Skip to main content

Overview

The Nexus Image Registry integration gives Backline read-only pull access to the container images your applications run from a private Sonatype Nexus Repository, so those images are analyzed for vulnerabilities and remediated. You supply the docker registry endpoint of your Nexus instance and, if the repository requires authentication, one set of credentials. Backline uses them for every image whose address matches that endpoint — you do not list repositories or images.
This integration is for container images. Private packages hosted in Nexus (npm, PyPI, Go, Maven, NuGet) are a separate integration, Nexus Package Registry. See Two Nexus integrations below.

What You Can Do

With the Nexus Image Registry integration, Backline can:
  • Analyze image layers for vulnerabilities
  • Detect security issues in dependencies
  • Attribute findings to the image’s base image and track them across versions
  • Suggest a safer base image tag where a newer tag resolves the reported vulnerabilities
Where an image carries no source provenance, Backline asks you to map it to its repository and Dockerfile once. See Image to Code Mapping.

Which URL to Use

Enter the docker registry endpoint — the host (and port) that appears in your image references, exactly as you would use it in docker pull <host>[:port]/<image>:<tag>. This is not the Nexus web UI URL. How that endpoint looks depends on how your Nexus repository’s docker connector is exposed: Backline matches images to this connection by the exact host and port of the image reference. An image referenced through a different alias or port — nexus.example.com:8443/... when you configured https://nexus.example.com — is not resolved through this connection. Configure the address your image references actually use.
The Nexus UI URL (typically port 8081) does not serve the Docker registry API. Entering it fails Test Connection with “This URL does not answer as a Docker registry (/v2/) endpoint”.

Prerequisites

Before connecting Nexus Image Registry, ensure you have:
  • A Sonatype Nexus Repository instance hosting docker repositories (hosted, proxy, or group)
  • The Docker Bearer Token Realm active — in Nexus, Administration > Security > Realms
  • The docker registry endpoint, as described above

Anonymous Pulls

If your docker repository allows anonymous pulls, leave both credential fields empty. Anonymous docker access in Nexus requires all of:
  • Anonymous access enabled globally — Administration > Security > Anonymous Access
  • The Docker Bearer Token Realm active
  • On the repository’s docker connector, Allow anonymous docker pull checked (in older versions: Force basic authentication unchecked)

Authenticated Pulls

If the repository requires authentication, create a dedicated Nexus user for Backline with read-only access to the docker repositories your images live in — a role holding the nx-repository-view-docker-<repository>-read and -browse privileges is enough. Backline only pulls images; it never pushes. Supply either:
  • Username and password of that user, or
  • A user token (Nexus Repository Pro): the token name code goes in Username and the pass code in Password
Provide both Username and Password, or neither. A username without a password is rejected.

Connecting Nexus Image Registry

1

Go to Integration Hub

In Backline, navigate to Integrations from the main menu.
2

Select Nexus Image Registry

Find and click on the Nexus Image Registry integration card, among the container registries.
3

Enter the Registry URL

Enter the docker registry endpoint as described in Which URL to Use, including the scheme — for example https://nexus.example.com:8443.
4

Enter Credentials (Optional)

Provide the Username and Password (or user token name code and pass code) of the read-only Nexus user. Leave both empty for anonymous pulls.
5

Test Connection

Click Test Connection. See What Test Connection Checks for how to read the result.
6

Save

Click Save to complete the integration.
Backline supports one Nexus Image Registry connection per tenant.

What Test Connection Checks

Backline validates the connection from its cloud by contacting the registry’s /v2/ endpoint and completing the same authentication flow a docker pull would. Saving the integration runs the same check.
Validation is best-effort. A registry that Backline’s cloud cannot reach — the common case for a firewalled or on-premises Nexus — passes with a green result. Green therefore confirms the configuration is not provably wrong; it does not prove Backline’s cloud can reach the registry.
A reachable registry that is misconfigured fails with the specific reason: Credentials that break after setup — a rotated password, a revoked user token, a removed role — surface when you next click Test Connection, and as failed image pulls in the meantime.

Plain HTTP Registries

http:// registry URLs are accepted, but credentials then travel unencrypted. Use plain HTTP only on networks you control, and prefer HTTPS.Image analysis for an http:// registry additionally requires your Backline deployment to allow insecure registries — contact Backline to enable this. Vulnerability scanning and safer-base-image evaluation currently require HTTPS. These limits apply to any plain-HTTP registry, not only Nexus.

After Connection

Once Nexus Image Registry is connected, Backline will:
  1. Use the stored credentials (if any) each time it pulls one of your images from the configured registry
  2. Analyze the images your applications reference at that address
  3. Report findings, inventory, and base-image attribution for those images
  4. Suggest a safer base image tag where a newer tag resolves the reported vulnerabilities

Managing the Integration

Updating the Registry URL or Credentials

  1. Open the Integration Hub and click on the Nexus Image Registry integration
  2. Change the Registry URL, or enter new credentials — to switch to anonymous pulls, clear both Username and Password
  3. Click Test Connection, then Save

Disconnecting

  1. Go to the Integration Hub
  2. Click on the Nexus Image Registry integration
  3. Select Disconnect
  4. Confirm your choice
Disconnecting stops Backline from pulling images from your Nexus registry, so those images will no longer produce findings.

Two Nexus Integrations

Backline has two separate Nexus integrations, each with its own credentials, status, and lifecycle. You can hold both at once — including for the same Nexus instance.

Troubleshooting

Test Connection Fails

  • Match the failure to the table above — each message names the misconfiguration
  • For “does not answer as a Docker registry”, confirm you entered the docker connector URL, not the Nexus UI URL
  • For “rejected the credentials”, confirm the user has read access to the docker repository and that a user token’s name code and pass code are in the right fields

Connected, but Images Produce No Findings

  • Confirm your image references use exactly the host and port configured in the Registry URL
  • Test Connection passes for a registry Backline’s cloud cannot reach, so it does not prove pulls work: Backline must be able to pull from the registry at analysis time — from your on-premises Backline agent if you run one; otherwise from Backline’s cloud
  • Confirm the docker repository (or the group it belongs to) still contains the image tags your applications reference
  • Click Test Connection; a failure names the reason