Open Source

Container Registries at the Edge

Harbor Satellite extends Harbor to edge computing environments. A lightweight, standalone OCI registry at each edge location that automatically syncs images from your central registry, with zero-trust identity and fleet management.

Harbor Satellite architecture overview

Why Harbor Satellite

Extend your container registry to every edge location with reliability, security, and central management.

Reliability

Local registry at each edge location. Workloads always have access to the images they need, even when the network goes down.

Security

SPIFFE/SPIRE zero-trust identity with automatic credential rotation. No static secrets shipped to edge devices.

Fleet Management

Centrally manage image distribution across hundreds of edge locations. Group images and assign them to satellites.

Air-Gapped Ready

Works without internet. Images are served from the local Zot registry. Replication resumes automatically when connectivity returns.

CRI Integration

Auto-configure containerd, Docker, CRI-O, and Podman to use the local registry as a mirror with upstream fallback.

Lightweight

Single binary with an embedded Zot OCI registry. Minimal resource footprint for constrained edge environments.

Join the Community

Harbor Satellite is part of the Harbor CNCF project. Connect with us.

CNCF Slack

Join #harbor-satellite on the CNCF Slack for questions, discussions, and support.

Join Slack Channel →

GitHub

Star the repo, report issues, and contribute to Harbor Satellite.

View Repository →

Harbor Project

Harbor Satellite extends the Harbor container registry. Learn more about the broader project.

Harbor Community →