skip to content

Repositories and Metadata

Where Gradle looks for modules and what it reads when it finds them: repository declarations, filtering and credentials, Gradle Module Metadata, variant matching, metadata rules, and the local cache. Interviewers ask because this metadata model is where Gradle diverges most from Maven.

on this pageshow

explore

questions

page 2 of 2

Why does Gradle recommend wiring repository credentials lazily via the Provider API, and what changes when you do?

level: seniorimportance: should knowfreq 35%

basics

~20 s

Lazy credentials (e.g. credentials(PasswordCredentials::class) resolved through providers) are only required when the repo is actually used. Gradle then fails fast at configuration time with a clear error if a credential is missing — but only for tasks that need it.

open as a page

How do you attach credentials to a repository declaration in Gradle without hardcoding secrets in the build script?

level: seniorimportance: should knowfreq 48%

basics

~10 s

Add a credentials {} block to the repository and read username/password from gradle.properties or the environment instead of inlining them. With a named repo, Gradle can also auto-map <name>Username/<name>Password properties.

open as a page

Where can repositories be declared in a Gradle build, and how do project-dependency repositories differ from plugin repositories?

level: seniorimportance: should knowfreq 45%

basics

~10 s

Project-dependency repositories go in each project's repositories {} (or centrally in dependencyResolutionManagement in settings). Plugin repositories for the plugins {} block go in pluginManagement { repositories {} } in settings.gradle.kts. They're separate lookup paths.

open as a page

How do you use a Component Metadata Rule to align a family of modules to a single version, and what is `belongsTo`?

level: seniorimportance: should knowfreq 30%

basics

~10 s

Make every module in a family (e.g. all Jackson modules) belongsTo a shared virtual platform. Gradle then aligns them to one consistent version, so you never mix 2.13 and 2.15 of related modules.

open as a page

What does `@CacheableRule` mean for a Component Metadata Rule, and how do you keep a rule cache-correct while passing external inputs?

level: seniorimportance: should knowfreq 22%

basics

~20 s

@CacheableRule tells Gradle it may cache the rule's output across builds. The rule must be a pure function of its inputs — no env/file reads. To use external data, inject it via an @Inject constructor parameter so Gradle tracks it for invalidation.

open as a page

How can a Component Metadata Rule use capabilities to resolve a 'same library, different coordinates' conflict?

level: seniorimportance: should knowfreq 35%

basics

~10 s

Declare that two equivalent modules provide the same capability (e.g. give old google-collections Guava's capability). Gradle then detects the conflict and you resolve it by choosing one module, avoiding duplicate classes on the classpath.

open as a page

What does a variant inside Gradle Module Metadata carry, and how do dependencies vs. dependencyConstraints differ within it?

level: seniorimportance: should knowfreq 35%

basics

~10 s

A variant carries attributes, capabilities, files, and two dependency lists: dependencies (modules this variant actually needs) and dependencyConstraints (version recommendations/limits applied only if that module is pulled in by someone else).

open as a page

What is the attributesSchema, and what is the difference between a compatibility rule and a disambiguation rule?

level: seniorimportance: should knowfreq 35%

basics

~20 s

The attributesSchema declares each attribute and how Gradle compares values. A compatibility rule decides whether a producer value is acceptable for what the consumer asked. A disambiguation rule picks the best one when several are acceptable.

open as a page

What are the consumer and producer sides of variant selection, and how do resolvable vs consumable configurations and their attributes participate?

level: seniorimportance: should knowfreq 30%

basics

~10 s

The producer exposes variants through consumable configurations carrying attributes. The consumer asks for artifacts through a resolvable configuration carrying requested attributes. Variant selection matches the consumer's attributes against the producer's consumable variants.

open as a page

How would you design dependency-cache handling across a CI fleet for fast, reproducible builds?

level: principalimportance: should knowfreq 25%

basics

~10 s

Persist and restore GRADLE_USER_HOME (the modules-2 cache) as a CI cache keyed on lockfiles, keep release builds on fixed/locked versions, and use --offline once the cache is warm to make builds fast and network-independent.

open as a page

What does the `authentication {}` block control on a repository, and when would you explicitly choose BasicAuthentication versus the default behavior?

level: middleimportance: nice to knowfreq 25%

basics

~10 s

The authentication {} block picks which auth scheme Gradle uses for a repo. Adding create<BasicAuthentication>("basic") forces Gradle to send Basic credentials preemptively instead of waiting for a 401 challenge.

open as a page

A consumer build picks an unexpected variant or fails with 'no variants match' for a dependency. How does Gradle Module Metadata factor into diagnosing this?

level: seniorimportance: nice to knowfreq 25%

basics

~20 s

GMM exposes the published variants and their attributes. When resolution fails, you compare the consumer's requested attributes against each variant's attributes — usually with dependencyInsight or by reading the .module file — and reconcile the mismatch via attributes, capabilities, or a component metadata rule.

open as a page

showing 31–42 of 42