Skip to main content

Azure Blob Store

You must create the Azure storage account in Azure before using Nexus Repository to create an Azure blob store. The Azure storage container name must be a valid DNS name that follows the rules stated in the Microsoft documentation.

Below are the recommended storage account settings:

  • Location: the location hosting Nexus Repository

  • Performance: Standard general-purpose v2 or Premium block blobs

  • Account kind: StorageV2 if using Standard general-purpose v2 or BlockBlobStorage if using Premium block blobs

  • Replication: Any

When creating a new Azure blob store, Nexus Repository automatically creates an Azure container when one does not exist.

Changing the Blob Store Server

If you need to change the server that is contacted for Azure blob storage from "blob.core.windows.net" to something else, edit the existing <data-dir>/etc/nexus.properties file or set a Java system property as demonstrated below:

nexus.azure.server=<your.desired.blob.storage.server>

Restart the Nexus Repository for the change to take effect.

Accessing the Azure Storage Account

There are three methods of gaining access to the Azure storage account from Nexus Repository:

  1. Use a secret access key supplied by the Azure storage account.

  2. If you're running Nexus Repository on an Azure VM, you can use System Managed Identity access.

  3. Use environment variables.

System Managed Identity Access

System Managed Identity allows Azure to manage access via roles assigned to the VM in which you are running Nexus Repository. See the Microsoft documentation for details.

To properly use the System Managed Identity, the Azure VM will need the following roles assigned to the Azure storage container:

  • Storage Account Contributor

  • Storage Blob Data Contributor

Warning

For versions earlier than 3.96.0, Nexus Repository does not validate the roles before storing the configuration. When not properly granted to the VM, you must delete the blob store and then re-add it after the roles have been set up in the Azure storage instance.

Environment Variables

There are three environment variables for Azure blob stores:

AZURE_CLIENT_SECRET
AZURE_CLIENT_ID
AZURE_TENANT_ID

Register an Azure AD application and provide access to the blob storage.

Following Microsoft's documentation, complete the following steps:

  1. Create an application.

  2. Grant permission to Azure storage.

  3. Create a Client Secret.

  4. Copy the secret value to use as AZURE_CLIENT_SECRET.

  5. Retrieve the environment variables from the app registration overview screen:

    1. Directory (tenant) ID - the value for AZURE_TENANT_ID

    2. Application (client) ID - the value for AZURE_CLIENT_ID

You must then navigate to the storage container and grant the Storage Blob Data Contributor role to the application:

  1. Select Storage Accounts and then the storage account to which you want to grant access.

  2. Select Access Control (IAM); then, add a role assignment.

  3. Select Storage Blob Data Contributor.

  4. Select Next and then Add Member.

  5. Search for your application and add it as a member.

Now, set the environment variables in the terminal before launching the Nexus Repository.

Optimizing Performance

For optimum performance, you'll want to take the following steps:

  • Run Nexus Repository on Azure on virtual machines

  • Ensure that the Azure connection is using the location where Nexus Repository is being run

The chunk size when uploading to Azure can be adjusted by setting the property nexus.azure.blocksize in the nexus.properties file (e.g., nexus.azure.blocksize=1000000). By default, this is set to 5242880 bytes (5MB). You can tune this for optimal performance on your network.

Direct Download (SAS URLs)

Direct Download (SAS URLs) allows eligible binary downloads to go directly from Azure Blob Storage to the requesting client. This reduces outbound bandwidth and download-related resource use on the Nexus Repository host. Note that this behaviour is confined to downloads alone and the uploads always go through Nexus Repository

Direct Download is available only in Nexus Repository Pro versions. In versions earlier to 3.96.0, Azure-backed downloads continue to stream through the Nexus Repository server. Nexus Repository continues to authenticate and authorize the original request before issuing a redirect.

Requirements

Before enabling Direct Download, verify the following requirements:

  • You are using a self-hosted Nexus Repository Pro 3.96.0 or later instance.

  • The repository uses an Azure blob store.

  • Downloading clients can connect directly to the Azure Blob Storage endpoint returned in the redirect.

  • The Azure identity has the permissions required for the selected authentication method.

Direct Download is configured separately for each Azure blob store. There is no global Direct Download setting.

