You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用OIDC的Harbor实例Docker登录失败:认证未授权求助

Harbor启用OIDC认证后Web登录正常但docker login失败的解决方案

问题现象

部署启用OIDC认证的Harbor实例后,Web门户可正常登录,但执行docker login时失败,报错:

Error response from daemon: Get "https://myharborurl": unauthorized: authentication required

查看core.log发现两条关键错误:

Jul 19 16:42:41 xxxxxxxx core[2104879]: 2023-07-19T16:42:41Z [ERROR] [/server/middleware/security/oidc_cli.go:62][requestID="1fc3f9c5-b2e3-4e0c-9c31-a6bee346b741"]: failed to verify secret, username: 'myname@mycompany.com', error: failed to get oidc user info, error: no row found
Jul 19 16:42:41 xxxxxxxx core[2104879]: 2023-07-19T16:42:41Z [ERROR] [/server/middleware/security/basic_auth.go:72][client IP="10.91.17.18" requestID="1fc3f9c5-b2e3-4e0c-9c31-a6bee346b741" user agent="docker/24.0.2 go/go1.20.4 git-commit/659604f kernel/5.10.102.1-microsoft-standard-WSL2 os/linux arch/amd64 UpstreamClient(Docker-Client/24.0.2 (windows))"]: failed to authenticate user:'myname@mycompany.com', error:not supported

原因分析

  1. 用户本地记录缺失:OIDC用户首次通过Web门户登录前,Harbor本地数据库不会生成该用户的条目,导致CLI认证时提示no row found。
  2. 认证方式不兼容:docker login默认使用Basic Auth认证,但OIDC用户默认未启用该认证方式,因此报错not supported。

解决步骤

1. 完成OIDC用户首次Web登录

先通过Web门户登录一次目标OIDC账户,Harbor会自动在本地数据库创建该用户的记录,这是CLI认证的前提。

2. 配置CLI认证方式

推荐两种方式:

方式一:创建机器人账户(权限更可控,推荐)

  • 登录Harbor Web门户,进入用户管理 > 机器人账户
  • 点击新建机器人,填写机器人名称(如cli-robot-myname),选择关联项目并设置对应权限(如推送/拉取),设置有效期
  • 生成令牌后,执行以下命令登录:
docker login myharborurl -u robot$cli-robot-myname -p <生成的令牌>

方式二:为OIDC用户设置本地密码

  • 登录Harbor Web门户,进入用户管理 > 用户,找到对应的OIDC用户
  • 点击编辑按钮,设置本地密码(该密码仅用于CLI认证,不影响OIDC Web登录)
  • 使用OIDC用户名和设置的本地密码执行登录:
docker login myharborurl

3. 验证Harbor配置

检查Harbor配置文件(如harbor.yml)中的OIDC相关设置:

  • 确保oidc_auto_onboard: true(默认开启),保证用户首次Web登录时自动创建本地记录
  • 确认auth_mode: oidc_auth,避免混合认证模式导致冲突

内容的提问来源于stack exchange,提问作者JakeUT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 14:56:33