Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Jenkins

In Oracle review

DCA Hardened CI/CD Automation Server for Jenkins — Support & Quick Start

A hardened, CVE-patched virtual machine image running Jenkins® 2.580 LTS — the open-source automation server for continuous integration and continuous delivery (CI/CD) — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version2.580.1
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8443/tcp
CategoryDeveloper tools
Upstream licenceMIT
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. On first boot the image creates the administrator account and an instance-unique TLS keystore, then starts Jenkins (the first start takes a minute or two). Check both units:
    sudo systemctl status jenkins-firstboot jenkins
  3. Read the administrator password generated uniquely for this instance (root only):
    sudo cat /root/.jenkins_default_credentials
  4. Jenkins serves HTTPS only, on 127.0.0.1:8443 as shipped. Open it from your workstation through an SSH tunnel:
    ssh -L 8443:127.0.0.1:8443 opc@PUBLIC_IP
    then browse to https://localhost:8443 and sign in as admin. Change the password, and create API tokens for scripts, at https://localhost:8443/me/security/
  5. Call the REST API with an API token (requests authenticated by a token need no CSRF crumb):
    sudo curl -s --cacert /etc/jenkins/tls/cert.pem -u admin:API_TOKEN https://127.0.0.1:8443/api/json
  6. To serve your team directly instead of through the tunnel, rebind and restart:
    sudo sed -i 's/^JENKINS_LISTEN_ADDRESS=127.0.0.1$/JENKINS_LISTEN_ADDRESS=0.0.0.0/' /etc/jenkins/jenkins.env && sudo systemctl restart jenkins

    Then set Manage Jenkins, System, Jenkins URL to https://PRIVATE_IP:8443/ (or your DNS name). Clients verify the server with /etc/jenkins/tls/cert.pem (its SAN lists the instance's private IPs).

  7. Port 8443 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR; never expose it to the internet. Hardened defaults: sign-up and anonymous read are off, CSRF protection is on, the inbound TCP agent port is disabled (connect agents over WebSocket on 8443), and usage statistics are off (hudson.model.UsageStatistics.disabled).
  8. Jobs, credentials and plugins live in /var/lib/jenkins; for anything beyond evaluation place it on a block volume. Builds run on the built-in node out of the box; for production add agents and set the built-in node's executors to 0.

The image is CVE-patched at build time. Apply ongoing operating system updates with:

sudo dnf -y update

Jenkins and its pinned plugins come from upstream releases: update plugins under Manage Jenkins, Plugins, and refresh Jenkins itself by launching a newer image version of this listing.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Jenkins® is a registered trademark of LF Charities Inc. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by LF Charities Inc. or the Jenkins project.