nexus repository manager可统一管理maven、npm、docker、yum四类仓库,核心是正确部署(推荐docker容器化)、配置proxy/hosted/group三类仓库、落实权限与网络收口,开箱即用且企业级稳定。

直接用 Nexus Repository Manager 就能统一管 Maven、Npm、Docker、Yum 四类仓库,核心是选对部署方式、配好三类仓库类型(hosted / proxy / group),再做权限和网络收口。不依赖数据库、开箱即用,企业级稳定性和扩展性足够。
推荐用 Docker 部署,省去 Java 环境和系统配置麻烦
生产环境强烈建议容器化运行,避免 JDK 版本冲突、ulimit 限制、用户权限等问题:
- 拉取官方镜像:
docker pull sonatype/nexus3 - 创建持久化目录并授权:
mkdir -p /app/nexus-data && chown -R 200:200 /app/nexus-data(Nexus 默认以 UID 200 运行) - 启动容器(带内存限制和自动重启):
docker run -d \<br> -p 8081:8081 \<br> -v /app/nexus-data:/nexus-data \<br> --name nexus \<br> --restart=always \<br> -e "INSTALL4J_ADD_VM_PARAMS=-Xms2g -Xmx4g" \<br> sonatype/nexus3
- 首次访问
http://IP:8081,等待 2–3 分钟(初始化较慢),用cat /app/nexus-data/admin.password查初始密码
一次配齐四类仓库:Maven、Npm、Docker、Yum
登录后进 Settings → Repositories → Create repository,按需创建以下三类仓库:
-
Maven 代理仓库(proxy):名称
maven-aliyun,Remote storage 填https://maven.aliyun.com/repository/public;启用 Download remote indexes -
Npm 代理仓库(proxy):名称
npm-registry,Remote storage 填https://registry.npmjs.org/;勾选 Strict SSL 和 Auto blocking -
Docker 代理仓库(proxy):名称
docker-hub,Remote storage 填https://registry-1.docker.io;必须开启 HTTP port(如 8082)并配置反向代理,或启用 HTTPS port(需证书) -
Yum 代理仓库(proxy):名称
yum-centos-base,Remote storage 填https://mirrors.aliyun.com/centos/7/os/x86_64/;注意路径末尾带/,且只支持 HTTP/HTTPS 协议 -
统一入口用 Group 仓库:创建
maven-group、npm-group、docker-group,把对应 proxy + hosted 仓库全加进去,对外只暴露这一个 URL
安全与可用性必须做的几件事
上线前务必完成这些基础加固,否则容易被爆破或误用:
- 禁用匿名访问:Settings → Security → Anonymous Access → 关闭 Enable anonymous access
- 创建专用用户组(如
dev-team),分配nx-repository-view-*-*-read或-edit权限,避免直接给 admin 权限 - 为 Docker 仓库开启 BLOB store 配额限制,防止镜像堆积占满磁盘(默认使用
defaultblob store) - 配置反向代理(如 Nginx)暴露 80/443,并终止 HTTPS;同时把 Nexus 的
nexus-default.properties中的application-port改为非 8081 端口,隐藏管理端口 - 定期清理 snapshot 仓库(Tasks → Create task,选
Remove Snapshots from Repository),设置保留最近 30 天
客户端对接示例(关键配置不写错)
不同工具连私服,URL 和参数不能混用:
-
Maven:在
settings.xml的<mirrors></mirrors>里加:<mirror><br> <id>nexus-maven</id><br> <url>http://nexus.example.com/repository/maven-group/</url><br> <mirrorof>*</mirrorof><br></mirror>
-
Npm:全局设 registry:
npm config set registry http://nexus.example.com/repository/npm-group/
发布私有包时,确保package.json中"publishConfig": { "registry": "http://nexus.example.com/repository/npm-hosted/" } -
Docker:修改
/etc/docker/daemon.json:{ "insecure-registries": ["nexus.example.com:8082"] },然后systemctl restart docker;登录用docker login nexus.example.com:8082 -
Yum:新建
/etc/yum.repos.d/nexus.repo:[nexus-yum]<br>name=Nexus Yum Proxy<br>baseurl=http://nexus.example.com/repository/yum-centos-base/<br>enabled=1<br>gpgcheck=0











