2025-12-19 18:31:48 -03:00
# services/jenkins/configmap-jcasc.yaml
apiVersion : v1
kind : ConfigMap
metadata :
name : jenkins-jcasc
namespace : jenkins
data :
securityrealm.yaml : |
jenkins :
securityRealm :
oic :
clientId : "${OIDC_CLIENT_ID}"
clientSecret : "${OIDC_CLIENT_SECRET}"
serverConfiguration :
wellKnown :
wellKnownOpenIDConfigurationUrl : "${OIDC_ISSUER}/.well-known/openid-configuration"
scopesOverride : "openid profile email"
logoutFromOpenIdProvider : true
postLogoutRedirectUrl : "https://ci.bstein.dev"
sendScopesInTokenRequest : true
2026-01-20 09:37:21 -03:00
rootURLFromRequest : false
2025-12-19 18:31:48 -03:00
userNameField : "preferred_username"
fullNameFieldName : "name"
emailFieldName : "email"
groupsFieldName : "groups"
authorization.yaml : |
jenkins :
authorizationStrategy :
loggedInUsersCanDoAnything :
allowAnonymousRead : false
creds.yaml : |
credentials :
system :
domainCredentials :
- credentials :
- usernamePassword :
scope : GLOBAL
id : gitea-pat
username : "${GITEA_PAT_USERNAME}"
password : "${GITEA_PAT_TOKEN}"
description : "Gitea PAT for pipelines"
- usernamePassword :
scope : GLOBAL
id : harbor-robot
username : "${HARBOR_ROBOT_USERNAME}"
password : "${HARBOR_ROBOT_PASSWORD}"
description : "Harbor robot for pipelines"
2026-04-19 22:40:56 -03:00
- usernamePassword :
scope : GLOBAL
id : harbor-robot-streaming
username : "${HARBOR_STREAMING_ROBOT_USERNAME}"
password : "${HARBOR_STREAMING_ROBOT_PASSWORD}"
description : "Harbor robot for streaming pushes"
2026-04-21 19:42:43 -03:00
- string :
scope : GLOBAL
id : sonarqube-token
secret : "${SONARQUBE_TOKEN}"
description : "SonarQube token for quality-gate evidence collection"
2025-12-19 18:31:48 -03:00
jobs.yaml : |
jobs :
- script : |
pipelineJob('harbor-arm-build') {
2026-01-20 10:59:51 -03:00
properties {
pipelineTriggers {
triggers {
2026-01-20 11:14:29 -03:00
scmTrigger {
2026-01-20 11:23:06 -03:00
scmpoll_spec('H/5 * * * *')
2026-01-20 11:14:29 -03:00
ignorePostCommitHooks(false)
}
2026-01-20 10:59:51 -03:00
}
}
2025-12-19 18:31:48 -03:00
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/harbor-arm-build.git')
credentials('gitea-pat')
}
branches('*/master')
}
}
}
}
}
pipelineJob('bstein-dev-home') {
2026-01-20 10:59:51 -03:00
properties {
pipelineTriggers {
triggers {
2026-01-20 11:14:29 -03:00
scmTrigger {
2026-01-20 11:23:06 -03:00
scmpoll_spec('H/2 * * * *')
2026-01-20 11:14:29 -03:00
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-01-20 10:59:51 -03:00
}
}
2025-12-19 18:31:48 -03:00
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/bstein-dev-home.git')
credentials('gitea-pat')
}
branches('*/master')
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-01-20 03:30:48 -03:00
pipelineJob('ariadne') {
2026-01-20 10:59:51 -03:00
properties {
pipelineTriggers {
triggers {
2026-01-20 11:14:29 -03:00
scmTrigger {
2026-01-20 11:23:06 -03:00
scmpoll_spec('H/2 * * * *')
2026-01-20 11:14:29 -03:00
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-01-20 10:59:51 -03:00
}
}
2026-01-20 03:30:48 -03:00
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/ariadne.git')
credentials('gitea-pat')
}
branches('*/master')
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-04-10 16:38:55 -03:00
pipelineJob('metis') {
2026-04-10 05:19:25 -03:00
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-04-10 05:19:25 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
2026-04-10 16:38:55 -03:00
url('https://scm.bstein.dev/bstein/metis.git')
2026-04-10 05:19:25 -03:00
credentials('gitea-pat')
}
2026-04-10 16:38:55 -03:00
branches('*/master')
2026-04-10 05:19:25 -03:00
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-04-10 16:38:55 -03:00
pipelineJob('ananke') {
2026-03-31 15:03:55 -03:00
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-03-31 15:03:55 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
