Cheat Sheets / CI/CD & GitOps

Jenkins cheat sheet

63 commands from every lesson of Jenkins — Level by Level, on one page.

01 · Jenkins architecture and installation

Run Jenkins

docker run -d --name jenkins -p 8080:8080 -p 50000:50000 -v jenkins_home:/var/jenkins_home jenkins/jenkins:lts-jdk21Jenkins LTS in Docker with a persistent volume
docker exec jenkins cat /var/jenkins_home/secrets/initialAdminPasswordPassword for the setup wizard
helm repo add jenkins https://charts.jenkins.io && helm repo updateAdd the official Helm chart repository
helm install jenkins jenkins/jenkins -n jenkins --create-namespace -f values.yamlInstall on Kubernetes
kubectl -n jenkins port-forward svc/jenkins 8080:8080Reach it locally

Look around

curl -s http://localhost:8080/api/json?pretty=trueJenkins REST API (authenticate for most data)
http://localhost:8080/manage/systemInfoJava, system properties, environment
java -jar jenkins-cli.jar -s http://localhost:8080/ -auth user:token list-pluginsList plugins from the CLI

02 · Declarative pipelines

Building blocks

pipeline { agent any; stages { stage('Build') { steps { sh 'make' } } } }The minimum declarative pipeline
when { branch 'main' }Run a stage only on main
post { always { junit 'reports/*.xml' } failure { ... } }Always publish tests; act on failure
options { timeout(time: 30, unit: 'MINUTES'); disableConcurrentBuilds() }Guard rails for the whole pipeline
parallel { stage('Unit') {...} stage('Lint') {...} }Run stages side by side
input message: 'Deploy to prod?', submitter: 'release-managers'Manual approval gate

Credentials

environment { REG = credentials('registry-creds') }Username/password → REG_USR and REG_PSW, masked in logs
withCredentials([string(credentialsId: 'api-token', variable: 'TOKEN')]) { sh 'curl -H "Authorization: Bearer $TOKEN" ...' }Scoped secret for one block (single quotes!)

Check before you commit

curl -X POST -F "jenkinsfile=<Jenkinsfile" -u user:token https://jenkins.example.com/pipeline-model-converter/validateValidate a Jenkinsfile's syntax

03 · Build, test and publish images

Build and push (inside an agent container)

buildctl-daemonless.sh build --frontend dockerfile.v0 --local context=. --local dockerfile=. --output type=image,name=$IMAGE:$TAG,push=trueRootless BuildKit build and push
buildah bud -t $IMAGE:$TAG . && buildah push $IMAGE:$TAGBuild and push with Buildah
trivy image --exit-code 1 --severity CRITICAL $IMAGE:$TAGFail the build on critical CVEs
crane digest $IMAGE:$TAGGet the pushed image's digest

Reports and artifacts

junit 'reports/**/*.xml'Test results with trends in the Jenkins UI
archiveArtifacts artifacts: 'dist/*.tgz', fingerprint: trueKeep build outputs, traceable by fingerprint
recordIssues tools: [spotBugs()]Static-analysis results (Warnings NG plugin)

04 · Multibranch pipelines and webhooks

Conditions in a multibranch Jenkinsfile

when { changeRequest() }Only for pull-request builds
when { branch 'main' }Only for main
when { buildingTag() }Only when building a tag
when { tag pattern: 'v\\d+\\.\\d+\\.\\d+', comparator: 'REGEXP' }Only for semantic-version tags
env.CHANGE_ID / env.CHANGE_TARGET / env.BRANCH_NAMEPR number, PR target branch, branch name

Webhooks

https://jenkins.example.com/github-webhook/GitHub webhook endpoint (GitHub plugin)
https://jenkins.example.com/multibranch-webhook-trigger/invoke?token=<token>Generic trigger for other Git servers (Multibranch Scan Webhook Trigger plugin)

05 · Shared libraries

Using a library

@Library('platform-lib@v2.3.0') _Load a specific library version (top of the Jenkinsfile)
standardServicePipeline(app: 'orders-api')Call a whole pipeline defined in vars/standardServicePipeline.groovy
buildImage(name: 'orders-api')Call a step defined in vars/buildImage.groovy
def cfg = libraryResource 'templates/buildkit-pod.yaml'Load a file from resources/

Library layout

vars/<name>.groovyGlobal steps/variables, one file per step, with a call() method
src/com/acme/ci/Versioning.groovyClasses for more complex logic
resources/Non-Groovy files: pod templates, scripts, config
test/Unit tests (JenkinsPipelineUnit)

06 · Agents on Kubernetes

In the Jenkinsfile

agent { kubernetes { yaml '''...pod spec...''' } }Define the agent pod inline
agent { kubernetes { yamlFile 'ci/pod.yaml' } }Pod spec from a file in the repo
agent { kubernetes { inheritFrom 'python-311' } }Use a pod template defined centrally
container('node') { sh 'npm ci' }Run steps in a specific container of the pod

Troubleshoot

kubectl -n jenkins-agents get pods -wWatch agent pods being created and removed
kubectl -n jenkins-agents describe pod <agent-pod>Why it's Pending or failing (resources, image pull)
kubectl -n jenkins-agents logs <agent-pod> -c jnlpAgent connection logs

07 · Security and operations

As code

CASC_JENKINS_CONFIG=/var/jenkins_home/casc_configsWhere JCasC reads its YAML
https://jenkins.example.com/manage/configuration-as-code/View, export and reload JCasC
jenkins-plugin-cli --plugin-file plugins.txtInstall exactly the pinned plugin list (in the image build)
jenkins-plugin-cli --plugin-file plugins.txt --available-updates --output txtWhat could be updated

Operate

https://jenkins.example.com/manage/pluginManager/Plugin versions and security warnings
kubectl -n jenkins exec jenkins-0 -- du -sh /var/jenkins_home/jobsWhere the disk goes
https://jenkins.example.com/manage/scriptApproval/Pending script approvals (review carefully)
https://jenkins.example.com/safeRestartRestart after running builds finish

08 · Jenkins in the real world

Jenkinsfile

pipeline { agent … stages { stage('x') { steps { … } } } post { … } }Declarative skeleton
options { timeout(time: 30, unit: 'MINUTES'); buildDiscarder(logRotator(numToKeepStr: '30')) }Timeouts and build retention
withCredentials([string(credentialsId: 'api-token', variable: 'TOKEN')]) { sh 'use-token' }Credentials binding (masked in logs)
@Library('platform-lib@v2') _Load a versioned shared library
agent { kubernetes { yaml '''…pod spec…''' } }Ephemeral pod agent (Kubernetes plugin)

Operating

Built-in node executors: 0Never build on the controller
Configuration as Code (JCasC) YAMLController config in Git
plugins.txt + jenkins-plugin-cliPinned plugin set, baked into the image
Back up JENKINS_HOME (jobs, credentials, config)Restore path for the controller