Chapter 02Lesson 05~165 minutes

Checkpoint Lab — Nexus Repository Editions, Deployment Models, Architecture, Installation, and Java Runtime Planning

Complete a deployment checkpoint: bring up a disposable loopback Nexus instance, prove persistent state, exercise safe administration and restart, collect evidence, diagnose a controlled failure, and remove it safely.

Checkpoint labPersistenceEvidence packetSafe cleanupOperating model

Learning objectives

  • Bring up a disposable single-node Community instance on loopback using the pinned archive baseline.
  • Predict and verify persistent-state changes across first start, bootstrap, repository configuration and restart.
  • Collect a sanitized evidence packet covering version, runtime, data/database/blob state, listener, logs and API readiness.
  • Use a non-production administrative workflow without embedding credentials in commands or evidence.
  • Remove the disposable instance only after proving the cleanup target and preserving any desired evidence.

Version checkpoint — reviewed 2026-08-26. Sonatype's official download page currently offers Nexus Repository 3.94.1 (build line 3.94.1-06), while Sonatype also publishes an official 3.95.0 release-notes page dated August 5, 2026. Because those primary pages are temporarily out of sync, the executable labs in this chapter pin the currently downloadable 3.94.1-06 archive. Re-check the download page, version-status page, release notes, and known issues before using a newer build. Java 21 is required for current H2/PostgreSQL releases; current official packages include a supported runtime.

Checkpoint boundary. This lab destroys its own instance at the end. Create it under the exact disposable parent $HOME/nexus-ch02-checkpoint (or an equivalently isolated path you control). Never substitute a production install/data path, shared database, employer blob store, public hostname, or normal package-client home.

1. Scenario and success criteria

You are preparing a proof-of-concept artifact service for a development team. Before any package-format work, you must prove that the service has a supported runtime, an explicit persistence boundary, a safe process/network identity, a known database/blob model, and repeatable restart behavior. The handoff packet must let another engineer reconstruct what existed without receiving your admin password.

Invariant Prediction before action Independent verification
P-01 first start Data tree, H2 metadata and default blob/log state will appear outside the versioned install directory Directory inventory + System Information + startup log
P-02 bootstrap Changing the admin bootstrap state changes database/security metadata, not artifact blob bytes UI sign-in after restart + blob size comparison + no credential in evidence
P-03 repository config Creating one disposable Raw hosted repository changes repository metadata; no package blob exists until content is uploaded Repositories UI/API + blob/storage measurement before upload
P-04 restart Process PID changes but persistent repository/security configuration survives PID/status before/after + repository present after restart

2. Setup and exact assumptions

  • Nexus: self-hosted Community Edition, pinned lab archive 3.94.1-06 because that is the current official downloadable baseline at review time.
  • Runtime: supported bundled/current Java 21 path; do not force an external JVM.
  • Database: embedded H2, valid only for this small, non-containerized, disposable lab.
  • Blobs: default local filesystem blob storage inside the disposable data tree.
  • Network: 127.0.0.1:8081 only; no public/LAN exposure.
  • Process: ordinary disposable user, never root/Administrator merely to make startup succeed.
  • Paid features: none. HA, SAML, user tokens, resilient deployments and Pro-only capabilities are architecture notes only.
LAB="$HOME/nexus-ch02-checkpoint"
test ! -e "$LAB" || { echo "Refusing: checkpoint path already exists" >&2; exit 1; }
mkdir -p "$LAB"/{evidence,instance}
cd "$LAB"

uname -a | tee evidence/01-os.txt
ulimit -n | tee evidence/02-file-limit.txt
df -h . | tee evidence/03-disk.txt
free -h 2>/dev/null | tee evidence/04-memory.txt || true

Download the 3.94.1-06 archive from Sonatype's official download/archive page and verify its published checksum. Copy it into $LAB/nexus-3.94.1-06.tar.gz. The evidence packet should record the verified hash, not an untrusted mirror URL.

3. Extract and preconfigure the safe listener

cd "$LAB/instance"
tar xvz --keep-directory-symlink -f ../nexus-3.94.1-06.tar.gz
NX_INSTALL="$(find "$PWD" -maxdepth 1 -type d -name 'nexus-*' -print -quit)"
NX_DATA="$PWD/sonatype-work/nexus3"
test -n "$NX_INSTALL"

mkdir -p "$NX_DATA/etc"
cat > "$NX_DATA/etc/nexus.properties" <<'EOF'
application-host=127.0.0.1
application-port=8081
nexus-context-path=/
EOF
chmod 600 "$NX_DATA/etc/nexus.properties"
printf 'install=%s\ndata=%s\n' "$NX_INSTALL" "$NX_DATA" | tee "$LAB/evidence/05-paths.txt"
cat "$NX_DATA/etc/nexus.properties" | tee "$LAB/evidence/06-listener-config.txt"

Prediction P-01: before the first run, the install tree exists but the full persistent work tree is not populated. After startup, logs/database/blob-related directories and files should appear under $NX_DATA.

