Credentials Management
Secure third-party integrations by learning how to store, scope, inject, and mask sensitive authentication assets like API tokens, SSH keys, and passwords within Jenkins.
What is Credentials Management?
Automation pipelines require access to external systems like GitHub, Docker Hub, AWS, and internal databases. Hardcoding plain-text passwords or private tokens directly into scripts creates severe security vulnerabilities.
Credentials Management in Jenkins provides a centralized database to encrypt and safeguard these sensitive assets. Using the core Credentials Plugin, Jenkins securely decrypts these values at runtime inside execution memory and masks them within the console log streams to prevent accidental exposure.
Key Security Concepts
Credential Types
Jenkins supports multiple credential formats out of the box, including *Username with Password*, *Secret text* (API keys), *Secret file*, *SSH Username with private key*, and *OpenID Connect* tokens.
Scoping and Domains
Limit asset visibility by applying scopes. *Global* credentials are available everywhere, while *System* credentials are restricted to the controller machine, and *Folder-level* scopes isolate keys to specific teams.
Secure Log Masking
When credentials are bound to environment variables during build runtime, the execution engine automatically replaces occurrences of those sensitive strings in the log files with asterisks (`****`).
Third-Party Vault Integration
For advanced compliance architectures, plugins enable Jenkins to dynamically fetch credentials from enterprise vault services such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault at runtime.
Practical Secure Pipeline Example
Below is a declarative pipeline that demonstrates standard secure pattern binding for a Docker Hub password and a GitHub secret token:
pipeline {
agent any
environment {
// Dynamic binding of simple secret text strings
GITHUB_API_KEY = credentials('github-enterprise-token')
}
stages {
stage('Authenticate Services') {
steps {
// Multi-variable binding for complex credential profiles (Username/Password)
withCredentials([usernamePassword(
credentialsId: 'docker-hub-production',
usernameVariable: 'DOCKER_USER',
passwordVariable: 'DOCKER_PASS'
)]) {
echo 'Logging into external registry...'
// sh "docker login -u \${DOCKER_USER} -p \${DOCKER_PASS}"
}
}
}
stage('Verify Token Injection') {
steps {
echo 'Checking API variables securely...'
// The log wrapper will automatically mask the output string value below
// sh "curl -H 'Authorization: token \${GITHUB_API_KEY}' https://github.com"
}
}
}
}
Credentials Practice Exercise
- Add a Test Secret: Navigate to Manage Jenkins → Credentials → System → Global credentials and create a new item of type Secret text. Set the ID to `test-pipeline-secret`.
- Build the Pipeline Wrapper: Create a new pipeline script that utilizes the `withCredentials` block or the `credentials()` helper referencing your new ID.
- Verify the Output Masking: Execute your pipeline. Inspect the Console Output logs and confirm that any explicit attempt to echo or print the secret variable is replaced by `****`.
- Apply Local Scopes: Create a secure sub-folder inside your Jenkins dashboard, relocate or create a credential inside that folder, and observe how sibling jobs outside that folder are denied access.
Summary
You have completed the Credentials Management lesson. You now understand how to avoid hardcoded security flaws and protect corporate access policies across automated deployment frameworks. Continue to the next topic to deep dive into advanced secrets processing.