Chapter 10: Jenkins Introduction
10.10 Safety for lab Jenkins
- Do not expose Jenkins to
0.0.0.0on a public IP without authentication and network restriction. - Prefer laptop Docker Desktop or private lab network for first week.
- If on a cloud VM, Security Group: only your IP to the UI counter; ban password SSH; stop/destroy when idle (cost + safety).
- Use throwaway lab credentials; rotate if the VM was ever world-open.
We do not walk exploit steps — only hardening reminders aligned with the Cyber/AWS safety culture on this site.