Manage Jenkins Credentials
You may occasionally need to add additional credentials to Jenkins. In the past, teams added credentials manually in the Jenkins web interface. The recommended way is now via the AWS Secrets Manager integration described in this page. This capability is included out-of-the-box in CloudOps for Kubernetes release 3.7.x and higher. If you add custom Jenkins credentials this way then those credentials will always be available.
Credentials that you may have added manually might eventually be lost if Jenkins ever needs to be rebuilt from the ground up. We recommend that you replace any manually added credentials using this new approach.
For more information about the Jenkins integration, see the AWS Secrets Manager Credentials Provider plugin and the plugin documentation.
Supported Credential Types
The AWS Secrets Manager credentials provider supports the following Jenkins credential types in CloudOps for Kubernetes:
| Jenkins credential type | Required AWS secret value | Required tags |
|---|---|---|
| SSH username with private key | The private key PEM in SecretString | jenkins:credentials:type=sshUserPrivateKey, jenkins:credentials:username=<username> |
| Username with password | The password in SecretString | jenkins:credentials:type=usernamePassword, jenkins:credentials:username=<username> |
| Secret text | The secret text in SecretString | jenkins:credentials:type=string |
The Secrets Manager secret name becomes the Jenkins credential ID. For example, a secret named ep-commerce-git-ssh is available in Jenkins as a credential with ID ep-commerce-git-ssh.
Use credential IDs that contain only letters, numbers, underscores, periods, and hyphens. Avoid spaces and special characters.
Add a Jenkins Credential in AWS Secrets Manager
You can create the secret in the AWS Management Console or with the AWS CLI. For the complete AWS procedure, see Create an AWS Secrets Manager secret.
Create a secret in the AWS Management Console
To create the secret in the AWS Management Console:
- Open the AWS Secrets Manager console in the same AWS Region as the CloudOps for Kubernetes cluster.
- Choose Store a new secret.
- For Secret type, choose Other type of secret.
- In Key/value pairs, choose the Plaintext tab.
- Remove the existing JSON example value and replace it with the desired credential value:
- For an SSH private key credential, enter the private key file contents, including the dashed lines at the top and bottom.
- For a username and password credential, enter the password.
- For a secret text credential, enter the secret text.
- Choose Next.
- For Secret name, enter the desired Jenkins credential ID.
- For Description, enter a very short description. This is what Jenkins will show in drop-down boxes when you select credentials.
- In Tags, add the required Jenkins credential tags from Supported Credential Types.
- For an SSH private key credential:
- Set
jenkins:credentials:typetosshUserPrivateKey. - Set the
jenkins:credentials:usernametag with the tag value set to the username (e.g.,gitfor most Git SSH keys).
- Set
- For a username and password credential:
- Set
jenkins:credentials:typetousernamePassword. - Set the
jenkins:credentials:usernametag with the tag value set to the username.
- Set
- For a secret text credential:
- Set
jenkins:credentials:typetostring.
- Set
- For an SSH private key credential:
- Choose Next.
- Keep automatic rotation disabled for this procedure, then choose Next.
- Review the secret details and choose Store.
Properly tagged credentials will quickly appear in the Jenkins credentials manager page, and be available for use.
Create a secret using the AWS CLI
The following examples show the AWS CLI commands for creating the supported secret types.
Create an SSH username with private key credential:
aws secretsmanager create-secret \
--name my-git-ssh-key \
--secret-string file://./id_rsa \
--tags \
Key=jenkins:credentials:type,Value=sshUserPrivateKey \
Key=jenkins:credentials:username,Value=git
Create a username with password credential:
aws secretsmanager create-secret \
--name my-username-password \
--secret-string "password value" \
--tags \
Key=jenkins:credentials:type,Value=usernamePassword \
Key=jenkins:credentials:username,Value=my-user
Create a secret text credential:
aws secretsmanager create-secret \
--name my-secret-text \
--secret-string "secret value" \
--tags Key=jenkins:credentials:type,Value=string
Properly tagged credentials will quickly appear in the Jenkins credentials manager page, and be available for use.
Use a Secrets Manager Credential in Jenkins Jobs
After Jenkins discovers a Secrets Manager credential, use the AWS secret name anywhere a Jenkins credential ID is requested.
Examples of job parameters that can use Secrets Manager credential IDs include:
epCommerceCredentialIddockerCredentialIdEP_COMMERCE_CONFIG_SSH_KEYEP_COMMERCE_CONFIG_GPG_KEY
Switch the Default Git Credential to Secrets Manager
In past releases you needed to set a volume map in your docker-compose.override.yml file to specify the value for the default Git credential. In release 3.6.x and higher bootstrap you can specify the key value by pointing at an AWS Secrets Manager secret. Switching to Secrets Manager is optional and recommended when you want the bootstrap Git credential to be managed in AWS.
-
Create an AWS Secrets Manager secret containing the Git SSH private key file contents, including the dashed lines at the top and bottom.
-
Ensure your bootstrap AWS user has permission to call
secretsmanager:GetSecretValuefor that secret. For more information, see Identity and Access Management (IAM) Permissions.- The bootstrap AWS user is controlled in your
docker-compose.override.ymlfile by the fieldTF_VAR_aws_access_key_id.
- The bootstrap AWS user is controlled in your
-
Set the following variables in
docker-compose.override.yml:TF_VAR_bootstrap_mode: "setup"TF_VAR_git_credential_secret_arn: "<secret-arn>" -
Remove the local Git SSH private key volume mount if it is no longer needed.
-
From the operations workstation, run
docker-compose up.
When TF_VAR_git_credential_secret_arn is set, the bootstrap container downloads the private key from Secrets Manager and uses it as the Git SSH credential for the bootstrap run.
Back Up Existing Jenkins Credentials to Secrets Manager
CloudOps for Kubernetes includes the backup-jenkins-credentials-to-sm Jenkins job. This job is a safety net to back up any manually added credentials. When it runs, the job finds any supported manually added credentials and backs them up to Secrets Manager secrets. These backups are available in Secrets Manager in case the manually added credentials are lost. These backups do not get automatically restored to Jenkins.
The backup job:
- Finds Jenkins-local system credentials.
- Checks if the credential has previously been backed up as
backup-<credentialId>. If it has, then it skips backing up that credential. - Creates backup secrets named
backup-<credentialId>. - Adds backup metadata tags such as
backup:credential:type,backup:credential:id, andbackup:credential:username. - Archives a
jenkins-credentials-backup-report.mdartifact with the result for each credential.
The backup job creates backup copies. It does not automatically update Jenkins job parameters or delete Jenkins-local credentials.