如何用jq向Artifactory AQL JSON配置文件动态添加GitLab获取的SHA列表
Got it, let's break down how to dynamically add GitLab commit SHAs to your Artifactory AQL JSON using jq. This approach handles variable SHA lists and fits right into shell workflows.
Step 1: Fetch the SHA list from GitLab API
First, use curl to pull commit data from GitLab, then pipe it through jq to extract just the SHA values into a JSON array. Don't forget to add your GitLab access token for authentication:
# Replace these with your actual GitLab details GITLAB_TOKEN="your-personal-access-token" PROJECT_ID="123" API_URL="https://gitlab.example.com/api/v4/projects/$PROJECT_ID/commits" # Fetch SHA list as a JSON array SHA_LIST=$(curl -s -H "PRIVATE-TOKEN: $GITLAB_TOKEN" "$API_URL" | jq '[.[] | .id]')
This stores a JSON array like ["abc123", "def456", "ghi789"] in the SHA_LIST variable.
Step 2: Understand your AQL structure
Let's assume your base AQL JSON (let's call it aql-base.json) looks something like this—common for filtering artifacts by SHA:
{ "items.find": { "repo": "my-artifactory-repo", "filters": [] } }
We'll be adding the SHA conditions to the filters array. Adjust the jq path later if your AQL uses a different structure (e.g., include or a different field name).
Step 3: Merge SHA list into AQL with jq
You have two common options here, depending on how you want the AQL to filter:
Option 1: Use $in for efficient multi-SHA matching (recommended)
This adds a single filter that matches any of the SHAs—cleaner and more efficient than multiple separate filters:
jq --argjson shas "$SHA_LIST" \ '.items.find.filters += [{"artifact.sha256": {"$in": $shas}}]' \ aql-base.json > updated-aql.json
The --argjson flag passes the SHA array directly to jq as a JSON variable (no string escaping headaches). The += appends the new filter to your existing filters array; use = instead if you want to replace the array entirely.
Option 2: Add individual $eq filters (if you need granular conditions)
If you need each SHA as a separate filter (e.g., combined with other logic), use this to wrap each SHA in a $eq condition inside a $or block:
jq --argjson shas "$SHA_LIST" \ '.items.find.filters += [{"$or": [$shas[] | {"artifact.sha256": {"$eq": .}}]}]' \ aql-base.json > updated-aql.json
Full Workflow Example
Putting it all together in one go:
# Set your variables GITLAB_TOKEN="your-token" PROJECT_ID="456" BASE_AQL="./aql-base.json" UPDATED_AQL="./aql-updated.json" # Fetch SHAs and update AQL SHA_LIST=$(curl -s -H "PRIVATE-TOKEN: $GITLAB_TOKEN" "https://gitlab.example.com/api/v4/projects/$PROJECT_ID/commits" | jq '[.[] | .id]') jq --argjson shas "$SHA_LIST" '.items.find.filters += [{"artifact.sha256": {"$in": $shas}}]' "$BASE_AQL" > "$UPDATED_AQL"
Notes
- Adjust the jq path (
.items.find.filters) to match your actual AQL structure. For example, if your AQL uses.include.sha_values, change it to.include.sha_values += $shas. - If the GitLab API returns an empty SHA list, jq will handle it gracefully (adding an empty
$inarray or no conditions).
内容的提问来源于stack exchange,提问作者Ebrahim Moshaya

