Chapter 14Lesson 03~115 minutes

Artifacts, stash/unstash, archiveArtifacts, Fingerprints, Test Reports, Coverage, and Build Evidence: Configuration, Design Choices, and Tradeoffs

Choose deliberately among stash, Jenkins build artifacts, external repositories, fingerprints, report visualization, and retention policies by mapping each option to lifecycle, trust, scale, auditability, and rollback needs.

ArchitectureRetentionArtifact repositoryProvenanceReportsTradeoffs

Learning objectives

  • Choose stash, archiveArtifacts, or an external repository based on lifetime, size, ownership, and downstream use.
  • Distinguish Jenkins fingerprint relationship tracking from cryptographic digest/signature/provenance evidence.
  • Decide when raw reports are sufficient and when Jenkins-native visualization/trending adds operational value.
  • Design bounded retention that preserves necessary audit/recovery evidence without turning controller storage into an unbounded repository.
  • State plugin, storage, trust, and rollback prerequisites before changing artifact/report architecture.

1. Start with the lifecycle question, not the Jenkins step

“Should I use stash or archiveArtifacts?” is incomplete until you state who needs the bytes, for how long, and for what purpose. The same file may pass through several states: generated in a workspace, stashed for a later test stage, archived with the CI build, then published to a release repository. Those are not duplicates; each transition serves a different ownership and retention contract.

2. Stash vs archiveArtifacts vs external artifact repository

Mechanism Best fit Lifetime/identity Scaling concern Rollback/recovery
stash/unstash Small same-run handoff between workspaces Named within Pipeline run Large stashes can tax controller unless external Artifact Manager is configured Recreate from same run; optional bounded preserveStashes for stage restart
archiveArtifacts Build-owned diagnostics/package evidence Job + build number + artifact path Controller/artifact-manager retention and storage growth Build retention governs availability
External repository Release/package distribution and long-lived promotion Repository + coordinates/version + digest Separate service capacity/cost/policy Repository retention/immutability/replication policy

Jenkins documents artifact archiving as useful basic retention, not a replacement for a repository manager such as Nexus or Artifactory. For production releases, the external repository usually becomes the distribution system of record while Jenkins retains build evidence and the exact published coordinates/digest.

3. Fingerprint vs cryptographic provenance

A Jenkins fingerprint answers dependency-lineage questions inside Jenkins. A SHA-256 digest answers whether two byte sequences are identical with modern cryptographic collision resistance. A signature or provenance attestation answers stronger questions about who/what asserted a build statement and how the artifact was produced. These controls are complementary.

Evidence Primary question Use in this course
Jenkins fingerprint (MD5) Which Jenkins builds produced/used this file? Dependency/relationship discovery
SHA-256 Are these bytes the same? Artifact identity and transfer verification
Signature/attestation Who/what vouches for this artifact/build statement? Supply-chain provenance; later integration topic
Repository coordinates Where is the promoted immutable object? External release-system identity

4. Raw report versus Jenkins visualization

Raw XML is portable and can be archived. Jenkins-native report ingestion adds searchable failure/test history, trends, stage annotations, and quality-gate status. The tradeoff is plugin ownership: parser behavior and UI storage become version-sensitive operational dependencies.

A good pattern keeps the original report file when it has audit/debug value, records the producer tool/schema version, and also ingests it into Jenkins for developer feedback. Do not treat a pretty dashboard as the only copy of evidence.

5. Retain forever vs bounded retention

Retention should follow policy, not convenience. CI snapshots may have short retention; release artifacts may belong in an immutable repository for years; security/audit evidence may have policy-defined retention. Jenkins controller disks should not silently become the organization’s permanent package store.

When using build discarder policies, first classify which build records are still referenced by releases, investigations, or regulatory requirements. Deleting a build can remove artifacts and reports that a human expected to remain available.

6. Default artifact manager vs external Artifact Manager

Jenkins can delegate artifact/stash storage through Artifact Manager plugins. That can reduce controller data transfer and move storage durability/scaling to an object store. It also adds an external dependency, credentials/IAM scope, network path, plugin compatibility, and disaster-recovery requirement.

Optional architecture only: this chapter does not require an AWS account or S3 plugin. If an organization adopts an external Artifact Manager, test it on a cloned/disposable controller, use least-privilege identity, and document how Jenkins build deletion interacts with external object retention.

7. Worked scenario: release candidate for a CLI tool

A team builds cli-2.4.0-rc.1.tgz, runs unit tests on a second agent, and wants a later release job to promote exactly those bytes. Choose the design before writing Jenkinsfile code.

Requirement Choice Prerequisite Observable evidence
Transfer to second agent during build stash/unstash Pipeline Basic Steps Named stash + verified SHA-256 after transfer
Keep CI result for investigation archiveArtifacts + JUnit Retention policy + JUnit plugin Build URL, artifact list, test result
Trace Jenkins consumers fingerprint Producer and consumer fingerprint same file Fingerprint relationship page
Release/promotion lifecycle external repository Scoped repository identity + immutable coordinate policy Repository coordinates + digest + publication response
Authenticity signature/provenance Signing/attestation system Verifiable signature/attestation, not Jenkins fingerprint

8. Cost and performance implications

  • Large stashes can consume compression CPU and I/O; external Artifact Managers can alter the transfer path.
  • Thousands of tiny fingerprints consume metadata/database resources; fingerprint intentional outputs/dependencies rather than **/*.
  • Coverage source retention can copy significant source data into build records; choose NEVER, LAST_BUILD, MODIFIED, or EVERY_BUILD intentionally.
  • Retention must include logs, artifacts, test/coverage data, and external storage cost—not just Jenkins build count.

9. Keep ownership boundaries explicit

Jenkins knows its job/build record and whatever plugins persist. The agent owns transient workspace bytes. The artifact repository owns published packages. The SCM owns source history. A deployment target owns runtime state. Troubleshooting and audit become much easier when each system has a stable identifier and Jenkins stores enough correlation evidence—including the exact source SHA—to join those records without pretending to own them all.

Next lesson

Diagnostics, Failure Modes, Security, and Performance

Diagnose missing reports, secret leakage, misuse of stash, weak fingerprint assumptions, and rebuild-during-promotion without destroying the original evidence.

Knowledge check

When is stash preferable to archiveArtifacts?

Why can an external artifact manager improve stash scalability?

What extra evidence should accompany a Jenkins fingerprint?

Why retain raw JUnit/coverage files even after Jenkins parses them?

What is the first question before choosing a retention mechanism?

Official references and version notes

Version and compatibility note

Rechecked on 2026-09-16. Examples assume Jenkins 2.568.3 LTS (tested with Java 21 and 25), Pipeline: Basic Steps 1098.v808b_fd7f8cf4, Pipeline: Job 1600.v6f36ed83529d, and JUnit 1425.v9c7318dca_96d. The optional coverage extension uses Coverage 3.3358.v9487dde48783, which requires Jenkins 2.555.3 or newer and is therefore compatible with this LTS baseline. The mandatory path is free/local/disposable. Record the versions actually installed on your controller before applying the examples.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this address.