Skip to main content
Version: 3.6.x

Login Credentials

Default credential information is available on this page.

Jenkins Administrator Credentials​

The default username and password for the Jenkins administrator are as follows:

  • User: admin
  • Password: El4stic123

Change the Jenkins Administrator Credentials​

In CloudOps for Kubernetes release 3.2.x or higher, the Jenkins administration username and password can be controlled by variables in your docker-compose.override.yml file.

  1. Variable TF_VAR_jenkins_admin_username can be used to modify the administration user's username.
  2. Variable TF_VAR_jenkins_admin_password can be used to modify the administration user's password.

Follow the below procedure to update either the username or password:

  1. Identify a maintenance window during which no Jenkins jobs will be running to apply the change. The Jenkins server pod will be restarted when the change is applied, causing any running jobs to fail.
  2. Obtain the most recent copy of the docker-compose.override.yml file for your CloudOps for Kubernetes cluster.
  3. Modify one or both of the TF_VAR_jenkins_admin_username and TF_VAR_jenkins_admin_password variables. If the desired variable does not exist in your copy of docker-compose.override.yml, then you can add it. The values need to be specified in plain-text.
  4. (Optional) Set variable TF_VAR_rebuild_nodegroups to false to avoid unnecessary work.
  5. Follow the procedure described in Updating Cluster Configuration to apply the change.

Jenkins Non-Administrator Credentials​

In CloudOps for Kubernetes release 3.5.x or higher, additional Jenkins users with different levels of non-administrator privileges are available. The non-administrator accounts should be used by most users, depending on the level of job access they require. These accounts cannot reconfigure Jenkins in any way.

Default User NameDefault PasswordDescription
poweruserPoweruser123Power User can view, run, and configure all jobs, and can read all build output
developerDeveloper123Developer User can view and run all jobs, and can read all build output
viewerViewer123Viewer User can view all jobs, and can read all build output

Change the Jenkins Non-Administrator Credentials​

The usernames and passwords for Jenkins non-administrator users can be controlled by variables in your docker-compose.override.yml file.

Username VariablePassword Variable
TF_VAR_jenkins_poweruser_usernameTF_VAR_jenkins_poweruser_password
TF_VAR_jenkins_developer_usernameTF_VAR_jenkins_developer_password
TF_VAR_jenkins_viewer_usernameTF_VAR_jenkins_viewer_password

Follow the below procedure to update either the username or password:

  1. Identify a maintenance window during which no Jenkins jobs will be running to apply the change. The Jenkins server pod will be restarted when the change is applied, causing any running jobs to fail.
  2. Obtain the most recent copy of the docker-compose.override.yml file for your CloudOps for Kubernetes cluster.
  3. Modify one or both of the Username and Password variables found in the table above. If the desired variable does not exist in your copy of docker-compose.override.yml, then you can add it. The values need to be specified in plain-text.
  4. (Optional) Set variable TF_VAR_rebuild_nodegroups to false to avoid unnecessary work.
  5. Follow the procedure described in Updating Cluster Configuration to apply the change.

Jenkins Authorization Configuration​

In CloudOps for Kubernetes release 3.6.0 or higher, the Jenkins authorization strategy configuration is sourced from an external file. This makes it easier to switch or customize authorization without modifying the out-of-the-box configuration files.

The authorization configuration file is selected by setting variable TF_VAR_jenkins_authorization_configuration_file in your docker-compose.override.yml file.

The following authorization configuration files are available out of the box:

  • default-role-based-authorization.yaml: the default configuration. This is equivalent to the previously provided matrix-based approach.
  • default-matrix-authorization.yaml: the legacy matrix-based authorization strategy that was provided in release 3.5.x.
important

When the Jenkins controller starts, by default CloudOps for Kubernetes attempts to combine the authorization configuration already in Jenkins with the configuration defined in the file you select using TF_VAR_jenkins_authorization_configuration_file in docker-compose.override.yml. Roles and permission assignments from that file are applied; assignments you added or changed in the Jenkins web interface are kept unless you choose a full reset (below).

This merge works when your existing authorization configuration is based on the approach defined in the selected configuration file, and when the configuration in the file is based on one of the approaches in the provided authorization files (default-matrix-authorization.yaml, default-role-based-authorization.yaml, saml-role-based-authorization.yaml). More complex authorization configurations may not merge automatically; plan a maintenance window to test and validate the behaviour with your configuration. Make a note of the existing configuration before testing.

Whether merging is enabled is controlled by the TF_VAR_jenkins_retain_manual_authorization parameter in docker-compose.override.yml, which defaults to "true". When it is set to "true", the Jenkins startup process will always attempt to merge existing authorization configuration with that defined in the selected file. Set it to "false" to reset the configuration to that defined in the selected file. Follow the procedure in Updating Cluster Configuration to apply configuration changes.

To switch approaches, or to replace Jenkins authorization entirely with only what is defined in the configuration file, set TF_VAR_jenkins_retain_manual_authorization to "false" in docker-compose.override.yml and apply the change. Setting TF_VAR_jenkins_overwrite_config to "true" also resets authorization to match the configuration file.

Removing a user, role, or assignment from the authorization file does not remove it from Jenkins while merge behaviour is enabled. Use one of the reset options above if you need Jenkins to match the file exactly.

Change the Jenkins Authorization Configuration​

Follow the below procedure to update the authorization configuration:

  1. Identify a maintenance window during which no Jenkins jobs will be running to apply the change. The Jenkins server pod will be restarted when the change is applied, causing any running jobs to fail.
  2. Obtain the most recent copy of the docker-compose.override.yml file for your CloudOps for Kubernetes cluster.
  3. Set variable TF_VAR_jenkins_authorization_configuration_file to the authorization configuration file you want to use. If the variable does not exist in your copy of docker-compose.override.yml, then you can add it.
  4. (Optional) Set variable TF_VAR_rebuild_nodegroups to false to avoid unnecessary work.
  5. Follow the procedure described in Updating Cluster Configuration to apply the change.

Use a Custom Authorization Configuration​

You can create and use a custom authorization configuration file without modifying the out-of-the-box authorization files.

  1. Create a custom authorization configuration file suitable for Jenkins authorization strategy configuration-as-code. You can use bootstrap/terraform/config/jenkins-authorization-config/default-role-based-authorization.yaml as a template.
  2. Save the file under bootstrap/terraform/config/jenkins-authorization-config/ in your CloudOps for Kubernetes project.
  3. Set variable TF_VAR_jenkins_authorization_configuration_file to your custom file name (for example, custom-authorization.yaml) in your docker-compose.override.yml file.
  4. Follow the procedure described in Updating Cluster Configuration to apply the change.

Nexus Credentials​

Nexus is the Maven artifact repository manager used in CloudOps for Kubernetes. The Nexus credentials are given below, and are as set in Sonatype’s official Nexus 2 Docker image:

  • User: admin
  • Password: admin123