Skip to main content
See All Integrations

Jenkins

Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.

First-party Pomerium access capability

Categories
Developer Tools, Upstream Applications

Overview

Jenkins is an automation server for software build, test, and delivery workflows. Its web interface and API use HTTP. Modern inbound agents can use WebSocket. Legacy inbound agents can use a separate TCP port.

Jenkins can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Jenkins. Jenkins remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.

Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.

Set the Jenkins public URL and trusted proxy headers. The Pomerium guide uses the JWT Auth plugin, the X-Pomerium-Jwt-Assertion header, and Pomerium signing keys for validation. Prefer WebSocket agents when that model fits. Use a separate TCP route for a required legacy agent endpoint.

Example

Engineers use a Pomerium HTTPS route for Jenkins. WebSocket agents use the reviewed web route when enabled. A legacy agent port receives a separate TCP route only when the deployment still needs it.

Considerations

  • An HTTP route does not cover the legacy inbound-agent TCP port.
  • Build agents, webhooks, and API clients need compatible noninteractive credentials. Keep Jenkins authorization and credential controls active.
  • Block direct access to Jenkins when Jenkins trusts Pomerium identity headers. A direct route can bypass the proxy identity check.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect access to self-hosted CircleCI Server web and API services.

  • Protect GitHub Enterprise Server web and API access, with a separate route for Git over SSH when required.

  • Protect access to Spinnaker deployment services as upstream web applications.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo