如何通过Jenkins利用Artifactory Pro插件晋升制品?求无API无凭证暴露方案
Absolutely! Since you're using Artifactory Pro, the official Jenkins Artifactory plugin has native, built-in promotion features that let you skip the inefficient download/re-upload step—and keep your credentials completely out of pipeline code. Here's a step-by-step breakdown of how to set this up:
Prerequisites
- Make sure you're using the latest stable version of the Jenkins Artifactory plugin (v3.10.0+ recommended, as it refined promotion capabilities).
- First, configure a global Artifactory server connection in Jenkins:
- Go to
Manage Jenkins > Configure System - Scroll to the "Artifactory" section, click "Add Artifactory Server"
- Give it a unique ID (e.g.,
JFrog_Artifactory), enter your Artifactory URL, and add credentials (username/password or API key) via Jenkins' credential store - Test the connection to confirm it works
- Go to
Option 1: Promote a Full Build (Recommended)
If your artifacts were published to Artifactory alongside build metadata (using the same plugin), you can promote the entire build's artifacts in one go. This is the cleanest approach because it leverages Artifactory's build tracking.
Declarative Pipeline Example
pipeline { agent any stages { stage('Promote to Production') { steps { rtPromote( serverId: 'JFrog_Artifactory', // Match your global Artifactory server ID spec: '''{ "sourceRepo": "dev-builds", "targetRepo": "prod-builds", "buildName": "${BUILD_NAME}", "buildNumber": "${BUILD_NUMBER}", "status": "Released", "comment": "Promoted via Jenkins pipeline - ready for production", "copy": true, // Set to false to MOVE instead of copy (Artifactory Pro-only) "props": { "promoted-by": "Jenkins", "environment": "Production" } }''' ) } } } }
Option 2: Promote Specific Artifacts (No Build Metadata)
If you need to promote individual artifacts without tying them to a build, you can target specific file patterns in your promotion spec:
Declarative Pipeline Example
pipeline { agent any stages { stage('Promote Specific Jar to Production') { steps { rtPromote( serverId: 'JFrog_Artifactory', spec: '''{ "sourceRepo": "dev-artifacts", "targetRepo": "prod-artifacts", "files": [ { "pattern": "com/yourcompany/app/1.0.0/app-1.0.0.jar", "target": "com/yourcompany/app/1.0.0/", "props": { "status": "production-ready", "promoted-date": "${BUILD_TIMESTAMP}" } } ] }''' ) } } } }
Key Advantages of This Approach
- No download/re-upload: Artifactory handles the promotion internally, saving time and bandwidth.
- Credentials stay secure: Credentials are stored in Jenkins' global credential store—never hardcoded in pipeline scripts or exposed in logs.
- Pro-only features: You can choose to copy OR move artifacts (move is exclusive to Artifactory Pro), which helps keep your dev repos clean.
- Auditable: All promotions are tracked in Artifactory's audit logs, with comments and custom properties for full visibility.
Important Notes
- Ensure the Jenkins service account has the right Artifactory permissions: Read access to the source repo, write access to the target repo, and permission to perform promotions (configure this in Artifactory's
Admin > Security > Permissions). - If using build-based promotion, make sure your earlier publish stage uses the Artifactory plugin (e.g.,
rtUpload) to link artifacts to the build metadata—this is what lets you reference${BUILD_NAME}and${BUILD_NUMBER}in the promotion spec.
内容的提问来源于stack exchange,提问作者Camila Naranjo

