Digital Ocean
Deploy Nexus on Digital Ocean Droplets
This reference describes the underlying platform. Use a Nexus school release with its school membership, class policy, and cost controls. Installing a base engine alone does not add those controls.
Create a Droplet#
Create a Droplet with the appropriate resources. For this guide, we will use a recommended configuration with Docker pre-installed.
Read our Resourcing guide for more details.
Give your Droplet a descriptive name like
onyx-prodSelect a region close to your users
Select the
Dockerimage from the Marketplace tabChoose a Droplet size with at least 4 vCPUs and 16GB RAM
Configure storage following the Resourcing Guide
Add your SSH key for secure access
Create the Droplet#
Click Create Droplet and then view your Droplet details.
Save the Public IP address of the Droplet!
Point domain to the instance#
If you don't have a domain, buy one from a DNS provider like GoDaddy or just skip HTTPS for now.
To point our domain to the new instance, we need to add an A and CNAME record to our DNS provider.
The A record should be the subdomain that you would like to use for the Nexus instance like prod.
The CNAME record should be the same name with the www. in front resulting in www.prod pointing to the full
domain like prod.onyx.app.
Install Nexus requirements#
Since we selected the Docker Marketplace image, Docker and Docker Compose are already installed.
We just need to install git:
sudo apt update
sudo apt install -y gitInstall and Configure Nexus#
To install Nexus, we'll need to clone the repo and set the necessary environment variables.
git clone --depth 1 https://github.com/onyx-dot-app/onyx.git
cd onyx/deployment/docker_compose
cp env.prod.template .env
cp env.nginx.template .env.nginxFill out the .env and .env.nginx files.
WEB_DOMAIN=<YOUR_DOMAIN> # Something like "onyx.app"
# If your email is something like "chris@onyx.app", then this should be "onyx.app"
# This prevents people outside your school from creating an account
VALID_EMAIL_DOMAINS=<YOUR_COMPANIES_EMAIL_DOMAIN>Email/password login works out of the box, and SSO (Google / OIDC / SAML) is configured later from the admin panel. See our auth guides for details.
DOMAIN=<YOUR_DOMAIN> # Something like "onyx.app"Launch Nexus#
Running the init-letsencrypt.sh script will get us a SSL certificate from letsencrypt and launch the Nexus stack.
./init-letsencrypt.shYou will hit an error if you fail the letsencrypt workflow more than 5 times. You will need to wait 72 hours or request a new domain.
If you are skipping the HTTPS setup, start Nexus manually:
docker compose -f docker-compose.dev.yml -p onyx-stack up -d --build --force-recreateGive Nexus a few minutes to start up.
You can monitor the progress with `docker logs onyx-stack-api_server-1 -f`.You can access Nexus from the instance Public IPv4 or from the domain you set up earlier!
Next Steps#
Configure Authentication#
Set up authentication for your Nexus deployment with OAuth, OIDC, or SAML.
More Nexus Configuration Options#
Learn about all available configuration options for your Nexus deployment.