Overview
Deploy a production ready Sonatype™ Nexus™ Repository Community Edition server on AWS in minutes: one private registry for your Maven, npm, Docker, PyPI, NuGet, Cargo, Composer and other components, proxying and caching the public registries your builds depend on. Built for development teams and platform engineers who want build dependencies cached close to CI, private artifacts hosted under their control, and protection from public registry outages and rate limits, without the Java, storage and reverse proxy assembly a correct deployment requires. This image ships the environment hardened and assembled; the latest Community Edition installs from Sonatype's official distribution on first start, and you accept Sonatype's EULA in the product's own onboarding wizard.
Why a repository manager, and why this image
Every build your team runs pulls dependencies from public registries that rate limit, change and occasionally disappear. A repository manager caches those dependencies once, close to your CI runners, and gives your own artifacts a home with access control. Nexus Repository is the long standing standard for the job. This image handles the deployment realities: correct Java runtime, data directory on its own path with sizing guidance (artifact storage grows relentlessly).
Common use cases
- Dependency caching: proxy Maven Central, npmjs, PyPI and Docker Hub once, insulate CI from rate limits and outages
- Private artifact hosting: your libraries, packages and images with access control
- Private Docker registry: hosted images for your deployments without per seat registry pricing
- Air gap and controlled environments: a single, auditable path for components entering your network
- Build performance: dependencies served from your VPC instead of the public internet, CI minutes saved on every run
Usage notes
- To activate CloudWatch and Session Manager, attach an IAM instance role with the AWS-managed policies CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore. No AWS credentials are stored on the image.
- Web UI: http://:8081 (open TCP 8081 and 22 in the security group). Initial admin password: sudo cat /opt/sonatype-work/nexus3/admin.password, then complete the setup wizard. Install: /opt/nexus; data: /opt/sonatype-work/nexus3; secrets key: /opt/nexus/nexus.secrets.json; JVM options: /opt/nexus/bin/nexus.vmoptions.
- CloudWatch agent configuration: /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.d/nexus-oss.json.
Quick Start:
- Browse to http://:8081.
- First admin password (per Sonatype convention): SSH in as 'ubuntu' and run sudo cat /opt/sonatype-work/nexus3/admin.password.
- Complete the setup wizard to set your own password.
- Monitoring: attach an IAM instance role with the AWS-managed policies CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore to enable CloudWatch logs/metrics (namespace CloudSOE/nexus-oss) and Session Manager. No AWS credentials are stored on the image.
Sizing guidance
Nexus is a JVM service with appetite. Minimum listed: t3.large (8 GB), suitable for small teams. Recommended production: m7i.large with gp3 storage sized generously for artifacts.
Trademark and licensing notice
Sonatype™, Nexus™ and Sonatype Nexus Repository™ are trademarks of Sonatype, Inc. This product is independently packaged and maintained and is not affiliated with, endorsed by, or supported by Sonatype, Inc. Nexus Repository Community Edition is Sonatype's software, installed at first boot from Sonatype's official distribution and licensed to you directly by Sonatype under the Community Edition EULA you accept in the onboarding wizard.
Highlights
- Nexus Repository (Community Edition) installed under /opt/nexus with a dedicated nexus service user, a hardened systemd unit (raised file-descriptor limit, restart on failure), data in /opt/sonatype-work and a bundled nexus-upgrade script that backs up and upgrades in place.
- Per-instance security: the Nexus secrets encryption key (nexus.secrets.json) is generated at first boot rather than shipped in the image; the initial admin password follows Sonatype's one-time admin.password convention; key-only SSH, root login disabled, no baked-in secrets.
- Built-in observability and access: the Amazon CloudWatch agent ships nexus.log, request.log, jvm.log, syslog and auth.log and publishes host metrics under CloudSOE/nexus-oss; Amazon SSM Agent enables Session Manager; a support file identifies the exact build; vendor support from CloudSOE.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
- ...
Dimension | Cost/hour |
|---|---|
t3.2xlarge Recommended | $0.03 |
t3.micro | $0.03 |
t2.micro | $0.03 |
r5n.16xlarge | $0.03 |
t2.large | $0.03 |
r5ad.xlarge | $0.03 |
m7i.metal-24xl | $0.03 |
r5a.8xlarge | $0.03 |
m6id.2xlarge | $0.03 |
m7i-flex.12xlarge | $0.03 |
Vendor refund policy
Cancel Anytime
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Includes:
- Latest Nexus Community
- Latest OS patches
Additional details
Usage instructions
Quick Start:
- Browse to http://<instance-ip>:8081.
- First admin password (per Sonatype convention): SSH in as ubuntu and run sudo cat /opt/sonatype-work/nexus3/admin.password.
- Complete the setup wizard to set your own password.
Support
Vendor support
Vendor support for this AMI is provided by CloudSOE. To reach the support team, email support@cloudsoe.com with a description of your issue.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.