Level 1 — Foundations · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Run Jenkins
docker run -d --name jenkins -p 8080:8080 -p 50000:50000 -v jenkins_home:/var/jenkins_home jenkins/jenkins:lts-jdk21 | Jenkins LTS in Docker with a persistent volume |
docker exec jenkins cat /var/jenkins_home/secrets/initialAdminPassword | Password for the setup wizard |
helm repo add jenkins https://charts.jenkins.io && helm repo update | Add the official Helm chart repository |
helm install jenkins jenkins/jenkins -n jenkins --create-namespace -f values.yaml | Install on Kubernetes |
kubectl -n jenkins port-forward svc/jenkins 8080:8080 | Reach it locally |
Look around
curl -s http://localhost:8080/api/json?pretty=true | Jenkins REST API (authenticate for most data) |
http://localhost:8080/manage/systemInfo | Java, system properties, environment |
java -jar jenkins-cli.jar -s http://localhost:8080/ -auth user:token list-plugins | List plugins from the CLI |
Building blocks
pipeline { agent any; stages { stage('Build') { steps { sh 'make' } } } } | The minimum declarative pipeline |
when { branch 'main' } | Run a stage only on main |
post { always { junit 'reports/*.xml' } failure { ... } } | Always publish tests; act on failure |
options { timeout(time: 30, unit: 'MINUTES'); disableConcurrentBuilds() } | Guard rails for the whole pipeline |
parallel { stage('Unit') {...} stage('Lint') {...} } | Run stages side by side |
input message: 'Deploy to prod?', submitter: 'release-managers' | Manual approval gate |
Credentials
environment { REG = credentials('registry-creds') } | Username/password → REG_USR and REG_PSW, masked in logs |
withCredentials([string(credentialsId: 'api-token', variable: 'TOKEN')]) { sh 'curl -H "Authorization: Bearer $TOKEN" ...' } | Scoped secret for one block (single quotes!) |
Check before you commit
curl -X POST -F "jenkinsfile=<Jenkinsfile" -u user:token https://jenkins.example.com/pipeline-model-converter/validate | Validate a Jenkinsfile's syntax |
Build and push (inside an agent container)
buildctl-daemonless.sh build --frontend dockerfile.v0 --local context=. --local dockerfile=. --output type=image,name=$IMAGE:$TAG,push=true | Rootless BuildKit build and push |
buildah bud -t $IMAGE:$TAG . && buildah push $IMAGE:$TAG | Build and push with Buildah |
trivy image --exit-code 1 --severity CRITICAL $IMAGE:$TAG | Fail the build on critical CVEs |
crane digest $IMAGE:$TAG | Get the pushed image's digest |
Reports and artifacts
junit 'reports/**/*.xml' | Test results with trends in the Jenkins UI |
archiveArtifacts artifacts: 'dist/*.tgz', fingerprint: true | Keep build outputs, traceable by fingerprint |
recordIssues tools: [spotBugs()] | Static-analysis results (Warnings NG plugin) |