4. First start and read-only evidence

Start $NX_INSTALL/bin/nexus run in Terminal A. In Terminal B:

LAB="$HOME/nexus-ch02-checkpoint"
cd "$LAB/instance"
NX_INSTALL="$(find "$PWD" -maxdepth 1 -type d -name 'nexus-*' -print -quit)"
NX_DATA="$PWD/sonatype-work/nexus3"
NX_URL=http://127.0.0.1:8081

until curl -fsS "$NX_URL/service/rest/v1/status" >/dev/null; do sleep 3; done
curl -sS -o /dev/null -w 'read=%{http_code} writable=' "$NX_URL/service/rest/v1/status"   | tee "$LAB/evidence/07-status.txt"
curl -sS -o /dev/null -w '%{http_code}\n' "$NX_URL/service/rest/v1/status/writable"   | tee -a "$LAB/evidence/07-status.txt"
ps -eo user,pid,ppid,args | grep '[n]exus' | tee "$LAB/evidence/08-process-before.txt"
ss -ltnp 2>/dev/null | grep ':8081' | tee "$LAB/evidence/09-listener.txt" || true
find "$NX_DATA" -maxdepth 2 -type d -printf '%P\n' 2>/dev/null | sort | tee "$LAB/evidence/10-data-map.txt"
du -sk "$NX_DATA" | tee "$LAB/evidence/11-data-size-before.txt"

Verify P-01: the data tree now exists, the listener is loopback, and the status endpoint is ready. In Settings → Support → System Information later, confirm Nexus version, Java runtime, install/work directories and host/port. Do not infer those values from a tutorial screenshot.

5. Bootstrap admin safely and create one disposable repository

Open http://127.0.0.1:8081/. Sign in as admin using the generated $NX_DATA/admin.password without printing or copying it into evidence. Complete Community onboarding, including the current CE EULA acceptance step, set a lab-only unique admin password, and disable anonymous access for this checkpoint.

Then go to Settings → Repository → Repositories → Create repository → raw (hosted). Create exactly:

Field Value Reason
Name academy-ch02-persistence Synthetic and unmistakably disposable
Online enabled Allows controlled read/write behavior
Blob store default Keeps the checkpoint in the disposable instance state
Deployment policy Disable redeploy / write-once if offered for Raw Reinforces release-like immutability; exact UI wording can vary by pinned release

Prediction P-02: bootstrap changes security metadata while artifact blob usage should not materially grow from package content because no package was uploaded. Prediction P-03: creating the empty hosted repository changes repository configuration metadata but creates no learner artifact asset.

Capture a repository-list screenshot or sanitized API/UI export without credentials, and record du -sk "$NX_DATA". Explain small background growth from logs/index/application activity rather than claiming “zero bytes changed.” The prediction concerns the absence of a learner artifact payload.

6. Record runtime/database/blob/edition evidence

Create evidence/12-system-summary.txt manually from System Information with: Nexus version/build, Community/edition state, Java vendor/version, install directory, work/data directory, application host/port, OS. Do not dump every environment variable.

# Sanitize a narrow log extract only.
grep -E 'Started|Java|H2|datastore|blob|Nexus Repository|ERROR|WARN' "$NX_DATA/log/nexus.log"   | tail -120   | sed -E 's/(password|token|secret|authorization)=[^ ]+/\1=[REDACTED]/Ig'   | tee "$LAB/evidence/13-log-extract.txt"

find "$NX_DATA" -maxdepth 2 -type f -printf '%P\t%s\n' 2>/dev/null   | sort | head -120 | tee "$LAB/evidence/14-state-files.txt"
du -sk "$NX_DATA" | tee "$LAB/evidence/15-data-size-after-config.txt"

The evidence should demonstrate H2/default local-state assumptions through current UI/log/runtime evidence, while avoiding unsupported direct database inspection. Do not open H2 files with another tool while Nexus is running and do not edit blob metadata.

7. Clean restart and persistence proof

Record the current PID. Stop foreground Nexus cleanly with Ctrl+C; wait for port 8081 to close. Start the same $NX_INSTALL/bin/nexus run again and wait for readiness.

curl -sS -o /dev/null -w 'after-restart=%{http_code}\n'   http://127.0.0.1:8081/service/rest/v1/status   | tee "$LAB/evidence/16-status-after-restart.txt"
ps -eo user,pid,ppid,args | grep '[n]exus' | tee "$LAB/evidence/17-process-after.txt"
ss -ltnp 2>/dev/null | grep ':8081' | tee "$LAB/evidence/18-listener-after.txt" || true

Sign in with the lab-only password you set—not the initial password—and confirm academy-ch02-persistence still exists. That verifies P-02/P-04: process identity/PID is transient; application configuration/security metadata persists in the data state. The empty repository still has no learner artifact payload.

