R / Richie全部文章 ↑

Linux · 2 分钟阅读

11. Nexus 3.x 私有仓库

2026 年视角:Nexus 仍是"一站式仓库"的事实标准——Docker、Maven、npm、PyPI、Yum/APT 同一个 UI 管。但纯 Docker 场景下 Harbor 越来越主流,Nexus 的优势在多语言制品仓库。

启动

docker volume create nexus-data

docker run -d --name nexus3 --restart=always \
    -p 8081:8081 \
    -v nexus-data:/nexus-data \
    sonatype/nexus3:3.68
  • 8081:Web UI
  • 数据落 nexus-data 卷,重建容器不丢
  • 启动慢,约 1–2 分钟看日志

初始化

访问 http://<ip>:8081,默认账号 admin,密码在容器内:

docker exec nexus3 cat /nexus-data/admin.password

第一次登录强制改密。

创建 Docker 仓库

  1. 齿轮 → Repositories → Create repository
  2. 选 docker (hosted)
  3. 配置:
项 建议值
Name docker-hosted
HTTP 8082
Enable Docker V1 API 关掉

端口冲突时改 8082 → 其他端口,记得同步给 docker daemon。

客户端推送

// /etc/docker/daemon.json
{
  "insecure-registries": ["<nexus-ip>:8082"]
}
systemctl restart docker

docker login <nexus-ip>:8082
docker tag nginx:1.27 <nexus-ip>:8082/nginx:1.27
docker push <nexus-ip>:8082/nginx:1.27

备份

# 停服
docker stop nexus3

# 打包数据卷
docker run --rm -v nexus-data:/data -v $(pwd):/backup \
    alpine tar czf /backup/nexus-$(date +%F).tgz -C /data .

清理策略

  • Web UI → Administration → System → Tasks
  • 配 Admin - Cleanup repositories using their associated policies
  • 配合 Retention 策略,删 N 天前未使用的镜像

实践

  • 生产开 HTTPS:用 nginx / traefik 反向代理 + Let’s Encrypt
  • 内存给足:Nexus 比较吃内存,建议 8 GB+ 起
  • LDAP 接入:和公司账号系统打通,UI 一次登录
  • 镜像上传加审核:开启 Content Selectors + Privileges

参考