How do you configure where Maven deploys artifacts, and how does it choose between the release and snapshot repositories?
answer
- distributionManagement = deploy targets
- <repository> releases, <snapshotRepository> snapshots
- version -SNAPSHOT routes the choice
- creds in settings.xml <server> by id
- id must match -> else 401
basics
~10 sYou add <distributionManagement> to the POM with <repository> (for releases) and <snapshotRepository> (for SNAPSHOTs). Maven picks based on the version: -SNAPSHOT versions go to snapshotRepository, all others go to repository.
solid answer
~40 sDeploy targets are declared in `<distributionManagement>` in the POM (usually the parent). It contains `<repository>` for release versions and `<snapshotRepository>` for SNAPSHOT versions; each has an `<id>` and `<url>`. At deploy time the maven-deploy-plugin inspects the project version: if it ends in `-SNAPSHOT` it uploads to `<snapshotRepository>`, otherwise to `<repository>`. Credentials are never put in the POM — instead the repository `<id>` is matched to a `<server>` entry in `settings.xml` (typically `~/.m2/settings.xml`) that holds the username/password or token, ideally encrypted with `mvn --encrypt-password`. This separation keeps secrets out of version control while letting the POM remain shareable. Repository managers like Nexus or Artifactory expose these two URLs.
code
xml · 10 lines<distributionManagement>
<repository>
<id>company-releases</id>
<url>https://nexus.acme.com/repository/maven-releases/</url>
</repository>
<snapshotRepository>
<id>company-snapshots</id>
<url>https://nexus.acme.com/repository/maven-snapshots/</url>
</snapshotRepository>
</distributionManagement>go deeper
Knows distributionManagement names the deploy target and there are two repos.
Explains version-based routing and that credentials go in settings.xml matched by id.
Handles encrypted passwords/tokens, CI deploy users, and the repositories-vs-distributionManagement distinction.
Standardizes deploy config in a corporate parent POM and governs repo-manager access and credential rotation.
## Declaring deploy targets `mvn deploy` needs to know **where** to upload. That is declared in `<distributionManagement>`: ```xml <distributionManagement> <repository> <id>company-releases</id> <url>https://nexus.acme.com/repository/maven-releases/</url> </repository> <snapshotRepository> <id>company-snapshots</id> <url>https://nexus.acme.com/repository/maven-snapshots/</url> </snapshotRepository> </distributionManagement> ``` - `<repository>` — destination for **release** versions. - `<snapshotRepository>` — destination for **SNAPSHOT** versions. ## How Maven chooses The selection is automatic and based purely on the project `<version>`: - Version ends in `-SNAPSHOT` -> upload to `<snapshotRepository>`. - Otherwise -> upload to `<repository>`. If the version is a SNAPSHOT but no `<snapshotRepository>` is defined, deploy fails. ## Credentials live in settings.xml, not the POM The POM is shared/committed, so it must not contain secrets. Authentication is matched by **id**: the repository `<id>` in `distributionManagement` must equal a `<server><id>` in `settings.xml`: ```xml <!-- ~/.m2/settings.xml --> <servers> <server> <id>company-releases</id> <username>ci-deployer</username> <password>{ENCRYPTED-OR-TOKEN}</password> </server> <server> <id>company-snapshots</id> <username>ci-deployer</username> <password>{ENCRYPTED-OR-TOKEN}</password> </server> </servers> ``` Use `mvn --encrypt-password` (with a master password) to avoid plaintext. ## Related elements - `<site>` — for `mvn site:deploy`. - `<relocation>` — to signal an artifact moved to new coordinates. ## Common pitfalls - Mismatched `id` between distributionManagement and settings.xml -> 401 Unauthorized. - Putting credentials in the POM -> secret leak. - Forgetting `<snapshotRepository>` -> SNAPSHOT deploys fail.
- Where do deploy credentials go and how are they linked to the repo?In settings.xml <server> entries; the <server><id> must exactly match the distributionManagement repository <id>. The POM holds no secrets.
- What happens if you deploy a SNAPSHOT but only define <repository>?Deploy fails because there is no <snapshotRepository> target for the SNAPSHOT version.
saying these in an interview costs you the question
- Putting usernames/passwords directly in the POM.
- Saying you manually choose the repo per deploy — it's automatic by version.
- Confusing distributionManagement (where to publish) with <repositories> (where to download).