Lightweight SAML 2.0 & OIDC test client with Fluent UI and raw token debugging.
1.4K
This guide describes how to deploy the Nexus SP Identity Lab using the official image from Docker Hub. This setup is "Secure by Default," requiring HTTPS and SAML signing certificates to boot.
Before pulling the image, create a deployment folder on your host machine. The application expects the following layout to mount its configuration:
nexus-lab/
āāā docker-compose.yml
āāā nexus-data/ # Autogenerated (Stores H2 Database & Logs)
āāā config/
āāā application.properties
āāā config.json
āāā logback-spring.xml
āāā certs/ # š CRITICAL: Place all certificates here
āāā tls.crt # HTTPS Public Certificate
āāā tls.key # HTTPS Private Key
āāā cert.pem # SAML SP Public Certificate
āāā key.pem # SAML SP Private Key
If you do not have CA-signed certificates, run these commands inside your config/certs/ folder to generate self-signed versions for testing:
tls)openssl req -x509 -newkey rsa:4096 -keyout tls.key -out tls.crt -sha256 -days 365 -nodes -subj "/CN=localhost"
cert/key.pem)openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 365 -nodes -subj "/CN=nexus-sp-saml"
config/application.propertiesEnsure your properties file points to the internal container paths:
server.port=8443
server.ssl.enabled=true
server.ssl.certificate=file:/app/config/certs/tls.crt
server.ssl.certificate-private-key=file:/app/config/certs/tls.key
# Persistence
spring.datasource.url=jdbc:h2:file:/app/data/nexusdb
server.forward-headers-strategy=framework
config/config.jsonUpdate your SAML provider entry to use the mounted volume paths:
[
{
"displayName": "MockSAML Lab",
"enabled": true,
"type": "SAML",
"metadataUrl": "https://mocksaml.com/api/saml/metadata",
"entityId": "{baseUrl}/saml2/service-provider-metadata/1",
"signingCertificatePath": "file:/app/config/certs/saml.cer",
"signingPrivateKeyPath": "file:/app/config/certs/saml.key"
},
{
"displayName": "Duende Mock OIDC",
"enabled": true,
"type": "OIDC",
"metadataUrl": "https://demo.duendesoftware.com",
"clientId": "interactive.confidential",
"clientSecret": "secret",
"oidcScopes": "openid profile email",
"pkceEnabled": false
}
]
docker-compose.yml)Copy this manifest into your root nexus-lab/ folder. Replace yourusername with your Docker Hub handle.
services:
nexus-sp:
image: kowama/nexus-sp:latest
container_name: nexus-sp-runtime
ports:
- "443:8443" # Standard HTTPS
restart: unless-stopped
environment:
- SPRING_CONFIG_ADDITIONAL_LOCATION=file:/app/config/
- LOGGING_CONFIG=file:/app/config/logback-spring.xml
- NEXUS_CONFIG_PATH=/app/config/config.json
volumes:
- ./config:/app/config:ro
- ./nexus-data:/app/data
# Pull and start
docker compose up -d
# Check if the app found your certificates
docker compose logs -f
| Symptom | Cause | Solution |
|---|---|---|
| Container crashes immediately | Missing tls.crt or tls.key | Check config/certs/ folder permissions and filenames. |
| SAML Login fails (500 Error) | Missing cert.pem or key.pem | Ensure SAML keys exist and are referenced correctly in config.json. |
| "Permission Denied" in logs | Root-owned config files | Ensure the host files are readable by the Docker user (or use chmod 644). |
Content type
Image
Digest
sha256:868fe57f2ā¦
Size
147.4 MB
Last updated
7 months ago
docker pull kowama/nexus-sp