在Jenkins构建后任务中执行含环境变量的Artifactory AQL查询
Let's break down the common issues you might be hitting with this curl command in your Jenkins post-build task, and fix them step by step:
1. Jenkins Environment Variable Parsing Issue
First off, the way you reference Jenkins environment variables depends on the execution shell:
- For Linux/macOS shell (Execute Shell step), drop the
env.prefix — use${SUBSYSTEM}instead of${env.SUBSYSTEM}. Theenv.syntax is specific to Jenkins Pipeline scripts, not raw shell commands. - For Windows Batch (Execute Windows batch command), use
%SUBSYSTEM%instead. - If you're using a Jenkins Pipeline
shstep, you can still use${SUBSYSTEM}, but make sure your curl command is wrapped appropriately to let the shell resolve the variable.
2. Broken AQL Syntax
Your AQL has duplicate name keys, which will be ignored by Artifactory (JSON doesn't allow duplicate keys). Merge these into a single $and condition to apply both matching rules:
items.find( { "repo": {"$eq": "REPO"}, "$and": [ {"name": {"$match": "*${SUBSYSTEM}*"}}, {"name": {"$nmatch": "*pdf*"}} ] } ).include("repo","name","path")
3. Curl Command Escaping & Formatting
When passing the AQL string via curl's -d flag, you need to handle shell escaping correctly to ensure the variable is resolved while keeping the AQL valid:
- Use single quotes for the AQL base string, then break out of single quotes to insert the variable (wrapped in double quotes for safety):
curl -X POST https://artifactory_url/artifactory/api/search/aql \ -H "X-JFrog-Art-Api:***********" \ -H "Content-Type: text/plain" \ -d 'items.find( { "repo": {"$eq": "REPO"}, "$and": [ {"name": {"$match": "*'"${SUBSYSTEM}"'*"}}, {"name": {"$nmatch": "*pdf*"}} ] } ).include("repo","name","path")'
4. Quick Validation Steps
Before debugging further in Jenkins:
- Verify the variable exists: Add an
echo ${SUBSYSTEM}line before your curl command in the post-build task to confirm Jenkins is setting the variable correctly. - Test locally: Run the curl command on your machine (replace
${SUBSYSTEM}with a real value) to confirm the AQL works with your Artifactory instance and API key. - Check permissions: Ensure your API key has read access to the
REPOrepository — a 403 error in the Jenkins logs means permission issues.
Full Working Example (Linux Shell)
Here's a complete, validated script you can drop into your Execute Shell post-build task:
# Confirm the subsystem variable is set echo "Using SUBSYSTEM value: ${SUBSYSTEM}" # Execute the fixed AQL query curl -X POST https://artifactory_url/artifactory/api/search/aql \ -H "X-JFrog-Art-Api:***********" \ -H "Content-Type: text/plain" \ -d 'items.find( { "repo": {"$eq": "REPO"}, "$and": [ {"name": {"$match": "*'"${SUBSYSTEM}"'*"}}, {"name": {"$nmatch": "*pdf*"}} ] } ).include("repo","name","path")'
If you still hit issues, check the Jenkins build logs for curl's raw output — it will show HTTP error codes or AQL syntax errors that point directly to the problem.
内容的提问来源于stack exchange,提问作者garci86

