Home / Docs / DCA Hardened CI Server — for Jenkins® / Security
| Port | Purpose | State |
|---|---|---|
| 22 | SSH — key-only, OS Login (IAM); the deployment package adds no SSH rule | your VPC's firewall rules |
| 8080 | Jenkins web UI and API — bound to 127.0.0.1 (listen address in /etc/jenkins/jenkins.env) | customer-must-open (config + firewall toggle) |
"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.
| We maintain | The hardened image: package selection, hardening baseline, CVE rebuilds, listing freshness, and these docs. |
|---|---|
| You control | The running instance: OS patching between image versions, network exposure, IAM, data, and backups. |
| Your cloud provides | Physical/hypervisor security, marketplace billing, and the firewall primitives this design relies on. |
Jenkins® is a registered trademark of LF Charities Inc.