Interrogation Services is the Harbor feature area used to register and manage external image scanners. It tells Harbor where to send scan requests and which scanner should be treated as the default for image analysis, manual scans, and scheduled scans.
What Interrogation Services Does in Harbor
Interrogation Services is Harbor’s scanner management area. It defines which external image scanners Harbor can use, where scan requests are sent, and which scanner becomes the default for manual, scheduled, and analysis-driven scans.
This makes the feature less about the scanner itself and more about the control plane around scanning. Harbor is deciding which external service it trusts for image analysis, how requests are routed, and what happens when administrators change the default scanner.
How Harbor Uses Scanner Registration and Routing
In practice, Interrogation Services acts as a configuration layer between Harbor and the scanning engines it can reach. Once a scanner is registered, Harbor can direct image checks to that service instead of treating scanning as a purely local capability.
That routing choice matters because different scanners may have different coverage, scoring models, update cadences, or output formats. A Harbor deployment can therefore produce different scan results depending on which scanner is selected, how it is configured, and whether the default is aligned with the intended security workflow.
Why the Default Scanner Setting Matters
The default scanner affects the operational path users experience most often. When a default is set for image analysis, manual scans, or scheduled scans, Harbor is effectively standardizing one analysis source for routine activity.
That reduces ambiguity for operators, but it also creates a governance decision: the chosen default becomes the scanner most teams will rely on for day-to-day decisions. If that scanner is stale, misconfigured, or no longer trusted, the impact reaches beyond one isolated job and can shape the quality of the entire registry’s scanning output.
Configuration Boundaries and Operational Context
Interrogation Services is not a vulnerability scanner by itself. It is the registry-side control surface that tells Harbor which external scanner to call, how to coordinate scan requests, and which service should anchor the scanning experience.
Because of that, the feature sits at the boundary between registry operations and security tooling integration. Its value comes from making scanner choice explicit, repeatable, and manageable rather than hard-coded or ad hoc. In environments with more than one scanner, that boundary is especially important for consistency and auditability.
Risk and Threat Considerations
When scanner registration and default selection are mismanaged, Harbor may send scan requests to the wrong service or rely on analysis that is outdated, incomplete, or no longer trusted. The risk is not just a missed finding, it is a false sense of assurance around image security.
Failure mechanism: A weak default, stale registration, or incorrect routing choice can shift image analysis onto an unintended scanner, which can reduce detection quality or break operational consistency across manual and scheduled scans.
Impact: Security teams may approve images based on unreliable results, miss exposure in vulnerable artifacts, or lose confidence that Harbor’s scan outcomes reflect the intended control baseline.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-2 — Flaw Remediation | Scanner choice affects how vulnerabilities are found in container images. |
| AC-6 — Least Privilege | Scanner registration should restrict who can change trusted analysis paths. | |
| Recommendation — Align image scanning with SI-2 to ensure findings drive timely remediation. Limit who can change scanner defaults and registrations under AC-6. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | Configuring trusted scanners and defaults is an access-controlled security function. |
| GV.OC-01 — Organizational Context | Selecting a default scanner reflects the organisation’s security operating model. | |
| Recommendation — Apply PR.AA-05 to protect scanner configuration and approval paths. Document scanner ownership and trust assumptions under GV.OC-01. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Harbor scanner settings should be governed through controlled administrative access. |
| Recommendation — Use CIS-6 to restrict scanner registration and default changes. | ||
Practitioner Guidance
Why practitioners should care: Interrogation Services is one of the places where scanning governance becomes operational. The scanner you register and set as default determines which analysis path Harbor actually follows, so the configuration should match the organisation’s security standard, not just the easiest integration.
What to watch for: Pay attention when multiple scanners are available, when a default changes, or when scan output looks inconsistent across workflows. Those are often the moments when routing, trust, or coverage drift becomes visible.
Practitioner takeaway: Treat the scanner list and default setting as part of your registry control design, not as a minor UI preference.
Related resources from NHI Mgmt Group
- When do managed identity services help, and when do they create risk?
- How should security teams handle weak credentials on exposed Linux services?
- How should organisations reduce identity friction in customer-facing services?
- How should security teams govern AI services that can generate offensive content?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org