Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened CI Server — for Jenkins®

DCA Hardened CI Server — for Jenkins® — documentation & support card

Jenkins® LTS 2.580 with 70 pinned, checksum-verified plugins, the web UI on loopback, and the setup wizard kept: the unlock password and keys are generated on each VM's first start.

Install Configure Troubleshoot Security

At a glance

TypeHardened VM image
Upstream / licenseJenkins (MIT) — see licenses
VersionJenkins® LTS 2.580.1 (upstream jenkins.war, sha256- and signature-verified) on Ubuntu's OpenJDK 21, Ubuntu 24.04 LTS, with 70 pinned plugins; Google Cloud image built 2026-10-07. Exact image version: see the listing. Current builds: release notes.
Architecturex86-64
SizingAny current-generation instance with ≥ 4 vCPU (pay-as-you-go floor); 8 vCPU recommended for production.

Marketplaces

Network ports

PortPurposeState
22SSH — key-only, OS Login (IAM); the deployment package adds no SSH ruleyour VPC's firewall rules
8080Jenkins web UI and API — bound to 127.0.0.1 (listen address in /etc/jenkins/jenkins.env)customer-must-open (config + firewall toggle)

"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.

Access & credentials

No shared or default credentials are included in this image. Access uses the SSH key you supply at launch; any application credential is generated uniquely on your instance at first boot and stored only there — we never know it.

Log in: SSH in with OS Login and forward port 8080 (gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap -- -L 8080:127.0.0.1:8080), then open http://localhost:8080/ and unlock Jenkins.

The setup wizard's unlock password, which Jenkins itself generates on its first start on THIS VM in /var/lib/jenkins/secrets/initialAdminPassword (owned by jenkins, not world-readable), together with secret.key, secrets/master.key and the instance identity. JENKINS_HOME ships with nothing but the pinned plugin archives.

sudo cat /var/lib/jenkins/secrets/initialAdminPassword

Rotation: Finish the setup wizard: create your own administrator (Jenkins then deletes initialAdminPassword). Afterwards manage users and their API tokens from Manage Jenkins.

Step-by-step: first login / credentials.

Data & dependencies

Operate

Known limitations

Single controller with no agents configured; Declarative Pipeline and the other held-back plugins are not preinstalled (see Configuration). Plain HTTP on loopback until you put HTTPS in front.

Support

Email support@dcassociatesgroup.com — first response within 1 business day (US Eastern), most tickets same-day. To escalate an open ticket, reply "ESCALATE"; it is reviewed by the founder within 1 business day. Security reports: vulnerability disclosure.

Privacy: policy · Terms: terms · Security practices: security & trust · Vulnerability reports: disclosure policy

Jenkins® is a registered trademark of LF Charities Inc.