Skip to content

Migration Tool 1.5.0#

Release Date: 05 October 2026

Addressed Issues#

  • [MSRH-1495] Fixed an issue wherein a team that was previously migrated under its LDAP group CN kept its MSR4 project access after its group DN was removed from the source data. The migration tool now records the group name and DN it resolves for each LDAP team in ldap_group_state.json in the data directory, and on later runs it uses that record to revoke the stale access per project.

  • [MSRH-1485] Fixed an issue wherein the migration tool skipped an LDAP team whose group DN was missing or empty but kept the Harbor project access that an earlier migration run had granted to that team. The tool now removes that stale access, as it already did for teams that it skips for other reasons.

  • [MSRH-1484] Fixed an issue in which changing the Harbor group naming format between migration runs left the group created under the previous format in place, with its project access intact, alongside the new group. The issue occurred, for example, when you switched ENZI_TEAM_NAME_PREFIX_OR_SUFFIX from prefix to suffix or enabled IS_ENZI_TEAM_NAME_UNIQUE. The migration tool now removes groups that it created under previous naming formats.

  • [MSRH-1483] Fixed an issue wherein manage_source_registry_db.sh failed with the message Failed to determine MSR type (Swarm or Kube) when it was run with an MKE client bundle sourced, which is the setup that the script recommends.

  • [MSRH-1463] Fixed an issue wherein the project members migration step completed successfully without migrating any project members when data from an earlier migration step was missing. The step now fails with an error that reports the missing data.

  • [MSRH-1060] Fixed an issue wherein the Migration Tool, when run in granular mode, created MSR 4 LDAP groups named <organization>-<team> instead of the CN of the LDAP group. LDAP groups are now named after the CN in their group DN. If two different DNs share the same CN, the tool keeps the <organization>-<team> name for those groups.

  • [MSRH-955] Fixed an issue wherein LDAP teams were migrated with incorrect Distinguished Names (DNs); teams using unsupported search-based LDAP sync are now skipped with a warning instead of being migrated broken.

  • [MSRH-279] Fixed an issue wherein manage_source_registry_db.sh --copy-enzidb copied the MSR database instead of the MKE authentication store (eNZi) when the source registry was MSR 3.x on Kubernetes. The script now always copies the eNZi database from MKE, and kubectl is now listed in the prerequisites of the script help.