Prerequisites
- An account on the target cloud with permission to launch VM instances (no special IAM roles are required by this product unless stated below — IAM required: none).
- An SSH key pair registered in the target cloud (all access is key-only; password SSH is disabled).
- Instance size ≥ 4 vCPU (pricing floor; 8 vCPU recommended).
- No internet access or external dependency is required at deploy time — the image is self-contained.
Google Cloud
- Deploy from the Google Cloud Marketplace listing (or its deployment package): at least 4 vCPU and 16 GB RAM (default n2-standard-8, 50 GB balanced boot disk). Leave the tcp:8080 firewall toggle off for now.
Expected result The VM DEPLOYMENT-vm is RUNNING; on it, curl http://127.0.0.1:8080/login answers 200. - Tunnel port 8080, unlock Jenkins with /var/lib/jenkins/secrets/initialAdminPassword and finish the setup wizard.
Expected result You are signed in as the administrator you created. - To serve users on your VPC: put HTTPS in front of 127.0.0.1:8080, or set JENKINS_LISTEN_ADDRESS in /etc/jenkins/jenkins.env and allow tcp:8080 from your users' range only.
Expected result Users in that range reach Jenkins; nothing else can.
Validate
curl -s -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8080/login → 200
First boot: Jenkins generates its unlock password, keys and instance identity on its first start; jenkins-verify-firstboot.service then proves the unlock password signs in as admin, a wrong one gets 401 and anonymous access 403, the version is 2.580.1, every pinned plugin is active at its pinned version and every Jenkins listener is loopback-only, and writes /var/lib/dca-firstboot/jenkins.verified.
First login / credentials
- Connect with OS Login and forward the UI: gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap -- -L 8080:127.0.0.1:8080 (reading the unlock password needs sudo, i.e. roles/compute.osAdminLogin).
- Read the unlock password Jenkins generated on this VM: sudo cat /var/lib/jenkins/secrets/initialAdminPassword.
- Open http://localhost:8080/, paste it into Unlock Jenkins, choose plugins (see Configuration: some suggested plugins are held back on purpose), create your administrator and set the Jenkins URL.
Secure it
- Restrict SSH (22) to your own IP range in the cloud firewall/security group.
- Open application ports only per the ports table — closed-by-default is deliberate.
- Volume encryption: use your cloud's native volume encryption (enabled by default on most accounts); the image adds no proprietary encryption layer.
Costs & quotas
Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed
by your cloud at its standard rates. The recommended size fits default service quotas in most accounts —
if you scale out, review your cloud's quota console before launch.
Next: configuration · troubleshooting · security notes
Jenkins® is a registered trademark of LF Charities Inc.