Chapter 10: Jenkins Introduction
10.5 Credentials store (high level)
Jenkins Credentials bind secrets (SSH keys, usernames/passwords, secret text) into builds without hardcoding them in the Jenkinsfile.
Habits:
- Create credentials in the Jenkins UI (or sync from a vault in advanced setups).
- Reference them with credential IDs in steps (
withCredentials, Docker registry helpers, SSH agents). - Never
echothe secret. - Separate lab credentials from anything production-shaped.
Deep vault/OIDC designs vary by company. For this chapter: know where secrets live (credentials store) vs where they must not live (Git).
Practice task
List three credential types you might create for a badge API lab (for example SSH private key, registry password, API token) and one sentence each on who should access them.