Join our Newsletter — 33% off our NHI Course

Interrogation Services

Interrogation Services is the Harbor feature area used to register and manage external image scanners. It tells Harbor where to send scan requests and which scanner should be treated as the default for image analysis, manual scans, and scheduled scans.

What Interrogation Services Does in Harbor

Interrogation Services is Harbor’s scanner management area. It defines which external image scanners Harbor can use, where scan requests are sent, and which scanner becomes the default for manual, scheduled, and analysis-driven scans.

This makes the feature less about the scanner itself and more about the control plane around scanning. Harbor is deciding which external service it trusts for image analysis, how requests are routed, and what happens when administrators change the default scanner.

How Harbor Uses Scanner Registration and Routing

In practice, Interrogation Services acts as a configuration layer between Harbor and the scanning engines it can reach. Once a scanner is registered, Harbor can direct image checks to that service instead of treating scanning as a purely local capability.

That routing choice matters because different scanners may have different coverage, scoring models, update cadences, or output formats. A Harbor deployment can therefore produce different scan results depending on which scanner is selected, how it is configured, and whether the default is aligned with the intended security workflow.

Why the Default Scanner Setting Matters

The default scanner affects the operational path users experience most often. When a default is set for image analysis, manual scans, or scheduled scans, Harbor is effectively standardizing one analysis source for routine activity.

That reduces ambiguity for operators, but it also creates a governance decision: the chosen default becomes the scanner most teams will rely on for day-to-day decisions. If that scanner is stale, misconfigured, or no longer trusted, the impact reaches beyond one isolated job and can shape the quality of the entire registry’s scanning output.

Configuration Boundaries and Operational Context

Interrogation Services is not a vulnerability scanner by itself. It is the registry-side control surface that tells Harbor which external scanner to call, how to coordinate scan requests, and which service should anchor the scanning experience.

Because of that, the feature sits at the boundary between registry operations and security tooling integration. Its value comes from making scanner choice explicit, repeatable, and manageable rather than hard-coded or ad hoc. In environments with more than one scanner, that boundary is especially important for consistency and auditability.

Risk and Threat Considerations

When scanner registration and default selection are mismanaged, Harbor may send scan requests to the wrong service or rely on analysis that is outdated, incomplete, or no longer trusted. The risk is not just a missed finding, it is a false sense of assurance around image security.

Failure mechanism: A weak default, stale registration, or incorrect routing choice can shift image analysis onto an unintended scanner, which can reduce detection quality or break operational consistency across manual and scheduled scans.

Impact: Security teams may approve images based on unreliable results, miss exposure in vulnerable artifacts, or lose confidence that Harbor’s scan outcomes reflect the intended control baseline.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 SI-2 — Flaw Remediation Scanner choice affects how vulnerabilities are found in container images.
AC-6 — Least Privilege Scanner registration should restrict who can change trusted analysis paths.
Recommendation — Align image scanning with SI-2 to ensure findings drive timely remediation. Limit who can change scanner defaults and registrations under AC-6.
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication, and Access Control Configuring trusted scanners and defaults is an access-controlled security function.
GV.OC-01 — Organizational Context Selecting a default scanner reflects the organisation’s security operating model.
Recommendation — Apply PR.AA-05 to protect scanner configuration and approval paths. Document scanner ownership and trust assumptions under GV.OC-01.
CIS Controls v8 CIS-6 — Access Control Management Harbor scanner settings should be governed through controlled administrative access.
Recommendation — Use CIS-6 to restrict scanner registration and default changes.

Practitioner Guidance

Why practitioners should care: Interrogation Services is one of the places where scanning governance becomes operational. The scanner you register and set as default determines which analysis path Harbor actually follows, so the configuration should match the organisation’s security standard, not just the easiest integration.

What to watch for: Pay attention when multiple scanners are available, when a default changes, or when scan output looks inconsistent across workflows. Those are often the moments when routing, trust, or coverage drift becomes visible.

Practitioner takeaway: Treat the scanner list and default setting as part of your registry control design, not as a minor UI preference.