Jenkins Pipeline Tutorial: Declarative CI/CD That Scales
Jenkins Pipeline Tutorial: Declarative CI/CD That Scales
Jenkins remains the workhorse of enterprise CI/CD — self-hosted, endlessly extensible, and still the right answer when you need full control. This tutorial covers modern, declarative Jenkinsfiles — the way pipelines are meant to be written.
Table of Contents
- Install Jenkins in one minute
- Declarative pipeline anatomy
- The pieces
- Multibranch pipelines: the feature that makes Jenkins modern
- Credentials: do it right
- Scaling and survival tips
Install Jenkins in one minute
docker run -d --name jenkins \
-p 8080:8080 -p 50000:50000 \
-v jenkins_home:/var/jenkins_home \
jenkins/jenkins:lts
docker exec jenkins cat /var/jenkins_home/secrets/initialAdminPassword
Open http://localhost:8080, paste the password, install suggested plugins, create your admin user.
Declarative pipeline anatomy
Create a Jenkinsfile at your repo root:
pipeline {
agent any
options {
timeout(time: 15, unit: 'MINUTES')
disableConcurrentBuilds()
}
stages {
stage('Build') {
steps {
sh 'docker build -t myapp:$GIT_COMMIT .'
}
}
stage('Test') {
steps {
sh 'docker run --rm myapp:$GIT_COMMIT npm test'
}
}
stage('Deploy') {
when { branch 'main' }
steps {
sh 'docker push myapp:$GIT_COMMIT'
}
}
}
post {
failure {
echo 'Build failed — notify the channel'
}
}
}
The pieces
- agent any — run on any available node. Use agent { docker { image 'node:22' } } for a clean container per build.
- stages / stage / steps — the visible pipeline in the UI; each stage shows its own status and timing.
- when — conditional stages (branch filters, tags, expressions). Deploy only from main.
- post — always/success/failure blocks for notifications and cleanup.
- options — timeouts, retries, log rotation (buildDiscarder) so Jenkins doesn't fill its own disk.
- environment — env vars, including credentials('my-secret-id') bound safely from the credential store.
Multibranch pipelines: the feature that makes Jenkins modern
Create a Multibranch Pipeline job pointing at your repo. Jenkins scans it, finds every branch/PR with a Jenkinsfile, and creates jobs automatically. PRs get tested; stale branches get garbage-collected. Combined with webhooks (github-webhook), pushes trigger builds in seconds — no polling.
Credentials: do it right
Never put secrets in the Jenkinsfile. Store them under Manage Jenkins → Credentials, then:
environment {
REGISTRY = credentials('docker-registry-creds')
}
// $REGISTRY_USR and $REGISTRY_PSW become available
Scaling and survival tips
- Use agents/workers for real workloads — the controller should orchestrate, not compile.
- Back up jenkins_home — it's the entire state: jobs, history, credentials.
- Keep plugins minimal and updated — most Jenkins CVEs land in plugins, not core.
- Put Jenkinsfile under code review like application code.
Jenkins asks more of you than hosted CI, but pays back control: private networks, exotic toolchains, no per-minute pricing. Declarative pipelines keep that power readable.
Related Articles
Last Updated: October 2026 Author: CloudOpsGuide Team Difficulty: Intermediate Estimated Reading Time: 13 minutes