2026-04-10 16:38:55 -03:00
url('https://scm.bstein.dev/bstein/ananke.git')
2026-03-31 15:03:55 -03:00
credentials('gitea-pat')
}
2026-04-10 16:38:55 -03:00
branches('*/main')
2026-03-31 15:03:55 -03:00
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-04-10 16:38:55 -03:00
pipelineJob('lesavka') {
2026-04-10 03:26:51 -03:00
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-16 13:48:01 -03:00
cron {
spec('H H * * *')
}
2026-04-10 03:26:51 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
2026-04-10 16:38:55 -03:00
url('https://scm.bstein.dev/bstein/lesavka.git')
2026-04-10 03:26:51 -03:00
credentials('gitea-pat')
}
2026-04-10 16:38:55 -03:00
branches('*/master')
2026-04-10 03:26:51 -03:00
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-04-19 14:18:41 -03:00
pipelineJob('arcanagon') {
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
}
}
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/arcanagon.git')
credentials('gitea-pat')
}
branches('*/master')
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-04-10 16:38:55 -03:00
pipelineJob('pegasus') {
2026-01-20 10:59:51 -03:00
properties {
pipelineTriggers {
triggers {
2026-01-20 11:14:29 -03:00
scmTrigger {
2026-01-20 11:23:06 -03:00
scmpoll_spec('H/5 * * * *')
2026-01-20 11:14:29 -03:00
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-01-20 10:59:51 -03:00
}
}
2026-01-10 05:01:17 -03:00
}
definition {
cpsScm {
scm {
git {
remote {
2026-04-10 16:38:55 -03:00
url('https://scm.bstein.dev/bstein/pegasus.git')
2026-01-10 05:01:17 -03:00
credentials('gitea-pat')
}
2026-04-10 05:19:25 -03:00
branches('*/main')
2026-01-10 05:01:17 -03:00
}
}
2026-04-10 16:38:55 -03:00
scriptPath('Jenkinsfile')
2026-04-12 04:35:12 -03:00
}
}
}
pipelineJob('atlasbot') {
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-04-12 04:35:12 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/atlasbot.git')
credentials('gitea-pat')
}
branches('*/main')
}
}
scriptPath('Jenkinsfile')
}
}
}
pipelineJob('soteria') {
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-04-12 04:35:12 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/soteria.git')
credentials('gitea-pat')
}
branches('*/main')
}
}
scriptPath('Jenkinsfile')
2026-01-10 05:01:17 -03:00
}
}
}
2026-04-10 16:38:55 -03:00
pipelineJob('data-prepper') {
2026-04-10 05:19:25 -03:00
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-04-10 05:19:25 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
2026-04-10 16:38:55 -03:00
url('https://scm.bstein.dev/bstein/titan-iac.git')
2026-04-10 05:19:25 -03:00
credentials('gitea-pat')
}
2026-04-12 05:26:45 -03:00
branches('*/main')
2026-04-10 05:19:25 -03:00
}
}
2026-04-10 16:38:55 -03:00
scriptPath('services/logging/Jenkinsfile.data-prepper')
2026-04-10 05:19:25 -03:00
}
}
}
2026-04-10 17:12:46 -03:00
pipelineJob('titan-iac') {
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-09 23:18:32 -03:00
cron {
2026-06-04 20:38:02 -03:00
spec('H H/12 * * *')
2026-05-09 23:18:32 -03:00
}
2026-04-10 17:12:46 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/titan-iac.git')
credentials('gitea-pat')
}
branches('*/main')
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-04-13 03:35:39 -03:00
pipelineJob('typhon') {
properties {
pipelineTriggers {
triggers {
scmTrigger {
scmpoll_spec('H/5 * * * *')
ignorePostCommitHooks(false)
}
2026-05-16 15:37:11 -03:00
cron {
spec('H H * * *')
}
2026-04-13 03:35:39 -03:00
}
}
}
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/typhon.git')
credentials('gitea-pat')
}
branches('*/main')
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-07-25 00:52:21 -03:00
pipelineJob('cassandra') {
2026-06-10 04:55:58 -03:00
disabled(false)
2026-07-25 00:52:21 -03:00
description('Staged Cassandra alpha image pipeline. Backend/frontend should build linux/amd64 and linux/arm64; sim-worker may begin amd64-only if Forge dependencies require it.')
