KeyStore YUM Nexus Docker - Sonatype Nexus Repository - Sonatype Community

KeyStore YUM Nexus Docker

Hello together,

In following, I refer to Proxying RHEL Yum Repositories.


A few days ago, I moved our Nexus Repository Manager from a local install to a docker install as a container. To ensure our RHEL servers can get software packages via the Nexus Repository Manager, I followed the documentation I printed at the beginning. While the Nexus Repository Manager ran as a local install, it also worked very well. However, after I moved to a docker install, it didn't work.


nexus:
  image: sonatype/nexus3
  volumes:
    - ./rundir:/nexus-data:rw
    - ./nexus.vmoptions:/opt/sonatype/nexus/bin/nexus.vmoptions:ro
    - ./keystore.yum.p12:/opt/keystore.yum.p12:ro
  restart: always
-Djavax.net.ssl.keyStore=/opt/keystore.yum.p12
-Djavax.net.ssl.keyStorePassword=iKeepMySecreats

The keystoreFile is mounted as /opt/keystore.yum.p12. The nexusVmoptions is mounted in ($app-dir/bin/nexus.vmoptions) /opt/sonatype/nexus/bin/nexus.vmoptions. Both have the permissions owner id 200:200 (nexus), permissions 0400 and 0466.

Inside the container, the setup looks like this:


Have someone got this problem once and know how to solve?

Best regards,

Christopher Hofmann

post by mpiggott on May 5

Hi Christopher,

From your description, I’m not really sure what issue you’re experiencing with Nexus?

post by CHofmann on May 6

Hello Matthew,

Sorry, I forgot to tell. While I used the (locally installed) Nexus instance, I could receive the RPM packages from RedHat's official package source, for and on RHEL. Afterwards, using the (docker installed) Nexus, the packages aren’t accessible anymore. I just got the error 404, not found.

It’s important to say that I didn’t change any settings; I moved the config files from the old instance to the new one. Everything else works perfectly, including access to the RedHat source.

Best regards,

Christopher Hofmann

post by justin_z on May 7

That doc is for RHEL 7 and is out of date. I have tried with 10 and did not have any luck. What version are you trying? I also use a container for this.

post by CHofmann on May 11

I use RHEL 9 and 10. While I used the local (bare-metal) installation, it worked well.

post by justin_z on May 11

Well, I wonder if it was running through a container that's causing the problem. I gave it root privileges too.

post by mpiggott on May 12

I can’t see how running Nexus in a container would make a difference. You might try reading this thread also - Adding RHEL9 repos to Nexus.

Aside from that and the help documentation, I would suggest looking at the client logs, the request log, the nexus log, and interacting with the repository manually to identify any misconfiguration. We also offer support as part of Nexus Repository PRO.

post by rost3x on May 12

Hi Christopher,

As you can see from Matthew’s reply, I’ve had a similar issue to yours. However, we run Nexus on Alma Linux (not dockerized). Have you tried changing permissions to 0644? I have to update my p12 every couple of months and if the permissions aren’t right then it gives us a 404 error.

post by justin_z on May 12

All this link talks about is the deprecated SHA1, which is already mentioned in the proxying-rhel-yum-repositories page. FYI: Proxy repo for RHN anyone?.

post by CHofmann on May 13

Hello together,

Thanks for your help, but I still couldn’t solve the problem.

First of all, the logs show how the request reaches, but gets denied: HTTP code 403.

[13/May/2026:10:11:14 +0200] - "GET https://cdn.redhat.com:443/ HTTP/1.1" 403 368 434
[13/May/2026:10:11:54 +0200] - "GET https://cdn.redhat.com/content/dist/rhel10/10/x86_64/baseos/os/repodata/repomd.xml HTTP/1.1" 403 467 233
...

In addition, I tried to run Nexus with different permission settings. Neither running the container with root solved the problem nor changing the permissions of the files to 0644. Also, neither solution worked in combination.

admin@nexus:/opt/nexus/compose$ ll keystore.yum.p12
-rw-r--r-- 1 root root 4658 May 13 10:02 keystore.yum.p12
  nexus:
    image: sonatype/nexus3
    user: "root:root"
    volumes:

Last but not least, with the new version, I can see the files via the web interface. Both exist, are accessible, and readable.

When someone is interested in how I created my keystore file, I have written once something for: Costum-Ansible-Modules/keystore_for_nexus at main · Alphabeit/Costum-Ansible-Modules · GitHub.