set vulnerability scan policy across all images, and Harbor’s default public project, library, is owned by the administrator account. A system administrator can also switch the whole registry to read-only mode and restrict which authenticated users are allowed to create new projects at all. We test who holds the administrator role, what the default library project actually contains, and whether registry-wide settings like project-creation restriction match what the business believes is configured.

HB-04

Authentication Backends: Database, LDAP/AD and OIDC

Harbor supports three authentication modes: a local database where accounts are created directly in Harbor, LDAP or Active Directory where accounts are managed by an external directory, and an OIDC provider where accounts are managed externally through a compliant identity provider. Harbor’s documentation is explicit that once local user accounts exist in database mode, the instance is locked into database authentication and cannot be switched to LDAP or OIDC afterwards, so a hurried initial deployment can permanently rule out centralising logins later. We confirm which authentication mode is actually configured, and where LDAP or OIDC is in use, test how group or claim mappings translate into Harbor’s project roles.

HB-05

Project-Scoped Robot Accounts for CI/CD

A project-scoped robot account is a non-interactive, token-based credential limited to a single project, typically used by a CI/CD pipeline to push and pull images without a human’s own login, and Harbor’s documentation confirms a robot account can never be used to sign into the web interface itself. Its permissions are assigned individually within that one project, so a robot created for a single build job can end up carrying far more push, pull or delete capability than the pipeline that uses it actually needs. We test every project-scoped robot account’s assigned permissions against the pipeline or automation it is meant to serve.

HB-06

System-Wide Robot Accounts and Token Expiry

A system-wide robot account, created only by an administrator, can carry system-level permissions plus project-level permissions across multiple projects at once, making it capable of far more than any single project-scoped robot. Harbor sets a robot account token to expire after 30 days by default, but the system-wide expiry period can be changed and any individual robot can instead be marked Never Expired, so a broadly scoped credential created for a one-off task can keep working indefinitely if nobody revokes it. We test which system-wide robot accounts exist, what they can actually reach across projects, and their real expiry setting.

HB-07

Content Trust: Cosign and Notation Signing

Harbor supports content trust through integrations with Cosign and Notation, and a Project Admin can enforce content trust on a project so every artifact has to be signed before it can be pulled from it. Where enforcement is off, or a project’s signing policy was set up once and never revisited, an unsigned image can still be pushed and pulled like any other, regardless of whether the deployment pipeline downstream expects signing to be in place. We test whether content trust enforcement is actually switched on for every project that should require it, and verify what happens when an unsigned artifact is pushed.

HB-08

Vulnerability Scanning and Deployment Security Gating

Harbor’s supported scanner, Aqua Trivy, can scan an image on push or on a schedule, and a project’s deployment security setting can block a pull outright once a vulnerability at or above a chosen severity is found, though Harbor’s own documentation notes this policy is applied per referenced image inside a multi-platform OCI index rather than to the index as a whole, and that Helm charts cannot be scanned by Trivy at all. A project where automatic scanning or the pull-blocking policy was never turned on lets a vulnerable image sit and be pulled exactly like a clean one. We test whether scanning and deployment security gating are actually enabled per project, and confirm what artifact types the configured scanner does and does not cover.

HB-09

Replication Rules Between Registries

A replication rule filters resources to copy by name, tag, label or resource type using wildcard patterns, and runs on a manual trigger, a schedule, or an event-based trigger fired by a push, retag or deletion; Harbor’s documentation notes that changing a label never fires an event-based rule, only those three actions do. A push-based rule also lets you choose a destination namespace and how far to flatten the image hierarchy on the way there, and a badly scoped filter can replicate far more, or far less, than the business assumes is being mirrored. We test every replication rule’s filters, trigger type and destination against what your team believes is being kept in sync.

HB-10

Helm Charts and OCI Artifact Index Coverage

Harbor treats a Helm chart as an OCI artifact like any image, but its supported scanner, Aqua Trivy, does not have the metadata support to scan a Helm chart for vulnerabilities at all, and a multi-platform OCI image index is scanned and policed per referenced platform image rather than as a single unit. That means a Helm chart pushed into a project with deployment security enabled can still be pulled with zero scan coverage, and an index built for a Kubernetes deployment can pass policy on one platform’s image while a different platform’s image in the same index fails it. We test what artifact types are actually reaching your registry unscanned, and whether that gap lines up with what a Kubernetes or OpenShift cluster ends up pulling.

OUR PROCESS

Harbor Security Review: From Scope to Attestation

01

Scope and Access

We agree which Harbor projects, robot accounts and roles are in scope, plus a login or token for each role tier and robot type in use.

02

Role and Access Mapping

We map every project role, robot account, authentication backend, replication rule and signing policy against what it actually grants.

03

Manual Testing

A CREST-certified tester manually tests RBAC boundaries, robot account scope, authentication configuration, signing enforcement and scanning gating, chaining findings where they compound.

04

Reporting and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Harbor pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Harbor Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,740–£5,500
3 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,790–£13,390
6 to 8 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Harbor Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Harbor instance?

We need at least one login or token for each project role you use, from Limited Guest through to Project Admin, plus a system administrator account if system-wide robot accounts or global settings are in scope. A robot account token for each CI/CD integration you want tested is useful but not required to start scoping.

Will testing touch our live images or registry data?

Testing focuses on project visibility, roles, robot accounts, authentication, and signing and scanning policy rather than the contents of images you have already pushed. Where proving a finding needs a test image, a test robot account or a temporary project, we agree the exact scope with you first and remove anything we create once testing is complete.

Is this for a self-hosted Harbor instance or a managed one?

This review covers self-managed Harbor, typically run on Kubernetes or OpenShift in your own environment or cloud account. Where Harbor sits on top of a managed Kubernetes service such as EKS, AKS or GKE, we scope that platform separately alongside this review.

How long does a Harbor security review take?

A single Harbor instance with a typical number of projects and robot accounts sits in our 3-day single-registry scope, with a report landing around 5 working days after kickoff. An instance running many projects, a large number of robot accounts or multiple replication targets extends that scope.

What is out of scope for a single-registry review?

Testing Harbor’s own source code, container runtime or the underlying Kubernetes cluster it runs on is not included; those are scoped separately under our Kubernetes penetration testing or the relevant cloud platform review. Denial-of-service testing against the registry is not part of this engagement.

Do you need our source code or admin access?

No. We test with the role-scoped logins and robot account tokens you provide, and we only need administrator access to verify a specific finding, such as a global setting, during the engagement itself.

Does Harbor have a policy on customer penetration testing?

Self-managed Harbor is software you run yourself, so there is no vendor notification process to follow before testing your own instance. Where a genuine vulnerability is found in Harbor’s own open-source code rather than your configuration, it is reported through the project’s published security process instead of tested against directly.

Are your testers CREST certified?

Yes. Every Harbor engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Harbor registry

A public Harbor project or an over-permissioned robot account can leak the images your Kubernetes clusters pull into production. We test project visibility, RBAC roles and robot accounts on your registry. CREST-certified testers, fixed price from £3,740 for a 3-day single-registry scope, quoted within 24 hours.