推荐使用官方 docker 镜像部署 nexus3,因其省去手动配置 java/tomcat、环境隔离、一键启停;需挂载 /nexus-data 卷并赋权 uid 200,首次登录后必须修改 admin 密码,且 maven 的 settings.xml 中 server id 必须与 pom.xml distributionmanagement 中 id 完全一致,否则 401;release/snapshot 包须对应正确仓库类型,且 hosted 仓库的 deployment policy 需按需开启。

直接用官方 Docker 镜像最省事,别硬装 Java + Tomcat + Nexus 手动部署
官方早就不推荐传统 WAR 包部署方式了,nexus3 从 3.0 开始只提供 docker 和 tar.gz 两种分发形式,而 tar.gz 方式仍需手动管理 JVM 参数、启动脚本、权限、日志轮转——出问题时排查路径长、干扰因素多。Docker 方式能隔离依赖、固化环境、一键启停,连 systemd 都不用配。
实操建议:
- 确保宿主机已安装
docker且当前用户在docker组里(避免每次加sudo) - 拉镜像:
docker pull sonatype/nexus3(注意不是sonatype/nexus,那是旧版 Nexus2) - 挂载数据卷(关键!否则容器重启后仓库全丢):
docker run -d -p 8081:8081 --name nexus -v /opt/nexus-data:/nexus-data sonatype/nexus3 -
/opt/nexus-data目录需提前创建并赋权:mkdir -p /opt/nexus-data && chown -R 200:200 /opt/nexus-data(Nexus3 容器内默认以 UID 200 运行)
首次访问 Nexus 后必须改 admin 密码,否则 Maven 上传会 401
安装完打开 http://localhost:8081,初始账号是 admin,密码在容器日志里:docker logs nexus | grep 'password is'。但这个临时密码只能登录一次,系统强制跳转到改密页——很多人卡在这儿,以为登录成功就完事了,结果后续用 mvn deploy 时一直报 401 Unauthorized。
容易踩的坑:
- 改密页没点「Save」而是直接关页面,下次登录仍用旧密码会失败
- 新密码不符合策略(至少 8 位、含大小写字母+数字+特殊字符),页面无明确提示,只静默失败
- 改完密码后,Maven 的
settings.xml里<server></server>的<password></password>必须同步更新,否则所有 deploy 操作都 401
maven settings.xml 里 <server></server> 的 id 必须和 <distributionmanagement></distributionmanagement> 中的 id 完全一致
这是 Maven 私服最常配置错的一环。Nexus 不认 URL,只靠 id 字符串做凭证匹配。哪怕只差一个空格或大小写,Maven 就找不到对应账号密码,最终报 401 或 403。
示例片段(注意两处 nexus-releases 必须一模一样):
<settings><servers><server><id>nexus-releases</id><username>admin</username><password>your_new_password</password></server></servers><profiles><profile><id>my-nexus</id><repositories><repository><id>nexus</id><url>http://localhost:8081/repository/maven-public/</url></repository></repositories></profile></profiles><activeprofiles><activeprofile>my-nexus</activeprofile></activeprofiles></settings>
对应项目 pom.xml 中:
<distributionmanagement><repository><id>nexus-releases</id><url>http://localhost:8081/repository/maven-releases/</url></repository><snapshotrepository><id>nexus-snapshots</id><url>http://localhost:8081/repository/maven-snapshots/</url></snapshotrepository></distributionmanagement>
仓库类型选错会导致 deploy 失败:release 包不能发到 snapshot 仓库,反之亦然
Nexus 默认建了三个关键仓库:maven-releases(type: hosted, Release)、maven-snapshots(type: hosted, Snapshot)、maven-public(type: group)。Maven 的 deploy 行为严格按 <version></version> 结尾是否含 -SNAPSHOT 判定目标仓库——不是看 URL,也不是看 profile 激活状态。
常见错误现象:
- 项目
<version>1.0.0-SNAPSHOT</version>却配置了<repository></repository>指向maven-releases→ 报错Failed to deploy artifacts: Could not transfer artifact ... Failed to transfer file ... Return code is: 400 - 非 SNAPSHOT 版本发到
maven-snapshots→ 报错400 Bad Request,日志里提示Snapshot artifacts may not be deployed to a release repository - 想让 CI 自动发布 release 包,却忘了在 Nexus 后台关闭
maven-releases的Deployment policy(默认是Disable redeploy),导致重复构建失败
真正需要关注的是 Nexus 界面里每个 hosted 仓库的「Configuration」页签下的 Version policy 和 Deployment policy,而不是 Maven 配置本身。










