Skip to main content
Version: 0.5.3

Jenkins on Aruba Cloud

Deploy a production-ready Jenkins CI/CD automation server on Aruba Cloud using Terraform and cloud-init. Java 21 + Jenkins LTS installed from the official APT repository — no manual configuration required.

Provider version: arubacloud/arubacloud ~> 0.5 | Terraform: ≥ 1.9


Introduction​

Jenkins is the most widely used open-source automation server for building, testing, and deploying software. This example provisions a complete Jenkins LTS stack on Aruba Cloud with:

  • A CloudServer VM (CSO4A8 — 4 vCPU / 8 GB) running Jenkins LTS behind an nginx reverse proxy, fully bootstrapped by cloud-init
  • Java 21 (OpenJDK) — the recommended JVM for Jenkins LTS
  • A dedicated VPC, subnet, and security group via the shared network module
  • An Elastic IP for stable external access
  • Port 50000 open for remote build agents connecting via the JNLP protocol
  • Optional Let's Encrypt HTTPS when a custom domain is provided

The initial admin password is generated automatically and printed in the bootstrap log. The first login completes the Jenkins setup wizard.


Architecture Overview​

Jenkins listens on port 8080. nginx proxies all HTTP/HTTPS traffic to Jenkins on the same host, with proxy_buffering off to support pipeline log streaming. Remote agents connect directly on port 50000.


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectjenkins-prodProject container
arubacloud_vpcjenkins-prod-vpcVirtual Private Cloud
arubacloud_subnetjenkins-prod-subnetBasic subnet
arubacloud_securitygroupjenkins-prod-vm-sgSecurity group
arubacloud_securityrulejenkins-prod-vm-sshSSH ingress (restricted CIDR)
arubacloud_securityrulejenkins-prod-vm-httpHTTP ingress
arubacloud_securityrulejenkins-prod-vm-httpsHTTPS ingress
arubacloud_securityrulejenkins-prod-vm-jnlpJNLP agent ingress (port 50000)
arubacloud_elasticipjenkins-prod-vm-eipVM public IP
arubacloud_blockstoragejenkins-prod-boot50 GB boot disk (Performance)
arubacloud_keypairjenkins-prod-keypairSSH public key
arubacloud_cloudserverjenkins-prod-vmCloudServer VM

VM Sizing Recommendation​

WorkloadvCPURAMDiskFlavor
Small team / few pipelines48 GB50 GBCSO4A8 (default)
Medium team / many parallel builds816 GB100 GBCSO8A16

Jenkins runs builds directly on the controller by default. For production, offload builds to dedicated agents and increase vm_disk_size_gb to store build artifacts and workspace data.


Estimated Monthly Cost​

Approximate prices for ITBG-Bergamo, hourly billing.

ResourceSpecEst. cost/mo
CloudServer VMCSO4A8 — 4 vCPU / 8 GB~€36
Boot disk50 GB Performance~€6
Elastic IP—~€3
Total~€45/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 0.5
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content

Optional​

VariableDefaultDescription
app_name"jenkins"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO4A8"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb50Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH — restrict to your IP in production
agent_cidr"0.0.0.0/0"CIDR for JNLP agent port 50000 — restrict to your agent network
domain""Custom domain for HTTPS — leave empty to use the Elastic IP

Outputs​

OutputDescription
jenkins_urlJenkins web interface URL
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM
initial_password_cmdCommand to retrieve the initial admin password
jnlp_agent_portJNLP port for remote build agents (50000)

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/jenkins

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Edit terraform.tfvars with your credentials and SSH key.

3. Initialize and deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 5–8 minutes (Java and Jenkins install from APT).

4. Retrieve the initial admin password​

terraform output -raw initial_password_cmd | bash

5. Complete the setup wizard​

Open the Jenkins URL in your browser:

terraform output jenkins_url

Paste the initial admin password, install suggested plugins, and create your admin account.

6. Follow cloud-init progress (optional)​

ssh ubuntu@$(terraform output -raw vm_public_ip)
sudo tail -f /var/log/cloud-init-output.log

Destroy Instructions​

terraform destroy

All resources including the boot disk (and any Jenkins jobs, credentials, and build history stored on it) are permanently deleted.


Security Recommendations​

  1. Restrict SSH to your IP. Set ssh_cidr = "your.ip/32".

  2. Restrict JNLP to your agent network. Set agent_cidr to the IP range of your build agents. Exposing port 50000 publicly allows anyone to attempt agent registration.

  3. Use a custom domain with HTTPS. Set the domain variable to enable TLS. Without HTTPS, credentials submitted via the web UI are transmitted in cleartext.

  4. Disable agent-to-controller security bypass. In Jenkins → Manage Jenkins → Security, ensure "Agent → Controller Security" is enabled.

  5. Create a non-admin service account for pipelines. Avoid running pipelines as the Jenkins admin.

  6. Back up JENKINS_HOME. All job configuration, credentials, and build history live in /var/lib/jenkins. Schedule regular snapshots.


Upgrade Considerations​

Jenkins LTS upgrade​

Jenkins LTS is installed via APT. To upgrade:

ssh ubuntu@$(terraform output -raw vm_public_ip)
sudo apt-get update
sudo apt-get install --only-upgrade jenkins
sudo systemctl status jenkins

Jenkins performs automatic data migration on startup. Review the Jenkins LTS changelog for breaking changes before upgrading.

Java upgrade​

If a future Jenkins LTS requires a newer Java version, update the openjdk-21-jdk-headless package name in cloud-init.yaml.tpl and redeploy the VM.


Troubleshooting​

Jenkins not reachable after apply​

ssh ubuntu@$(terraform output -raw vm_public_ip)
sudo systemctl status jenkins
sudo journalctl -u jenkins -n 50
sudo tail -f /var/log/cloud-init-output.log

nginx returns 502 Bad Gateway​

Jenkins is still starting. Jenkins takes 1–2 minutes to initialize on first boot:

sudo systemctl status jenkins
# Wait for "Jenkins is fully up and running" in the logs:
sudo journalctl -u jenkins -f

Setup wizard asks for initial password after Certbot redirect​

The initial password file does not move after HTTPS is configured:

sudo cat /var/lib/jenkins/secrets/initialAdminPassword

Build agents cannot connect on port 50000​

Verify the security group rule and the configured TCP port in Jenkins → Manage Jenkins → Security → Agent protocols. The JNLP port must match both the security group rule and the Jenkins configuration.


References​