skip to content

Settings.xml

The user and global settings.xml: server credentials, mirrors, proxies, local repository location, offline mode, and active profiles. Asked because these belong in settings, never in a committed POM.

on this pageshow

explore

questions

6

What is the difference between the global and user settings.xml files, and how does Maven combine them?

level: juniorimportance: must knowfreq 70%

answer

  1. global = ${maven.home}/conf
  2. user = ~/.m2/settings.xml
  3. user overrides global on merge
  4. machine config, not project config
  5. help:effective-settings shows merged

basics

~20 s

Maven reads two settings.xml files: a global one in the Maven install directory (${maven.home}/conf) and a user one in ~/.m2. The user file overrides the global file. Settings hold machine-level config like credentials and mirrors, not project info.

solid answer

~30 s

Maven has two `settings.xml` locations. The **global** settings live at `${maven.home}/conf/settings.xml` (since Maven 3.9, `${maven.home}/conf/settings.xml`) and apply to everyone using that installation. The **user** settings live at `~/.m2/settings.xml` and apply to one OS user. When both exist, Maven **merges** them and the user file **wins** on conflicts. `settings.xml` is for environment/machine-specific configuration that must NOT be checked into a project: server credentials (`<servers>`), repository mirrors (`<mirrors>`), proxies (`<proxies>`), the local repo path, offline mode, active profiles, and plugin groups. Anything build-portable (dependencies, plugins, build config) belongs in `pom.xml` instead, because the POM travels with the project and settings.xml does not.

code

bash · 5 lines
bash
# inspect the merged effective settings
mvn help:effective-settings

# build with a custom user + global settings file
mvn -s ~/work/settings.xml -gs /opt/maven/conf/settings.xml clean install

go deeper

for a junior

Knows there are two files (global in install dir, user in ~/.m2) and that settings hold local config not committed to the project.

for a middle

Knows they merge with user winning, and can use -s/-gs and help:effective-settings.

for a senior

Articulates the settings-vs-pom boundary and why secrets/environment config must stay out of the POM.

for a principal

Designs org policy: locked-down global settings for mirrors/proxies, templated user settings, secret handling guidance.

## What settings.xml is Maven separates **what to build** (the `pom.xml`, committed to the project) from **how this machine connects to build it** (the `settings.xml`, local to a machine/user). Settings hold environment-specific, often secret, configuration that should never live in version control. ## The two locations - **Global settings**: `${maven.home}/conf/settings.xml`. `${maven.home}` is wherever Maven is installed (e.g. `/opt/maven`). This applies to every user who runs that Maven installation. Admins use it to set org-wide mirrors/proxies. - **User settings**: `${user.home}/.m2/settings.xml` (e.g. `~/.m2/settings.xml`). This applies to a single OS user and is where individual developers put their own credentials. ## How they combine If both files exist, Maven **merges** them into one effective configuration. On any conflict, the **user settings take precedence** over the global settings. You can inspect the merged result with `mvn help:effective-settings`. You can also point to non-default files on the command line: ```bash mvn -s /path/to/user-settings.xml -gs /path/to/global-settings.xml clean install mvn help:effective-settings # show the merged, effective settings ``` ## What belongs in settings vs pom - **settings.xml**: `<servers>` (auth), `<mirrors>`, `<proxies>`, `<localRepository>`, `<offline>`, `<pluginGroups>`, and machine-specific `<profiles>`/`<activeProfiles>`. - **pom.xml**: dependencies, plugins, build lifecycle config, repository *declarations* — anything that must be identical for every developer and the CI server. ## Why the split matters Because settings.xml is not committed, two developers can build the same project with different credentials, mirrors, or proxy configs, while the project definition stays identical and portable. Putting a password in pom.xml would leak it to everyone with repo access; putting it in settings.xml keeps it on the developer's machine.

  • Which file wins if a mirror is defined in both global and user settings?
    They are merged and the user settings.xml takes precedence on conflicts, so the user-defined mirror wins.
  • Why not put database or repo credentials in pom.xml?
    pom.xml is committed to version control and travels with the project, so secrets would leak to everyone with repo access; settings.xml stays local and uncommitted.

Like OS-wide vs per-user preferences: an admin sets defaults for the whole machine, but your personal account settings override them for you.

saying these in an interview costs you the question

  • Saying settings.xml is committed alongside the project — it is machine-local and not in the POM.
  • Claiming global settings override user settings (it's the reverse).
  • Putting dependency/build config in settings.xml instead of the POM.

context

open as a page

How do you configure repository authentication in Maven, and how is a server linked to a repository?

level: middleimportance: must knowfreq 65%

basics

~10 s

Put credentials in a <server> entry inside <servers> in settings.xml. The <server>'s <id> must match the <id> of the repository (or mirror) it authenticates. Use username/password, or privateKey for SSH-style transports.

open as a page

How do <mirrors> and the mirrorOf syntax work in settings.xml?

level: seniorimportance: must knowfreq 60%

basics

~10 s

A <mirror> redirects requests for one or more repositories to a different URL. The <mirrorOf> element says which repository IDs the mirror replaces. mirrorOf=* matches every repo; you can also use patterns and exclusions.

open as a page

How do you configure <proxies>, <localRepository>, and <offline> in settings.xml, and when does each matter?

level: middleimportance: should knowfreq 45%

basics

~10 s

<proxies> sets an HTTP/HTTPS network proxy (with optional nonProxyHosts). <localRepository> changes where downloaded artifacts are cached (default ~/.m2/repository). <offline>true</offline> makes Maven build only from the local cache, never hitting the network.

open as a page

How do profiles in settings.xml work, including activeProfiles and activation, and how do they differ from POM profiles?

level: seniorimportance: should knowfreq 40%

basics

~20 s

settings.xml can define <profiles> for machine-specific config (repos, properties) and turn them on with <activeProfiles> or activation rules. Unlike POM profiles, settings profiles can't change build steps (plugins/dependencies) — only repositories, plugin repositories, and properties.

open as a page

What is <pluginGroups> in settings.xml, and how does it affect running plugin goals by prefix?

level: juniorimportance: nice to knowfreq 25%

basics

~10 s

<pluginGroups> lists extra groupIds Maven searches when you run a plugin by short prefix (like mvn spring-boot:run). It lets you use a plugin's prefix without typing its full groupId:artifactId.

open as a page