启用OIDC的Harbor实例Docker登录失败:认证未授权求助
问题现象
部署启用OIDC认证的Harbor实例后,Web门户可正常登录,但执行docker login时失败,报错:
Error response from daemon: Get "https://myharborurl": unauthorized: authentication required
查看core.log发现两条关键错误:
Jul 19 16:42:41 xxxxxxxx core[2104879]: 2023-07-19T16:42:41Z [ERROR] [/server/middleware/security/oidc_cli.go:62][requestID="1fc3f9c5-b2e3-4e0c-9c31-a6bee346b741"]: failed to verify secret, username: 'myname@mycompany.com', error: failed to get oidc user info, error: no row found
Jul 19 16:42:41 xxxxxxxx core[2104879]: 2023-07-19T16:42:41Z [ERROR] [/server/middleware/security/basic_auth.go:72][client IP="10.91.17.18" requestID="1fc3f9c5-b2e3-4e0c-9c31-a6bee346b741" user agent="docker/24.0.2 go/go1.20.4 git-commit/659604f kernel/5.10.102.1-microsoft-standard-WSL2 os/linux arch/amd64 UpstreamClient(Docker-Client/24.0.2 (windows))"]: failed to authenticate user:'myname@mycompany.com', error:not supported
原因分析
- 用户本地记录缺失:OIDC用户首次通过Web门户登录前,Harbor本地数据库不会生成该用户的条目,导致CLI认证时提示
no row found。 - 认证方式不兼容:
docker login默认使用Basic Auth认证,但OIDC用户默认未启用该认证方式,因此报错not supported。
解决步骤
1. 完成OIDC用户首次Web登录
先通过Web门户登录一次目标OIDC账户,Harbor会自动在本地数据库创建该用户的记录,这是CLI认证的前提。
2. 配置CLI认证方式
推荐两种方式:
方式一:创建机器人账户(权限更可控,推荐)
- 登录Harbor Web门户,进入用户管理 > 机器人账户
- 点击新建机器人,填写机器人名称(如
cli-robot-myname),选择关联项目并设置对应权限(如推送/拉取),设置有效期 - 生成令牌后,执行以下命令登录:
docker login myharborurl -u robot$cli-robot-myname -p <生成的令牌>
方式二:为OIDC用户设置本地密码
- 登录Harbor Web门户,进入用户管理 > 用户,找到对应的OIDC用户
- 点击编辑按钮,设置本地密码(该密码仅用于CLI认证,不影响OIDC Web登录)
- 使用OIDC用户名和设置的本地密码执行登录:
docker login myharborurl
3. 验证Harbor配置
检查Harbor配置文件(如harbor.yml)中的OIDC相关设置:
- 确保
oidc_auto_onboard: true(默认开启),保证用户首次Web登录时自动创建本地记录 - 确认
auth_mode: oidc_auth,避免混合认证模式导致冲突
内容的提问来源于stack exchange,提问作者JakeUT

