How to go about Nexus access for CI/CD pipeline?

Hello, not sure how to tag this.

I am setting up a pipeline in Gitlab that builds our LEAF services and publishes them to a container image registry. I am trying to think of how to include the gradle plugins/LEAF Nexus packages for the build stage.

My ideas:

  1. Use my personal gradle.properties as a CICD environment variable that is injected into the pipeline, this should allow the runner to authenticate with Leaf’s nexus repo, but this would potentially expose my credentials to anyone viewing the CICD variables for the project.

  2. Create a LEAF user specifically for CICD work, then use those credentials to populate a gradle.properties file on my runner so it can fetch the needed dependencies. However, I am not sure if I am able to create a LEAF account for this purpose, as LEAF accounts seem to be tied to our employee IDs/ email addresses.

  3. Clone dependencies from LEAF’s nexus repo to our own Nexus, then create a user there to authenticate with in order to fetch dependencies in the build stage. However, I am not sure how to do this. I am wondering if there are permissions I must request that would allow me to perform this clone.

Could anyone advise on what the best approach would be here? I am uncertain if I will need special LEAF permissions if I do clone the artifacts over to our repository.

Thanks!
Josh

Hi Josh,

I believe we have a service account that we can use to pull dependencies from LEAF’s Nexus. I’ll reach out via Slack and try to get you access to those credentials. With regards to the best way to use them in Gitlab, I’ll defer to others with more knowledge of CI/CD in general and Gitlab specifically who can make better recommendations.

Kerwin

1 Like