Client setup
Configure your client to pull and push artifacts.
Client Setup simplifies authentication and ensures proper configuration for different artifact types (e.g., container images, Helm charts). It also helps prevent common misconfigurations when pulling or pushing artifacts.
Client setup
On the Registries tab, select a registry of type
ARTIFACT REGISTRY, such as Docker or Maven.Select Set up client.
Follow the on-screen instructions.
Configuration steps
The Client Setup process provides step-by-step guidance, including:
Logging in to the registry.
Generating a password token.
Pulling an image or package.
Pushing an image or package.
The artifact appears in your Docker registry and on the Artifacts tab.
Authentication model
Harness Artifact Registry uses token-based authentication (PAT or service account tokens). The pipeline identity model determines which permissions apply:
Manual triggers: The pipeline uses the triggering user's RBAC permissions.
Webhook, IDP (Internal Developer Portal), or schedule triggers: The pipeline runs as a service/bot principal and uses that bot's RBAC permissions.
This applies to both image pulls (requires read access) and the Upload Artifacts to HAR CI step (requires write access). If the triggering principal lacks the appropriate permission, the operation returns a 403 error.
Token expiry and management
Tokens generated from the Setup Client page are scoped tokens with a 30-day expiry. For longer-lived tokens, generate them at the project or account level from your account settings.
Independent expiry: Each token expires based on its own creation time. Generating a new token has no effect on existing tokens.
Secure by design: The token value is shown only once at creation time. Copy and store it securely before closing the dialog.
Manage tokens: Go to Add and manage API keys to view token names, check expiration dates, or delete tokens. You can also access this from Profile Overview (bottom-left icon in the Harness UI).
Troubleshooting
Last updated
Was this helpful?