If you’ve ever deployed Harbor Container Registry on Kubernetes, you know it’s an incredibly powerful tool. But you also know that it has a lot of moving parts. A standard Harbor deployment consists of multiple Deployments and StatefulSets: harbor-core, harbor-jobservice, harbor-portal, registry, trivy, redis, and a database.
When everything is running smoothly, Harbor is a joy to use. But what happens when the harbor-jobservice quietly crashes? Your images stop being scanned for vulnerabilities, replication policies fail, and you might not notice until a developer complains hours later.
You need a way to monitor pod availability.
The industry standard is to deploy Prometheus, set up Grafana, write PromQL queries, configure Alertmanager, and maintain all of this infrastructure. If you just want to answer the simple question: "Are my Harbor pods actually running?", this feels like massive overkill.
I wanted a simpler solution. I didn't want to install more heavy monitoring agents inside my cluster just to check if my pods were alive.
That’s why I used AliveSignal to monitor the entire Harbor namespace using a zero-agent, heartbeat-based approach. The best part? It took me exactly 60 seconds. Here is how you can do it too.
The Push vs. Pull Paradigm
Traditional monitoring systems (like Prometheus) use a Pull model. A central server scrapes metrics from your pods. This requires your pods to expose metric endpoints and often requires a dedicated agent running on your cluster nodes.
AliveSignal flips this into a Push model (Heartbeat monitoring). Instead of constantly asking the cluster "Are you okay?", we run a tiny, lightweight, concurrent CronJob inside the cluster that simply pings AliveSignal every minute: "I'm okay!".
If AliveSignal doesn't receive the ping, it alerts you immediately via Email or Webhook.
Step-by-Step: Automating Harbor Health Checks
Usually, setting up individual heartbeat monitors for 7 different deployments is tedious. But AliveSignal has a feature called Kubernetes Auto-Discovery that makes this feel like magic.
Here is the exact workflow.
Step 1: Export your Harbor Namespace
First, we tell Kubernetes to give us the current state of all Deployments and StatefulSets in the Harbor namespace, formatted as JSON.
Run this command in your terminal:
kubectl get deploy,sts -n harbor -o json > harbor.json
(Make sure to replace -n harbor with your actual namespace if it differs).
Step 2: Upload to AliveSignal
Log into your AliveSignal Dashboard. Click on "K8s Auto-Discovery" and upload the harbor.json file you just generated.
Instantly, AliveSignal parses the JSON and detects every single component of your Harbor registry. It automatically creates a separate monitor for harbor-core, harbor-jobservice, trivy, and so on. You don't have to type a single monitor name.
Step 3: Apply the Zero-Agent Manifest
Once the monitors are created, AliveSignal generates a custom Kubernetes manifest file for you: monitoring.yaml.
This file contains a lightweight Kubernetes CronJob. It doesn't require any special permissions (no heavy RBAC, no ClusterRoles) and doesn't run as a DaemonSet. It simply uses curl to concurrently ping the unique URLs for each of your newly created monitors based on pod availability.
Download the file and apply it to your cluster:
kubectl apply -f monitoring.yaml -n harbor
serviceaccount/dms-monitor-sa created
role.rbac.authorization.k8s.io/dms-monitor-role created
rolebinding.rbac.authorization.k8s.io/dms-monitor-rolebinding created
configmap/dms-monitor-config created
cronjob.batch/dms-monitor-cronjob created
That’s it. You are done.
The Result
Within 5 minutes, your AliveSignal dashboard will light up green. You now have deep visibility into your Harbor infrastructure without having installed a single heavy agent.
If the Kubernetes scheduler fails to start your trivy scanner pod, or if your harbor-core pod gets stuck in a CrashLoopBackOff, the internal CronJob will detect the missing pod, stop sending the ping for that specific component, and AliveSignal will alert you before your users notice.
Bonus: Instant Public Status Pages
Because you are running an infrastructure tool that your whole engineering team relies on, transparency is key.
With AliveSignal, you can take those newly created Harbor monitors and instantly publish them to a Public Status Page. Out-of-the-box, it supports custom domains and Dark Mode. You can link this Status Page in your internal developer documentation, so your team always knows if the Container Registry is healthy.
Conclusion
Monitoring doesn't always have to mean maintaining complex metric stacks. For many critical workloads, simple heartbeat monitoring is not just easier to set up—it's more reliable, because it exists completely outside of the infrastructure it is monitoring.
If you want to secure your Harbor Registry, Apache Airflow, or any other complex Kubernetes workload in under a minute, give AliveSignal a try. It’s built for developers who want peace of mind, without the maintenance overhead.






Top comments (0)