Skip to content

Pull Maven artifacts from CloudRepo

View as Markdown

Maven reads CloudRepo like any other Maven repository: declare it in your pom.xml, give Maven the credential in settings.xml, and build. This page is for the person whose build pulls from a repository. To put artifacts there, see Publish Maven artifacts.

You need a Maven repository, and a repository token that reaches it. If you have neither yet: create a repository and create a token. A token that is Read only is enough to pull.

  1. Put the credential in ~/.m2/settings.xml. The <id> is a name you choose, and the repository in your pom.xml must use the same one. The username is the email address of the account that created the token, and the password is the token.

    ~/.m2/settings.xml
    <settings>
    <servers>
    <server>
    <id>cloudrepo</id>
    <username>you@example.com</username>
    <password>${env.CLOUDREPO_TOKEN}</password>
    </server>
    </servers>
    </settings>

    ${env.CLOUDREPO_TOKEN} reads the token from an environment variable, so the file holds no token. Export it in the shell that runs Maven, or in your CI’s secret store.

  2. Declare the repository and the dependency in pom.xml.

    pom.xml
    <project>
    <modelVersion>4.0.0</modelVersion>
    <groupId>com.example</groupId>
    <artifactId>my-app</artifactId>
    <version>1.0.0</version>
    <repositories>
    <repository>
    <id>cloudrepo</id>
    <url>https://your-org.mycloudrepo.io/repositories/your-repo</url>
    </repository>
    </repositories>
    <dependencies>
    <dependency>
    <groupId>com.example</groupId>
    <artifactId>my-library</artifactId>
    <version>1.0.0</version>
    </dependency>
    </dependencies>
    </project>

    The repository URL is https://<organization>.mycloudrepo.io/repositories/<repository>: your organization’s name, then the repository’s name as the admin portal shows it. Put the <repositories> block in a parent POM if you have one, so a project states it once.

  3. Build.

    Terminal
    mvn --batch-mode package

    Expected: Maven prints Downloading from cloudrepo: and the artifact’s URL under your repository, then BUILD SUCCESS.

When you want a single file and no build, curl sends the same credential. Put it in ~/.netrc and ask curl to read it, and keep the file readable by you alone (chmod 600 ~/.netrc).

~/.netrc
machine your-org.mycloudrepo.io
login you@example.com
password YOUR_REPOSITORY_TOKEN
Terminal
curl --netrc --fail --remote-name \
https://your-org.mycloudrepo.io/repositories/your-repo/com/example/my-library/1.0.0/my-library-1.0.0.jar

Maven usually prints only the status. Check these in order:

  • 401 Unauthorized. The credential was refused. The username must be the email address of the account that created the token, and the password the token itself. A token that is expired or revoked fails the same way: the Repository Tokens page in the admin portal shows its status.
  • 403 Forbidden. The token does not reach this repository. A token reaches only the repositories ticked when it was created, so use one that includes it.
  • 404 Not Found. The path is wrong: check the organization and repository names in the URL, and the group, artifact and version in the dependency. A proxy repository that the token does not reach also answers 404, not 403.

More: Repository tokens, for every client’s credential; Proxy repositories, to pull Maven Central or another public repository through CloudRepo; Maven repositories, for publishing, snapshots and overwrite protection.