# k3s containerd registry config — apply on each node at /etc/rancher/k3s/registries.yaml # Proxy-cache only works through harbor-core (not harbor-registry or Traefik /v2/ alone). # # Apply: ./scripts/apply-k3s-registries.sh # Harbor EXT_ENDPOINT should be http://registry.abrban.com so OAuth realm uses HTTP # (kubelet mirror hits harbor-core on :80; https://:443 times out). mirrors: registry.abrban.com: endpoint: - http://harbor-core.cloudhost.svc.cluster.local # use ClusterIP on single-node (see script) configs: registry.abrban.com: auth: username: harbor_registry_user password: REPLACE_WITH_REGISTRY_CREDENTIAL_PASSWORD