Skip to main content

Getting Started with Repository Firewall Cloud

Use this page to connect your Nexus Repository SaaS instance to Repository Firewall Cloud. If you use self-hosted deployment, see Repository Firewall Getting Started.

Before You Begin

Sonatype manages the Firewall service endpoint for cloud tenants. Do not change the service endpoint unless Sonatype Support directs you to do so.

If you migrate from a self-hosted Nexus Repository deployment, configure this connection after your cloud cutover. The self-hosted Repository Firewall or IQ Server connection is not carried over to SaaS instances.

Contact Sonatype Support if you wish to migrate your existing waivers from your self-hosted instance to SaaS instance.

Repository Firewall Cloud can integrate only with Nexus Repository SaaS instances and not with Artifactory instances.

Prerequisites

Before you configure the connection, make sure that you have the following:

  • Administrator access to Nexus Repository SaaS instance.

  • Access to IQ SaaS with permission to assign the Component Evaluator role at the root organization level..

  • A dedicated service account for the connection between Nexus Repository Cloud and Repository Firewall Cloud.

  • The Component Evaluator role for the service account.

Create a Service Account and User Token

Use a dedicated service account for connecting your Nexus Repository SaaS instance with Repository Firewall Cloud.

  1. Create a dedicated service account in your Identity Provider for the connection between Nexus Repository Cloud and Repository Firewall Cloud.

  2. In the IQ SaaS tenant, assign the Component Evaluator role to the service account at the root organization level for Firewall evaluation.

  3. Generate an IQ user token for the service account.

Connect Nexus Repository Cloud to Repository Firewall Cloud

Use this procedure to configure the Repository Firewall Cloud connection in Nexus Repository Cloud.

  1. Sign in to Nexus Repository Cloud as an administrator. Navigate to SettingsIQ Server.

  2. Check the Enable IQ Server checkbox.

  3. Enter your IQ user token name code and passcode in the Username and Password fields.

  4. Select Verify Connection.

  5. If the connection succeeds, select Save.

After you save the configuration, confirm that Repository Firewall can evaluate components from Nexus Repository Cloud. If you migrated from a self-hosted deployment, confirm that the expected Firewall behaviour is available after cutover.

Common Issues

Use this section to troubleshoot the connection failures.

Symptom

Check

Resolution

Verify Connection fails.

The Username and Password fields use the service account sign-in password instead of the user token values.

Enter the IQ user token name code as the username and the user token passcode as the password.

Verify Connection fails.

The token was generated for a different account.

Sign in to IQ SaaS as the dedicated service account and generate a new user token.

Verify Connection fails.

The service account does not have the required evaluation access.

Grant the Component Evaluator role to service account for Repository Managers.

Repository Firewall does not evaluate components after a migration from self-hosted Nexus Repository.

The previous self-hosted Repository Firewall or IQ Server connection was assumed to migrate automatically.

Configure and verify the Repository Firewall Cloud connection in Nexus Repository Cloud after cutover.

The token and role settings appear correct, but the connection still fails.

The Cloud tenant pairing or managed service endpoint may need review.

Contact Sonatype Support. Include the tenant name, the approximate time of the failed verification, and a description of the validation steps.