Accessing the Geddes2 Harbor Container Registry¶
Overview¶
The Geddes2 Harbor container registry uses Purdue OIDC (Single Sign-On) for web interface access.
Because container tools like Docker cannot authenticate directly via browser-based OIDC logins, you must use a Harbor CLI Secret as your password when authenticating over the command line.
1. Log In to the Harbor Web UI¶
- Go to the registry interface: https://geddes2-registry.rcac.purdue.edu
- Click LOGIN WITH Purdue Account.
- Log in with your standard Purdue credentials:
- Username:
<username>@purdue.edu - Password: Your Purdue account password (MFA App or Duo authentication if prompted).
2. Retrieve Your Harbor CLI Secret¶
- Once logged in, click your account profile in the top-right corner.
- Select User Profile.
- Locate the CLI Secret field.
- Click the copy icon to copy your secret (or generate a new one if it is blank).
Important: Your CLI Secret functions as your password for CLI access. Never share it or commit it to public repositories.
3. Log In via Docker CLI¶
Open your terminal and initiate login:
Provide your Purdue email address and Harbor CLI Secret when prompted:
Upon successful authentication, you will see:
4. Quick Authentication Summary¶
| Interface | URL / Command | Username | Password |
|---|---|---|---|
| Harbor Web UI | https://geddes2-registry.rcac.purdue.edu | <username>@purdue.edu |
Purdue Account Password |
| Docker / CLI | docker login geddes2-registry.rcac.purdue.edu |
<username>@purdue.edu |
Harbor CLI Secret |
Note: Do not use your standard Purdue account password for
docker login.
5. Pulling and Pushing Images¶
Pull an Image¶
Example:
Push an Image¶
6. Logging Out¶
To remove stored registry credentials from your local machine:
7. Troubleshooting¶
unauthorized: authentication required
- Verify that you are entering your full Purdue email (
<username>@purdue.edu) as the username. - Ensure you entered your Harbor CLI Secret and not your Purdue login password.
- Try logging out (
docker logout geddes2-registry.rcac.purdue.edu) and runningdocker loginagain.
denied: requested access to the resource is denied
- Your login succeeded, but your account lacks permissions for the specified project or repository.
- Contact the project administrator or RCAC support to request access to the project namespace.