Sign inSign up

devops4me/s3jusers

By devops4me

•Updated about 7 years ago

Using S3 to manage the persistence of the Jenkins user database is the role of this container.

Image
0

986

devops4me/s3jusers repository overview

⁠Manage Jenkins User Database | Docker

The persistence of the file-based Jenkins user database is the role of this docker container. The Jenkins docker container runs alongside this container and the volumes-from connection is used to access the jenkins user database at '/var/jenkins_home/users'.


⁠docker build

To push the image to dockerhub you'll need to do a docker login before and a docker logout after.

docker rmi devops4me/s3jusers
docker build --rm --no-cache --tag devops4me/s3jusers:latest .
docker tag devops4me/s3jusers:latest devops4me/s3jusers:latest
docker push devops4me/s3jusers:latest

⁠docker run

Note that the Jenkins docker container can be running (or has ran) for the volumes from specifier to point to the docker managed volume stored on the host within the /var/lib/docker/volumes/_data/<<volume-hash>> directory.

docker run                    \
    --tty                     \
    --detach                  \
    --volumes-from vm.jenkins \
    --name vm.s3jusers        \
    --env JENKINS_USERS_BUCKET=<bucket_name> \
    devops4me/s3jusers:latest

The environment variable called JENKINS_USERS_BUCKET must be set to the S3 bucket name.

⁠Running Locally

If and when testing out this container locally you will need to provide AWS credentials to the environment. Your laptop unlike an EC2 instance, does not have an instance role profile allowing it to access the S3 bucket.

aws sts assume-role --role-arn <<role-arn>> --role-session-name test-s3jusers --profile <<profile-name>> --duration-seconds 3600
docker run                    \
    --tty                     \
    --detach                  \
    --volumes-from vm.jenkins \
    --name vm.s3jusers        \
    --env JENKINS_USERS_BUCKET=bucket.name \
    --env AWS_ACCESS_KEY_ID=access.key     \
    --env AWS_SECRET_ACCESS_KEY=secret.key \
    --env AWS_DEFAULT_REGION=region.key    \
    devops4me/s3jusers:latest

Also, if not running the docker container on an ec2 instance with a role profile for accessing S3, you'll need to pass in the AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_DEFAULT_REGION environment variables.


⁠copy (pull) jenkins users from S3

If upon examination the location '/var/jenkins_home/users' is empty, the script copies the user database files from the S3 bucket whose name is configured in the environment variables.

aws s3 cp --recursive s3://${JENKINS_USERS_BUCKET} /var/jenkins_home/users

⁠sync (push) jenkins users to S3

Use commands like the below. The first syncs from a jenkins folder to an S3 bucket. The second syncs from the current folder and the third does the same, but it also uses a local AWS role profile.

aws s3 sync /var/jenkins_home/users/ s3://${JENKINS_USERS_BUCKET} --delete --size-only
aws s3 sync . s3://<JENKINS_USERS_BUCKET> --delete --size-only
aws s3 sync . s3://<JENKINS_USERS_BUCKET> --delete --size-only --profile=<profile-name>

Tag summary

Content type

Image

Digest

Size

243.3 MB

Last updated

about 7 years ago

docker pull devops4me/s3jusers