Jenkins cheat sheet
63 commands from every lesson of Jenkins — Level by Level, on one page.
Run Jenkins
docker run -d --name jenkins -p 8080:8080 -p 50000:50000 -v jenkins_home:/var/jenkins_home jenkins/jenkins:lts-jdk21 | Jenkins LTS in Docker with a persistent volume |
docker exec jenkins cat /var/jenkins_home/secrets/initialAdminPassword | Password for the setup wizard |
helm repo add jenkins https://charts.jenkins.io && helm repo update | Add the official Helm chart repository |
helm install jenkins jenkins/jenkins -n jenkins --create-namespace -f values.yaml | Install on Kubernetes |
kubectl -n jenkins port-forward svc/jenkins 8080:8080 | Reach it locally |
Look around
curl -s http://localhost:8080/api/json?pretty=true | Jenkins REST API (authenticate for most data) |
http://localhost:8080/manage/systemInfo | Java, system properties, environment |
java -jar jenkins-cli.jar -s http://localhost:8080/ -auth user:token list-plugins | List plugins from the CLI |
Building blocks
pipeline { agent any; stages { stage('Build') { steps { sh 'make' } } } } | The minimum declarative pipeline |
when { branch 'main' } | Run a stage only on main |
post { always { junit 'reports/*.xml' } failure { ... } } | Always publish tests; act on failure |
options { timeout(time: 30, unit: 'MINUTES'); disableConcurrentBuilds() } | Guard rails for the whole pipeline |
parallel { stage('Unit') {...} stage('Lint') {...} } | Run stages side by side |
input message: 'Deploy to prod?', submitter: 'release-managers' | Manual approval gate |
Credentials
environment { REG = credentials('registry-creds') } | Username/password → REG_USR and REG_PSW, masked in logs |
withCredentials([string(credentialsId: 'api-token', variable: 'TOKEN')]) { sh 'curl -H "Authorization: Bearer $TOKEN" ...' } | Scoped secret for one block (single quotes!) |
Check before you commit
curl -X POST -F "jenkinsfile=<Jenkinsfile" -u user:token https://jenkins.example.com/pipeline-model-converter/validate | Validate a Jenkinsfile's syntax |
Build and push (inside an agent container)
buildctl-daemonless.sh build --frontend dockerfile.v0 --local context=. --local dockerfile=. --output type=image,name=$IMAGE:$TAG,push=true | Rootless BuildKit build and push |
buildah bud -t $IMAGE:$TAG . && buildah push $IMAGE:$TAG | Build and push with Buildah |
trivy image --exit-code 1 --severity CRITICAL $IMAGE:$TAG | Fail the build on critical CVEs |
crane digest $IMAGE:$TAG | Get the pushed image's digest |
Reports and artifacts
junit 'reports/**/*.xml' | Test results with trends in the Jenkins UI |
archiveArtifacts artifacts: 'dist/*.tgz', fingerprint: true | Keep build outputs, traceable by fingerprint |
recordIssues tools: [spotBugs()] | Static-analysis results (Warnings NG plugin) |
Conditions in a multibranch Jenkinsfile
when { changeRequest() } | Only for pull-request builds |
when { branch 'main' } | Only for main |
when { buildingTag() } | Only when building a tag |
when { tag pattern: 'v\\d+\\.\\d+\\.\\d+', comparator: 'REGEXP' } | Only for semantic-version tags |
env.CHANGE_ID / env.CHANGE_TARGET / env.BRANCH_NAME | PR number, PR target branch, branch name |
Webhooks
https://jenkins.example.com/github-webhook/ | GitHub webhook endpoint (GitHub plugin) |
https://jenkins.example.com/multibranch-webhook-trigger/invoke?token=<token> | Generic trigger for other Git servers (Multibranch Scan Webhook Trigger plugin) |
Using a library
@Library('platform-lib@v2.3.0') _ | Load a specific library version (top of the Jenkinsfile) |
standardServicePipeline(app: 'orders-api') | Call a whole pipeline defined in vars/standardServicePipeline.groovy |
buildImage(name: 'orders-api') | Call a step defined in vars/buildImage.groovy |
def cfg = libraryResource 'templates/buildkit-pod.yaml' | Load a file from resources/ |
Library layout
vars/<name>.groovy | Global steps/variables, one file per step, with a call() method |
src/com/acme/ci/Versioning.groovy | Classes for more complex logic |
resources/ | Non-Groovy files: pod templates, scripts, config |
test/ | Unit tests (JenkinsPipelineUnit) |
In the Jenkinsfile
agent { kubernetes { yaml '''...pod spec...''' } } | Define the agent pod inline |
agent { kubernetes { yamlFile 'ci/pod.yaml' } } | Pod spec from a file in the repo |
agent { kubernetes { inheritFrom 'python-311' } } | Use a pod template defined centrally |
container('node') { sh 'npm ci' } | Run steps in a specific container of the pod |
Troubleshoot
kubectl -n jenkins-agents get pods -w | Watch agent pods being created and removed |
kubectl -n jenkins-agents describe pod <agent-pod> | Why it's Pending or failing (resources, image pull) |
kubectl -n jenkins-agents logs <agent-pod> -c jnlp | Agent connection logs |
As code
CASC_JENKINS_CONFIG=/var/jenkins_home/casc_configs | Where JCasC reads its YAML |
https://jenkins.example.com/manage/configuration-as-code/ | View, export and reload JCasC |
jenkins-plugin-cli --plugin-file plugins.txt | Install exactly the pinned plugin list (in the image build) |
jenkins-plugin-cli --plugin-file plugins.txt --available-updates --output txt | What could be updated |
Operate
https://jenkins.example.com/manage/pluginManager/ | Plugin versions and security warnings |
kubectl -n jenkins exec jenkins-0 -- du -sh /var/jenkins_home/jobs | Where the disk goes |
https://jenkins.example.com/manage/scriptApproval/ | Pending script approvals (review carefully) |
https://jenkins.example.com/safeRestart | Restart after running builds finish |
Jenkinsfile
pipeline { agent … stages { stage('x') { steps { … } } } post { … } } | Declarative skeleton |
options { timeout(time: 30, unit: 'MINUTES'); buildDiscarder(logRotator(numToKeepStr: '30')) } | Timeouts and build retention |
withCredentials([string(credentialsId: 'api-token', variable: 'TOKEN')]) { sh 'use-token' } | Credentials binding (masked in logs) |
@Library('platform-lib@v2') _ | Load a versioned shared library |
agent { kubernetes { yaml '''…pod spec…''' } } | Ephemeral pod agent (Kubernetes plugin) |
Operating
Built-in node executors: 0 | Never build on the controller |
Configuration as Code (JCasC) YAML | Controller config in Git |
plugins.txt + jenkins-plugin-cli | Pinned plugin set, baked into the image |
Back up JENKINS_HOME (jobs, credentials, config) | Restore path for the controller |