2026-06-09 00:46:46 -03:00
definition {
cpsScm {
scm {
git {
remote {
2026-07-25 00:52:21 -03:00
url('https://scm.bstein.dev/bstein/cassandra.git')
2026-06-09 00:46:46 -03:00
credentials('gitea-pat')
}
branches('*/main')
}
}
scriptPath('Jenkinsfile')
2026-08-05 19:46:22 -03:00
}
}
}
multibranchPipelineJob('hermes-code-demo-branches') {
description('Branch validation for the Hermes code-repair demo. Builds hermes-repair/* proposal branches so a pull request carries a green test gate before a human merges it.')
branchSources {
branchSource {
source {
git {
id('hermes-code-demo-branches')
remote('https://scm.bstein.dev/bstein/hermes-code-demo.git')
credentialsId('gitea-pat')
2026-08-05 20:13:54 -03:00
traits {
gitBranchDiscovery()
}
2026-08-05 19:46:22 -03:00
}
}
}
}
factory {
workflowBranchProjectFactory {
scriptPath('Jenkinsfile')
}
}
orphanedItemStrategy {
discardOldItems {
numToKeep(20)
}
}
triggers {
periodicFolderTrigger {
interval('1m')
2026-06-09 00:46:46 -03:00
}
}
}
2026-08-05 19:19:05 -03:00
pipelineJob('hermes-code-demo') {
disabled(false)
description('Hermes code-repair demo : pytest gate over a small pricing helper. A seeded one-line defect fails the gate; Hermes proposes a minimal patch and Ariadne opens a pull request for human review.')
definition {
cpsScm {
scm {
git {
remote {
url('https://scm.bstein.dev/bstein/hermes-code-demo.git')
credentials('gitea-pat')
}
branches('*/master')
}
}
scriptPath('Jenkinsfile')
}
}
}
2026-08-05 16:42:33 -03:00
pipelineJob('hermes-triage-demo') {
disabled(false)
description('Hermes automated-triage demo : runs a deterministic fixture check as a Kubernetes Job in the hermes-triage-demo namespace. Build with SEED_FAILURE=true to arm the demo failure; the automated repair loop rebuilds with SEED_FAILURE=false.')
parameters {
booleanParam('SEED_FAILURE', false, 'Write "unhealthy" into the demo fixture before the check (arms the demo failure).')
