Chapter 14Lesson 04~125 minutes

Artifacts, stash/unstash, archiveArtifacts, Fingerprints, Test Reports, Coverage, and Build Evidence: Diagnostics, Failure Modes, Security, and Performance

Diagnose artifact/report failures from first evidence, repair wrong paths and lifecycle choices without hiding the original cause, and prevent secrets, oversized stashes, weak authenticity assumptions, or rebuild-on-promotion from becoming production failures.

DiagnosticsSecurityWrong globArtifact leakagePerformancePromotion

Learning objectives

  • Preserve first-failure build/source/node/report evidence before retrying, cleaning, or rebuilding.
  • Diagnose missing artifacts and reports by separating workspace production from Jenkins ingestion/retention.
  • Recognize secret leakage risks in archive/stash/report patterns and prevent broad workspace capture.
  • Explain why fingerprints do not prove authenticity and why release promotion must preserve original bytes.
  • Identify large-stash/controller-resource symptoms and select a less costly transfer/storage path.

1. Evidence-first diagnostic ladder

When an artifact or report is missing, do not immediately rerun the build. A rerun can change the source revision, agent, dependency resolution, timestamped package contents, or external side effects. Preserve the original build first.

  1. Record job full name, build number/URL, queue ID/cause, exact source/Jenkinsfile SHA.
  2. Record Jenkins core/Java and relevant Pipeline/JUnit/Coverage plugin versions.
  3. Record node, label, executor, workspace path, and first failing log lines.
  4. Prove whether the producer file existed before the Jenkins step.
  5. Inspect the stash/archiveArtifacts/junit/recordCoverage pattern and working directory.
  6. Inspect retained artifact/report/fingerprint state on the original build.
  7. Verify external repository state independently if publication was attempted.
  8. Apply the smallest correction and rerun only after the original evidence packet is complete.

2. Intentionally broken example: the report exists, the glob is wrong

Assume the producer writes reports/junit.xml but the Jenkinsfile contains:

stage('Publish reports') {
  steps {
    sh 'test -s reports/junit.xml && ls -l reports/junit.xml'
    junit testResults: 'report/*.xml', allowEmptyResults: false
  }
}

The shell proves the file exists. The JUnit step then reports that no matching test report files were found. Those facts are not contradictory: the producer succeeded, but report ingestion used a different path.

Repair: preserve the original console log and build number, change only the pattern to reports/*.xml, commit the Jenkinsfile change, and run a new build. The failed build remains valuable evidence of the ingestion-layer defect.

3. Failure: stash used as long-term storage

A downstream job asks for a stash created yesterday and cannot access it. This is expected: stashes are run-scoped. Even preserved stashes are intended for Declarative stage restart, not arbitrary cross-job consumption.

Repair the architecture, not the timeout: archive the build artifact for Jenkins retention or publish it to a repository manager. Give the consumer an immutable producer identity: job/build + artifact path or repository coordinate + SHA-256.

4. Failure: an archive pattern captures a secret

The dangerous pattern is broad collection after a tool has written credentials or debug files into the workspace:

// DO NOT USE: may capture source, caches, temp files, or secrets.
archiveArtifacts artifacts: '**/*', fingerprint: true

Do not “fix” this by hiding the artifact link. Authorization and UI visibility do not undo retention. Stop publication, preserve the incident identifiers, rotate/revoke the exposed credential if it was real, remove the secret from future workspace output, narrow the archive allowlist, and follow your organization’s approved evidence-removal procedure if sensitive bytes were persisted.

Lab rule: never place a real credential in this exercise. Demonstrate the risk with a file named DO_NOT_ARCHIVE-demo.txt containing non-secret text, and prove your allowlist excludes it.

5. Failure: “Fingerprint matched, therefore the artifact is authentic”

That conclusion exceeds what Jenkins fingerprints provide. The fingerprint database is useful for correlating producer and consumer builds, but its MD5 checksum is not a modern cryptographic authenticity mechanism. A matching fingerprint can help trace lineage inside Jenkins; use SHA-256 and, where required, signatures/attestations for integrity/provenance.

