ProdgatorDocs
Intégrations

Connect Jenkins (beta)

Connect a Jenkins server to Prodgator and send build results from your Jenkinsfiles with a signed request.

Pas encore traduite. Cette page est affichée en anglais. Lire l’original en anglais.

Beta

The Jenkins integration is in beta. It works as described here, but it has had less testing than the other providers and may change. Tell us at support@prodgator.io if something does not work.

Jenkins has no built-in way to push build events, so your pipelines post a small JSON message to Prodgator at the end of each build. Prodgator also calls the Jenkins API with a token you provide to read stages and console logs.

Requirements

  • In Prodgator: the Org admin role.
  • Jenkins reachable over HTTPS from the internet (Prodgator calls its API).
  • A Jenkins user and API token for Prodgator. A dedicated read-only user is best.
  • , and the Credentials Binding plugin on the agents that run your builds.

Step 1: Connect in Prodgator

  1. In Jenkins, create an API token: your user menu, Security > API Token > Add new token.
  2. In Prodgator open Organization > Integrations and use the Jenkins card.
  3. Enter the Jenkins URL (must start with ), the username and the API token, then click Connect.

Prodgator shows a dialog with:

  • Webhook URL:
  • Webhook secret: shown only once. Copy it before closing the dialog.
  • Jenkinsfile snippet: ready to paste.

Step 2: Store the secret in Jenkins

Add the webhook secret as a Secret text credential with the ID .

Step 3: Add the snippet to your Jenkinsfiles

Copy the snippet from the dialog. It looks like this:

post {
  always {
    withCredentials([string(credentialsId: 'prodgator-webhook-secret', variable: 'PRODGATOR_SECRET')]) {
      withEnv(["PRODGATOR_RESULT=${currentBuild.currentResult}", "PRODGATOR_DURATION=${currentBuild.duration}"]) {
        sh '''
          BODY=$(printf '{"projectName":"%s","buildNumber":%s,"buildStatus":"%s","buildUrl":"%s","branch":"%s","commit":"%s","duration":%s}' \
            "$JOB_NAME" "$BUILD_NUMBER" "$PRODGATOR_RESULT" "$BUILD_URL" "${GIT_BRANCH:-}" "${GIT_COMMIT:-}" "$PRODGATOR_DURATION")
          SIG=$(printf '%s' "$BODY" | openssl dgst -sha256 -hmac "$PRODGATOR_SECRET" | sed 's/^.* //')
          curl -fsS -X POST -H 'Content-Type: application/json' -H "X-Jenkins-Token: $SIG" --data "$BODY" '<your webhook URL>'
        '''
      }
    }
  }
}

The header carries the hex HMAC-SHA256 of the request body, keyed with the webhook secret. Prodgator rejects requests whose signature does not match.

Check the connection

Run a job that has the snippet. When it finishes, the build appears on the Pipelines page.

What you see

  • One pipeline run per build, named after the job ().
  • The status Prodgator shows is mapped from . See the Jenkins adapter for the table.
  • Stages and console logs are read from the Jenkins API when you open a run. Stages need the Pipeline Stage View plugin, which provides the endpoints.

Because the snippet runs in , Prodgator hears about a build when it finishes, not while it runs.

Limits

  • Deployment approvals are not available for Jenkins. Use the Jenkins step.
  • Freestyle jobs need their own post-build step that sends the same JSON and header.

Disconnecting

Click the delete icon next to the Jenkins server in Organization > Integrations. Prodgator deletes the stored token and secret, and later requests to the webhook URL are rejected. Remove the snippet from your Jenkinsfiles.

Sur cette page