8. Controlled diagnostic challenge

Without changing the server, request a misspelled path:

curl -sS -D "$LAB/evidence/19-broken-headers.txt"   -o "$LAB/evidence/19-broken-body.txt"   -w 'http=%{http_code}\n'   http://127.0.0.1:8081/repository/academy-ch02-persistance/example.txt   | tee "$LAB/evidence/19-broken-summary.txt"

Diagnose it in the required order: server readiness → URL/auth → repository name/type → authorization → component/asset state. The typo is persistance versus persistence. The correct action is to fix the client endpoint. Do not clear caches, delete the repository, edit the database, or touch blobs.

9. Evidence packet checklist

Evidence Must show Must not contain
OS/resource preflight OS, file limit, disk, memory assumptions Personal secrets
Release/runtime summary Pinned archive/build, Java 21 runtime, CE state License keys or full environment dump
Network evidence 127.0.0.1:8081 listener + readiness codes Public hostname/IP
Persistent-state map Install path distinct from data path; H2/local blob model Direct database/blob edits
Repository evidence academy-ch02-persistence exists before/after restart Employer namespaces
Logs Narrow sanitized startup/restart evidence Passwords, tokens, Authorization headers
Prediction review P-01 through P-04 observed vs expected Claims not independently checked

10. Safe cleanup and rollback

Cleanup is intentionally conservative. First stop Nexus and prove that the target is the exact disposable checkpoint directory. Preserve evidence/ elsewhere if you want it; otherwise remove the whole lab as one unit. Do not cherry-pick internal database/blob files for deletion.

# Nexus must already be stopped.
LAB="$HOME/nexus-ch02-checkpoint"
test -d "$LAB/instance" || { echo "Unexpected target" >&2; exit 1; }
test -f "$LAB/evidence/05-paths.txt" || { echo "Checkpoint marker missing" >&2; exit 1; }

# Verify no listener remains.
if ss -ltn 2>/dev/null | grep -q ':8081'; then
  echo "Port 8081 is still listening; investigate before cleanup" >&2
  exit 1
fi

# Optional: preserve evidence first.
# cp -a "$LAB/evidence" "$HOME/nexus-ch02-evidence-preserved"

printf 'About to remove only: %s\n' "$LAB"
# After visually confirming the exact disposable path:
rm -rf -- "$LAB"

Rollback note: before deletion, rollback is simply restart the known lab instance from its intact data tree. After deletion there is no rollback unless you preserved a backup; that is why the target proof happens first. This chapter intentionally does not teach “restore by copying internals.”

11. What Chapter 02 adds to the production operating model

You can now describe a Nexus platform before discussing individual package formats: exact release/runtime, edition, process identity, network connector, replaceable install tree, persistent data tree, database, blob storage, readiness, bootstrap security, resource limits, restart behavior and evidence. Those are the invariants an operator must preserve through deployment, upgrade and recovery.

Knowledge check

After restart, the repository disappeared but /status is 200. Which layer should you investigate before recreating it?

A colleague wants to copy only the H2 file as the “Nexus backup.” What is missing?

The listener is 0.0.0.0:8081 during initial admin bootstrap. What should happen?

The typo request returns an error. Why is deleting the proxy cache inappropriate?

Why is the final rm -rf acceptable here when broad deletion is normally forbidden?

What does Chapter 03 add next?

12. Summary

The checkpoint proved deployment causality: a pinned supported archive created a loopback service; first start created persistent H2/data/blob/log state outside the versioned application tree; bootstrap changed security metadata; repository configuration survived process restart; a routing typo was repaired at the client URL layer; and cleanup removed only the verified disposable instance.

Next chapter

User Interface, Search, Browse, Components, Assets, Tags, Uploads, and Repository Navigation: Concepts, Architecture, and Mental Model

Chapter 03 moves from platform foundations into day-to-day Nexus navigation: UI structure, search, browse, components, assets, tags, uploads and repository evidence.

Official references and version notes

Version-sensitive statements were rechecked against Sonatype primary documentation on 2026-08-26. The mandatory path remains self-hosted, Community/free-compatible, and disposable; production credentials, production repositories, and paid-only capabilities are outside the lab boundary.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0 Send only Ethereum/ERC-20 compatible assets to this address.