Overview
The Nexus Image Registry integration gives Backline read-only pull access to the container images your applications run from a private Sonatype Nexus Repository, so those images are analyzed for vulnerabilities and remediated. You supply the docker registry endpoint of your Nexus instance and, if the repository requires authentication, one set of credentials. Backline uses them for every image whose address matches that endpoint — you do not list repositories or images.This integration is for container images. Private packages hosted in Nexus (npm, PyPI, Go, Maven, NuGet) are a separate integration, Nexus Package Registry. See Two Nexus integrations below.
What You Can Do
With the Nexus Image Registry integration, Backline can:- Analyze image layers for vulnerabilities
- Detect security issues in dependencies
- Attribute findings to the image’s base image and track them across versions
- Suggest a safer base image tag where a newer tag resolves the reported vulnerabilities
Which URL to Use
Enter the docker registry endpoint — the host (and port) that appears in your image references, exactly as you would use it indocker pull <host>[:port]/<image>:<tag>. This is not the Nexus web UI URL.
How that endpoint looks depends on how your Nexus repository’s docker connector is exposed:
Backline matches images to this connection by the exact host and port of the image reference. An image referenced through a different alias or port —
nexus.example.com:8443/... when you configured https://nexus.example.com — is not resolved through this connection. Configure the address your image references actually use.
The Nexus UI URL (typically port
8081) does not serve the Docker registry API. Entering it fails Test Connection with “This URL does not answer as a Docker registry (/v2/) endpoint”.Prerequisites
Before connecting Nexus Image Registry, ensure you have:- A Sonatype Nexus Repository instance hosting docker repositories (hosted, proxy, or group)
- The Docker Bearer Token Realm active — in Nexus, Administration > Security > Realms
- The docker registry endpoint, as described above
Anonymous Pulls
If your docker repository allows anonymous pulls, leave both credential fields empty. Anonymous docker access in Nexus requires all of:- Anonymous access enabled globally — Administration > Security > Anonymous Access
- The Docker Bearer Token Realm active
- On the repository’s docker connector, Allow anonymous docker pull checked (in older versions: Force basic authentication unchecked)
Authenticated Pulls
If the repository requires authentication, create a dedicated Nexus user for Backline with read-only access to the docker repositories your images live in — a role holding thenx-repository-view-docker-<repository>-read and -browse privileges is enough. Backline only pulls images; it never pushes.
Supply either:
- Username and password of that user, or
- A user token (Nexus Repository Pro): the token name code goes in Username and the pass code in Password
Provide both Username and Password, or neither. A username without a password is rejected.
Connecting Nexus Image Registry
1
Go to Integration Hub
In Backline, navigate to Integrations from the main menu.
2
Select Nexus Image Registry
Find and click on the Nexus Image Registry integration card, among the container registries.
3
Enter the Registry URL
Enter the docker registry endpoint as described in Which URL to Use, including the scheme — for example
https://nexus.example.com:8443.4
Enter Credentials (Optional)
Provide the Username and Password (or user token name code and pass code) of the read-only Nexus user. Leave both empty for anonymous pulls.
5
Test Connection
Click Test Connection. See What Test Connection Checks for how to read the result.
6
Save
Click Save to complete the integration.
Backline supports one Nexus Image Registry connection per tenant.
What Test Connection Checks
Backline validates the connection from its cloud by contacting the registry’s/v2/ endpoint and completing the same authentication flow a docker pull would. Saving the integration runs the same check.
Validation is best-effort. A registry that Backline’s cloud cannot reach — the common case for a firewalled or on-premises Nexus — passes with a green result. Green therefore confirms the configuration is not provably wrong; it does not prove Backline’s cloud can reach the registry.
Credentials that break after setup — a rotated password, a revoked user token, a removed role — surface when you next click Test Connection, and as failed image pulls in the meantime.
Plain HTTP Registries
After Connection
Once Nexus Image Registry is connected, Backline will:- Use the stored credentials (if any) each time it pulls one of your images from the configured registry
- Analyze the images your applications reference at that address
- Report findings, inventory, and base-image attribution for those images
- Suggest a safer base image tag where a newer tag resolves the reported vulnerabilities
Managing the Integration
Updating the Registry URL or Credentials
- Open the Integration Hub and click on the Nexus Image Registry integration
- Change the Registry URL, or enter new credentials — to switch to anonymous pulls, clear both Username and Password
- Click Test Connection, then Save
Disconnecting
- Go to the Integration Hub
- Click on the Nexus Image Registry integration
- Select Disconnect
- Confirm your choice
Two Nexus Integrations
Backline has two separate Nexus integrations, each with its own credentials, status, and lifecycle. You can hold both at once — including for the same Nexus instance.Troubleshooting
Test Connection Fails
- Match the failure to the table above — each message names the misconfiguration
- For “does not answer as a Docker registry”, confirm you entered the docker connector URL, not the Nexus UI URL
- For “rejected the credentials”, confirm the user has read access to the docker repository and that a user token’s name code and pass code are in the right fields
Connected, but Images Produce No Findings
- Confirm your image references use exactly the host and port configured in the Registry URL
- Test Connection passes for a registry Backline’s cloud cannot reach, so it does not prove pulls work: Backline must be able to pull from the registry at analysis time — from your on-premises Backline agent if you run one; otherwise from Backline’s cloud
- Confirm the docker repository (or the group it belongs to) still contains the image tags your applications reference
- Click Test Connection; a failure names the reason