}
definition {
cps {
sandbox(true)
script('''
podTemplate(
cloud : 'kubernetes' ,
yaml : "" "
apiVersion : v1
kind : Pod
spec :
serviceAccountName : jenkins
securityContext :
2026-08-05 16:47:48 -03:00
runAsUser : 1000
runAsGroup : 1000
fsGroup : 1000
fsGroupChangePolicy : "OnRootMismatch"
2026-08-05 16:42:33 -03:00
nodeSelector :
kubernetes.io/arch : arm64
node-role.kubernetes.io/worker : "true"
containers :
- name : kubectl
image : bitnami/kubectl@sha256:554ab88b1858e8424c55de37ad417b16f2a0e65d1607aa0f3fe3ce9b9f10b131
command : [ "sleep" ]
args : [ "3600" ]
resources :
requests :
cpu : 50m
memory : 64Mi
limits :
cpu : 250m
memory : 128Mi
"" "
) {
node(POD_LABEL) {
container('kubectl') {
stage('Fixture check') {
2026-08-05 16:56:06 -03:00
def buildNum = '' + env.BUILD_NUMBER
def incidentId = 'hermes-triage-demo/' + buildNum
def jobName = 'hermes-demo-test-' + buildNum
2026-08-05 17:42:10 -03:00
sh 'kubectl -n hermes-triage-demo get configmap hermes-triage-demo-fixture || kubectl -n hermes-triage-demo create configmap hermes-triage-demo-fixture --from-literal=state=healthy'
if (params.SEED_FAILURE) {
writeFile file: 'seed.json', text : '{"data":{"state":"unhealthy"}}'
sh 'kubectl -n hermes-triage-demo patch configmap hermes-triage-demo-fixture --type merge --patch-file seed.json'
echo 'Demo failure armed : fixture state set to unhealthy'
}
2026-08-05 16:56:06 -03:00
def manifest = [
'apiVersion : batch/v1',
'kind : Job',
'metadata:' ,
' name : ' + jobName,
' namespace : hermes-triage-demo',
' labels:' ,
' app.kubernetes.io/part-of : hermes-triage-demo',
' atlas.bstein.dev/role : demo-test-runner',
'spec:' ,
' backoffLimit : 0 ',
' ttlSecondsAfterFinished : 3600 ',
' template:' ,
' metadata:' ,
' labels:' ,
' app.kubernetes.io/part-of : hermes-triage-demo',
' atlas.bstein.dev/role : demo-test-runner',
' spec:' ,
' restartPolicy : Never',
2026-08-05 17:18:12 -03:00
' nodeSelector:' ,
' node-role.kubernetes.io/worker : "true" ',
2026-08-05 16:56:06 -03:00
' containers:' ,
' - name : test-runner',
' image : busybox:1.37',
' env:' ,
' - name : INCIDENT_ID',
' value : "' + incidentId + '" ',
' command:' ,
' - sh' ,
' - -c' ,
' - |' ,
2026-08-05 17:42:10 -03:00
' STATE=$(cat /fixture/state)' ,
2026-08-05 16:56:06 -03:00
' if [ "$STATE" = "healthy" ]; then' ,
2026-08-05 17:45:40 -03:00
' echo "{\\\\"event\\\\":\\\\"hermes_demo_test_pass\\\\",\\\\"incident_id\\\\":\\\\"$INCIDENT_ID\\\\",\\\\"message\\\\":\\\\"fixture state healthy\\\\"}"' ,
2026-08-05 16:56:06 -03:00
' exit 0' ,
' fi' ,
2026-08-05 17:45:40 -03:00
' echo "{\\\\"event\\\\":\\\\"hermes_demo_test_failure\\\\",\\\\"incident_id\\\\":\\\\"$INCIDENT_ID\\\\",\\\\"classification_hint\\\\":\\\\"demo_fixture_unhealthy\\\\",\\\\"message\\\\":\\\\"expected fixture state healthy; found $STATE\\\\"}"' ,
2026-08-05 16:56:06 -03:00
' exit 1' ,
' volumeMounts:' ,
' - name : fixture',
' mountPath : /fixture',
2026-08-05 17:42:10 -03:00
' readOnly : true ',
2026-08-05 16:56:06 -03:00
' resources:' ,
' requests:' ,
' cpu : 25m',
' memory : 16Mi',
' limits:' ,
' cpu : 100m',
' memory : 32Mi',
' volumes:' ,
' - name : fixture',
2026-08-05 17:42:10 -03:00
' configMap:' ,
' name : hermes-triage-demo-fixture'
2026-08-05 16:56:06 -03:00
]
2026-08-05 17:45:40 -03:00
writeFile file: 'test-runner-job.yaml', text : manifest.join('\\n') + '\\n'
2026-08-05 16:56:06 -03:00
sh 'kubectl -n hermes-triage-demo create -f test-runner-job.yaml'
def verdict = 'unknown'
2026-08-06 17:11:40 -03:00
// Read the container's exit code, not the Job status.
// The kubelet records the exit code the moment the
// container stops; the Job controller can take minutes
// to reconcile .status.failed, and has been observed
// taking over half an hour on this cluster. Waiting on
// the Job made the build look hung long after the test
// had actually finished.
