Chapter 03Lesson 05~170 minutes

Checkpoint Lab — User Interface, Search, Browse, Components, Assets, Tags, Uploads, and Repository Navigation

Operate a small disposable repository from creation to cleanup: publish several synthetic versions/assets, verify them through independent views, document optional tag behavior without requiring Pro, capture an evidence packet, and remove only the lab repository after proving what will disappear.

Checkpoint labMultiple versionsEvidence packetSafe cleanupChapter 04 bridge

Learning objectives

  • Create and operate one disposable hosted repository without touching production or unrelated default repositories.
  • Publish at least three synthetic component versions/assets and predict the database/blob/search consequences before each mutation.
  • Verify every expected component through Browse, Search API, Assets API and direct retrieval with checksums.
  • Produce a compact evidence packet that distinguishes CE-verified behavior from optional/simulated Pro tagging.
  • Delete only the lab repository through a supported API after a pre-delete inventory, then prove removal and bridge to Chapter 04.

Checkpoint boundary. Use only academy-ch03-checkpoint on the loopback disposable instance. Deleting a repository removes its configuration and repository components. Never point the cleanup command at default repositories, employer repositories, production blob stores or a reused data directory.

1. Scenario and success criteria

A release-support team needs a small evidence-backed catalog for a synthetic library. You will create the hosted repository if it does not already exist, publish versions 1.0.0, 1.0.1 and 1.1.0, verify component/assets through multiple views, model a logical build label without requiring Pro, diagnose one intentionally wrong query, then remove only the lab repository.

The checkpoint passes when another operator can reconstruct what changed from the evidence directory without relying on screenshots or memory.

2. Setup, assumptions and preflight

AssumptionCheckpoint value
NexusSame Chapter 02 disposable self-hosted CE lab; pinned 3.94.1-06 unless the learner re-verifies and deliberately records another supported release.
Networkhttp://127.0.0.1:8081 only; no public exposure.
Database/blobEmbedded H2 + local default blob store for this disposable non-container lab only; not a production recommendation.
Repositoryacademy-ch03-checkpoint, Maven2 hosted, ALLOW_ONCE, reserved example namespace.
TaggingCurrent component tagging is Pro-only; CE checkpoint uses a clearly labeled external simulation manifest.
CredentialsDisposable lab administrator via permission-restricted temporary netrc; never committed or printed.
LAB="$HOME/nexus-ch03-lab"
NX_URL="http://127.0.0.1:8081"
mkdir -p "$LAB/evidence" "$LAB/payload"
umask 077
read -rsp "Disposable Nexus admin password: " NX_PASS; printf "\n"
printf 'machine 127.0.0.1 login admin password %s\n' "$NX_PASS" > "$LAB/nexus.netrc"
unset NX_PASS
NETRC="$LAB/nexus.netrc"

# Never commit or print $NETRC. Delete it when the lab ends.
curl -fsS "$NX_URL/service/rest/v1/status" | tee "$LAB/evidence/cp-01-status.txt"
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/repositories" \
  | tee "$LAB/evidence/cp-02-repositories-before.json"

# Stop if this name belongs to anything except your disposable lab.
curl --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/repositories/academy-ch03-checkpoint" \
  | tee "$LAB/evidence/cp-03-existing-repo-check.json" || true

3. Record predictions before mutation

PredictionBefore actionExpected after
P-01 Repository creationNo academy-ch03-checkpoint config unless continuing Lesson 2.Repository exists; still zero new synthetic versions if newly created.
P-02 Three releasesNo target coordinate or fewer than three versions.Three component-version records; each has JAR + POM assets; blob usage rises.
P-03 Wrong search queryCorrect artifacts still exist.Wrong query returns no matching item; direct retrieval remains valid.
P-04 Repository deletionRepository/config/components/assets exist.Repository no longer listed; direct URLs fail; unrelated repositories remain.

Write observed results next to each prediction. A prediction is useful even when wrong because it forces you to identify which state model needs correction.

4. Ensure the disposable repository exists

The checkpoint uses a fresh repository name, academy-ch03-checkpoint, so it does not depend on Lesson 2 state. First prove the name is absent; then create exactly one Maven hosted repository through the supported Repositories API.

cat > "$LAB/checkpoint-repo.json" <<'JSON'
{
  "name": "academy-ch03-checkpoint",
  "online": true,
  "storage": {
    "blobStoreName": "default",
    "strictContentTypeValidation": true,
    "writePolicy": "ALLOW_ONCE"
  },
  "maven": {
    "versionPolicy": "RELEASE",
    "layoutPolicy": "STRICT",
    "contentDisposition": "INLINE"
  }
}
JSON

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  -H 'Content-Type: application/json' \
  -X POST "$NX_URL/service/rest/v1/repositories/maven/hosted" \
  --data-binary @"$LAB/checkpoint-repo.json"

