Credentials & security
Never hardcode passwords, tokens, or API keys in a Jenkinsfile. Use the Credentials Store.
Adding credentials (recap)
- Manage Jenkins → Credentials → System → Global credentials
- Add Credentials → choose type → set a stable ID → OK
Credential types
| Type | Used for |
|---|---|
| Username & password | Docker Hub, Nexus, databases |
| Secret text | API tokens (Slack, etc.) |
| SSH Username with private key | SSH agents, Git over SSH, deploy hosts |
| Certificate | P12 / PKCS#12 |
| Secret file | .env, kubeconfig |
Using credentials in a Jenkinsfile
Username & password
withCredentials([usernamePassword(
credentialsId: 'dockerhub-credentials',
usernameVariable: 'DOCKER_USER',
passwordVariable: 'DOCKER_PASS'
)]) {
sh 'echo $DOCKER_PASS | docker login -u $DOCKER_USER --password-stdin'
}Secret text
withCredentials([string(
credentialsId: 'slack-token',
variable: 'SLACK_TOKEN'
)]) {
sh 'curl -H "Authorization: Bearer $SLACK_TOKEN" https://slack.com/api/chat.postMessage ...'
}SSH private key
withCredentials([sshUserPrivateKey(
credentialsId: 'prod-server-ssh',
keyFileVariable: 'SSH_KEY',
usernameVariable: 'SSH_USER'
)]) {
sh "ssh -i \$SSH_KEY \$SSH_USER@your-server.com 'docker pull my-app:latest && docker restart my-app'"
}Secret file
withCredentials([file(
credentialsId: 'production-env-file',
variable: 'ENV_FILE'
)]) {
sh 'cp $ENV_FILE .env'
sh 'docker run --env-file .env my-app:latest'
}Environment binding
pipeline {
environment {
DOCKER_CREDS = credentials('dockerhub-credentials')
// Creates DOCKER_CREDS_USR and DOCKER_CREDS_PSW
}
stages {
stage('Push') {
steps {
sh 'docker login -u $DOCKER_CREDS_USR -p $DOCKER_CREDS_PSW'
}
}
}
}Prefer withCredentials + --password-stdin over putting passwords on the CLI argv when possible.
Security best practices
- Never echo a secret — Jenkins masks known secrets in logs, but leaks still happen
- Use the most restrictive scope — prefer per-stage
withCredentialsover globalenvironmentbindings - Rotate credentials regularly — update the store without changing the Jenkinsfile ID
- Audit credential usage — Jenkins can show which jobs accessed which credentials
- Use folders — scope credentials to project folders for team separation
- Credential scope — Global vs folder-level; least privilege wins
Final CI/CD architecture
Developer
↓
GitHub
↓
Webhook
↓
Jenkins
↓
Multibranch Pipeline
↓
Build
↓
Test
↓
Docker Build
↓
Docker Hub
↓
Deploy
↓
Notification
Course mental map
Jenkins
├── Freestyle Jobs → Simple, UI-configured tasks
├── Pipelines → Code-defined in Jenkinsfile
│ ├── agent → Where it runs
│ ├── environment → Variables & secrets
│ ├── stages/stage → Logical phases
│ ├── steps → Actual commands
│ └── post → Cleanup & notifications
├── Multibranch Pipelines → Per-branch automation
│ ├── dev branch → Build + Test only
│ └── main/master → Full CI/CD + Deploy
├── Master–Agent → Distributed builds
│ ├── Master → Orchestrates
│ └── Agents → Execute
└── Credentials Store → Secrets management
What you completed
| Day | Main topics | Project |
|---|---|---|
| Day 1 | Jenkins + CI/CD + AWS + Docker + Freestyle | Project 1 |
| Day 2 | Triggers + Post-Build + Jenkinsfile + Pipeline | Project 2 |
| Day 3 | Webhook + Credentials + Docker CI/CD | Project 3 |
| Day 4 | Multibranch + Master-Agent + Security | Projects 4 & 5 |
You now have the path from Freestyle → Pipeline → Docker CI/CD → Multibranch → Master-Agent → Credentials. Start with Project 1 if you are new to the UI, then work forward until you are running Multibranch pipelines with Docker and distributed agents.
Happy automating.