          Continuous building and publishing is an essential step in our day-to-day work. Currently, most companies use Jenkins clusters to build the CI/CD process that meets the needs, and the continuous publishing process of Jenkins can better interface with Kubernetes clusters, better exert its deployment advantages, this document can specify users to integrate Jenkins publishing process with CCE clusters.

          1. Set Jenkins Storage Directory

          All applications under the Kubenetes environment are Dockerimage, and to keep the data secure in the event of an application restart, the data directory of Jenkins shall be persisted in the storage. Here, one of the much persistent storage provided by CCE to facilitate to maintain consistency of application data for node activiation to escape data under the Kubernetes environment. Of course, you can choose to store locally, but in order to maintain the consistency of the application data, it is required to fix Jenkins to a certain Kubernetes node.

          Refer to the Section Container Engine CCE – Operation Guide – Storage Management https://cloud.baidu.com/doc/CCE/s/mjxppo8qq

          Select any way to deploy and generate PVC and record the PVC name.

          2. Deploy Jenkins Server to Kubernetes


          apiVersion: v1
          kind: ServiceAccount
            name: jenkins
          kind: Role
          apiVersion: rbac.authorization.k8s.io/v1beta1
            name: jenkins
          - apiGroups: [""]
            resources: ["pods"]
            verbs: ["create","delete","get","list","patch","update","watch"]
          - apiGroups: [""]
            resources: ["pods/exec"]
            verbs: ["create","delete","get","list","patch","update","watch"]
          - apiGroups: [""]
            resources: ["pods/log"]
            verbs: ["get","list","watch"]
          - apiGroups: [""]
            resources: ["events"]
            verbs: ["watch"]
          - apiGroups: [""]
            resources: ["secrets"]
            verbs: ["get"]
          apiVersion: rbac.authorization.k8s.io/v1beta1
          kind: RoleBinding
            name: jenkins
            apiGroup: rbac.authorization.k8s.io
            kind: Role
            name: jenkins
          - kind: ServiceAccount
            name: jenkins


          # jenkins
          apiVersion: apps/v1
          kind: StatefulSet
            name: jenkins
              name: jenkins
                name: jenkins
            serviceName: jenkins
            replicas: 1
              type: RollingUpdate
                name: jenkins
                  name: jenkins
                terminationGracePeriodSeconds: 10
                serviceAccountName: jenkins
                  - name: jenkins
                    image: hub.baidubce.com/jpaas-public/jenkins-github:v0
                    imagePullPolicy: Always
                      - containerPort: 8080
                      - containerPort: 50000
                        cpu: 1
                        memory: 1Gi
                        cpu: 0.5
                        memory: 500Mi
                      - name: LIMITS_MEMORY
                            resource: limits.memory
                            divisor: 1Mi
                      - name: JAVA_OPTS
                        # value: -XX:+UnlockExperimentalVMOptions -XX:+UseCGroupMemoryLimitForHeap -XX:MaxRAMFraction=1 -XshowSettings:vm -Dhudson.slaves.NodeProvisioner.initialDelay=0 -Dhudson.slaves.NodeProvisioner.MARGIN=50 -Dhudson.slaves.NodeProvisioner.MARGIN0=0.85
                        value: -Xmx$(LIMITS_MEMORY)m -XshowSettings:vm -Dhudson.slaves.NodeProvisioner.initialDelay=0 -Dhudson.slaves.NodeProvisioner.MARGIN=50 -Dhudson.slaves.NodeProvisioner.MARGIN0=0.85
                      - name: jenkins-home
                        mountPath: /var/jenkins_home
                        path: /login
                        port: 8080
                      initialDelaySeconds: 60
                      timeoutSeconds: 5
                      failureThreshold: 12 # ~2 minutes
                        path: /login
                        port: 8080
                      initialDelaySeconds: 60
                      timeoutSeconds: 5
                      failureThreshold: 12 # ~2 minutes
                  fsGroup: 1000
                  - name: jenkins-home
                      claimName: myjenkinspvc
          apiVersion: v1
          kind: Service
            name: jenkins
            type: NodePort
              name: jenkins
            # ensure the client ip is propagated to avoid the invalid crumb issue when using LoadBalancer (k8s >=1.7)
            #externalTrafficPolicy: Local
                name: http
                port: 80
                targetPort: 8080
                protocol: TCP
                name: agent
                port: 50000
                protocol: TCP


          • The field claimName in jenkins.yaml file needs changing to 1. Set the PVC name generated in Jenkins storage directory

          Execute the following commands in CCE Kubernetes clusters

          kubectl create -f service-account.yaml
          kubectl create -f jenkins.yaml

          Generating the following contents in turn represents the success of the creation


          3. Initialize the Configuration ofJenkins

          At this point, the Jenkins Master service has been deployed and activated, and the port is exposed to80:30427, 50000:31598, at which point you can access Jenkins page by opening http:// <Node_IP>:30427 through the browser.

