Phase 3: Artifact migration
Migrating artifacts from Sonatype Nexus
Migration from Nexus typically uses one of two approaches: configuring Cloudsmith upstreams, or exporting hosted repositories for bulk upload. For the strategies behind these, see Migrating your artifacts.
Many organizations begin by publishing new build artifacts directly to Cloudsmith while continuing to serve downstream consumers through Nexus, using a proxy repository pointed at Cloudsmith. This is the registry proxy migration approach.
What to migrate
Only hosted repositories hold artifacts that need moving. Proxy and group repositories are configuration, and are recreated in Cloudsmith rather than exported.
| Nexus repository | Cloudsmith equivalent | Action |
|---|---|---|
| Hosted | Repository | Export, then import with the CLI. |
| Proxy | Upstream on a repository | Recreate as an upstream pointing at the same source. Nothing to export. |
| Group | One repository with several upstreams | Recreate. Cloudsmith repositories serve their own packages and their upstreams from one endpoint. |
See Configuring legacy platforms as upstreams if you want Cloudsmith to fetch from Nexus itself during the transition.
Exporting hosted repositories
Nexus Repository has no built-in command to export a repository's packages. Use its REST API instead: the
Assets API lists every asset in a repository, paged with a
continuation token, and each entry carries a downloadUrl you fetch with the same credentials. The
Components API and
Search API offer the same data grouped by component or
filtered by name and version. All three are documented under Sonatype's
REST and integration API.
You need a Nexus account that can read the repositories being migrated, and a machine that can reach the Nexus API and has disk for one repository at a time. Before you start, read Running a bulk import.
What matters for the Cloudsmith side:
- Keep the repository's path layout when you save files. The Maven import pairs POMs with their JARs by path, and the folder script searches subfolders, so there is nothing to flatten.
- Expect files that are not packages. Debian and RPM hosted repositories include generated
dists/andrepodata/index trees. The import scripts filter by extension, so these are skipped as long as you pass one. - Record how many files you downloaded for each repository, for example with
find ./export/REPOSITORY -type f | wc -l. The Assets API returns pages and a continuation token, not a total, so the count comes from what you saved. You compare it with what lands in Cloudsmith during verification. - Spaces in paths are returned unencoded in
downloadUrland must be URL-encoded before fetching.
Next steps
With your artifacts exported, publish them to Cloudsmith with Importing packages with the CLI, or Importing Docker images for container repositories, which need no export.
For the wider pipeline work, see Phase 2: Discovery and migration planning.