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/repositories/academy-ch03-checkpoint" \
  | tee "$LAB/evidence/cp-03b-repository-created.json"

5. Generate three synthetic versions

python3 - <<'PY'
from pathlib import Path
from zipfile import ZipFile, ZIP_DEFLATED
root = Path.home() / "nexus-ch03-lab" / "payload-checkpoint"
root.mkdir(parents=True, exist_ok=True)
for v in ("1.0.0", "1.0.1", "1.1.0"):
    note = root / f"README-{v}.txt"
    note.write_text(f"synthetic ui-demo version {v}\n", encoding="utf-8")
    jar = root / f"ui-demo-{v}.jar"
    with ZipFile(jar, "w", ZIP_DEFLATED) as z:
        z.write(note, "README.txt")
    pom = root / f"ui-demo-{v}.pom"
    pom.write_text(
        '<project xmlns="http://maven.apache.org/POM/4.0.0">\n'
        '  <modelVersion>4.0.0</modelVersion>\n'
        '  <groupId>com.example.academy</groupId>\n'
        '  <artifactId>ui-demo</artifactId>\n'
        f'  <version>{v}</version>\n'
        '</project>\n',
        encoding="utf-8",
    )
PY
sha256sum "$LAB"/payload-checkpoint/*.{jar,pom} 2>/dev/null \
  | tee "$LAB/evidence/cp-04-local-checksums.txt"

This fresh checkpoint repository starts empty and uses ALLOW_ONCE. Upload each release coordinate exactly once; a repeated upload is a failure to diagnose, not a reason to weaken the write policy.

6. Upload missing versions and capture status

for V in 1.0.0 1.0.1 1.1.0; do
  curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
    -X POST "$NX_URL/service/rest/v1/components?repository=academy-ch03-checkpoint" \
    -F maven2.groupId=com.example.academy \
    -F maven2.artifactId=ui-demo \
    -F maven2.version="$V" \
    -F maven2.asset1=@"$LAB/payload-checkpoint/ui-demo-$V.jar" \
    -F maven2.asset1.extension=jar \
    -F maven2.asset2=@"$LAB/payload-checkpoint/ui-demo-$V.pom" \
    -F maven2.asset2.extension=pom
done

All three versions are uploaded in this fresh checkpoint. If any POST fails, preserve the response and diagnose repository name/type, coordinate existence, payload fields and authorization before retrying.

7. Verify browse, search, assets and direct retrieval

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint&group=com.example.academy&name=ui-demo" \
  | tee "$LAB/evidence/cp-05-search-all.json"

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/assets?repository=academy-ch03-checkpoint" \
  | tee "$LAB/evidence/cp-06-assets.json"

for V in 1.0.0 1.0.1 1.1.0; do
  curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
    "$NX_URL/repository/academy-ch03-checkpoint/com/example/academy/ui-demo/$V/ui-demo-$V.jar" \
    -o "$LAB/evidence/download-$V.jar"
  sha256sum "$LAB/evidence/download-$V.jar"
done | tee "$LAB/evidence/cp-07-download-checksums.txt"

In Browse, navigate the repository and inspect one version's component plus both assets. In Search, filter by group/name and then by an exact version. In API evidence, record component IDs, asset IDs, paths and checksums. Direct retrieval proves the path can serve bytes under the current authorization.

8. Annotate/document the logical build without requiring Pro

cat > "$LAB/evidence/cp-08-logical-tag-simulation.json" <<'JSON'
{
  "simulation": true,
  "feature": "Nexus Repository component tagging",
  "licenseBoundary": "Pro-only at review time",
  "logicalTag": "chapter03-release-train-001",
  "components": [
    "com.example.academy:ui-demo:1.0.0",
    "com.example.academy:ui-demo:1.0.1",
    "com.example.academy:ui-demo:1.1.0"
  ],
  "note": "A real Nexus tag associates components, not individual assets."
}
JSON

Optional Pro trial: use the documented Tags API to create and associate a tag, then prove the association in UI/API. Mark that evidence optional Pro; the CE checkpoint passes using the simulation manifest.

9. Controlled diagnostic challenge

Query a deliberately misspelled artifact ID, save the empty result, then prove the correct coordinate and direct asset still work:

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint&group=com.example.academy&name=ui-dmeo" \
  | tee "$LAB/evidence/cp-09-wrong-search.json"

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint&group=com.example.academy&name=ui-demo&version=1.1.0" \
  | tee "$LAB/evidence/cp-10-correct-search.json"

Explain why index rebuild, database edits and cache deletion would be unrelated. The misspelled query is the fault; the correct repair is the query string.

