Overview
Nexus Repository OSS on AWS - Ready-to-Run Artifact Management
Deploy a fully configured Sonatype Nexus Repository 3 server on AWS with a single click. This AMI gives software development teams and IT operations a secure, central repository for hosting and proxying Maven, npm, PyPI, Docker, Go, PHP, Python, and other artifact formats - so your CI/CD pipelines can publish and retrieve versioned applications and their dependencies from one trusted source.
Nexus is installed from the official Sonatype distribution (currently 3.80.x), runs as a dedicated non-root user under systemd with raised file-descriptor limits, and generates a unique secrets-encryption key on first boot. The Amazon CloudWatch and SSM agents are pre-configured so application logs, request logs, and host metrics flow into CloudWatch as soon as you attach an instance profile.
Key Benefits
- Universal Repository Support - Host and proxy Docker, Maven, npm, PyPI, Go, and many more artifact formats from a single platform
- Private Hosted Repositories - Store proprietary packages and container images in repositories you fully control
- Role-Based Access Controls - Manage who can publish, read, and administer repositories across your teams
- Native AWS Integration - CloudWatch logging and metrics plus Systems Manager support are built in from first boot
- Full Root SSH Access - Complete control over your instance for advanced configuration and customization
What is Included
- Nexus Repository 3 (3.80.x) installed under /opt/nexus with Java, running as a dedicated nexus system user with no login shell. The systemd unit is configured with Type=forking, Restart=on-failure, and LimitNOFILE=65536. Data is stored at /opt/sonatype-work/nexus3, and the service starts automatically on boot on port 8081. A nexus-upgrade helper is available in /usr/local/sbin.
- Per-Instance Credential Generation - A first-boot script writes /opt/nexus/nexus.secrets.json with a fresh UUID key ID and random 256-bit key (mode 600, owned by nexus) and restarts Nexus. Nexus then creates its own one-time admin password at /opt/sonatype-work/nexus3/admin.password.
- Amazon CloudWatch Integration - The CloudWatch agent ships nexus.log, request.log, syslog, and auth.log to CloudWatch Logs with 30-day retention and per-instance-ID streams. CPU, memory, disk, TCP connection, and process metrics are published under the SolveDevOps/Nexus namespace.
- AWS Systems Manager Integration - SSM Agent is installed and enabled for Session Manager, Run Command, Patch Manager, and Inventory.
- Security Hardening - Key-based SSH only, no root login permitted, no secrets or AWS credentials baked into the image. Installer archives, cloud-init instance data, and SSH authorized keys are scrubbed at build time.
- Operational Quick-Start - A login banner (motd) displays the admin-password location, the Nexus URL, the upgrade command, and CloudWatch/SSM activation steps.
Example Use Case: Centralized Docker and Maven Repository for CI/CD
A development team running Jenkins or GitLab CI on AWS needs a private registry for Docker images and a hosted Maven repository for internal Java libraries. After launching this AMI, the team configures their CI/CD pipelines to push Docker images and Maven artifacts to Nexus after each successful build. Downstream services and deployment pipelines then pull verified, versioned artifacts from the same Nexus instance - eliminating reliance on external registries and ensuring consistent, repeatable builds across development, staging, and production environments.
Quick Start
- Launch the instance - Provision a VM with capacity appropriate for your workload. We recommend at least 4GB RAM and 30GB SSD for small PoC and development environments. Attach an IAM instance profile with CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore. The image stores no AWS credentials.
- Wait for bootstrap - Allow approximately 5 minutes for Nexus to finish starting.
- Access the Nexus Portal - Open http://:8081 and sign in as admin with the password from /opt/sonatype-work/nexus3/admin.password.
- Key paths - Install: /opt/nexus | JVM options: /opt/nexus/bin/nexus.vmoptions | Data: /opt/sonatype-work/nexus3 | Secrets key: /opt/nexus/nexus.secrets.json | Service: systemctl {start|stop|status} nexus | CloudWatch config: /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.d/nexus.json
- Advanced configuration - More use cases and documentation are available at https://solvedevops.com/docs/nexus-repository-oss-on-aws/
Disclaimer
All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.
Highlights
- Universal Repository Support
- Private Hosted Repositories
- Community Support
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
t3.medium Recommended | $0.09 |
t3.large | $0.09 |
r5.4xlarge | $0.14 |
r5.xlarge | $0.14 |
m4.2xlarge | $0.09 |
m5.16xlarge | $0.09 |
r5.12xlarge | $0.14 |
r4.large | $0.14 |
m5.2xlarge | $0.09 |
m4.16xlarge | $0.09 |
Vendor refund policy
Cancel Anytime
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Updates to the latest Security Patches for Nexus CE and Ubuntu Server
Additional details
Usage instructions
Getting Started: 1. Provision an EC2 instance with the right capacity for your needs. For smaller installations we suggest; - 4 GB RAM - 20 GB hard disk. For larger sites, m3.xlarge if you intend to store huge artifacts. 2. Access the web portal at: http://ip.adderss.of.instance:9000 e.g. (http://1.2.3.4:8081 ). The default Username is admin and unique instance password is stored here /opt/sonatype-work/nexus3/admin.password (As per Nexus documentation) 3. Enjoy
Resources
Vendor resources
Support
Vendor support
Solve DevOps provides vendor support for this Nexus Repository OSS AMI. For questions about deployment, configuration, or troubleshooting, contact the support team by email at support@solvedevops.com .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.