Overview

ARMO platform allows you to scan container images from your Nexus Container Registry for vulnerabilities. This guide provides step-by-step instructions to connect your Nexus registry with the ARMO platform.


Prerequisites

  • Access to the Nexus Repository Manager.
  • An active ARMO account.
  • Username and password with read permissions for the desired repository.

Quick Guide: Generating Nexus Registry Credentials

  1. Log in to the Nexus Repository Manager.
  2. Navigate to Security > Users in the Administration section of the Nexus dashboard.
  3. Create or identify a user account with the following permissions:
    • nx-repository-view-*-*-read (read-only access to all repositories).
  4. Copy the username and password for authentication.

Step-by-Step Guide

Step 1: Navigate to the Integrations Page

  1. Log in to the ARMO platform.
  2. Go to Settings > Integrations.
  3. Under Container Registries, click Connect for Nexus.


Step 2: Add a New Registry

  1. Click Add Registry to open the configuration panel.

  2. Fill in the required details:

    • Cluster: Select the cluster from which scanning will be initiated.
    • Registry URL: Enter your Nexus registry URL (e.g., nexus.example.com).
    • Username: Enter the Nexus user account with read access.
    • Password: Provide the password for the user account.
  3. Click Next to continue.


Step 3: Schedule Scans (Optional)

  1. Select the repository to scan.

  2. Configure periodic scans:

    • Frequency: Set to daily or weekly.
    • Time: Define the time in UTC.
  3. Click Save to finalize the schedule.


Step 4: Finalize the Connection

  1. Review the details of your configuration.
  2. Click Save to activate the integration.

Your Nexus Container Registry is now successfully connected to the ARMO platform.


Conclusion

By integrating your Nexus Container Registry with the ARMO platform, you gain continuous visibility into the security of your container images. This integration enables automated scanning, timely detection of vulnerabilities, and actionable insights to maintain compliance.