Checkpoint Lab — User Interface, Search, Browse, Components, Assets, Tags, Uploads, and Repository Navigation
Operate a small disposable repository from creation to cleanup: publish several synthetic versions/assets, verify them through independent views, document optional tag behavior without requiring Pro, capture an evidence packet, and remove only the lab repository after proving what will disappear.
Learning objectives
- Create and operate one disposable hosted repository without touching production or unrelated default repositories.
- Publish at least three synthetic component versions/assets and predict the database/blob/search consequences before each mutation.
- Verify every expected component through Browse, Search API, Assets API and direct retrieval with checksums.
- Produce a compact evidence packet that distinguishes CE-verified behavior from optional/simulated Pro tagging.
- Delete only the lab repository through a supported API after a pre-delete inventory, then prove removal and bridge to Chapter 04.
Checkpoint boundary. Use only academy-ch03-checkpoint on the loopback disposable instance. Deleting a repository removes its configuration and repository components. Never point the cleanup command at default repositories, employer repositories, production blob stores or a reused data directory.
1. Scenario and success criteria
A release-support team needs a small evidence-backed catalog for a synthetic library. You will create the hosted repository if it does not already exist, publish versions 1.0.0, 1.0.1 and 1.1.0, verify component/assets through multiple views, model a logical build label without requiring Pro, diagnose one intentionally wrong query, then remove only the lab repository.
The checkpoint passes when another operator can reconstruct what changed from the evidence directory without relying on screenshots or memory.
2. Setup, assumptions and preflight
| Assumption | Checkpoint value |
|---|---|
| Nexus | Same Chapter 02 disposable self-hosted CE lab; pinned 3.94.1-06 unless the learner re-verifies and deliberately records another supported release. |
| Network | http://127.0.0.1:8081 only; no public exposure. |
| Database/blob | Embedded H2 + local default blob store for this disposable non-container lab only; not a production recommendation. |
| Repository | academy-ch03-checkpoint, Maven2 hosted, ALLOW_ONCE, reserved example namespace. |
| Tagging | Current component tagging is Pro-only; CE checkpoint uses a clearly labeled external simulation manifest. |
| Credentials | Disposable lab administrator via permission-restricted temporary netrc; never committed or printed. |
LAB="$HOME/nexus-ch03-lab"
NX_URL="http://127.0.0.1:8081"
mkdir -p "$LAB/evidence" "$LAB/payload"
umask 077
read -rsp "Disposable Nexus admin password: " NX_PASS; printf "\n"
printf 'machine 127.0.0.1 login admin password %s\n' "$NX_PASS" > "$LAB/nexus.netrc"
unset NX_PASS
NETRC="$LAB/nexus.netrc"
# Never commit or print $NETRC. Delete it when the lab ends.curl -fsS "$NX_URL/service/rest/v1/status" | tee "$LAB/evidence/cp-01-status.txt"
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/repositories" \
| tee "$LAB/evidence/cp-02-repositories-before.json"
# Stop if this name belongs to anything except your disposable lab.
curl --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/repositories/academy-ch03-checkpoint" \
| tee "$LAB/evidence/cp-03-existing-repo-check.json" || true3. Record predictions before mutation
| Prediction | Before action | Expected after |
|---|---|---|
| P-01 Repository creation | No academy-ch03-checkpoint config unless continuing Lesson 2. | Repository exists; still zero new synthetic versions if newly created. |
| P-02 Three releases | No target coordinate or fewer than three versions. | Three component-version records; each has JAR + POM assets; blob usage rises. |
| P-03 Wrong search query | Correct artifacts still exist. | Wrong query returns no matching item; direct retrieval remains valid. |
| P-04 Repository deletion | Repository/config/components/assets exist. | Repository no longer listed; direct URLs fail; unrelated repositories remain. |
Write observed results next to each prediction. A prediction is useful even when wrong because it forces you to identify which state model needs correction.
4. Ensure the disposable repository exists
The checkpoint uses a fresh repository name, academy-ch03-checkpoint, so it does not depend on Lesson 2 state. First prove the name is absent; then create exactly one Maven hosted repository through the supported Repositories API.
