CloudOpsGuide
jenkins

Jenkins Docker Nexus Pipeline Example

Intermediate
15 minutes
October 2026
CloudOpsGuide Team

Jenkins Docker Nexus Pipeline Example

Build Docker images, push to Nexus registry, and deploy with this complete Jenkins pipeline — a real-world CI/CD pattern used in production environments.

Table of Contents

Architecture Overview

This pipeline covers the full delivery flow:

GitHub → Jenkins → Build → Test → Docker Build → Nexus Registry → Deploy to K8s
  1. Developer pushes code to GitHub
  2. Webhook triggers Jenkins
  3. Jenkins builds and tests the app
  4. Docker image is built and tagged
  5. Image pushed to Nexus Docker registry
  6. Kubernetes pulls and deploys the image

Prerequisites

  • Jenkins controller running (on Kubernetes or VM)
  • Nexus Repository Manager with a Docker (hosted) repository
  • Kubernetes cluster
  • Plugins: Pipeline, Docker Pipeline, Kubernetes CLI, Credentials Binding

Nexus Docker Repository Setup

  1. Nexus Admin → Repositories → Create repository
  2. Choose docker (hosted)
  3. Set an HTTP connector port (e.g., 8082)
  4. Enable Docker Bearer Token Realm in Security → Realms

Test push manually:

docker login nexus.example.com:8082
docker tag my-app:1.0 nexus.example.com:8082/my-app:1.0
docker push nexus.example.com:8082/my-app:1.0

Jenkins Credentials

Create these credentials in Manage Jenkins → Credentials:

IDTypeContains
nexus-dockerUsername/PasswordNexus registry credentials
kubeconfigSecret fileKubernetes config
github-tokenSecret textGitHub PAT

Complete Jenkinsfile

pipeline {
    agent any

    environment {
        NEXUS_REGISTRY  = 'nexus.example.com:8082'
        IMAGE_NAME      = 'my-app'
        IMAGE_TAG       = "${env.BRANCH_NAME}-${env.BUILD_NUMBER}-${env.GIT_COMMIT.take(7)}"
        DOCKER_CREDS    = credentials('nexus-docker')
    }

    options {
        buildDiscarder(logRotator(numToKeepStr: '10'))
        timeout(time: 30, unit: 'MINUTES')
        timestamps()
    }

    stages {
        stage('Checkout') {
            steps {
                checkout scm
            }
        }

        stage('Unit Tests') {
            steps {
                sh 'npm ci && npm test'
            }
        }

        stage('Build Docker Image') {
            steps {
                sh """
                    docker build \
                      --tag ${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG} \
                      --tag ${NEXUS_REGISTRY}/${IMAGE_NAME}:latest \
                      .
                """
            }
        }

        stage('Security Scan') {
            steps {
                sh """
                    trivy image --exit-code 0 \
                      --severity HIGH,CRITICAL \
                      ${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG}
                """
            }
        }

        stage('Push to Nexus') {
            steps {
                sh """
                    echo ${DOCKER_CREDS_PSW} | docker login ${NEXUS_REGISTRY} \
                      -u ${DOCKER_CREDS_USR} --password-stdin

                    docker push ${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG}
                    docker push ${NEXUS_REGISTRY}/${IMAGE_NAME}:latest
                """
            }
        }

        stage('Deploy to Kubernetes') {
            when { branch 'main' }
            steps {
                withKubeConfig([credentialsId: 'kubeconfig']) {
                    sh """
                        kubectl set image deployment/my-app \
                          my-app=${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG} \
                          -n production

                        kubectl rollout status deployment/my-app -n production --timeout=300s
                    """
                }
            }
        }
    }

    post {
        always {
            sh 'docker logout ${NEXUS_REGISTRY} || true'
            cleanWs()
        }
        success {
            echo "Deployed ${IMAGE_TAG} successfully"
        }
        failure {
            echo "Pipeline failed — check logs"
        }
    }
}

Deployment Stage Details

Pull Secret for Nexus

Kubernetes needs credentials to pull from Nexus:

kubectl create secret docker-registry nexus-regcred \
  --docker-server=nexus.example.com:8082 \
  --docker-username=<nexus-user> \
  --docker-password=<nexus-pass> \
  --namespace production

Reference in your deployment:

spec:
  imagePullSecrets:
    - name: nexus-regcred

Alternative: Helm-based Deploy

stage('Deploy with Helm') {
    steps {
        withKubeConfig([credentialsId: 'kubeconfig']) {
            sh """
                helm upgrade --install my-app ./charts/my-app \
                  --set image.repository=${NEXUS_REGISTRY}/${IMAGE_NAME} \
                  --set image.tag=${IMAGE_TAG} \
                  --namespace production \
                  --wait --timeout 5m
            """
        }
    }
}

Troubleshooting

"no basic auth credentials" on docker push

Fix: Check credentials are bound correctly and login succeeded. Verify the registry port is included in NEXUS_REGISTRY.

ImagePullBackOff on Kubernetes

kubectl describe pod <pod>  # check events
# Verify nexus-regcred exists and has correct server:port
kubectl get secret nexus-regcred -o jsonpath='{.data.\.dockerconfigjson}' | base64 -d

HTTPS vs HTTP registry

Nexus on plain HTTP needs Docker daemon config:

// /etc/docker/daemon.json
{ "insecure-registries": ["nexus.example.com:8082"] }

Better: put Nexus behind HTTPS with a proper certificate.

Pipeline runs as wrong user

// Ensure docker socket access or use dind
agent {
    docker {
        image 'docker:24-cli'
        args '-v /var/run/docker.sock:/var/run/docker.sock'
    }
}

Best Practices

  1. Immutable tags — tag with branch-build-commit, never rely on latest alone
  2. Scan before push — don't push vulnerable images to the registry
  3. Logout in post — always clean up credentials
  4. Timeout everything — prevent hung builds
  5. Use imagePullSecrets — never bake registry creds into images
  6. Archive scan reports — keep audit trail of security scans

Related Articles


Last Updated: October 2026
Author: CloudOpsGuide Team
Difficulty: Intermediate
Estimated Reading Time: 15 minutes