Skip to content

Import artifacts into CloudRepo

View as Markdown

You have the files on disk, exported from another repository manager. This page copies them into CloudRepo: one loop per format, each of which you can run again after a failure.

  • A CloudRepo repository for each repository whose files you are moving, of the same format. If you have none, create them. Import only those. For each other kind of repository in your old system, the page for that system says what to create in CloudRepo, if anything, such as a proxy repository.
  • A repository token with Read + write that reaches those repositories. See Repository tokens. Your username is the email address of the account that created the token.
  • The exported files in a directory, ./export, each repository in its own subdirectory. The page for the system you are leaving tells you how to get them: JFrog Artifactory, Sonatype Nexus, AWS CodeArtifact. For Azure Artifacts, see the Azure Artifacts guide.

What a second run does depends on the format and on whether Overwrite Protection is on. It is on for every Maven, npm and Python repository unless someone turned it off for that repository. See Overwrite Protection.

  • Maven. While Overwrite Protection is on, CloudRepo answers 409 Conflict for a release file, or a checksum or signature file that belongs to one, that is already in the repository, and leaves it as it is. maven-metadata.xml, its own checksum and signature files, and every file under a -SNAPSHOT version are rewritten and never refused.
  • npm and Python. While Overwrite Protection is on, CloudRepo answers 409 Conflict for an npm version or a Python file that is already in the repository, and leaves it as it is.
  • Docker. A Docker repository has no Overwrite Protection. Pushing a tag that already exists moves the tag to the new image.
  • Overwrite Protection turned off. The repository accepts overwrites, so a second run replaces what it already holds.

So a second run skips the Maven releases, npm versions and Python files the first run finished and uploads the rest, only while Overwrite Protection is on, and it re-points every Docker tag it pushes again.

A Maven repository is a directory tree, and CloudRepo’s Maven door takes a PUT at any path in that tree, which is what mvn deploy sends. So the whole tree goes up file by file, checksum files and maven-metadata.xml included, with the same paths.

1. Put the credential in ~/.netrc, so curl reads it from there and the token is on no command line. Keep the file readable by you alone (chmod 600 ~/.netrc).

~/.netrc
machine your-org.mycloudrepo.io
login you@example.com
password YOUR_REPOSITORY_TOKEN

2. Upload the tree. Run this from the repository’s directory in ./export. It prints one line per file: the status CloudRepo answered, then the path.

Terminal
BASE=https://your-org.mycloudrepo.io/repositories/your-repo
cd export/your-repo
find . -type f | sort | while IFS= read -r f; do
code=$(curl --netrc --proto =https --silent --output /dev/null --write-out '%{http_code}' \
--upload-file "$f" "$BASE/${f#./}")
printf '%s %s\n' "$code" "$f"
done | tee ../import.log

2xx means the file is in. With Overwrite Protection on, 409 means it was already there: a release file, or a checksum file that belongs to one, from an earlier run. maven-metadata.xml and -SNAPSHOT versions are rewritten, never refused. Look at every other status in import.log: 401 is the credential, 403 is a token that cannot write here, 413 is a file over 50 GB.

A count is not proof. Fetch a few files back from CloudRepo and compare them with the originals:

Terminal
f=com/example/my-library/1.0.0/my-library-1.0.0.jar
curl --netrc --fail --silent "https://your-org.mycloudrepo.io/repositories/your-repo/$f" | sha256sum
sha256sum "export/your-repo/$f"

The two lines must match. For npm, Python and Docker, install or pull one package or image from CloudRepo in a clean directory or on a clean machine, as on Pull npm packages, Pull Python packages and Pull Docker images. The files are also listed in the repository in the admin portal.

Each refusal has one cause, and it is the same as when you publish by hand. See the list at the end of Publish Maven artifacts, Publish npm packages, Publish Python packages or Push Docker images. If you are stuck, email support@cloudrepo.io with your organization name, the repository, the failing line from import.log and the command you ran.