Sign inSign up

kowama/nexus-sp

By kowama

•Updated 7 months ago

Lightweight SAML 2.0 & OIDC test client with Fluent UI and raw token debugging.

Image
Security
Developer tools
0

1.4K

kowama/nexus-sp repository overview

⁠🐳 Nexus SP | Docker Hub Deployment Guide

This guide describes how to deploy the Nexus SP Identity Lab using the official image from Docker Hub. This setup is "Secure by Default," requiring HTTPS and SAML signing certificates to boot.

ā šŸ“‚ 1. Required Directory Structure

Before pulling the image, create a deployment folder on your host machine. The application expects the following layout to mount its configuration:

nexus-lab/
ā”œā”€ā”€ docker-compose.yml
ā”œā”€ā”€ nexus-data/             # Autogenerated (Stores H2 Database & Logs)
└── config/
    ā”œā”€ā”€ application.properties
    ā”œā”€ā”€ config.json
    ā”œā”€ā”€ logback-spring.xml
    └── certs/              # šŸ” CRITICAL: Place all certificates here
        ā”œā”€ā”€ tls.crt         # HTTPS Public Certificate
        ā”œā”€ā”€ tls.key         # HTTPS Private Key
        ā”œā”€ā”€ cert.pem        # SAML SP Public Certificate
        └── key.pem         # SAML SP Private Key

ā šŸ”‘ 2. Generating Required Certificates

If you do not have CA-signed certificates, run these commands inside your config/certs/ folder to generate self-signed versions for testing:

⁠Create HTTPS Certificates (tls)
openssl req -x509 -newkey rsa:4096 -keyout tls.key -out tls.crt -sha256 -days 365 -nodes -subj "/CN=localhost"
⁠Create SAML Signing Keys (cert/key.pem)
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 365 -nodes -subj "/CN=nexus-sp-saml"

ā āš™ļø 3. Configuration Setup

⁠config/application.properties

Ensure your properties file points to the internal container paths:

server.port=8443
server.ssl.enabled=true
server.ssl.certificate=file:/app/config/certs/tls.crt
server.ssl.certificate-private-key=file:/app/config/certs/tls.key

# Persistence
spring.datasource.url=jdbc:h2:file:/app/data/nexusdb
server.forward-headers-strategy=framework
⁠config/config.json

Update your SAML provider entry to use the mounted volume paths:

[
  {
    "displayName": "MockSAML Lab",
    "enabled": true,
    "type": "SAML",
    "metadataUrl": "https://mocksaml.com/api/saml/metadata",
    "entityId": "{baseUrl}/saml2/service-provider-metadata/1",
    "signingCertificatePath": "file:/app/config/certs/saml.cer",
    "signingPrivateKeyPath": "file:/app/config/certs/saml.key"
  },
  {
    "displayName": "Duende Mock OIDC",
    "enabled": true,
    "type": "OIDC",
    "metadataUrl": "https://demo.duendesoftware.com",
    "clientId": "interactive.confidential",
    "clientSecret": "secret",
    "oidcScopes": "openid profile email",
    "pkceEnabled": false
  }
]

ā šŸš€ 4. Deployment (docker-compose.yml)

Copy this manifest into your root nexus-lab/ folder. Replace yourusername with your Docker Hub handle.


services:
  nexus-sp:
    image: kowama/nexus-sp:latest
    container_name: nexus-sp-runtime
    ports:
      - "443:8443"  # Standard HTTPS
    restart: unless-stopped
    environment:
      - SPRING_CONFIG_ADDITIONAL_LOCATION=file:/app/config/
      - LOGGING_CONFIG=file:/app/config/logback-spring.xml
      - NEXUS_CONFIG_PATH=/app/config/config.json
    volumes:
      - ./config:/app/config:ro
      - ./nexus-data:/app/data

ā šŸ› ļø 5. Running the Lab

⁠Run
# Pull and start
docker compose up -d

# Check if the app found your certificates
docker compose logs -f

ā šŸ›‘ 6. Troubleshooting

SymptomCauseSolution
Container crashes immediatelyMissing tls.crt or tls.keyCheck config/certs/ folder permissions and filenames.
SAML Login fails (500 Error)Missing cert.pem or key.pemEnsure SAML keys exist and are referenced correctly in config.json.
"Permission Denied" in logsRoot-owned config filesEnsure the host files are readable by the Docker user (or use chmod 644).

Tag summary

Content type

Image

Digest

sha256:868fe57f2…

Size

147.4 MB

Last updated

7 months ago

docker pull kowama/nexus-sp