10. Evidence packet

EvidenceRequired interpretation
Status + repository inventoryWhich instance/repository set was operated on.
Repository configurationName, format, hosted type, blob store and write policy.
Local checksum manifestExpected byte identity before upload.
Search JSONThree intended versions visible under exact coordinates.
Assets JSONExpected JAR/POM assets, paths/IDs/checksums; follow continuation token if present.
Direct downloads + checksumsServed bytes match the intended local payloads.
Tag simulation/optional Pro evidenceLicense boundary is explicit; no fake CE product capability.
Broken-query before/afterRoot cause interpreted without storage mutation.
Cleanup proofTarget repository removed; unrelated repository inventory retained.

11. Pre-delete inventory, supported deletion and verification

Repository deletion is intentionally last. Review the target name three times: in repository configuration, in search results, and in the command itself. Save a final component/asset inventory before deletion.

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/search?repository=academy-ch03-checkpoint" \
  > "$LAB/evidence/cp-11-predelete-search.json"

printf 'TARGET=%s\n' 'academy-ch03-checkpoint' | tee "$LAB/evidence/cp-12-delete-target.txt"

# Run only after manually verifying the disposable target above.
curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  -X DELETE "$NX_URL/service/rest/v1/repositories/academy-ch03-checkpoint"

curl --fail-with-body --silent --show-error --netrc-file "$NETRC" \
  "$NX_URL/service/rest/v1/repositories" \
  | tee "$LAB/evidence/cp-13-repositories-after.json"

# Expected non-success because the repository no longer exists.
curl --silent --show-error -o /dev/null -w 'http=%{http_code}\n' \
  "$NX_URL/repository/academy-ch03-checkpoint/com/example/academy/ui-demo/1.1.0/ui-demo-1.1.0.jar" \
  | tee "$LAB/evidence/cp-14-after-delete-request.txt"

rm -f "$NETRC"

Do not manually remove corresponding blob files. Nexus repository deletion is the supported control for this disposable object. Blob-store reclamation/cleanup has its own semantics and later chapters; direct filesystem deletion would bypass Nexus state tracking.

12. What Chapter 03 adds to the production operating model

Chapter 01 established artifact identity and repository-manager purpose. Chapter 02 established supported runtime, process and persistent-state boundaries. Chapter 03 adds an inspection and evidence discipline: operators can prove repository type, component/asset identity, searchable metadata, retrievable bytes and authorization-visible views before changing state. It also establishes that UI convenience, REST automation, package-native publication and Pro-only metadata features are separate controls.

Knowledge check

The checkpoint Search UI shows fewer entries than your complete API inventory. What is the likely explanation to test first?

Why must the cleanup command delete the repository through Nexus instead of deleting blob files?

A wrong search query returns zero items while direct retrieval works. What failed?

Why is a logical tag manifest marked simulation?

Why should the checkpoint never retry a successful release upload by switching the repository to mutable writes?

What is the next architectural question after learning to inspect one hosted repository?

13. Summary

You completed an end-to-end repository evidence cycle: preflight, predict, create/reuse, publish, search, browse, inspect assets, retrieve exact bytes, simulate a licensed metadata concept honestly, diagnose a harmless failure, inventory evidence and clean up through a supported Nexus API.

Next chapter

Hosted, Proxy, and Group Repositories: Design Patterns, Routing, Caching, and Promotion Flows

Chapter 04 expands from one hosted target to repository topology: where writes belong, how proxy caches mediate upstreams, how groups aggregate reads, why group order matters, and how promotion preserves artifact identity.

Official references and version notes

  • Download Nexus Repository — the official download page used to pin the same 3.94.1-06 self-hosted lab baseline as Chapter 02 while current indexes are rechecked before execution.
  • Browsing Repositories — browse-tree behavior, 10,000-component-per-level UI limit, HTML view, and browse/read privilege distinctions.
  • Searching for Components — current UI search behavior, first-300-result display, SQL-search semantics, tokenization, exact phrases, and wildcard rules.
  • Search API — component/asset search endpoints and continuation-token pagination.
  • Viewing Component Information — component identifiers and the relationship to associated assets.
  • Viewing Asset Information — asset path, content type, size, blob timestamps/reference, checksums, uploader metadata, and format-specific attributes.
  • Uploading Components — hosted-only UI upload boundary and required upload/browse/read privileges.
  • Components API — list/get/delete components and format-specific multipart component upload.
  • Assets API — paginated asset listing, asset details, paths, download URLs and checksums.
  • Repositories API — repository inventory and format/type-specific repository configuration endpoints.
  • Privileges — current browse, read, add, edit, delete and search privilege semantics.
  • Tagging and Self-Hosted Feature Matrix — component tagging is currently a Pro feature; mandatory Chapter 03 work does not require it.

Version-sensitive statements were rechecked against Sonatype primary documentation on 2026-08-26. The mandatory path remains self-hosted, Community/free-compatible and disposable. The chapter keeps the Chapter 02 lab baseline at Nexus Repository 3.94.1-06 because Sonatype's current download and versions-status pages still present 3.94.1 as the current downloadable/GA line; learners are told to re-check those pages before running the lab.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0 Send only Ethereum/ERC-20 compatible assets to this address.