Member CRD¶
A Member custom resource represents membership of a user or group in a Harbor project with a specific role (admin, developer, guest, etc.).
The operator ensures that the corresponding project member exists in Harbor.
Quick Start¶
Example: user member¶
apiVersion: harbor.harbor-operator.io/v1alpha1
kind: Member
metadata:
name: my-project-alice
spec:
harborConnectionRef:
name: my-harbor
kind: HarborConnection
creationPolicy: Create
projectRef:
name: my-project
# Role within the project. The operator converts this to Harbor's role ID.
role: "developer"
memberUser:
userRef:
name: alice
Example: group member¶
apiVersion: harbor.harbor-operator.io/v1alpha1
kind: Member
metadata:
name: my-project-dev-group
spec:
harborConnectionRef:
name: my-harbor
kind: HarborConnection
projectRef:
name: my-project
role: "maintainer"
memberGroup:
groupRef:
name: dev-team
Key Fields¶
-
spec.harborConnectionRef (object, required) Reference to the Harbor connection object to use. Set
nameand optionalkind(HarborConnectionby default orClusterHarborConnection). -
spec.projectRef (object, required) Project custom resource reference.
-
spec.role (string, required) Human-readable role name. The operator maps this to a Harbor role ID, e.g.:
-
admin→ 1 developer→ 2guest→ 3maintainer→ 4
(Exactly as implemented in your controller.)
-
spec.memberUser (object, optional) References the
Usercustom resource to grant membership to. -
spec.memberGroup (object, optional) References the
UserGroupcustom resource to grant membership to.
Exactly one of memberUser or memberGroup should be set.
- spec.creationPolicy (string, optional)
Controls whether the membership is created, adopted, or either. When omitted, uses the operator's default creation policy (
Createunless configured otherwise).
Common Fields¶
Member embeds HarborSpecBase. See Common Spec Fields
for the shared connection, deletion, and reconciliation controls, or jump to the
generated HarborSpecBase reference.
Behavior¶
-
Create
-
Converts
roleto Harbor’s role ID. - Calls Harbor’s project membership API with either
member_userormember_group. -
Applies
creationPolicywhen a matching membership already exists or is absent. -
Update
-
Changing
rolewill update the member’s role in Harbor (if supported by your client). -
Changing member identity is typically treated as a delete+create scenario.
-
Delete
-
On CR deletion, the operator attempts to remove the corresponding member from Harbor.
-
Error handling
-
If Harbor returns an error (e.g. unknown user, unknown project), the operator logs the details so you can diagnose configuration issues.