Artifacts, stash/unstash, archiveArtifacts, Fingerprints, Test Reports, Coverage, and Build Evidence: Configuration, Design Choices, and Tradeoffs
Choose deliberately among stash, Jenkins build artifacts, external repositories, fingerprints, report visualization, and retention policies by mapping each option to lifecycle, trust, scale, auditability, and rollback needs.
Learning objectives
- Choose stash, archiveArtifacts, or an external repository based on lifetime, size, ownership, and downstream use.
- Distinguish Jenkins fingerprint relationship tracking from cryptographic digest/signature/provenance evidence.
- Decide when raw reports are sufficient and when Jenkins-native visualization/trending adds operational value.
- Design bounded retention that preserves necessary audit/recovery evidence without turning controller storage into an unbounded repository.
- State plugin, storage, trust, and rollback prerequisites before changing artifact/report architecture.
1. Start with the lifecycle question, not the Jenkins step
“Should I use stash or archiveArtifacts?” is incomplete until you state who needs the bytes, for how long, and for what purpose. The same file may pass through several states: generated in a workspace, stashed for a later test stage, archived with the CI build, then published to a release repository. Those are not duplicates; each transition serves a different ownership and retention contract.
2. Stash vs archiveArtifacts vs external artifact repository
| Mechanism | Best fit | Lifetime/identity | Scaling concern | Rollback/recovery |
|---|---|---|---|---|
stash/unstash |
Small same-run handoff between workspaces | Named within Pipeline run | Large stashes can tax controller unless external Artifact Manager is configured | Recreate from same run; optional bounded preserveStashes for stage restart |
archiveArtifacts |
Build-owned diagnostics/package evidence | Job + build number + artifact path | Controller/artifact-manager retention and storage growth | Build retention governs availability |
| External repository | Release/package distribution and long-lived promotion | Repository + coordinates/version + digest | Separate service capacity/cost/policy | Repository retention/immutability/replication policy |
Jenkins documents artifact archiving as useful basic retention, not a replacement for a repository manager such as Nexus or Artifactory. For production releases, the external repository usually becomes the distribution system of record while Jenkins retains build evidence and the exact published coordinates/digest.
3. Fingerprint vs cryptographic provenance
A Jenkins fingerprint answers dependency-lineage questions inside Jenkins. A SHA-256 digest answers whether two byte sequences are identical with modern cryptographic collision resistance. A signature or provenance attestation answers stronger questions about who/what asserted a build statement and how the artifact was produced. These controls are complementary.
| Evidence | Primary question | Use in this course |
|---|---|---|
| Jenkins fingerprint (MD5) | Which Jenkins builds produced/used this file? | Dependency/relationship discovery |
| SHA-256 | Are these bytes the same? | Artifact identity and transfer verification |
| Signature/attestation | Who/what vouches for this artifact/build statement? | Supply-chain provenance; later integration topic |
| Repository coordinates | Where is the promoted immutable object? | External release-system identity |
4. Raw report versus Jenkins visualization
Raw XML is portable and can be archived. Jenkins-native report ingestion adds searchable failure/test history, trends, stage annotations, and quality-gate status. The tradeoff is plugin ownership: parser behavior and UI storage become version-sensitive operational dependencies.
A good pattern keeps the original report file when it has audit/debug value, records the producer tool/schema version, and also ingests it into Jenkins for developer feedback. Do not treat a pretty dashboard as the only copy of evidence.
5. Retain forever vs bounded retention
Retention should follow policy, not convenience. CI snapshots may have short retention; release artifacts may belong in an immutable repository for years; security/audit evidence may have policy-defined retention. Jenkins controller disks should not silently become the organization’s permanent package store.
When using build discarder policies, first classify which build records are still referenced by releases, investigations, or regulatory requirements. Deleting a build can remove artifacts and reports that a human expected to remain available.
6. Default artifact manager vs external Artifact Manager
Jenkins can delegate artifact/stash storage through Artifact Manager plugins. That can reduce controller data transfer and move storage durability/scaling to an object store. It also adds an external dependency, credentials/IAM scope, network path, plugin compatibility, and disaster-recovery requirement.
