→ Back to Home
Jenkins / CI

Jenkins ORAS Artifact Manager Plugin Elevates CI/CD Artifact Handling to OCI Registries

The Jenkins project has released the ORAS Artifact Manager Plugin, a new tool designed to change how Jenkins handles build artifacts. Traditionally, Jenkins stores artifacts and stashes on the controller's local disk. This new plugin integrates with Open Container Initiative (OCI) registries, allowing Jenkins to store these artifacts directly within them. This is achieved through a dedicated ORAS Java API Jenkins plugin, which bundles the official ORAS Java SDK. Each Jenkins job is mapped to an OCI repository, and for every build, a build root artifact is pushed, tagged with the build number. Individual archived files are then pushed as single-layer OCI manifests, linked back to the root artifact using the OCI 1.1 subject field. This development is crucial for practitioners because it tackles several limitations of local artifact storage. Relying on the controller's local disk for artifacts can lead to scalability issues, storage management overhead, and a lack of centralized discoverability, especially in distributed Jenkins environments. By leveraging OCI registries, organizations can centralize their artifact storage alongside their container images, simplifying governance, security scanning, and lifecycle management. This move aligns Jenkins with broader cloud-native practices, where OCI registries are becoming the de facto standard for storing and distributing all forms of software components. This initiative fits perfectly within the broader trend of shifting CI/CD workflows towards more cloud-native, distributed, and standardized architectures. The adoption of OCI for artifacts extends the benefits of containerization beyond just images, encompassing all build outputs. This trend is also evident in the increasing focus on supply chain security, where having a single, well-governed repository for all artifacts simplifies vulnerability scanning and provenance tracking. The plugin's reliance on the ORAS Java SDK, a CNCF project, further underscores this commitment to open standards and community-driven development in the cloud-native ecosystem. In practice, this means DevOps teams should evaluate integrating this plugin, especially if they are already using OCI registries for container images or are struggling with Jenkins artifact storage scalability. While the plugin and its underlying SDK are still in beta, early adoption in non-critical jobs can provide valuable insights. Practitioners should monitor the GitHub repository for updates and contribute feedback to help shape its development. This move represents a strategic opportunity to streamline artifact management, improve security postures, and enhance the overall efficiency of CI/CD pipelines by embracing a unified, industry-standard approach to artifact storage.
Read original source