2026-08-05 16:42:33 -03:00
timeout(time: 3, unit : 'MINUTES' ) {
2026-08-05 16:56:06 -03:00
waitUntil {
2026-08-06 17:11:40 -03:00
def code = sh(script : 'kubectl -n hermes-triage-demo get pods -l job-name=' + jobName + ' -o jsonpath="{.items[0].status.containerStatuses[0].state.terminated.exitCode}" 2>/dev/null || true', returnStdout: true).trim()
if (code == '0') { verdict = 'pass'; return true }
if (code != '') { verdict = 'fail'; return true }
2026-08-05 16:42:33 -03:00
return false
}
}
2026-08-05 16:56:06 -03:00
def runnerLog = sh(script: 'kubectl -n hermes-triage-demo logs job/' + jobName + ' --tail=20 || true', returnStdout : true ).trim()
echo 'test-runner output : ' + runnerLog
2026-08-05 16:42:33 -03:00
def junitBody
2026-08-05 16:56:06 -03:00
if (verdict == 'pass') {
junitBody = '<testsuite name="hermes-triage-demo" tests="1" failures="0"><testcase classname="hermes-triage-demo" name="fixture-state-check"/></testsuite>'
2026-08-05 16:42:33 -03:00
} else {
2026-08-05 16:56:06 -03:00
def safeLog = runnerLog.replace('&', '&').replace('<', '<').replace('>', '>')
junitBody = '<testsuite name="hermes-triage-demo" tests="1" failures="1"><testcase classname="hermes-triage-demo" name="fixture-state-check"><failure message="demo fixture unhealthy">' + safeLog + '</failure></testcase></testsuite>'
2026-08-05 16:42:33 -03:00
}
writeFile file: 'demo-junit.xml', text : junitBody
2026-08-05 17:32:25 -03:00
archiveArtifacts artifacts: 'demo-junit.xml', fingerprint : false
2026-08-05 16:56:06 -03:00
if (verdict != 'pass') {
error('Demo fixture check failed for incident ' + incidentId)
2026-08-05 16:42:33 -03:00
}
}
}
}
}
'' ')
}
}
}
2026-01-20 10:15:33 -03:00
multibranchPipelineJob('titan-iac-quality-gate') {
branchSources {
branchSource {
source {
2026-01-18 21:23:11 -03:00
git {
2026-01-20 10:15:33 -03:00
id('titan-iac-quality-gate')
remote('https://scm.bstein.dev/bstein/titan-iac.git')
credentialsId('gitea-pat')
2026-01-18 21:23:11 -03:00
}
}
2026-01-20 10:15:33 -03:00
}
}
factory {
workflowBranchProjectFactory {
2026-01-18 21:23:11 -03:00
scriptPath('ci/Jenkinsfile.titan-iac')
}
}
2026-01-20 10:15:33 -03:00
orphanedItemStrategy {
discardOldItems {
numToKeep(30)
}
}
triggers {
periodicFolderTrigger {
interval('12h')
}
}
configure { node ->
2026-01-20 10:31:30 -03:00
def webhookToken = System.getenv('TITAN_IAC_WEBHOOK_TOKEN') ? : ''
2026-01-20 10:15:33 -03:00
def triggers = node / 'triggers'
2026-01-20 10:31:30 -03:00
def webhook = triggers.appendNode('com.igalg.jenkins.plugins.mswt.trigger.ComputedFolderWebHookTrigger')
webhook.appendNode('token', webhookToken)
2026-01-20 10:15:33 -03:00
}
2026-01-18 21:23:11 -03:00
}
2025-12-19 18:31:48 -03:00
base.yaml : |
jenkins :
disableRememberMe : false
mode : NORMAL
numExecutors : 0
labelString : ""
projectNamingStrategy : "standard"
markupFormatter :
plainText
2026-06-10 05:14:41 -03:00
globalNodeProperties :
- envVars :
env :
- key : "GIT_CONFIG_COUNT"
value : "1"
- key : "GIT_CONFIG_KEY_0"
value : "safe.directory"
- key : "GIT_CONFIG_VALUE_0"
value : "*"
2025-12-19 18:31:48 -03:00
clouds :
- kubernetes :
2026-05-20 06:33:12 -03:00
