
Jenkins
Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.
Overview
Jenkins is an automation server for software build, test, and delivery workflows. Its web interface and API use HTTP. Modern inbound agents can use WebSocket. Legacy inbound agents can use a separate TCP port.
Jenkins can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Jenkins. Jenkins remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.
Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.
Set the Jenkins public URL and trusted proxy headers. The Pomerium guide uses the JWT Auth plugin, the X-Pomerium-Jwt-Assertion header, and Pomerium signing keys for validation. Prefer WebSocket agents when that model fits. Use a separate TCP route for a required legacy agent endpoint.
Example
Engineers use a Pomerium HTTPS route for Jenkins. WebSocket agents use the reviewed web route when enabled. A legacy agent port receives a separate TCP route only when the deployment still needs it.
Considerations
- An HTTP route does not cover the legacy inbound-agent TCP port.
- Build agents, webhooks, and API clients need compatible noninteractive credentials. Keep Jenkins authorization and credential controls active.
- Block direct access to Jenkins when Jenkins trusts Pomerium identity headers. A direct route can bypass the proxy identity check.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
Sources and official resources
- JenkinsOfficial website
- Jenkins reverse proxy guideOfficial documentation
- Jenkins securityPrimary source
- Jenkins source repositoryOfficial repository
- Secure Jenkins with PomeriumPomerium documentation
- Pomerium HTTP routingPomerium documentation
- Pomerium non-HTTP accessPomerium documentation
- Pomerium clientsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