7. Worked scenario: release candidate for a CLI tool
A team builds cli-2.4.0-rc.1.tgz, runs unit tests on a
second agent, and wants a later release job to promote exactly those
bytes. Choose the design before writing Jenkinsfile code.
| Requirement | Choice | Prerequisite | Observable evidence |
|---|---|---|---|
| Transfer to second agent during build | stash/unstash | Pipeline Basic Steps | Named stash + verified SHA-256 after transfer |
| Keep CI result for investigation | archiveArtifacts + JUnit | Retention policy + JUnit plugin | Build URL, artifact list, test result |
| Trace Jenkins consumers | fingerprint | Producer and consumer fingerprint same file | Fingerprint relationship page |
| Release/promotion lifecycle | external repository | Scoped repository identity + immutable coordinate policy | Repository coordinates + digest + publication response |
| Authenticity | signature/provenance | Signing/attestation system | Verifiable signature/attestation, not Jenkins fingerprint |
8. Cost and performance implications
- Large stashes can consume compression CPU and I/O; external Artifact Managers can alter the transfer path.
-
Thousands of tiny fingerprints consume metadata/database
resources; fingerprint intentional outputs/dependencies rather
than
**/*. -
Coverage source retention can copy significant source data into
build records; choose
NEVER,LAST_BUILD,MODIFIED, orEVERY_BUILDintentionally. - Retention must include logs, artifacts, test/coverage data, and external storage cost—not just Jenkins build count.
9. Keep ownership boundaries explicit
Jenkins knows its job/build record and whatever plugins persist. The agent owns transient workspace bytes. The artifact repository owns published packages. The SCM owns source history. A deployment target owns runtime state. Troubleshooting and audit become much easier when each system has a stable identifier and Jenkins stores enough correlation evidence—including the exact source SHA—to join those records without pretending to own them all.
Knowledge check
When is stash preferable to archiveArtifacts?
When a relatively small file must move between workspaces within the same Pipeline run and long-term retention is not the goal.
Why can an external artifact manager improve stash scalability?
Some artifact managers can stream stash/archive data between agent and external storage rather than routing large compressed payloads through controller storage/CPU.
What extra evidence should accompany a Jenkins fingerprint?
At minimum a modern digest such as SHA-256 for byte identity; signatures or provenance attestations are needed for stronger authenticity claims.
Why retain raw JUnit/coverage files even after Jenkins parses them?
Raw reports preserve portable/debuggable evidence and tool/schema context, while Jenkins visualization is plugin-dependent derived state.
What is the first question before choosing a retention mechanism?
Who needs the bytes/evidence, for how long, and for what purpose; mechanism follows lifecycle and ownership requirements.
Official references and version notes
-
Pipeline: Basic Steps reference
— current
stash/unstashsemantics and guidance for cross-stage transfer. -
Running Pipelines
— Declarative stage restart and
preserveStashesbehavior. -
Recording tests and artifacts
—
archiveArtifacts, fingerprinting, and JUnit publishing patterns. - Jenkins fingerprints — dependency/use tracking and the MD5-based fingerprint record.
- JUnit plugin — maintained test-result ingestion and build/test history.
- Coverage plugin — maintained coverage ingestion, quality gates, and source-retention choices.
-
Coverage Pipeline step reference
— current
recordCoverageparameters and supported parsers. - Artifact Manager on S3 plugin — optional example of external artifact-manager integration; not required by the labs.
- Jenkins LTS changelog — current LTS and tested Java configurations.
Rechecked on 2026-09-16. Examples assume Jenkins 2.568.3 LTS (tested with Java 21 and 25), Pipeline: Basic Steps 1098.v808b_fd7f8cf4, Pipeline: Job 1600.v6f36ed83529d, and JUnit 1425.v9c7318dca_96d. The optional coverage extension uses Coverage 3.3358.v9487dde48783, which requires Jenkins 2.555.3 or newer and is therefore compatible with this LTS baseline. The mandatory path is free/local/disposable. Record the versions actually installed on your controller before applying the examples.
Keep the academy open
Support free, practical DevOps education.
Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this
address.