cat > "$LAB/checkpoint-repo.json" <<'JSON'
{
"name": "academy-ch03-checkpoint",
"online": true,
"storage": {
"blobStoreName": "default",
"strictContentTypeValidation": true,
"writePolicy": "ALLOW_ONCE"
},
"maven": {
"versionPolicy": "RELEASE",
"layoutPolicy": "STRICT",
"contentDisposition": "INLINE"
}
}
JSON
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
-H 'Content-Type: application/json' \
-X POST "$NX_URL/service/rest/v1/repositories/maven/hosted" \
--data-binary @"$LAB/checkpoint-repo.json"
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/repositories/academy-ch03-checkpoint" \
| tee "$LAB/evidence/cp-03b-repository-created.json"5. Generate three synthetic versions
python3 - <<'PY'
from pathlib import Path
from zipfile import ZipFile, ZIP_DEFLATED
root = Path.home() / "nexus-ch03-lab" / "payload-checkpoint"
root.mkdir(parents=True, exist_ok=True)
for v in ("1.0.0", "1.0.1", "1.1.0"):
note = root / f"README-{v}.txt"
note.write_text(f"synthetic ui-demo version {v}\n", encoding="utf-8")
jar = root / f"ui-demo-{v}.jar"
with ZipFile(jar, "w", ZIP_DEFLATED) as z:
z.write(note, "README.txt")
pom = root / f"ui-demo-{v}.pom"
pom.write_text(
'<project xmlns="http://maven.apache.org/POM/4.0.0">\n'
' <modelVersion>4.0.0</modelVersion>\n'
' <groupId>com.example.academy</groupId>\n'
' <artifactId>ui-demo</artifactId>\n'
f' <version>{v}</version>\n'
'</project>\n',
encoding="utf-8",
)
PY
sha256sum "$LAB"/payload-checkpoint/*.{jar,pom} 2>/dev/null \
| tee "$LAB/evidence/cp-04-local-checksums.txt"This fresh checkpoint repository starts empty and uses ALLOW_ONCE. Upload each release coordinate exactly once; a repeated upload is a failure to diagnose, not a reason to weaken the write policy.
6. Upload missing versions and capture status
for V in 1.0.0 1.0.1 1.1.0; do
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
-X POST "$NX_URL/service/rest/v1/components?repository=academy-ch03-checkpoint" \
-F maven2.groupId=com.example.academy \
-F maven2.artifactId=ui-demo \
-F maven2.version="$V" \
-F maven2.asset1=@"$LAB/payload-checkpoint/ui-demo-$V.jar" \
-F maven2.asset1.extension=jar \
-F maven2.asset2=@"$LAB/payload-checkpoint/ui-demo-$V.pom" \
-F maven2.asset2.extension=pom
doneAll three versions are uploaded in this fresh checkpoint. If any POST fails, preserve the response and diagnose repository name/type, coordinate existence, payload fields and authorization before retrying.
7. Verify browse, search, assets and direct retrieval
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint&group=com.example.academy&name=ui-demo" \
| tee "$LAB/evidence/cp-05-search-all.json"
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/assets?repository=academy-ch03-checkpoint" \
| tee "$LAB/evidence/cp-06-assets.json"
for V in 1.0.0 1.0.1 1.1.0; do
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/repository/academy-ch03-checkpoint/com/example/academy/ui-demo/$V/ui-demo-$V.jar" \
-o "$LAB/evidence/download-$V.jar"
sha256sum "$LAB/evidence/download-$V.jar"
done | tee "$LAB/evidence/cp-07-download-checksums.txt"In Browse, navigate the repository and inspect one version's component plus both assets. In Search, filter by group/name and then by an exact version. In API evidence, record component IDs, asset IDs, paths and checksums. Direct retrieval proves the path can serve bytes under the current authorization.
8. Annotate/document the logical build without requiring Pro
cat > "$LAB/evidence/cp-08-logical-tag-simulation.json" <<'JSON'
{
"simulation": true,
"feature": "Nexus Repository component tagging",
"licenseBoundary": "Pro-only at review time",
"logicalTag": "chapter03-release-train-001",
"components": [
"com.example.academy:ui-demo:1.0.0",
"com.example.academy:ui-demo:1.0.1",
"com.example.academy:ui-demo:1.1.0"
],
"note": "A real Nexus tag associates components, not individual assets."
}
JSONOptional Pro trial: use the documented Tags API to create and associate a tag, then prove the association in UI/API. Mark that evidence optional Pro; the CE checkpoint passes using the simulation manifest.
9. Controlled diagnostic challenge
Query a deliberately misspelled artifact ID, save the empty result, then prove the correct coordinate and direct asset still work:
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint&group=com.example.academy&name=ui-dmeo" \
| tee "$LAB/evidence/cp-09-wrong-search.json"
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint&group=com.example.academy&name=ui-demo&version=1.1.0" \
| tee "$LAB/evidence/cp-10-correct-search.json"Explain why index rebuild, database edits and cache deletion would be unrelated. The misspelled query is the fault; the correct repair is the query string.
10. Evidence packet
| Evidence | Required interpretation |
|---|---|
| Status + repository inventory | Which instance/repository set was operated on. |
| Repository configuration | Name, format, hosted type, blob store and write policy. |
| Local checksum manifest | Expected byte identity before upload. |
| Search JSON | Three intended versions visible under exact coordinates. |
| Assets JSON | Expected JAR/POM assets, paths/IDs/checksums; follow continuation token if present. |
| Direct downloads + checksums | Served bytes match the intended local payloads. |
| Tag simulation/optional Pro evidence | License boundary is explicit; no fake CE product capability. |
| Broken-query before/after | Root cause interpreted without storage mutation. |
| Cleanup proof | Target repository removed; unrelated repository inventory retained. |
11. Pre-delete inventory, supported deletion and verification
Repository deletion is intentionally last. Review the target name three times: in repository configuration, in search results, and in the command itself. Save a final component/asset inventory before deletion.
