Scala Build Tool(sbt)1.0+能否配置SPNEGO认证访问Nexus仓库?
Absolutely! You can configure SPNEGO (Kerberos) authentication for sbt 1.0+ to work with your internal Nexus repository—even though it’s not out-of-the-box like sbt 0.13. Since Gigahorse (the HTTP client sbt 1.0+ uses under the hood) does support SPNEGO, we just need to wire up the right settings to make it work again.
Let’s break this down step by step:
1. Add Required Dependencies
Gigahorse relies on Apache HttpClient under the hood, so we need to include the HttpClient Kerberos module in sbt’s classpath. Add these lines to your project/plugins.sbt (or your global plugins file if you want this to apply to all your projects):
libraryDependencies += "org.apache.httpcomponents" % "httpclient" % "4.5.14" % "runtime" // Optional: Add this if you're on Windows for SSPI (integrated Windows authentication) support libraryDependencies += "org.apache.httpcomponents" % "httpclient-win" % "4.5.14" % "runtime"
2. Configure SPNEGO for sbt’s HTTP Client
Next, we’ll create a custom Gigahorse client that enables SPNEGO authentication, then tell sbt to use this client for resolver operations. Add these settings to your build.sbt (or ~/.sbt/1.0/global.sbt for global configuration):
import gigahorse._ import org.apache.http.impl.client.HttpClients import org.apache.http.auth.{AuthSchemeProvider, AuthSchemes} import org.apache.http.impl.auth.SPNegoSchemeFactory // Replace with your actual Nexus repository URL val nexusRepoUrl = "http://your-nexus-instance-url/" // Build a custom Gigahorse client with SPNEGO/Kerberos support val spnegoEnabledClient = Gigahorse.httpClient( HttpClients.custom() .setDefaultAuthSchemeRegistry { val authRegistry = org.apache.http.client.config.AuthSchemes.createDefault() // Register the SPNEGO scheme factory, enabling Kerberos credential usage authRegistry.register(AuthSchemes.SPNEGO, new SPNegoSchemeFactory(true)) authRegistry } .build() ) // Tell sbt to use our custom client for update/resolver operations updateOptions := updateOptions.value.withGigahorseClient(spnegoEnabledClient) // Add your Nexus repository as a resolver resolvers += "Internal Nexus Repository" at nexusRepoUrl // Configure empty credentials (SPNEGO uses your existing Kerberos ticket instead) credentials ++= Seq( Credentials( "SPNEGO Kerberos Authentication", new java.net.URI(nexusRepoUrl).getHost, "", // Username can be empty for SPNEGO "" // Password can be empty for SPNEGO ) )
3. Ensure a Valid Kerberos Ticket is Available
Before running any sbt commands that interact with Nexus, make sure you have a valid Kerberos ticket:
- On Linux/macOS: Run
kinit your-username@YOUR-REALM.COMin your terminal. - On Windows: If you’re logged into a domain-joined machine, your ticket should be automatically available (especially if you added the
httpclient-windependency for integrated authentication).
Troubleshooting Tips
- Check Dependency Compatibility: Ensure the HttpClient version you’re using matches the one compatible with your sbt version. sbt 1.x typically works with HttpClient 4.5.x releases.
- Enable Debug Logging: To diagnose authentication issues, turn on debug logging by adding these lines to your
build.sbt:logLevel := Level.Debug traceLevel := 20 - Validate Nexus Configuration: Double-check that your Nexus instance is properly set up to accept SPNEGO/Kerberos authentication, including a correctly configured service principal (e.g.,
HTTP/nexus.your-domain.com@YOUR-REALM.COM).
内容的提问来源于stack exchange,提问作者Erik Forsberg

