JFrog Azure DevOps Extension

Connect Azure Pipelines to the JFrog Platform with service connections and build tasks.

The JFrog Azure DevOps Extension adds Azure Pipelines tasks for JFrog CLI, package builds, generic artifacts, build-info, Xray scans, promotion, retention, and Distribution. Use it when you want Azure Pipelines to authenticate through managed service connections and publish traceable builds to the JFrog Platform.

📘

Note

Use the current JFrog Azure DevOps Extension. For custom flows, start with JFrog CLI V2. Use package-specific tasks when their structured inputs and build-info collection fit your pipeline.

Prerequisites

  • An Azure DevOps organization and project with permission to install extensions and create service connections.
  • A pipeline agent with network access to your JFrog Platform and JFrog CLI downloads.
  • Permissions in the JFrog Platform for the operations your tasks perform.
  • The package client required by your build, such as Maven, Gradle, npm, NuGet, pip, Go, or Conan.
  • A local repository of the matching package type, deploy plus publish-build-info permission, and the same build name and number on collect and publish tasks.

Before You Begin

See How Build Integration Works and Choose Plugin, CLI, or CI Wrapper before you mix package tasks with JFrog CLI V2.

JFrog tasks use the Azure Pipelines agent's Node execution handlers. Keep self-hosted agents current enough to provide the required handler. Do not install application Node.js solely for these task handlers. The agent supplies them.

Install the Extension

To install the JFrog Azure DevOps Extension:

  1. Open the JFrog extension in Visual Studio Marketplace.
  2. Install it into your Azure DevOps organization.
  3. Authorize it for the projects that will use JFrog tasks.

Create a Service Connection

Create the connection type required by the task.

ConnectionUsed by
JFrog Platform V2JFrog CLI V2
JFrog Artifactory V2Package, generic artifact, build-info, promotion, retention, and tools tasks
JFrog Xray V2Audit and build scan
JFrog Distribution V2Distribution task

For OIDC, enable OpenID Connect Integration on each connection type your pipeline uses and provide the matching JFrog OIDC provider name. A Platform connection is not a substitute for Artifactory, Xray, or Distribution connections on their specialized tasks.

Quick Start

Create a JFrog Platform V2 service connection, then add:

steps:
  - task: JfrogCliV2@1
    displayName: Verify JFrog connection
    inputs:
      jfrogPlatformConnection: '<JFROG_PLATFORM_CONNECTION>'
      command: 'jf rt ping'

Replace <JFROG_PLATFORM_CONNECTION> with the Azure DevOps service connection name. For example, jfrogPlatformConnection: 'jfrog-platform-prod'.

Expected result: the task installs or locates JFrog CLI, configures it from the selected service connection, and reports a successful Artifactory ping.

Publish Build Information

Package and generic-artifact tasks can collect build-info locally. Add JFrog Publish Build Info after those tasks:

- task: JFrogPublishBuildInfo@1
  inputs:
    artifactoryConnection: '<JFROG_ARTIFACTORY_CONNECTION>'
    buildName: '$(Build.DefinitionName)'
    buildNumber: '$(Build.BuildNumber)'

Replace <JFROG_ARTIFACTORY_CONNECTION> with the Azure DevOps service connection name.

Use the same build name and number on collecting and publishing tasks.

Confirm the Published Build

Open Builds in Artifactory and select the Azure Pipeline definition name and build number used by the tasks. Confirm artifacts and dependencies before adding scan or promotion steps.

Task Families

Build and Resolve

  • JFrog Maven
  • JFrog Gradle
  • JFrog npm
  • JFrog NuGet and .NET
  • JFrog Pip
  • JFrog Go
  • JFrog Conan
  • JFrog Generic Artifacts

Build Lifecycle

  • JFrog Collect Build Issues
  • JFrog Publish Build Info
  • JFrog Build Promotion
  • JFrog Discard Builds

Security and Distribution

  • JFrog Audit
  • JFrog Build Scan
  • JFrog Distribution
  • JFrog Docker

Tools and Custom Commands

  • JFrog Tools Installer
  • JFrog CLI V2

JFrog CLI V2 requires each command line to begin with jf . It accepts multiple newline-separated commands, uses a JFrog Platform V2 connection, and can pin a custom CLI version.

Configure Air-Gapped and Controlled Agents

By default, tasks download JFrog CLI and the Maven and Gradle extractors when needed.

To configure a restricted agent:

  1. Create Artifactory remote repositories for JFrog CLI and the extractors.
  2. Add JFrog Tools Installer before dependent tasks.
  3. Select the Artifactory connection and proxy repositories.

You can also place jf in $(Agent.ToolsDirectory)/_jf/current/ as described by the extension repository.

Troubleshooting

The following table lists common issues and how to resolve them.

What you seeCauseWhat to do
Task cannot find a Node handlerThe self-hosted agent is old or lacks a handler declared by the task.Upgrade the Azure Pipelines agent. The local descriptor supports Node10 and Node20_1.
Service connection is rejectedThe task received the wrong connection type.Match Platform, Artifactory, Xray, or Distribution to the task table.
OIDC authentication failsProvider name, identity mapping, or connection OIDC settings do not match.Compare the Azure token claims with the JFrog identity mapping and verify the provider name.
Tool download failsThe agent cannot reach JFrog releases.Use JFrog Tools Installer with Artifactory proxy repositories or preinstall the CLI.
Build is missingBuild-info was collected but not published, or names differ.Add JFrog Publish Build Info with the same build name and number.
JFrog CLI V2 rejects a commandThe line does not begin with jf .Include the binary prefix, for example jf rt ping.

Related Topics


Did this page help you?