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint" \
> "$LAB/evidence/cp-11-predelete-search.json"
printf 'TARGET=%s\n' 'academy-ch03-checkpoint' | tee "$LAB/evidence/cp-12-delete-target.txt"
# Run only after manually verifying the disposable target above.
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
-X DELETE "$NX_URL/service/rest/v1/repositories/academy-ch03-checkpoint"
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
"$NX_URL/service/rest/v1/repositories" \
| tee "$LAB/evidence/cp-13-repositories-after.json"
# Expected non-success because the repository no longer exists.
curl --silent --show-error -o /dev/null -w 'http=%{http_code}\n' \
"$NX_URL/repository/academy-ch03-checkpoint/com/example/academy/ui-demo/1.1.0/ui-demo-1.1.0.jar" \
| tee "$LAB/evidence/cp-14-after-delete-request.txt"
rm -f "$NETRC"Do not manually remove corresponding blob files. Nexus repository deletion is the supported control for this disposable object. Blob-store reclamation/cleanup has its own semantics and later chapters; direct filesystem deletion would bypass Nexus state tracking.
12. What Chapter 03 adds to the production operating model
Chapter 01 established artifact identity and repository-manager purpose. Chapter 02 established supported runtime, process and persistent-state boundaries. Chapter 03 adds an inspection and evidence discipline: operators can prove repository type, component/asset identity, searchable metadata, retrievable bytes and authorization-visible views before changing state. It also establishes that UI convenience, REST automation, package-native publication and Pro-only metadata features are separate controls.
Knowledge check
The checkpoint Search UI shows fewer entries than your complete API inventory. What is the likely explanation to test first?
UI result/presentation limits and API pagination. Follow continuation tokens and verify the same repository/privileges before claiming content is missing.
Why must the cleanup command delete the repository through Nexus instead of deleting blob files?
Repository configuration, database metadata and blob references must remain consistent. Manual blob deletion bypasses supported state management and can create corruption/orphans.
A wrong search query returns zero items while direct retrieval works. What failed?
The query, not artifact storage. Correct the search coordinate/semantics and preserve the empty response as diagnostic evidence.
Why is a logical tag manifest marked simulation?
Current component tagging is a Pro feature. The CE path may teach the concept but must not imply Nexus created a real tag.
Why should the checkpoint never retry a successful release upload by switching the repository to mutable writes?
The repository uses write-once behavior to model immutable release identity. Preserve the original result, inspect whether the coordinate already exists, and fix the workflow rather than weakening policy.
What is the next architectural question after learning to inspect one hosted repository?
How hosted, proxy and group repositories should be combined for publication, upstream mediation, read aggregation, routing/caching and promotion flows—Chapter 04.
13. Summary
You completed an end-to-end repository evidence cycle: preflight, predict, create/reuse, publish, search, browse, inspect assets, retrieve exact bytes, simulate a licensed metadata concept honestly, diagnose a harmless failure, inventory evidence and clean up through a supported Nexus API.
Official references and version notes
- Download Nexus Repository — the official download page used to pin the same 3.94.1-06 self-hosted lab baseline as Chapter 02 while current indexes are rechecked before execution.
- Browsing Repositories — browse-tree behavior, 10,000-component-per-level UI limit, HTML view, and browse/read privilege distinctions.
- Searching for Components — current UI search behavior, first-300-result display, SQL-search semantics, tokenization, exact phrases, and wildcard rules.
- Search API — component/asset search endpoints and continuation-token pagination.
- Viewing Component Information — component identifiers and the relationship to associated assets.
- Viewing Asset Information — asset path, content type, size, blob timestamps/reference, checksums, uploader metadata, and format-specific attributes.
- Uploading Components — hosted-only UI upload boundary and required upload/browse/read privileges.
- Components API — list/get/delete components and format-specific multipart component upload.
- Assets API — paginated asset listing, asset details, paths, download URLs and checksums.
- Repositories API — repository inventory and format/type-specific repository configuration endpoints.
- Privileges — current browse, read, add, edit, delete and search privilege semantics.
- Tagging and Self-Hosted Feature Matrix — component tagging is currently a Pro feature; mandatory Chapter 03 work does not require it.
Version-sensitive statements were rechecked against Sonatype primary documentation on 2026-08-26. The mandatory path remains self-hosted, Community/free-compatible and disposable. The chapter keeps the Chapter 02 lab baseline at Nexus Repository 3.94.1-06 because Sonatype's current download and versions-status pages still present 3.94.1 as the current downloadable/GA line; learners are told to re-check those pages before running the lab.
Keep the academy open
Support free, practical DevOps education.
Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0
Send only Ethereum/ERC-20 compatible assets to this address.