Registry access
This guide explains how to pull TokenTimer Enterprise container images and the
Helm chart from the private TokenTimer registry at harbor.tokentimer.ch.
What you receive from TokenTimer
When your enterprise license is issued you also receive a one-time
credentials file (.creds.txt) containing:
| Field | Example | Purpose |
|---|---|---|
| Robot username | robot$tokentimer-enterprise+customer-acme-001 | Identity for docker login and helm registry login |
| Robot token | a long opaque string | Password for the robot account |
| Expiry date | 2027-04-09 | Matches the validity of your license |
| Registry URL | harbor.tokentimer.ch | Endpoint to authenticate against |
| Project | tokentimer-enterprise | Path prefix for all enterprise artifacts |
The token grants pull-only access scoped to the tokentimer-enterprise
project. It cannot push, mutate, or list any other project. The token is
displayed once at issuance and is never recoverable from Harbor afterwards;
store it in a secret manager (1Password, Vault, AWS Secrets Manager).
The same credentials let you pull three kinds of artifact from Harbor:
| Artifact | Path | Used by |
|---|---|---|
| Container images | harbor.tokentimer.ch/tokentimer-enterprise/tokentimer-enterprise-{api,worker,dashboard} | Docker, containerd, Kubernetes nodes |
| Helm chart (OCI) | oci://harbor.tokentimer.ch/tokentimer-enterprise/charts/tokentimer-enterprise | helm pull and helm install |
| Delivery tarball (OCI generic) | harbor.tokentimer.ch/tokentimer-enterprise/bundles/tokentimer-enterprise | oras pull (Compose file, env template, Helm values, docs) |
Network requirements
- Outbound HTTPS to
harbor.tokentimer.ch:443from every node that will run TokenTimer Enterprise pods, plus the workstation runninghelm pull. - The TLS certificate is issued by Let's Encrypt; no custom CA bundle is required.
1. Pull the Helm chart
The chart is published as an OCI artifact. Use Helm 3.14 or newer.
helm registry login harbor.tokentimer.ch \
-u 'robot$tokentimer-enterprise+customer-acme-001' \
-p '<robot-token>'
helm pull oci://harbor.tokentimer.ch/tokentimer-enterprise/charts/tokentimer-enterprise \
--version 0.8.2
This downloads tokentimer-enterprise-0.8.2.tgz to the working directory. The chart bundles the core subchart, so no separate tokentimer-core install is required. Inspect the full values schema (enterprise keys plus tokentimer: subchart defaults) with:
helm show values ./tokentimer-enterprise-0.8.2.tgz
On an existing release: helm get values tokentimer -n tokentimer -a.
1b. Pull the delivery tarball (for upgrades)
Your initial license delivery already contains tokentimer-enterprise-<version>.tar.gz (Compose file, env template, Helm value examples and defaults, and documentation). It does not ship the Helm chart tarball; pull the chart separately (section 1) when you need helm show values or an air-gapped install artifact. For ongoing upgrades you can re-pull the bundle from Harbor using ORAS and the same robot credentials:
oras login harbor.tokentimer.ch \
-u 'robot$tokentimer-enterprise+customer-acme-001' \
-p '<robot-token>'
oras pull harbor.tokentimer.ch/tokentimer-enterprise/bundles/tokentimer-enterprise:0.2.0
tar -xzf tokentimer-enterprise-0.2.0.tar.gz -C /opt/tokentimer
The artifact mediaType is application/vnd.tokentimer.bundle.v1+tar+gzip. The latest tag always points at the most recent published version.
2. Create the image pull Secret
The chart references an imagePullSecret named tokentimer-enterprise-registry.
Create it in the namespace where you intend to install:
kubectl create namespace tokentimer
kubectl create secret docker-registry tokentimer-enterprise-registry \
--docker-server=harbor.tokentimer.ch \
--docker-username='robot$tokentimer-enterprise+customer-acme-001' \
--docker-password='<robot-token>' \
-n tokentimer
If you prefer a GitOps-friendly workflow, generate the manifest with
--dry-run=client -o yaml and store the result alongside your other secrets
(SOPS, Sealed Secrets, External Secrets Operator).
3. Install the chart
The chart's default values already point at harbor.tokentimer.ch and at the
secret created above. A minimal install looks like:
helm install tokentimer ./tokentimer-enterprise-0.8.2.tgz \
-n tokentimer --create-namespace \
-f my-values.yaml \
--set license.create=true \
--set-file license.content=./license.key
Use the example value files under helm/examples/ in the delivery as a starting point.
4. Verifying pulls
kubectl -n tokentimer get pods
kubectl -n tokentimer describe pod <pod-name> | grep -E 'Image|Events'
kubectl -n tokentimer get events --sort-by=.lastTimestamp
A successful pull shows Successfully pulled image "harbor.tokentimer.ch/...
in the events. If you see ImagePullBackOff or ErrImagePull, see the
troubleshooting section below.
5. Rotating credentials at renewal
When you renew your license, TokenTimer issues a new robot account; the old one is left in place until it expires naturally so there is no service gap.
Update the Kubernetes Secret in place:
kubectl create secret docker-registry tokentimer-enterprise-registry \
--docker-server=harbor.tokentimer.ch \
--docker-username='robot$tokentimer-enterprise+customer-acme-001' \
--docker-password='<new-token>' \
-n tokentimer \
--dry-run=client -o yaml | kubectl apply -f -
Pods only re-authenticate to the registry on the next image pull. To force a
fresh pull (e.g. for a chart upgrade), simply run helm upgrade or restart
the deployments.
If your license is revoked or terminated, ask TokenTimer to delete the robot account; once deleted, no further pulls succeed.
6. Troubleshooting
unauthorized: authentication required
- Ensure you used the full robot username including the
robot$prefix and the project namespace, e.g.robot$tokentimer-enterprise+customer-acme-001. - Confirm the token has not expired (check the
Expiry datefield on your delivery file). - Test interactively with
docker login harbor.tokentimer.ch -u <robot> -p <token>.
denied: requested access to the resource is denied
The robot is project-scoped. You can only pull from
harbor.tokentimer.ch/tokentimer-enterprise/.... Pulling from any other path
is denied by design.
ImagePullBackOff
kubectl -n tokentimer describe pod <pod>
Common causes:
- Pull secret missing in the namespace, or named differently. The chart
expects
tokentimer-enterprise-registry. Override with--set tokentimer.global.imagePullSecrets[0].name=<your-secret-name>. - Pull secret created in the wrong namespace. The Secret must live in the same namespace as the workload.
TLS / certificate errors
If your cluster sits behind a TLS-intercepting corporate proxy, add the proxy CA to each node's container runtime trust store. TokenTimer images are served with a public Let's Encrypt certificate and require no custom CA otherwise.
helm pull returns 404
Verify the chart version exists:
curl -sSf -u 'robot$tokentimer-enterprise+customer-acme-001:<token>' \
https://harbor.tokentimer.ch/api/v2.0/projects/tokentimer-enterprise/repositories/charts%2Ftokentimer-enterprise/artifacts \
| jq '.[].tags'
Reference
- Architecture overview: Architecture
- Helm chart values reference:
helm/values.yamlin the chart - Example value files:
helm/examples/in the delivery tarball