Skip to content

Artifacts Management

GitHub Actions and CI/CD Pipelines rely on efficient artifact management to ensure reliable, reproducible deployments. Build artifacts—such as compiled binaries, container images, or package files—must be stored, versioned, and retrieved consistently across pipeline stages. Poor artifact management can lead to deployment failures, version mismatches, or unnecessary resource consumption. This section outlines strategies for storing, versioning, and managing artifacts in CI/CD workflows.


Artifact Storage Strategies

Artifacts must be stored in a location accessible to all pipeline stages while balancing cost, speed, and security. Common approaches include:

1. GitHub Actions Artifacts

GitHub Actions provides built-in artifact storage for short-term use. Use actions/upload-artifact and actions/download-artifact for lightweight workflows.

# Upload an artifact
steps:
  - name: Build app
    run: ./build.sh
  - name: Upload artifact
    uses: actions/upload-artifact@v3
    with:
      name: my-app
      path: dist/

# Download an artifact in a subsequent job
steps:
  - name: Download artifact
    uses: actions/download-artifact@v3
    with:
      name: my-app
      path: ./dist

2. Cloud Object Storage

For long-term storage, use cloud providers like AWS S3, Google Cloud Storage (GCS), or Azure Blob Storage. Example for AWS S3:

# Upload to S3
aws s3 cp dist/ s3://my-bucket/artifacts/ --recursive
# Download from S3
aws s3 cp s3://my-bucket/artifacts/ dist/ --recursive

3. Local Filesystems

For ephemeral environments, store artifacts in shared network drives or NFS mounts. Ensure cleanup to avoid disk bloat.


Versioning Best Practices

Versioning ensures artifacts are traceable and compatible with deployments. Use semantic versioning (e.g., v1.2.3) and tie versions to Git tags or CI/CD pipeline IDs.

1. Git-Based Versioning

Link artifact versions to Git tags:

# Example: Tagging a release
git tag v1.2.3
git push origin v1.2.3
Use tags to reference artifacts in workflows:
jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - name: Use v1.2.3 artifact
        run: ./deploy.sh --version v1.2.3

2. Timestamp-Based Versioning

Automate versioning with timestamps or build numbers:

# Generate a version string
VERSION=$(date +%Y%m%d%H%M%S)
echo "Building version $VERSION"


Retrieval and Dependency Management

Artifacts must be retrievable by downstream stages. Use explicit paths and versioned references to avoid conflicts.

1. Cross-Stage Artifact Sharing

Pass artifacts between jobs in the same workflow:

jobs:
  build:
    steps:
      - name: Build and upload
        uses: actions/upload-artifact@v3
        with:
          name: build-output
          path: dist/
  deploy:
    needs: build
    steps:
      - name: Download and deploy
        uses: actions/download-artifact@v3
        with:
          name: build-output
          path: ./dist

2. Dependency Locking

Use lock files (e.g., package-lock.json, Pipfile.lock) to ensure consistent dependencies across builds.


Artifact Retention and Cleanup

Unused artifacts consume storage and pose security risks. Implement retention policies and automated cleanup.

1. Cloud Storage Retention

Configure S3 lifecycle policies to delete artifacts after a set period:

{
  "Rules": [
    {
      "ExpirationInDays": 30,
      "Prefix": "artifacts/",
      "Status": "Enabled"
    }
  ]
}

2. GitHub Actions Cleanup

Use actions/cleanup-artifacts@v2 to remove unused artifacts:

jobs:
  cleanup:
    runs-on: ubuntu-latest
    steps:
      - name: Clean up old artifacts
        uses: actions/cleanup-artifacts@v2
        with:
          keep: 5  # Retain the 5 most recent artifacts


Security and Access Control

Secure artifacts with encryption, access controls, and secrets management.

1. Encryption

Encrypt artifacts at rest and in transit: - Use AWS KMS for S3 encryption. - Leverage GitHub Actions' built-in encryption for uploaded artifacts.

2. Access Controls

Restrict access to artifacts using IAM roles (for cloud storage) or GitHub Actions' secret management:

# Example: Use a secret to access a private S3 bucket
env:
  AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
  AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}


Key takeaways

  • Use versioning (Git tags, semantic versions) to ensure reproducibility.
  • Choose storage based on workflow needs: GitHub Actions for short-term, cloud storage for long-term.
  • Automate cleanup to avoid storage bloat and security risks.
  • Secure artifacts with encryption and access controls.
  • Explicitly reference artifacts in workflows to avoid dependency conflicts.