All Products
Search
Document Center

Security Center:Add image repositories to Security Center

Last Updated:Sep 14, 2026

Before you scan container images for security risks, you must add image repositories to Security Center. This topic describes how to add image repositories to Security Center.

Image limitations

Security Center supports the following container image repositories:

  • Alibaba Cloud Container Registry (ACR): Enterprise Edition and Personal Edition.

    Security Center synchronizes image data from both ACR Enterprise Edition and Personal Edition, but only supports security scanning for ACR Enterprise Edition images.

  • Third-party image repositories (private image repositories): Harbor, Quay, and GitLab.

Prerequisites

The container image scan feature is enabled. For more information, see Purchase Security Center or Enable container image scan.

Add Alibaba Cloud Container Registry image repositories

ACR Personal Edition instances have no restrictions and can be added to Security Center after creation. To add ACR Enterprise Edition image repositories to Security Center, you only need to add a VPC to the ACR Enterprise Edition instance. For more information, see Configure VPC access control.

Security Center supports the following methods to synchronize image data from ACR Enterprise Edition and Personal Edition:

  • Automatic synchronization: Security Center synchronizes image data from ACR daily in the early morning by default.

  • Manual synchronization of latest assets: For more information, see Synchronize assets.

Add a third-party image repository (private image repository)

If your container image repository has an access control policy configured, make sure you have added the IP address pool IPs for the region of your image repository to the access control whitelist.

View IP addresses to add to the whitelist

Region

Public IP address

Private IP address

China (Hangzhou)

47.96.166.214

100.104.12.64/26

China (Shanghai)

139.224.15.48, 101.132.180.26, 47.100.18.171, 47.100.0.176, 139.224.8.64, 101.132.70.106, 101.132.156.228, 106.15.36.12, 139.196.168.125, 47.101.178.223, 47.101.220.176

100.104.43.0/26

China (Qingdao)

47.104.111.68

100.104.87.192/26

China (Beijing)

47.95.202.245

100.104.114.192/26

China (Zhangjiakou)

39.99.229.195

100.104.187.64/26

China (Hohhot)

39.104.147.68

100.104.36.0/26

China (Shenzhen)

120.78.64.225

100.104.250.64/26

China (Guangzhou)

8.134.118.184

100.104.111.0/26

China (Hong Kong)

8.218.59.176

100.104.130.128/26

Japan (Tokyo)

47.74.24.20

100.104.69.0/26

Singapore

8.219.240.137

100.104.67.64/26

US (Silicon Valley)

47.254.39.224

100.104.145.64/26

US (Virginia)

47.252.4.238

100.104.36.0/26

Germany (Frankfurt)

47.254.158.71

172.16.0.0/20

UK (London)

8.208.14.12

172.16.0.0/20

Indonesia (Jakarta)

149.129.238.99

100.104.193.128/26

  1. If your third-party image service is deployed in a hybrid cloud setup (on-premises IDC + cloud VPC), you must configure traffic forwarding rules. Designate an ECS instance and forward its traffic to the IDC server where the third-party image service is hosted.

    Example: Forward traffic from Port A on the ECS instance to Port B on the IDC server at 192.168.XX.XX.

    • CentOS 7 commands:

      • Using firewall-cmd:

        firewall-cmd --permanent --add-forward-port=port=<Port A>:proto=tcp:toaddr=<192.168.XX.XX>:toport=<Port B>
      • Using iptables:

        1. Enable port forwarding.

          echo "1" > /proc/sys/net/ipv4/ip_forward
        2. Configure port forwarding.

          iptables -t nat -A PREROUTING -p tcp --dport <Port A> -j DNAT --to-destination <192.168.XX.XX>:<Port B>
    • Windows command:

      netsh interface portproxy add v4tov4 listenport=<Port A> listenaddress=* connectaddress=<192.168.XX.XX> connectport=<Port B> protocol=tcp
  2. Log on to Security Center console.

  3. In the left-side navigation pane, choose Asset Center > Container. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  4. On the Container page, click the Image tab, locate the Add Third-party Image Repository section, and click Add.

  5. In the Add Image Repository panel, configure the parameters for your private repository, and then click OK.

    Parameter

    Description

    Private Repository Type

    Select the type of private repository based on where your container images are stored. Valid values: harbor, quay, gitlab.

    Version

    Select the version of the third-party image repository. Valid values:

    • Version: Select this version if the image repository version is 1.X.X.

    • V2: Select this version if the image repository version is 2.X.X or later.

    Private Repository Type is set to gitlab, V1 is selected by default and cannot be changed.

    Communication Type

    Select the communication protocol between Security Center and the third-party image repository. Valid values: http, https.

    Network Type

    Select the network type of the third-party image repository. Valid values: Public, VPC.

    RegionId

    Select the region where the third-party image repository is located.

    IP

    Enter the IP address and port number of the third-party image repository. If you configured traffic forwarding rules for the third-party image repository, enter the IP address and port number of the ECS instance with forwarding rules configured.

    Port

    Domain Name

    Enter the domain name of the third-party image repository.

    Speed Limit

    Select the maximum number of images that can be synced per hour. Default value: 10.

    Important

    If too many images are synced per hour, your normal business operations may be affected. We recommend that you do not select Unlimited.

    Username

    Enter the username with administrator permissions used to access the third-party image repository.

    Password

    Enter the password for accessing the third-party image repository.

    Quay Namespace Information

    This parameter is required only when Private Repository Type is set to quay.

    In the Image Repository Organization text box, enter the name of the image repository organization. In the Auth_token text box, enter the Auth_token of the image repository organization.

    You can click Add to add multiple image repository organizations.

    GitLab Group Information

    This parameter is required only when Private Repository Type is set to gitlab.

    In the Group Information text box, enter the group name. In the Logon-free Configuration text box, enter the Access_token of the group.

    You can click Add to add multiple image repository groups.

    After you add a third-party image repository, you can go to the Protection Configuration > Container Protection > Container Image Scan page and click Scan Settings in the upper-right corner to view the information about the connected image repositories in the Scan Settings panel.

Image repository connection error codes

Code

Message

Solution

FailedToVerifyUsernameOrPwd

Username or password is invalid.

Check whether the username and password are correct.

RegistryVersionError

The version of the image repository is invalid.

Check whether the selected version (V1 or V2) matches your registry version.

UserDoesNotHaveAdminRole

You do not have administrative rights.

Log in to the Harbor server and grant the account administrative rights.

NetworkConnectError

The network connection timed out. Check network connectivity and verify that port 80 or port 443 is open.

Check whether the network is connected and port 80 or 443 is open.

What to do next

After you add image repositories to Security Center, you can view information about images protected by Security Center in Asset Center. For more information, see View container security status.

You must also perform an image security scan to detect risks in your images through Security Center. For more information, see Configure and run image security scans.