Jenkins — Level by Level›Level 3 · Cheat sheet & self-check

Level 3 — Operating Jenkins · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

07 · Security and operations

As code

CASC_JENKINS_CONFIG=/var/jenkins_home/casc_configsWhere JCasC reads its YAML
https://jenkins.example.com/manage/configuration-as-code/View, export and reload JCasC
jenkins-plugin-cli --plugin-file plugins.txtInstall exactly the pinned plugin list (in the image build)
jenkins-plugin-cli --plugin-file plugins.txt --available-updates --output txtWhat could be updated

Operate

https://jenkins.example.com/manage/pluginManager/Plugin versions and security warnings
kubectl -n jenkins exec jenkins-0 -- du -sh /var/jenkins_home/jobsWhere the disk goes
https://jenkins.example.com/manage/scriptApproval/Pending script approvals (review carefully)
https://jenkins.example.com/safeRestartRestart after running builds finish

08 · Jenkins in the real world

Jenkinsfile

pipeline { agent … stages { stage('x') { steps { … } } } post { … } }Declarative skeleton
options { timeout(time: 30, unit: 'MINUTES'); buildDiscarder(logRotator(numToKeepStr: '30')) }Timeouts and build retention
withCredentials([string(credentialsId: 'api-token', variable: 'TOKEN')]) { sh 'use-token' }Credentials binding (masked in logs)
@Library('platform-lib@v2') _Load a versioned shared library
agent { kubernetes { yaml '''…pod spec…''' } }Ephemeral pod agent (Kubernetes plugin)

Operating

Built-in node executors: 0Never build on the controller
Configuration as Code (JCasC) YAMLController config in Git
plugins.txt + jenkins-plugin-cliPinned plugin set, baked into the image
Back up JENKINS_HOME (jobs, credentials, config)Restore path for the controller