Oh NGINX how do I love thee - Sonatype Nexus Repository - Sonatype Community

Oh NGINX how do I love thee

post by robert.dietz on Jul 26, 2023

Bob Dietz

We are on Sonatype Nexus Repository Pro v3.56.0-01

I have it running ssl behind a nginx proxy

I am able to push items into a RAW repository but not HELM or Docker… with HELM it acts like it’s being pushed but gives no real errors…

Our project is time critical to move this data… please help or advise… using the -v tag I see the following:

Upload file Helm file

CApath: none

PUT /repository/helm-release/power-planning-service-0.3.1-dev.4.tgz HTTP/2

Host: repo.wallyswonderworld.com

Authorization: Basic SFFSLkudfdjlsksldfjODDFDfdsfdsadfad=

User-Agent: curl/7.61.1

Accept: /

Content-Length: 26073

< HTTP/2 500

< server: nginx/1.14.1

< date: Wed, 26 Jul 2023 12:05:54 GMT

< x-content-type-options: nosniff

< content-security-policy: sandbox allow-forms allow-modals allow-popups allow-presentation allow-scripts allow-top-navigation

< x-xss-protection: 1; mode=block

< x-frame-options: DENY

<

curl -k -u fuzzy:booya https://repo.wallyswonderworld.com/repository/helm-release/ --upload-file /data01/tmp/power-planning-service-0.3.1-dev.4.tgz

My NGINX config:

HTTPS SSL required server settings

server {

listen 443 ssl http2;

server_name [nexus.wallyswonderworld.com](http://nexus.wallyswonderworld.com/);

ssl on;
ssl_certificate                 /etc/ssl/certs/nexus.cer;
ssl_certificate_key             /etc/ssl/certs/nexus.key;
client_max_body_size          0;

ssl_prefer_server_ciphers on;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:50m;
ssl_session_tickets off;

location / {

proxy_pass http://nexus.wallyswonderworld.com:8081;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto https;

}
}

server {

listen *:5000;

location / {
  proxy_pass            http://nexus.wallyswonderworld.com:5000/;
  proxy_redirect        off;
  proxy_set_header      Host $host;
  proxy_set_header      X-Real-IP $remote_addr;
  proxy_set_header      X-Forwarded-For $proxy_add_x_forwarded_for;
  proxy_set_header      X-Forwarded-Host $server_name;
  proxy_set_header      X-Forwarded-Proto $scheme;
}
}

For trying to logon with Podman we get the following:

[root@RPTBWILCS060 ~]# podman login repo.wallyswonderworld.com

Username: fuzzy

Password: booya

Error: authenticating creds for “ repo.wallyswonderworld.com”: pinging container registry repo.wallyswonderworld.com: StatusCode: 404,

.. [root@RPTBWILCS060 ~]# podman login repo.wallyswonderworld.com:443 Username: fuzzy

Password: booya

Error: authenticating creds for "repo.wallyswonderworld.com:443": pinging container registry repo.wallyswonderworld.com:443: StatusCode: 404,

.. [root@RPTBWILCS060 ~]# podman login https://repo.wallyswonderworld.com Username: fuzzy

Password: booya

Error: authenticating creds for "repo.wallyswonderworld.com": pinging container registry repo.wallyswonderworld.com: StatusCode: 404,

.. [root@RPTBWILCS060 ~]#