jenkins
Jenkins Docker Nexus Pipeline Example
Intermediate
15 minutes
October 2026
CloudOpsGuide Team
Jenkins Docker Nexus Pipeline Example
Build Docker images, push to Nexus registry, and deploy with this complete Jenkins pipeline — a real-world CI/CD pattern used in production environments.
Table of Contents
- Architecture Overview
- Prerequisites
- Nexus Setup
- Jenkins Credentials
- Complete Jenkinsfile
- Deployment Stage
- Troubleshooting
Architecture Overview
This pipeline covers the full delivery flow:
GitHub → Jenkins → Build → Test → Docker Build → Nexus Registry → Deploy to K8s
- Developer pushes code to GitHub
- Webhook triggers Jenkins
- Jenkins builds and tests the app
- Docker image is built and tagged
- Image pushed to Nexus Docker registry
- Kubernetes pulls and deploys the image
Prerequisites
- Jenkins controller running (on Kubernetes or VM)
- Nexus Repository Manager with a Docker (hosted) repository
- Kubernetes cluster
- Plugins: Pipeline, Docker Pipeline, Kubernetes CLI, Credentials Binding
Nexus Docker Repository Setup
- Nexus Admin → Repositories → Create repository
- Choose docker (hosted)
- Set an HTTP connector port (e.g.,
8082) - Enable Docker Bearer Token Realm in Security → Realms
Test push manually:
docker login nexus.example.com:8082
docker tag my-app:1.0 nexus.example.com:8082/my-app:1.0
docker push nexus.example.com:8082/my-app:1.0
Jenkins Credentials
Create these credentials in Manage Jenkins → Credentials:
| ID | Type | Contains |
|---|---|---|
nexus-docker | Username/Password | Nexus registry credentials |
kubeconfig | Secret file | Kubernetes config |
github-token | Secret text | GitHub PAT |
Complete Jenkinsfile
pipeline {
agent any
environment {
NEXUS_REGISTRY = 'nexus.example.com:8082'
IMAGE_NAME = 'my-app'
IMAGE_TAG = "${env.BRANCH_NAME}-${env.BUILD_NUMBER}-${env.GIT_COMMIT.take(7)}"
DOCKER_CREDS = credentials('nexus-docker')
}
options {
buildDiscarder(logRotator(numToKeepStr: '10'))
timeout(time: 30, unit: 'MINUTES')
timestamps()
}
stages {
stage('Checkout') {
steps {
checkout scm
}
}
stage('Unit Tests') {
steps {
sh 'npm ci && npm test'
}
}
stage('Build Docker Image') {
steps {
sh """
docker build \
--tag ${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG} \
--tag ${NEXUS_REGISTRY}/${IMAGE_NAME}:latest \
.
"""
}
}
stage('Security Scan') {
steps {
sh """
trivy image --exit-code 0 \
--severity HIGH,CRITICAL \
${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG}
"""
}
}
stage('Push to Nexus') {
steps {
sh """
echo ${DOCKER_CREDS_PSW} | docker login ${NEXUS_REGISTRY} \
-u ${DOCKER_CREDS_USR} --password-stdin
docker push ${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG}
docker push ${NEXUS_REGISTRY}/${IMAGE_NAME}:latest
"""
}
}
stage('Deploy to Kubernetes') {
when { branch 'main' }
steps {
withKubeConfig([credentialsId: 'kubeconfig']) {
sh """
kubectl set image deployment/my-app \
my-app=${NEXUS_REGISTRY}/${IMAGE_NAME}:${IMAGE_TAG} \
-n production
kubectl rollout status deployment/my-app -n production --timeout=300s
"""
}
}
}
}
post {
always {
sh 'docker logout ${NEXUS_REGISTRY} || true'
cleanWs()
}
success {
echo "Deployed ${IMAGE_TAG} successfully"
}
failure {
echo "Pipeline failed — check logs"
}
}
}
Deployment Stage Details
Pull Secret for Nexus
Kubernetes needs credentials to pull from Nexus:
kubectl create secret docker-registry nexus-regcred \
--docker-server=nexus.example.com:8082 \
--docker-username=<nexus-user> \
--docker-password=<nexus-pass> \
--namespace production
Reference in your deployment:
spec:
imagePullSecrets:
- name: nexus-regcred
Alternative: Helm-based Deploy
stage('Deploy with Helm') {
steps {
withKubeConfig([credentialsId: 'kubeconfig']) {
sh """
helm upgrade --install my-app ./charts/my-app \
--set image.repository=${NEXUS_REGISTRY}/${IMAGE_NAME} \
--set image.tag=${IMAGE_TAG} \
--namespace production \
--wait --timeout 5m
"""
}
}
}
Troubleshooting
"no basic auth credentials" on docker push
Fix: Check credentials are bound correctly and login succeeded. Verify the registry port is included in NEXUS_REGISTRY.
ImagePullBackOff on Kubernetes
kubectl describe pod <pod> # check events
# Verify nexus-regcred exists and has correct server:port
kubectl get secret nexus-regcred -o jsonpath='{.data.\.dockerconfigjson}' | base64 -d
HTTPS vs HTTP registry
Nexus on plain HTTP needs Docker daemon config:
// /etc/docker/daemon.json
{ "insecure-registries": ["nexus.example.com:8082"] }
Better: put Nexus behind HTTPS with a proper certificate.
Pipeline runs as wrong user
// Ensure docker socket access or use dind
agent {
docker {
image 'docker:24-cli'
args '-v /var/run/docker.sock:/var/run/docker.sock'
}
}
Best Practices
- Immutable tags — tag with
branch-build-commit, never rely onlatestalone - Scan before push — don't push vulnerable images to the registry
- Logout in post — always clean up credentials
- Timeout everything — prevent hung builds
- Use imagePullSecrets — never bake registry creds into images
- Archive scan reports — keep audit trail of security scans
Related Articles
Last Updated: October 2026
Author: CloudOpsGuide Team
Difficulty: Intermediate
Estimated Reading Time: 15 minutes