          Complete the initialization plug-in installation of Jenkins on the browser, configure the account information of administrator, which is ignored here, and the interface after the initialization is shown as follows:


          • During the initialization, when you are required to enter the initial passward for /var/jenkins_home/secret/initialAdminPassword, you can read it by mounting to PVC persistent directory directly, or access it inside the container directly.

          kubectl exec -it jenkins-0 cat /var/jenkins_home/secrets/initialAdminPassword

          4. Jenkins Installs the Plug-in Kubernetes Plugin

          The administrator logs in the Jenkins Master page and clicks on "System Management" - "Plug-in Management" - "Optional Plug-ins" - and "Kubernetes" to check the installation.

          Once installed, click "System Management" - "System Setting" - "Add a New Cloud" - select "Kubernetes" and enter the Kubernetes and Jenkins configuration information.


            1. Name defaults tokubernetes, or can be modified to a different name; if you modify it here, you shall specify the parameter cloud of podTemplate() as its corresponding name when executing Job in the following; otherwise, you cannot find it, and cloud defaults to: kubernetes
            1. Enter https://kubernetes.default in Kubernetes URL, and enter the DNS records corresponding to Kubernetes Service, you can resolve the Cluster IP of the Service through the DNS record.

          Note Or, you can enter the complete DNS record of https://kubernetes.default.svc.cluster.local, as it shall meet the name mode of <svc_name>.<namespace_name>.svc.cluster.local, or enter the address https://<ClusterIP>:<Ports> of external Kubernetes directly.

            1. Enter http://jenkins.default at Jenkins URL, which is to use the DNS record corresponding to Jenkins Service as similar to the above, or use the mode of http://<ClusterIP>:<Node_Port> at the same time. For example, we can enter http://x.x.x.x:30427 here, and 30427 here is the NodePort exposed outside.
            1. Once configured, click "Test Connection" button to test if t is possible to connect Kubernetes, and if Connection test successful appears, it indicates that the connection succeeded, without problem in configuration

          5. Non-clustered Jenkins Connects to Kubernetes

          5.1. Enter Kubernetes configuration contents

          Take a kubeconfig file as an example

          apiVersion: v1
          - cluster:
            name: kubernetes
          - context:
              cluster: kubernetes
              user: kubernetes-admin
            name: kubernetes-admin@kubernetes
          current-context: kubernetes-admin@kubernetes
          kind: Config
          preferences: {}
          - name: kubernetes-admin
          • No. 1: Remain unchanged, it defaults to kubernetes
          • No. 2: Enter the address of clusters.cluster.server in the kubeconfig file
          • No. 3: Access the content of certificate-authority-data in the kubeconfig file, and convert it into a base64 encoded file
          ecbo xxx | base64 -d > /opt/crt/ca.crt

          Enter the content of ca.crt into the key colume of Kubernetes service certificate of jenkins kubernetes, and access the content of client-certificate-data and client-key-data in kubeconfig, and convert it into a base64 encoded file

          echo xxxxx== | base64 -d > /opt/crt/client.crt
          echo xxxxx== | base64 -d > /opt/crt/client.key
          # Generate client p12 authentication file cert.pfx, and download to local
          openssl pkcs12 -export -out /opt/crt/cert.pfx -inkey /opt/crt/client.key -in /opt/crt/client.crt -certfile /opt/crt/ca.crt
          Enter Export Password:
          Verifying - Enter Export Password:
          # Note: Custom a password and remember it
          • No. 4: Add credentials in the cloud kubernetes

          Note Upload certificate generated last time and downloaded locally to cert.pfx file, enter the key when adding Password value to generate the cert.pfx file, and select the certificate in No. 4.

          Finally, click the connection test: Its appearance indicates the success of connection.

          6. Test and Verification

          Well, install Jenkins Master through Kubernetes and configure the connection, and next, we can configure a Job to test if the publish will succeed.

          6.1. pipeline type support

          Create a Job of Pipeline type, and name it as my-k8s-jenkins-pipeline, and enter a simple testing script at the Pipeline script as follows:

          def label = "mypod-${UUID.randomUUID().toString()}"
          podTemplate(label: label, cloud: 'kubernetes') {
              node(label) {
                  stage('Run shell') {
                      sh 'sleep 130s'
                      sh 'echo hello world.'

          To execute the build, you can see a build task in the Build Queue at this point, and after click immediately for building, it will publish successfully after the success of initialization. We can see the entire automatic creation and deletion process through the kubectl command line.

          Note: The image used in the example will time out if dragged directly, and the following command can be used to execute in advance in the machine.

          docker pull hub.baidubce.com/jpaas-public/jenkins/jnlp-slave:v0
          docker tag hub.baidubce.com/jpaas-public/jenkins/jnlp-slave:v0 jenkins/jnlp-slave:4.0.1-1