Azure Authentication And Permission Requirements

The method Nexus Repository uses to create the SAS URL depends on the Azure blob store authentication method.

Authentication Method

SAS Type

Additional Requirement

Account Key

Service SAS signed with the configured storage account key

No additional Azure permission is required.

Managed Identity (System)

User delegation SAS

The managed identity must be able to request a user delegation key.

Use Environment Variables

User delegation SAS

The Microsoft Entra service principal must be able to request a user delegation key.

For Managed Identity and Environment Variable authentication, the Azure identity requires the Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action permission. This can be either a Storage Blob Data role (Reader, Contributor, or Owner) or Storage Blob Delegator permission.

Enable Direct Download

Use this procedure to enable Direct Download for an Azure blob store.

  1. In the Nexus Repository user interface, select Settings.

  2. Select Repository and then Blob Stores.

  3. Create an Azure blob store or select your existing Azure blob store.

  4. In Direct Download (SAS URLs), select Redirect downloads directly to Azure Blob Storage.

  5. Select Save.

    Direct_Download_URLs.png

When the blob store uses Account Key authentication, Nexus Repository signs SAS URLs with the configured account key. No additional Azure permission validation occurs when you save.

When the blob store uses Managed Identity or Environment Variable authentication, Nexus Repository verifies that the configured identity can request a user delegation key. If Azure rejects the request, Nexus Repository does not save the Direct Download configuration.

Download And Fallback Behavior

The following table describes how Direct Download handles different requests and conditions:

Request Or Condition

Behavior

Eligible binary GET request

Nexus Repository returns HTTP 302 with a short-lived Azure SAS URL in the Location response header.

HEAD request

Nexus Repository returns the metadata response without redirecting the request to Azure.

Upload request

The upload continues through Nexus Repository.

Direct Download disabled

The download continues through Nexus Repository.

SAS URL generation fails

Nexus Repository falls back to the normal proxied-download path.

Azure permission removed after enablement

Nexus Repository falls back to the normal proxied-download path after it can no longer obtain a valid delegation key.

Microsoft Entra ID or Azure temporarily unavailable

Nexus Repository uses a valid cached delegation key when one is available. Otherwise, it falls back to the normal proxied-download path.

The generated SAS URL is:

  • Restricted to read access.

  • Restricted to one Azure blob.

  • Available through HTTPS only.

  • Valid for a short period.

For Managed Identity and Environment Variable authentication, Nexus Repository holds the user delegation key in memory and refreshes it automatically. Nexus Repository does not store the delegation key in its database.

Monitor Direct Download

Use the Azure Direct Download (SAS URLs) status check to determine whether Direct Download is operating normally.

You can view the check under Settings → Support → Status or retrieve it from the following endpoint:

GET /service/rest/v1/status/check

The check can report the following states:

Status Message

Meaning

No Azure blob stores configured.

The instance does not have an Azure blob store.

Direct Download (SAS URLs) is not enabled on any Azure blob store.

Azure blob stores exist, but Direct Download is disabled on all of them.

Direct Download (SAS URLs) is nominal.

Direct Download is enabled and SAS URL generation is operating normally.

Direct Download (SAS URLs) failing on: [<blob-store-name>]

Repeated SAS URL generation failures have occurred for the listed blob store.

The check returns to a healthy state automatically after Nexus Repository successfully generates an SAS URL again.

Review the Nexus Repository application log for the detailed failure reason. The status check intentionally identifies only the affected blob store names.

Configure Direct Download With The REST API

The following endpoints manage Azure blob stores:

Method

Endpoint

Required Permission

Description

POST

/service/rest/v1/blobstores/azure

nexus:blobstores:create

Creates an Azure blob store. A successful request returns 201 Created.

PUT

/service/rest/v1/blobstores/azure/{name}

nexus:blobstores:update

Updates an Azure blob store. A successful request returns 204 No Content.

GET

/service/rest/v1/blobstores/azure/{name}

nexus:blobstores:read

Retrieves an Azure blob store configuration.

The following Direct Download errors can occur:

Status Code

Description

402 Payment Required

The request attempts to enable a feature that is unavailable for the running Nexus Repository edition.

422 Unprocessable Entity

Nexus Repository could not validate that the configured Azure identity can request a user delegation key.

See the in-product API reference under Settings → System → API for complete Azure blob store request and response schemas.