You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Jenkins Pipeline将构建产物上传至SharePoint的方案咨询

Jenkins Pipeline 上传构建产物至 SharePoint(Linux环境)

由于没有现成插件,推荐基于Microsoft Graph API或SharePoint REST API结合Linux原生工具curl实现,无需额外安装插件,适配Linux环境且安全性可控。

方案一:Microsoft Graph API(推荐,权限管理更灵活)

前置准备

  1. 在Azure AD中注册应用,获取以下信息:
    • 租户ID(Tenant ID)
    • 客户端ID(Client ID)
    • 客户端密钥(Client Secret)
  2. 为应用授予Files.ReadWrite.All或Sites.ReadWrite.All权限(根据需求选择,需管理员同意)
  3. 确认Jenkins服务器可访问https://graph.microsoft.com和目标SharePoint站点

Pipeline 代码示例

pipeline {
    agent any
    environment {
        // 从Jenkins凭据管理中读取敏感信息
        TENANT_ID = credentials('azure-tenant-id')
        CLIENT_ID = credentials('azure-client-id')
        CLIENT_SECRET = credentials('azure-client-secret')
        // 替换为你的SharePoint站点ID、文档库名称、目标路径
        SITE_ID = 'your-sharepoint-site-id'
        DOC_LIB_NAME = 'Documents'
        LOCAL_FILE_PATH = './dist/build-output.zip'
        TARGET_FILE_PATH = '/Builds/20240520-build.zip'
    }
    stages {
        stage('Upload to SharePoint') {
            steps {
                script {
                    // 1. 获取访问令牌
                    def tokenResponse = sh(
                        script: """
                            curl -s -X POST "https://login.microsoftonline.com/${TENANT_ID}/oauth2/v2.0/token" \
                                -H "Content-Type: application/x-www-form-urlencoded" \
                                -d "client_id=${CLIENT_ID}" \
                                -d "scope=https://graph.microsoft.com/.default" \
                                -d "client_secret=${CLIENT_SECRET}" \
                                -d "grant_type=client_credentials"
                        """,
                        returnStdout: true
                    )
                    def accessToken = new groovy.json.JsonSlurper().parseText(tokenResponse).access_token

                    // 2. 上传文件到SharePoint文档库
                    def uploadResult = sh(
                        script: """
                            curl -s -X PUT "https://graph.microsoft.com/v1.0/sites/${SITE_ID}/drive/root:${TARGET_FILE_PATH}:/content" \
                                -H "Authorization: Bearer ${accessToken}" \
                                -H "Content-Type: application/octet-stream" \
                                --data-binary @${LOCAL_FILE_PATH}
                        """,
                        returnStatus: true
                    )

                    if (uploadResult != 0) {
                        error "文件上传失败,返回码:${uploadResult}"
                    }
                    echo "构建产物已成功上传至SharePoint"
                }
            }
        }
    }
}

方案二:SharePoint 传统REST API

如果无法使用Graph API,可直接调用SharePoint站点的REST接口:

前置准备

  1. 同样需要Azure AD应用注册并授予站点权限
  2. 获取SharePoint站点的基础URL(如https://your-domain.sharepoint.com/sites/your-site)

Pipeline 代码示例

pipeline {
    agent any
    environment {
        TENANT_ID = credentials('azure-tenant-id')
        CLIENT_ID = credentials('azure-client-id')
        CLIENT_SECRET = credentials('azure-client-secret')
        SP_SITE_URL = 'https://your-domain.sharepoint.com/sites/your-site'
        DOC_LIB_NAME = 'Documents'
        LOCAL_FILE_PATH = './dist/build-output.zip'
        TARGET_FOLDER = 'Builds'
        TARGET_FILENAME = '20240520-build.zip'
    }
    stages {
        stage('Upload to SharePoint') {
            steps {
                script {
                    // 1. 获取访问令牌
                    def tokenResponse = sh(
                        script: """
                            curl -s -X POST "https://login.microsoftonline.com/${TENANT_ID}/oauth2/v2.0/token" \
                                -H "Content-Type: application/x-www-form-urlencoded" \
                                -d "client_id=${CLIENT_ID}" \
                                -d "scope=${SP_SITE_URL}/.default" \
                                -d "client_secret=${CLIENT_SECRET}" \
                                -d "grant_type=client_credentials"
                        """,
                        returnStdout: true
                    )
                    def accessToken = new groovy.json.JsonSlurper().parseText(tokenResponse).access_token

                    // 2. 获取文档库文件夹的相对路径ID
                    def folderResponse = sh(
                        script: """
                            curl -s -X GET "${SP_SITE_URL}/_api/web/GetFolderByServerRelativeUrl('/sites/your-site/${DOC_LIB_NAME}/${TARGET_FOLDER}')" \
                                -H "Authorization: Bearer ${accessToken}" \
                                -H "Accept: application/json;odata=nometadata"
                        """,
                        returnStdout: true
                    )
                    def folderId = new groovy.json.JsonSlurper().parseText(folderResponse).UniqueId

                    // 3. 上传文件
                    def uploadResult = sh(
                        script: """
                            curl -s -X POST "${SP_SITE_URL}/_api/web/GetFolderById('${folderId}')/Files/add(overwrite=true,url='${TARGET_FILENAME}')" \
                                -H "Authorization: Bearer ${accessToken}" \
                                -H "Content-Type: application/octet-stream" \
                                --data-binary @${LOCAL_FILE_PATH}
                        """,
                        returnStatus: true
                    )

                    if (uploadResult != 0) {
                        error "文件上传失败,返回码:${uploadResult}"
                    }
                    echo "构建产物已成功上传至SharePoint"
                }
            }
        }
    }
}

关键注意事项

  • 凭据安全:所有敏感信息(租户ID、客户端密钥等)必须存储在Jenkins凭据管理中,禁止硬编码
  • 大文件处理:若文件超过4MB,需使用分片上传逻辑(Graph API支持分块上传,可通过createUploadSession接口实现)
  • 错误处理:添加返回码检查和异常捕获,确保上传失败时构建标记为失败
  • 网络连通性:确认Jenkins服务器能访问Azure AD和SharePoint的相关域名

内容的提问来源于stack exchange,提问作者Goutham Nithyananda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 16:05:48