6. Failure: release job rebuilds instead of promoting

CI build 42 passed tests for source SHA abc…, but the release job checks out main and rebuilds. Even if main still points to the same commit, timestamps, dependency mirrors, toolchain changes, or non-reproducible build inputs can produce different bytes. The release job has lost the strongest evidence chain.

Repair the workflow by consuming the exact archived/external artifact identity from build 42, verify the digest before publication, and record the repository/deployment response. Do not “reconstruct” a release artifact from branch state when a verified artifact already exists.

7. Performance: oversized stashes and controller pressure

Pipeline Basic Steps documentation cautions that stashes use compressed TAR transfer and can demand controller CPU, especially for larger files. Symptoms can include slow stash/unstash steps, controller CPU spikes, queue delay unrelated to executor scarcity, and increased I/O. Measure before tuning.

Symptom Evidence Likely layer Correction
Stash takes minutes for hundreds of MB Step timing + controller CPU/I/O Transfer/storage External repository/workspace manager/artifact manager
Artifact archive fills controller disk Build artifact volume + retention Retention policy Bound retention or external artifact manager
Fingerprint database grows rapidly File count fingerprinted per build Metadata scope Fingerprint intentional outputs/dependencies only
Coverage consumes large storage Coverage source-retention settings Plugin report storage Use appropriate sourceCodeRetention policy

8. Causal separation checklist

  • Trigger/SCM: was the correct source SHA built?
  • Queue/agent: did the intended node/workspace execute?
  • Producer: did the tool create the expected file/report?
  • Transfer: did stash/unstash preserve the same digest?
  • Ingestion: did JUnit/Coverage parse the expected path?
  • Retention: did archiveArtifacts store the intended allowlist?
  • Fingerprint: was relationship metadata recorded for the exact file?
  • External: did a repository accept the exact digest?

9. Security rules for evidence handling

Do not archive credentials, private keys, token files, support bundles with secrets, or broad home directories. Do not disable authorization so a consumer can retrieve artifacts. Grant build/artifact read access deliberately. Treat test reports as potentially sensitive: test names, failure messages, paths, stack traces, and captured output can reveal internal data.

When external artifact managers are used, use least-privilege service identity and verify retention/deletion semantics. Jenkins build deletion and external object deletion may be different operations.

10. Smallest safe repair

The repair target should match the failing layer. Wrong glob? Fix the glob. Missing plugin? Review/install on a disposable controller. Oversized stash? Change transfer/storage architecture. Secret captured? Rotate and narrow collection. Rebuild-during-promotion? Rewire promotion to the original immutable artifact. Avoid delete-and-recreate debugging because it destroys the history needed to prove what happened.

Next lesson

Checkpoint Lab — Artifacts, stash/unstash, archiveArtifacts, Fingerprints, Test Reports, Coverage, and Build Evidence

Build once, move the same bytes across agents, retain and fingerprint them, ingest reports, erase workspace state, and prove exactly which evidence survives.

Knowledge check

A JUnit XML file exists but Jenkins shows no tests. What should you inspect first?

Why is archiveArtifacts artifacts: "**/*" dangerous?

What should a release job do with a CI artifact that already passed verification?

What evidence indicates stash is becoming a controller-performance problem?

If a fingerprint matches, what can you safely conclude?

Official references and version notes

Version and compatibility note

Rechecked on 2026-09-16. Examples assume Jenkins 2.568.3 LTS (tested with Java 21 and 25), Pipeline: Basic Steps 1098.v808b_fd7f8cf4, Pipeline: Job 1600.v6f36ed83529d, and JUnit 1425.v9c7318dca_96d. The optional coverage extension uses Coverage 3.3358.v9487dde48783, which requires Jenkins 2.555.3 or newer and is therefore compatible with this LTS baseline. The mandatory path is free/local/disposable. Record the versions actually installed on your controller before applying the examples.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this address.