EC2
Deploy Nexus on AWS EC2
This reference describes the underlying platform. Use a Nexus school release with its school membership, class policy, and cost controls. Installing a base engine alone does not add those controls.
Using AWS EC2 is the recommended way of deploying Nexus. It is simple to set up and should meet the performance needs of 90% of organizations looking to use Nexus!
Guide#
Create an EC2 instance#
Create an EC2 instance with the appropriate resources. For this guide,
we will use the recommended m7g.xlarge instance.
Read our Resourcing guide for more details.
Give your instance a descriptive name like
onyx-prodSelect the
Amazon Linux 2023AMISelect the
64-bit (Arm)architectureSelect the
m7g.xlargeinstance typeSelect
Allow HTTPS traffic from the internetin the Network settings sectionConfigure storage following the Resourcing Guide
Create the instance#
Click Launch instance and then view your instance details.
Save the Public IPv4 address of the instance!
Point domain to the instance#
If you don't have a domain, buy one from a DNS provider like GoDaddy or just skip HTTPS for now.
To point our domain to the new instance, we need to add an A and CNAME record to our DNS provider.
The A record should be the subdomain that you would like to use for the Nexus instance like prod.
The CNAME record should be the same name with the www. in front resulting in www.prod pointing to the full
domain like prod.onyx.app.
Install Nexus requirements#
Nexus requires git, docker, and docker compose.
To install these on Amazon Linux 2023, run the following:
sudo yum update -y
sudo yum install docker -y
sudo service docker start
sudo curl -L https://github.com/docker/compose/releases/latest/download/docker-compose-$(uname -s)-$(uname -m) -o /usr/local/bin/docker-compose
sudo chmod +x /usr/local/bin/docker-compose
sudo yum install gitInstall and Configure Nexus#
To install Nexus, we'll need to clone the repo and set the necessary environment variables.
git clone --depth 1 https://github.com/onyx-dot-app/onyx.git
cd onyx/deployment/docker_compose
cp env.prod.template .env
cp env.nginx.template .env.nginxFill out the .env and .env.nginx files.
WEB_DOMAIN=<YOUR_DOMAIN> # Something like "onyx.app"
# If your email is something like "chris@onyx.app", then this should be "onyx.app"
# This prevents people outside your school from creating an account
VALID_EMAIL_DOMAINS=<YOUR_COMPANIES_EMAIL_DOMAIN>Email/password login works out of the box, and SSO (Google / OIDC / SAML) is configured later from the admin panel. See our auth guides for details.
DOMAIN=<YOUR_DOMAIN> # Something like "onyx.app"Launch Nexus#
Running the init-letsencrypt.sh script will get us a SSL certificate from letsencrypt and launch the Nexus stack.
./init-letsencrypt.shYou will hit an error if you fail the letsencrypt workflow more than 5 times. You will need to wait 72 hours or request a new domain.
If you are skipping the HTTPS setup, start Nexus manually:
docker compose -f docker-compose.dev.yml -p onyx-stack up -d --build --force-recreateGive Nexus a few minutes to start up.
You can monitor the progress with `docker logs onyx-stack-api_server-1 -f`.You can access Nexus from the instance Public IPv4 or from the domain you set up earlier!
Next Steps#
Configure Authentication#
Set up authentication for your Nexus deployment with OAuth, OIDC, or SAML.
More Nexus Configuration Options#
Learn about all available configuration options for your Nexus deployment.