Artifacts, stash/unstash, archiveArtifacts, Fingerprints, Test Reports, Coverage, and Build Evidence: Diagnostics, Failure Modes, Security, and Performance
Diagnose artifact/report failures from first evidence, repair wrong paths and lifecycle choices without hiding the original cause, and prevent secrets, oversized stashes, weak authenticity assumptions, or rebuild-on-promotion from becoming production failures.
Learning objectives
- Preserve first-failure build/source/node/report evidence before retrying, cleaning, or rebuilding.
- Diagnose missing artifacts and reports by separating workspace production from Jenkins ingestion/retention.
- Recognize secret leakage risks in archive/stash/report patterns and prevent broad workspace capture.
- Explain why fingerprints do not prove authenticity and why release promotion must preserve original bytes.
- Identify large-stash/controller-resource symptoms and select a less costly transfer/storage path.
1. Evidence-first diagnostic ladder
When an artifact or report is missing, do not immediately rerun the build. A rerun can change the source revision, agent, dependency resolution, timestamped package contents, or external side effects. Preserve the original build first.
- Record job full name, build number/URL, queue ID/cause, exact source/Jenkinsfile SHA.
- Record Jenkins core/Java and relevant Pipeline/JUnit/Coverage plugin versions.
- Record node, label, executor, workspace path, and first failing log lines.
- Prove whether the producer file existed before the Jenkins step.
-
Inspect the
stash/archiveArtifacts/junit/recordCoveragepattern and working directory. - Inspect retained artifact/report/fingerprint state on the original build.
- Verify external repository state independently if publication was attempted.
- Apply the smallest correction and rerun only after the original evidence packet is complete.
2. Intentionally broken example: the report exists, the glob is wrong
Assume the producer writes reports/junit.xml but the
Jenkinsfile contains:
stage('Publish reports') {
steps {
sh 'test -s reports/junit.xml && ls -l reports/junit.xml'
junit testResults: 'report/*.xml', allowEmptyResults: false
}
}
The shell proves the file exists. The JUnit step then reports that no matching test report files were found. Those facts are not contradictory: the producer succeeded, but report ingestion used a different path.
Repair: preserve the original console log and build
number, change only the pattern to reports/*.xml,
commit the Jenkinsfile change, and run a new build. The failed build
remains valuable evidence of the ingestion-layer defect.
3. Failure: stash used as long-term storage
A downstream job asks for a stash created yesterday and cannot access it. This is expected: stashes are run-scoped. Even preserved stashes are intended for Declarative stage restart, not arbitrary cross-job consumption.
Repair the architecture, not the timeout: archive the build artifact for Jenkins retention or publish it to a repository manager. Give the consumer an immutable producer identity: job/build + artifact path or repository coordinate + SHA-256.
4. Failure: an archive pattern captures a secret
The dangerous pattern is broad collection after a tool has written credentials or debug files into the workspace:
// DO NOT USE: may capture source, caches, temp files, or secrets.
archiveArtifacts artifacts: '**/*', fingerprint: true
Do not “fix” this by hiding the artifact link. Authorization and UI visibility do not undo retention. Stop publication, preserve the incident identifiers, rotate/revoke the exposed credential if it was real, remove the secret from future workspace output, narrow the archive allowlist, and follow your organization’s approved evidence-removal procedure if sensitive bytes were persisted.
DO_NOT_ARCHIVE-demo.txt containing non-secret text, and
prove your allowlist excludes it.
5. Failure: “Fingerprint matched, therefore the artifact is authentic”
That conclusion exceeds what Jenkins fingerprints provide. The fingerprint database is useful for correlating producer and consumer builds, but its MD5 checksum is not a modern cryptographic authenticity mechanism. A matching fingerprint can help trace lineage inside Jenkins; use SHA-256 and, where required, signatures/attestations for integrity/provenance.
6. Failure: release job rebuilds instead of promoting
CI build 42 passed tests for source SHA abc…, but the
release job checks out main and rebuilds. Even if
main still points to the same commit, timestamps,
dependency mirrors, toolchain changes, or non-reproducible build
inputs can produce different bytes. The release job has lost the
strongest evidence chain.
Repair the workflow by consuming the exact archived/external artifact identity from build 42, verify the digest before publication, and record the repository/deployment response. Do not “reconstruct” a release artifact from branch state when a verified artifact already exists.
