Phase 3: Artifact migration

Migrating artifacts from Sonatype Nexus

Migration from Nexus typically uses one of two approaches: configuring Cloudsmith upstreams, or exporting hosted repositories for bulk upload. For the strategies behind these, see Migrating your artifacts.

Many organizations begin by publishing new build artifacts directly to Cloudsmith while continuing to serve downstream consumers through Nexus, using a proxy repository pointed at Cloudsmith. This is the registry proxy migration approach.

What to migrate

Only hosted repositories hold artifacts that need moving. Proxy and group repositories are configuration, and are recreated in Cloudsmith rather than exported.

Nexus repositoryCloudsmith equivalentAction
HostedRepositoryExport, then import with the CLI.
ProxyUpstream on a repositoryRecreate as an upstream pointing at the same source. Nothing to export.
GroupOne repository with several upstreamsRecreate. Cloudsmith repositories serve their own packages and their upstreams from one endpoint.

See Configuring legacy platforms as upstreams if you want Cloudsmith to fetch from Nexus itself during the transition.

Exporting hosted repositories

Nexus Repository has no built-in command to export a repository's packages. Use its REST API instead: the Assets API lists every asset in a repository, paged with a continuation token, and each entry carries a downloadUrl you fetch with the same credentials. The Components API and Search API offer the same data grouped by component or filtered by name and version. All three are documented under Sonatype's REST and integration API.

You need a Nexus account that can read the repositories being migrated, and a machine that can reach the Nexus API and has disk for one repository at a time. Before you start, read Running a bulk import.

What matters for the Cloudsmith side:

  • Keep the repository's path layout when you save files. The Maven import pairs POMs with their JARs by path, and the folder script searches subfolders, so there is nothing to flatten.
  • Expect files that are not packages. Debian and RPM hosted repositories include generated dists/ and repodata/ index trees. The import scripts filter by extension, so these are skipped as long as you pass one.
  • Record how many files you downloaded for each repository, for example with find ./export/REPOSITORY -type f | wc -l. The Assets API returns pages and a continuation token, not a total, so the count comes from what you saved. You compare it with what lands in Cloudsmith during verification.
  • Spaces in paths are returned unencoded in downloadUrl and must be URL-encoded before fetching.

Next steps

With your artifacts exported, publish them to Cloudsmith with Importing packages with the CLI, or Importing Docker images for container repositories, which need no export.

For the wider pipeline work, see Phase 2: Discovery and migration planning.