containerCapStr : "5"
2026-05-10 02:17:30 -03:00
connectTimeout : "20"
readTimeout : "90"
2025-12-19 18:31:48 -03:00
jenkinsUrl : "http://jenkins.jenkins.svc.cluster.local:8080"
2025-12-20 18:42:16 -03:00
jenkinsTunnel : "jenkins.jenkins.svc.cluster.local:50000"
2025-12-19 18:31:48 -03:00
skipTlsVerify : false
maxRequestsPerHostStr : "32"
retentionTimeout : "5"
waitForPodSec : "600"
name : "kubernetes"
namespace : "jenkins"
restrictedPssSecurityContext : false
serverUrl : "https://kubernetes.default"
credentialsId : ""
podLabels :
- key : "jenkins/jenkins-jenkins-agent"
value : "true"
templates :
- name : "default"
namespace : "jenkins"
2026-01-20 17:04:24 -03:00
workspaceVolume :
2026-04-19 14:18:41 -03:00
dynamicPVC :
accessModes : "ReadWriteOnce"
requestsSize : "20Gi"
storageClassName : "astreae"
2025-12-19 18:31:48 -03:00
containers :
- name : "jnlp"
args : "^${computer.jnlpmac} ^${computer.name}"
envVars :
- envVar :
key : "JENKINS_URL"
value : "http://jenkins.jenkins.svc.cluster.local:8080/"
image : "jenkins/inbound-agent:3355.v388858a_47b_33-3"
privileged : "false"
resourceLimitCpu : 512m
resourceLimitMemory : 512Mi
resourceRequestCpu : 512m
resourceRequestMemory : 512Mi
ttyEnabled : false
workingDir : /home/jenkins/agent
idleMinutes : 0
instanceCap : 2147483647
2026-04-19 14:18:41 -03:00
label : "jenkins-jenkins-agent "
2025-12-19 18:31:48 -03:00
nodeUsageMode : "NORMAL"
podRetention : Never
2025-12-20 18:08:30 -03:00
serviceAccount : "jenkins"
2025-12-19 18:31:48 -03:00
slaveConnectTimeoutStr : "100"
2026-04-21 20:48:02 -03:00
yaml : |
spec :
2026-06-10 04:49:10 -03:00
securityContext :
runAsUser : 1000
runAsGroup : 1000
fsGroup : 1000
fsGroupChangePolicy : "OnRootMismatch"
2026-05-10 03:24:51 -03:00
nodeSelector :
kubernetes.io/arch : arm64
node-role.kubernetes.io/worker : "true"
2026-04-21 20:48:02 -03:00
affinity :
nodeAffinity :
2026-05-10 03:24:51 -03:00
requiredDuringSchedulingIgnoredDuringExecution :
nodeSelectorTerms :
- matchExpressions :
- key : kubernetes.io/hostname
operator : NotIn
values :
- titan-06
2026-04-21 20:48:02 -03:00
preferredDuringSchedulingIgnoredDuringExecution :
- weight : 100
preference :
matchExpressions :
- key : atlas.bstein.dev/spillover
operator : DoesNotExist
- weight : 95
preference :
matchExpressions :
- key : kubernetes.io/hostname
operator : NotIn
values :
- titan-13
- titan-15
- titan-17
- titan-19
- weight : 85
preference :
matchExpressions :
- key : hardware
operator : In
values :
- rpi5
2026-05-19 23:30:34 -03:00
- weight : 45
preference :
matchExpressions :
- key : hardware
operator : In
values :
- rpi4
2026-04-21 20:48:02 -03:00
topologySpreadConstraints :
- maxSkew : 1
topologyKey : kubernetes.io/hostname
2026-05-20 06:53:29 -03:00
whenUnsatisfiable : ScheduleAnyway
2026-04-21 20:48:02 -03:00
labelSelector :
matchLabels :
jenkins/jenkins-jenkins-agent : "true"
2025-12-19 18:31:48 -03:00
yamlMergeStrategy : override
inheritYamlMergeStrategy : false
slaveAgentPort : 50000
crumbIssuer :
standard :
excludeClientIPFromCrumb : true
2026-01-20 09:37:21 -03:00
unclassified :
location :
url : "https://ci.bstein.dev/"