https://github.com/goharbor/harbor/blob/master/docs/configure_https.mdhtml
./install.sh --with-notary git
开启https后,客户端需把ca.crt 复制到 /etc/docker/certs.d/domain.com(或ip)/ 和$HOME/.docker/tls/domain.com(ip):4443/
github
若是要启用内容信任以确保图像已签名,请在推送或拉取任何图像以前在命令行中设置两个环境变量 参考: https://github.com/goharbor/harbor/blob/master/docs/user_guide.md#content-trust
docker
export DOCKER_CONTENT_TRUST=1 export DOCKER_CONTENT_TRUST_SERVER=https://ip:4443
docker build --disable-content-trust=false -t xxx
.请参阅Docker的文档:https://docs.docker.com/engine/security/trust/content_trust/dom