DevOps Training beginner

Sonatype Nexus Training — Artifact Repository, Binary Management & Supply Chain Security

Master Sonatype Nexus Repository: proxy, hosted, and group repositories for Maven, Docker, npm, PyPI, NuGet. Binary lifecycle management with vulnerability scanning and CI/CD integration.

What Is Sonatype Nexus?

Sonatype Nexus Repository is an artifact repository manager supporting Maven, Gradle, Docker, npm, PyPI, NuGet, Helm, RubyGems, and more. Nexus provides proxy repositories (cache external dependencies), hosted repositories (store internal artifacts), and group repositories (unified access). Combined with Nexus Lifecycle (IQ Server), it provides vulnerability scanning, license compliance, and policy enforcement — blocking vulnerable components before they enter your supply chain.

Role in the DevOps Supply Chain

Nexus is the central store for all binaries. Builds resolve dependencies through Nexus (caching for speed and resilience). Builds publish artifacts to Nexus (single source of truth). Deployments pull from Nexus (guaranteed provenance). Nexus Lifecycle adds security: every component is evaluated against known vulnerabilities and license policies before it can be used or deployed. This is supply chain security at the artifact level.

Who Should Attend

  • DevOps engineers managing artifact repositories and supply chain security
  • Build/release engineers implementing artifact lifecycle management
  • Security engineers enforcing open-source governance policies
  • Teams evaluating Nexus vs. Artifactory

Learning Outcomes

  • Configure Nexus repositories — proxy, hosted, group — for Maven, Docker, npm, PyPI
  • Implement artifact promotion across environments with staging repositories
  • Integrate Nexus with Jenkins, GitHub Actions, Maven, Gradle, and Docker
  • Deploy Nexus Lifecycle for vulnerability and license policy enforcement
  • Manage RBAC, content selectors, cleanup policies, and backup

Course Modules

  1. Nexus Architecture — Repository types. Blob stores. Repository formats. High availability. Deployment options.
  2. Maven/Gradle Repositories — Proxy, hosted, group repos. Staging repositories. Build integration via settings.xml.
  3. Docker Registry — Docker hosted and proxy repos. Image push/pull. Docker group repos. Image cleanup.
  4. npm, PyPI, NuGet Repositories — npm registry configuration. PyPI proxy cache. NuGet hosted repos.
  5. CI/CD Integration — Jenkins + Nexus. GitHub Actions + Nexus. Artifact upload and promotion pipelines.
  6. Nexus Lifecycle (IQ Server) — Policy engine. Vulnerability database. License compliance. Build blockage. SBOM.
  7. Administration — RBAC and content selectors. User token authentication. Backup and restore. Monitoring.
  8. Capstone: Secure Artifact Pipeline — Build a Nexus + Lifecycle pipeline: build → publish → scan → promote → deploy.

Hands-on Labs (14 total)

Configure Maven, Docker, and npm repositories with proxy, hosted, and group types. Set up Maven staging repositories with artifact promotion. Integrate Nexus with Jenkins pipeline. Configure Nexus Lifecycle policies and block vulnerable components. Implement cleanup policies for Docker image retention.

Related Courses

See Artifactory Training, DevOps Engineering, and DevSecOps Engineering.

TOOLS_COVERED

Nexus Repository Nexus Lifecycle Jenkins GitHub Actions Maven Gradle Docker npm

PREREQUISITES

  • Basic CI/CD concepts
  • Understanding of build tools

CURRICULUM

Covers: Jenkins, Bamboo, TeamCity, GitHub Actions, GitLab CI, Azure DevOps. Hands-on labs and real-world scenarios.
Covers: Apache Maven, Gradle, Apache Ant, MSBuild, Makefile, NAnt, Grunt. Hands-on labs and real-world scenarios.
Covers: Nexus, Artifactory, NuGet, Chocolatey, APT, YUM, RPM, Apache Archiva. Hands-on labs and real-world scenarios.
Covers: Jira, Zendesk. Hands-on labs and real-world scenarios.
Covers: Python, Bash, PowerShell, Groovy, Ruby, Perl. Hands-on labs and real-world scenarios.

READY TO UPSKILL YOUR ENGINEERING TEAM?

Browse our training catalog, check upcoming cohorts, and enroll in the program that fits your transformation goals.

FIND YOUR TRAINING PATH

Online · Classroom · Corporate · Self-paced · Certification-aligned