Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 2.580.1 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 8443/tcp |
|---|
| Category | Developer tools |
|---|
| Upstream licence | MIT |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@PUBLIC_IP
- On first boot the image creates the administrator account and an instance-unique TLS keystore, then starts Jenkins (the first start takes a minute or two). Check both units:
sudo systemctl status jenkins-firstboot jenkins
- Read the administrator password generated uniquely for this instance (root only):
sudo cat /root/.jenkins_default_credentials
- Jenkins serves HTTPS only, on 127.0.0.1:8443 as shipped. Open it from your workstation through an SSH tunnel:
ssh -L 8443:127.0.0.1:8443 opc@PUBLIC_IP
then browse to https://localhost:8443 and sign in as admin. Change the password, and create API tokens for scripts, at https://localhost:8443/me/security/
- Call the REST API with an API token (requests authenticated by a token need no CSRF crumb):
sudo curl -s --cacert /etc/jenkins/tls/cert.pem -u admin:API_TOKEN https://127.0.0.1:8443/api/json
- To serve your team directly instead of through the tunnel, rebind and restart:
sudo sed -i 's/^JENKINS_LISTEN_ADDRESS=127.0.0.1$/JENKINS_LISTEN_ADDRESS=0.0.0.0/' /etc/jenkins/jenkins.env && sudo systemctl restart jenkins
Then set Manage Jenkins, System, Jenkins URL to https://PRIVATE_IP:8443/ (or your DNS name). Clients verify the server with /etc/jenkins/tls/cert.pem (its SAN lists the instance's private IPs).
- Port 8443 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR; never expose it to the internet. Hardened defaults: sign-up and anonymous read are off, CSRF protection is on, the inbound TCP agent port is disabled (connect agents over WebSocket on 8443), and usage statistics are off (hudson.model.UsageStatistics.disabled).
- Jobs, credentials and plugins live in /var/lib/jenkins; for anything beyond evaluation place it on a block volume. Builds run on the built-in node out of the box; for production add agents and set the built-in node's executors to 0.
The image is CVE-patched at build time. Apply ongoing operating system updates with:
sudo dnf -y update
Jenkins and its pinned plugins come from upstream releases: update plugins under Manage Jenkins, Plugins, and refresh Jenkins itself by launching a newer image version of this listing.
What the image provides
- Jenkins 2.580.1 LTS from the project's official release, its SHA-256 digest pinned and verified at build time, running on OpenJDK 21 from Oracle Linux 9 AppStream as a dedicated unprivileged systemd service with a read-only system view and write access only to its home and cache directories.
- A curated, version-pinned plugin set — Pipeline (declarative and scripted), Git, Credentials and Matrix Authorization, with their dependencies — every plugin verified against the Jenkins update center's SHA-256 digest at build time.
- No setup wizard and no shared default credential: the administrator account is created uniquely for this instance at first boot and surfaced to the operator over SSH; public sign-up and anonymous read access are off, and CSRF protection is on.
- Encryption in transit: HTTPS only, on port 8443, with an instance-unique certificate generated at first boot; plain HTTP is disabled.
- Reduced attack surface and privacy by default: the inbound TCP agent port is disabled (agents connect over WebSocket on the HTTPS port) and usage statistics reporting to the Jenkins project is off.
- Safe-by-default network posture: Jenkins listens on loopback until you expose it with one documented command; security hardening aligned to the Oracle Cloud Marketplace image standards — SELinux enforcing, host firewall default-deny with only SSH and 8443 permitted, no account with a usable password, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Jenkins® is a registered trademark of LF Charities Inc. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by LF Charities Inc. or the Jenkins project.