7. Performance: oversized stashes and controller pressure
Pipeline Basic Steps documentation cautions that stashes use compressed TAR transfer and can demand controller CPU, especially for larger files. Symptoms can include slow stash/unstash steps, controller CPU spikes, queue delay unrelated to executor scarcity, and increased I/O. Measure before tuning.
| Symptom | Evidence | Likely layer | Correction |
|---|---|---|---|
| Stash takes minutes for hundreds of MB | Step timing + controller CPU/I/O | Transfer/storage | External repository/workspace manager/artifact manager |
| Artifact archive fills controller disk | Build artifact volume + retention | Retention policy | Bound retention or external artifact manager |
| Fingerprint database grows rapidly | File count fingerprinted per build | Metadata scope | Fingerprint intentional outputs/dependencies only |
| Coverage consumes large storage | Coverage source-retention settings | Plugin report storage | Use appropriate sourceCodeRetention policy |
8. Causal separation checklist
- Trigger/SCM: was the correct source SHA built?
- Queue/agent: did the intended node/workspace execute?
- Producer: did the tool create the expected file/report?
- Transfer: did stash/unstash preserve the same digest?
- Ingestion: did JUnit/Coverage parse the expected path?
- Retention: did archiveArtifacts store the intended allowlist?
- Fingerprint: was relationship metadata recorded for the exact file?
- External: did a repository accept the exact digest?
9. Security rules for evidence handling
Do not archive credentials, private keys, token files, support bundles with secrets, or broad home directories. Do not disable authorization so a consumer can retrieve artifacts. Grant build/artifact read access deliberately. Treat test reports as potentially sensitive: test names, failure messages, paths, stack traces, and captured output can reveal internal data.
When external artifact managers are used, use least-privilege service identity and verify retention/deletion semantics. Jenkins build deletion and external object deletion may be different operations.
10. Smallest safe repair
The repair target should match the failing layer. Wrong glob? Fix the glob. Missing plugin? Review/install on a disposable controller. Oversized stash? Change transfer/storage architecture. Secret captured? Rotate and narrow collection. Rebuild-during-promotion? Rewire promotion to the original immutable artifact. Avoid delete-and-recreate debugging because it destroys the history needed to prove what happened.
Knowledge check
A JUnit XML file exists but Jenkins shows no tests. What should you inspect first?
The report-ingestion layer: working directory, Ant-style path/glob, JUnit step log, and plugin version—while preserving the original build evidence.
Why is
archiveArtifacts artifacts: "**/*"
dangerous?
It can retain secrets, caches, source, debug dumps, or enormous directories. Archive patterns should be narrow allowlists.
What should a release job do with a CI artifact that already passed verification?
Consume and promote the exact retained artifact by immutable build/repository identity and verify its digest; do not rebuild it from a branch name.
What evidence indicates stash is becoming a controller-performance problem?
Stash step duration correlated with controller CPU/I/O and payload size, not merely queue wait or agent execution time.
If a fingerprint matches, what can you safely conclude?
Jenkins recognized the same MD5-keyed file relationship for tracking purposes; you cannot conclude cryptographic authenticity or provenance.
Official references and version notes
-
Pipeline: Basic Steps reference
— current
stash/unstashsemantics and guidance for cross-stage transfer. -
Running Pipelines
— Declarative stage restart and
preserveStashesbehavior. -
Recording tests and artifacts
—
archiveArtifacts, fingerprinting, and JUnit publishing patterns. - Jenkins fingerprints — dependency/use tracking and the MD5-based fingerprint record.
- JUnit plugin — maintained test-result ingestion and build/test history.
- Coverage plugin — maintained coverage ingestion, quality gates, and source-retention choices.
-
Coverage Pipeline step reference
— current
recordCoverageparameters and supported parsers. - Artifact Manager on S3 plugin — optional example of external artifact-manager integration; not required by the labs.
- Jenkins LTS changelog — current LTS and tested Java configurations.
Rechecked on 2026-09-16. Examples assume Jenkins 2.568.3 LTS (tested with Java 21 and 25), Pipeline: Basic Steps 1098.v808b_fd7f8cf4, Pipeline: Job 1600.v6f36ed83529d, and JUnit 1425.v9c7318dca_96d. The optional coverage extension uses Coverage 3.3358.v9487dde48783, which requires Jenkins 2.555.3 or newer and is therefore compatible with this LTS baseline. The mandatory path is free/local/disposable. Record the versions actually installed on your controller before applying the examples.
Keep the academy open
Support free, practical DevOps education.
Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this
address.