Skip to main content
Version: 1.0.0

Jenkins on Aruba Cloud

Deploy a production-ready Jenkins CI/CD automation server on Aruba Cloud using Terraform and cloud-init. Java 21 + Jenkins LTS installed from the official APT repository — no manual configuration required.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

Jenkins is the most widely used open-source automation server for building, testing, and deploying software. This example provisions a complete Jenkins LTS stack on Aruba Cloud with:

  • A CloudServer VM (CSO4A8 — 4 vCPU / 8 GB) running Jenkins LTS behind an nginx reverse proxy, fully bootstrapped by cloud-init
  • Java 21 (OpenJDK) — the recommended JVM for Jenkins LTS
  • A dedicated VPC, subnet, and security group via the shared network module
  • An Elastic IP for stable external access
  • Port 50000 open for remote build agents connecting via the JNLP protocol
  • Optional ACME HTTPS when a custom domain is provided (via an ACME provider such as Actalis ACME Certificates or Let's Encrypt)

The initial admin password is generated automatically and printed in the bootstrap log. The first login completes the Jenkins setup wizard.


Architecture Overview​

Jenkins listens on port 8080. nginx proxies all HTTP/HTTPS traffic to Jenkins on the same host, with proxy_buffering off to support pipeline log streaming. Remote agents connect directly on port 50000.


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectjenkins-prodProject container
arubacloud_vpcjenkins-prod-vpcVirtual Private Cloud
arubacloud_subnetjenkins-prod-subnetBasic subnet
arubacloud_securitygroupjenkins-prod-vm-sgSecurity group
arubacloud_securityrulejenkins-prod-vm-sshSSH ingress (restricted CIDR)
arubacloud_securityrulejenkins-prod-vm-httpHTTP ingress
arubacloud_securityrulejenkins-prod-vm-httpsHTTPS ingress
arubacloud_securityrulejenkins-prod-vm-jnlpJNLP agent ingress (port 50000)
arubacloud_elasticipjenkins-prod-vm-eipVM public IP
arubacloud_blockstoragejenkins-prod-boot50 GB boot disk (Performance)
arubacloud_keypairjenkins-prod-keypairSSH public key
arubacloud_cloudserverjenkins-prod-vmCloudServer VM

VM Sizing Recommendation​

WorkloadvCPURAMDiskFlavor
Small team / few pipelines48 GB50 GBCSO4A8 (default)
Medium team / many parallel builds816 GB100 GBCSO8A16

Jenkins runs builds directly on the controller by default. For production, offload builds to dedicated agents and increase vm_disk_size_gb to store build artifacts and workspace data.


Estimated Monthly Cost​

Approximate prices for ITBG-Bergamo, hourly billing.

ResourceSpecEst. cost/mo
CloudServer VMCSO4A8 — 4 vCPU / 8 GB~€36
Boot disk50 GB Performance~€6
Elastic IP—~€3
Total~€45/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content

Optional​

VariableDefaultDescription
app_name"jenkins"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO4A8"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb50Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH — restrict to your IP in production
agent_cidr"0.0.0.0/0"CIDR for JNLP agent port 50000 — restrict to your agent network
domain""Custom domain for HTTPS — leave empty to use the Elastic IP

Outputs​

OutputDescription
jenkins_urlJenkins web interface URL
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM
initial_password_cmdCommand to retrieve the initial admin password
jnlp_agent_portJNLP port for remote build agents (50000)

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/jenkins

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Edit terraform.tfvars with your credentials and SSH key.

3. Initialize and deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 5–8 minutes (Java and Jenkins install from APT).

4. Retrieve the initial admin password​

terraform output -raw initial_password_cmd | bash

5. Complete the setup wizard​

Open the Jenkins URL in your browser:

terraform output jenkins_url

Paste the initial admin password, install suggested plugins, and create your admin account.

6. Follow cloud-init progress (optional)​

ssh ubuntu@$(terraform output -raw vm_public_ip)
sudo tail -f /var/log/cloud-init-output.log

Destroy Instructions​

terraform destroy

All resources including the boot disk (and any Jenkins jobs, credentials, and build history stored on it) are permanently deleted.


Security Recommendations​

  1. Restrict SSH to your IP. Set ssh_cidr = "your.ip/32".

  2. Restrict JNLP to your agent network. Set agent_cidr to the IP range of your build agents. Exposing port 50000 publicly allows anyone to attempt agent registration.

  3. Use a custom domain with HTTPS. Set the domain variable to enable TLS. Without HTTPS, credentials submitted via the web UI are transmitted in cleartext.

  4. Disable agent-to-controller security bypass. In Jenkins → Manage Jenkins → Security, ensure "Agent → Controller Security" is enabled.

  5. Create a non-admin service account for pipelines. Avoid running pipelines as the Jenkins admin.

  6. Back up JENKINS_HOME. All job configuration, credentials, and build history live in /var/lib/jenkins. Schedule regular snapshots.


Upgrade Considerations​

Jenkins LTS upgrade​

Jenkins LTS is installed via APT. To upgrade:

ssh ubuntu@$(terraform output -raw vm_public_ip)
sudo apt-get update
sudo apt-get install --only-upgrade jenkins
sudo systemctl status jenkins

Jenkins performs automatic data migration on startup. Review the Jenkins LTS changelog for breaking changes before upgrading.

Java upgrade​

If a future Jenkins LTS requires a newer Java version, update the openjdk-21-jdk-headless package name in cloud-init.yaml.tpl and redeploy the VM.


Troubleshooting​

Jenkins not reachable after apply​

ssh ubuntu@$(terraform output -raw vm_public_ip)
sudo systemctl status jenkins
sudo journalctl -u jenkins -n 50
sudo tail -f /var/log/cloud-init-output.log

nginx returns 502 Bad Gateway​

Jenkins is still starting. Jenkins takes 1–2 minutes to initialize on first boot:

sudo systemctl status jenkins
# Wait for "Jenkins is fully up and running" in the logs:
sudo journalctl -u jenkins -f

Setup wizard asks for initial password after Certbot redirect​

The initial password file does not move after HTTPS is configured:

sudo cat /var/lib/jenkins/secrets/initialAdminPassword

Build agents cannot connect on port 50000​

Verify the security group rule and the configured TCP port in Jenkins → Manage Jenkins → Security → Agent protocols. The JNLP port must match both the security group rule and the Jenkins configuration.


References​