基于Jenkins Pipeline将构建产物上传至SharePoint的方案咨询
由于没有现成插件,推荐基于Microsoft Graph API或SharePoint REST API结合Linux原生工具curl实现,无需额外安装插件,适配Linux环境且安全性可控。
方案一:Microsoft Graph API(推荐,权限管理更灵活)
前置准备
- 在Azure AD中注册应用,获取以下信息:
- 租户ID(Tenant ID)
- 客户端ID(Client ID)
- 客户端密钥(Client Secret)
- 为应用授予
Files.ReadWrite.All或Sites.ReadWrite.All权限(根据需求选择,需管理员同意) - 确认Jenkins服务器可访问
https://graph.microsoft.com和目标SharePoint站点
Pipeline 代码示例
pipeline { agent any environment { // 从Jenkins凭据管理中读取敏感信息 TENANT_ID = credentials('azure-tenant-id') CLIENT_ID = credentials('azure-client-id') CLIENT_SECRET = credentials('azure-client-secret') // 替换为你的SharePoint站点ID、文档库名称、目标路径 SITE_ID = 'your-sharepoint-site-id' DOC_LIB_NAME = 'Documents' LOCAL_FILE_PATH = './dist/build-output.zip' TARGET_FILE_PATH = '/Builds/20240520-build.zip' } stages { stage('Upload to SharePoint') { steps { script { // 1. 获取访问令牌 def tokenResponse = sh( script: """ curl -s -X POST "https://login.microsoftonline.com/${TENANT_ID}/oauth2/v2.0/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "client_id=${CLIENT_ID}" \ -d "scope=https://graph.microsoft.com/.default" \ -d "client_secret=${CLIENT_SECRET}" \ -d "grant_type=client_credentials" """, returnStdout: true ) def accessToken = new groovy.json.JsonSlurper().parseText(tokenResponse).access_token // 2. 上传文件到SharePoint文档库 def uploadResult = sh( script: """ curl -s -X PUT "https://graph.microsoft.com/v1.0/sites/${SITE_ID}/drive/root:${TARGET_FILE_PATH}:/content" \ -H "Authorization: Bearer ${accessToken}" \ -H "Content-Type: application/octet-stream" \ --data-binary @${LOCAL_FILE_PATH} """, returnStatus: true ) if (uploadResult != 0) { error "文件上传失败,返回码:${uploadResult}" } echo "构建产物已成功上传至SharePoint" } } } } }
方案二:SharePoint 传统REST API
如果无法使用Graph API,可直接调用SharePoint站点的REST接口:
前置准备
- 同样需要Azure AD应用注册并授予站点权限
- 获取SharePoint站点的基础URL(如
https://your-domain.sharepoint.com/sites/your-site)
Pipeline 代码示例
pipeline { agent any environment { TENANT_ID = credentials('azure-tenant-id') CLIENT_ID = credentials('azure-client-id') CLIENT_SECRET = credentials('azure-client-secret') SP_SITE_URL = 'https://your-domain.sharepoint.com/sites/your-site' DOC_LIB_NAME = 'Documents' LOCAL_FILE_PATH = './dist/build-output.zip' TARGET_FOLDER = 'Builds' TARGET_FILENAME = '20240520-build.zip' } stages { stage('Upload to SharePoint') { steps { script { // 1. 获取访问令牌 def tokenResponse = sh( script: """ curl -s -X POST "https://login.microsoftonline.com/${TENANT_ID}/oauth2/v2.0/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "client_id=${CLIENT_ID}" \ -d "scope=${SP_SITE_URL}/.default" \ -d "client_secret=${CLIENT_SECRET}" \ -d "grant_type=client_credentials" """, returnStdout: true ) def accessToken = new groovy.json.JsonSlurper().parseText(tokenResponse).access_token // 2. 获取文档库文件夹的相对路径ID def folderResponse = sh( script: """ curl -s -X GET "${SP_SITE_URL}/_api/web/GetFolderByServerRelativeUrl('/sites/your-site/${DOC_LIB_NAME}/${TARGET_FOLDER}')" \ -H "Authorization: Bearer ${accessToken}" \ -H "Accept: application/json;odata=nometadata" """, returnStdout: true ) def folderId = new groovy.json.JsonSlurper().parseText(folderResponse).UniqueId // 3. 上传文件 def uploadResult = sh( script: """ curl -s -X POST "${SP_SITE_URL}/_api/web/GetFolderById('${folderId}')/Files/add(overwrite=true,url='${TARGET_FILENAME}')" \ -H "Authorization: Bearer ${accessToken}" \ -H "Content-Type: application/octet-stream" \ --data-binary @${LOCAL_FILE_PATH} """, returnStatus: true ) if (uploadResult != 0) { error "文件上传失败,返回码:${uploadResult}" } echo "构建产物已成功上传至SharePoint" } } } } }
关键注意事项
- 凭据安全:所有敏感信息(租户ID、客户端密钥等)必须存储在Jenkins凭据管理中,禁止硬编码
- 大文件处理:若文件超过4MB,需使用分片上传逻辑(Graph API支持分块上传,可通过
createUploadSession接口实现) - 错误处理:添加返回码检查和异常捕获,确保上传失败时构建标记为失败
- 网络连通性:确认Jenkins服务器能访问Azure AD和SharePoint的相关域名
内容的提问来源于stack exchange,提问作者Goutham Nithyananda
相关产品推荐
相关产品推荐

