All Products
Search
Document Center

Container Registry:Image replication and geo-disaster recovery with Harbor in ACR Enterprise Edition

Last Updated:Sep 21, 2026

Use Harbor remote replication for one-way image replication from a self-managed Harbor registry to a Container Registry (ACR) Enterprise Edition instance. Add a custom domain name for geo-disaster recovery of the container image registry.

Note

If you prefer not to use the remote replication feature of Harbor, or if replication speed is critical, see Migrate self-managed Harbor to ACR Enterprise Edition.

Prerequisites

An ACR Enterprise Edition instance is created. For more information, see Create an Enterprise Edition instance.

Procedure

Replicate Harbor images to an Enterprise Edition instance

If the Harbor registry is deployed in an on-premises data center, you must first connect the data center to your VPC on Alibaba Cloud. For more information, see Access an Enterprise Edition instance across regions or from a data center.

Step 1: Create a namespace

  1. Log on to the Container Registry console.

  2. In the top navigation bar, select a region.

  3. In the left-side navigation pane, click Instances.

  4. On the Instances page, click the destination Enterprise Edition instance.

  5. On the management page of the Enterprise Edition instance, choose Repository > Namespace.

  6. On the Namespace page, click Create Namespace.

  7. In the Create Namespace sidebar, specify the Namespace name and select On or Off for Automatically Create Repository. Then, click Confirm.

    Parameter

    Description

    Namespace

    Enter the name of the Harbor project that you want to replicate, such as test-project.

    Automatically Create Repository

    Select On.

    Note

    If you select Off, you must create the corresponding repository in the namespace before replicating images.

Step 2: Configure the destination repository in Harbor

  1. Log on to Harbor.

  2. In the left-side navigation pane, choose Administration > Registries.

  3. On the Registries page, click NEW ENDPOINT.

  4. In the New Registry Endpoint dialog box, configure the parameters described in the following table:

    Parameter

    Description

    Provider

    Select Docker Registry.

    Name

    Enter a name for the new endpoint.

    Description

    Enter a description for the new endpoint.

    Endpoint URL

    Enter the endpoint of the destination repository on the Enterprise Edition instance, and make sure that access control is enabled. For more information, see Configure VPC access control and Configure Internet access.

    • VPC:

      Example: https://<Name of the Enterprise Edition instance>-registry-vpc.cn-qingdao.cr.aliyuncs.com.

    • Internet:

      Example: https://<Name of the Enterprise Edition instance>-registry.cn-qingdao.cr.aliyuncs.com.

    Access ID

    Enter the logon name of the destination repository, which is your Alibaba Cloud account name.

    Access Secret

    Enter the password that you use to access the destination repository. For more information, see Use a permanent password.

  5. Select the Verify Remote Cert checkbox and click TEST CONNECTION. If the Connection tested successfully message appears, the parameters that you entered are valid. Click OK.

Step 3: Configure a replication rule

  1. Log on to Harbor.

  2. In the left-side navigation pane, choose Administration > Replications.

  3. On the Replications page, click NEW REPLICATION RULE.

  4. In the New Replication Rule dialog box, configure the parameters described in the following table. Then, click Save.

    Parameter

    Description

    Name

    Enter a name for the replication rule.

    Description

    Enter a description for the replication rule.

    Replication mode

    Select Push-based.

    Source resource filter

    Filter the resources that you want to replicate as prompted in the Harbor UI. By default, all resources are replicated.

    Destination registry

    Select the endpoint that you created in Step 2.

    Destination

    In the Namespace field, enter the namespace that you created in Step 1 on the Enterprise Edition instance. Flattening reduces the repository hierarchy during replication. Select Flatten 1 Level. Example: harbor-project/nginx -> acr-ns/nginx.

    Trigger Mode

    Specify a trigger mode. Select Event-driven Operations to synchronize image changes in Harbor.

    Bandwidth

    Limits the maximum network bandwidth during replication. The default value -1 indicates no limit.

  5. On the Replications page, select the rule that you created in the previous step and click REPLICATE to manually replicate existing Harbor images to the Enterprise Edition instance. The replication task list shows the task ID, status (Succeeded or Failed), trigger mode, and duration of each task. When the task status changes to Succeeded, the images are replicated. Subsequent changes to the Harbor repository are replicated to the Enterprise Edition instance based on events.

Configure a custom domain name for geo-disaster recovery

ACR Enterprise Edition supports adding a custom domain name and an SSL certificate to an instance. The custom domain name then enables HTTPS access to the instance.

Choose one of the following disaster recovery solutions based on your network environment.

Use case 1: Harbor is deployed on Alibaba Cloud and applications access the instance over the Internet

In this example, the Enterprise Edition instance resides in the China (Hangzhou) region and the Harbor registry resides in the China (Zhangjiakou) region. Both use the same custom domain name, for which PrivateZone is configured. For information about how to configure PrivateZone, see Accessing an instance with a custom domain name.

The following table describes the basic information about the two registries:

Instance ID

Public Endpoint

Associated VPC

Custom Domain Name

ACR-A

a-registry.cn-hangzhou.cr.aliyuncs.com

vpc-aaaaa

cross-region.registry.io

Harbor-B

-

vpc-bbbbb

cross-region.registry.io

If the Harbor registry in the China (Zhangjiakou) region fails, applications cannot push or pull images. Modify the PrivateZone record for the custom domain name to pull the synchronized images from the Enterprise Edition instance in another region. Perform the following steps:

  1. Log on to the Alibaba Cloud DNS console.

  2. In the left-side navigation pane, click Private Zone.

  3. On the Authoritative Zone tab, enter the custom domain name cross-region.registry.io to search for zones. Two zones are returned. Click the zone associated with the vpc-bbbbb VPC.

  4. On the Resource Record Settings tab, find the record that you want to edit and click Modify in the Actions column.

  5. In the Modify Record panel, configure the parameters described in the following table. Then, click Confirm.

    Parameter

    Description

    Record Type

    Select CNAME.

    Hostname

    Set this parameter to @.

    Record Value

    Set this parameter to the public endpoint of the Enterprise Edition instance: a-registry.cn-hangzhou.cr.aliyuncs.com.

    TTL

    Retain the default value.

Use case 2: Harbor is not deployed on Alibaba Cloud and applications access the instance over the Internet

Set the custom domain name of the Enterprise Edition instance to the domain name that the self-managed Harbor registry uses, such as www.ha****.com. For more information, see Accessing an instance with a custom domain name.

If the Harbor registry fails, applications cannot push or pull images. Modify the DNS resolution so that the Harbor domain name, such as www.harbor.com, resolves to the public IP address of the Enterprise Edition instance. Applications can then access the instance over the Internet to push and pull images.

Use case 3: Harbor is not deployed on Alibaba Cloud and applications access the instance over a VPC

If the Harbor registry fails, applications cannot push or pull images. Obtain the IP address of the Enterprise Edition instance. Configure a route and DNS resolution so that the Harbor domain name, such as www.harbor.com, resolves to that IP address. Applications can then access the instance over the VPC to push and pull images. For more information, see Access an Enterprise Edition instance across regions or from a data center.