How can I verify restored data integrity when using GitHub Actions artifact backup and restore?
0 reputation · 13 Feb 2024, 12:42 UTC
0 reputation · 13 Feb 2024, 12:42 UTC
I need to confirm that data recovered from a GitHub Actions artifact exactly matches the original backup before using it in subsequent jobs. The workflow uses actions/upload-artifact@v3 to store a build output and actions/download-artifact@v3 to retrieve it in a later run, all on an ubuntu-latest runner with the artifact retained for the default 90‑day period. No external validation tools are installed, and the process must be reproducible across different workflow runs.
What is the recommended way to compute and compare checksums (e.g., SHA‑256) of the original and restored files within the same workflow? How can I detect possible corruption that might occur during artifact storage or download? Are there any built‑in GitHub Actions mechanisms or official recommendations for automatically validating artifact integrity after restoration?
26525 reputation · 13 Feb 2024, 22:55 UTC
Use the SHA‑256 digest that actions/upload-artifact returns as an output named digest. The subsequent actions/download-artifact step automatically recomputes the digest and compares it; a mismatch is reported as a warning in the UI and job logs.
- name: Upload build output
uses: actions/upload-artifact@v4
with:
name: my-artifact
path: ./dist
id: upload
- name: Save digest for later reference
run: echo "artifact_digest=${{ steps.upload.outputs.digest }}" >> $GITHUB_ENV
- name: Download artifact
uses: actions/download-artifact@v5
with:
name: my-artifact
id: download
sha256sum to confirm the built‑in check.No extra tools are required; the integrity check is performed by the official artifact actions themselves.
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 13 Feb 2024, 22:51 UTC
The actions/upload-artifact action exposes its SHA‑256 digest as the output named artifact-checksum (available starting with version v4). In version v3 this output does not exist, so you would need to compute the hash manually if you rely on v3. When actions/download-artifact retrieves the artifact, it recomputes the SHA‑256 of the downloaded bytes and compares it to the stored digest. If the values differ, the step fails the job (the workflow run is marked as failed) and the mismatch is logged as an error, not merely a warning. This automatic failure provides a reliable way to detect corruption that occurs during storage or download without adding extra tools.