Chapter 29Lesson 04~195 minutes

Security Hardening, CSRF, Agent-to-Controller Controls, Script Security, CSP, TLS, and Reverse Proxies: Diagnostics, Failure Modes, Security, and Performance

Diagnose hardening failures without weakening security: preserve first-failure evidence, separate proxy/TLS/session problems from authorization and queue issues, interpret CSP and Script Security evidence, and apply the smallest safe correction.

Evidence firstProxy diagnosticsCSP violationsApprovalsAgent boundaryLeast change

Learning objectives

  • Preserve first-failure evidence before changing hardening controls.
  • Separate proxy/TLS/session failures from authorization and queue failures.
  • Diagnose controller-build, script-approval and CSP/user-content risks causally.
  • Interpret an intentionally broken reverse-proxy example and repair it narrowly.
  • Avoid “security-off” troubleshooting shortcuts and rerun only the smallest safe scope.

1. Evidence-first diagnostic sequence

  1. Record item full name, queue/build IDs, source revision and first error.
  2. Confirm Jenkins 2.568.3/Java baseline and security-sensitive plugin versions, especially Script Security 1422+.
  3. Confirm identity and authorization separately from CSRF/session state.
  4. Inspect queue eligibility and ensure the built-in node is not executing the build.
  5. Confirm agent/Remoting/workspace/toolchain and OS trust boundary.
  6. Inspect Pipeline/CPS/script approval evidence.
  7. Inspect proxy/TLS/header/CSP evidence and external services.
  8. Apply the least destructive fix, then rerun only the affected request/job.

2. Intentionally broken example: HTTPS outside, HTTP identity inside

This local-only fragment terminates TLS but fails to tell Jenkins the original scheme and omits WebSocket upgrade handling:

# BROKEN teaching example — do not deploy.
location / {
  proxy_pass http://jenkins:8080;
  proxy_set_header Host $host;
  # Missing X-Forwarded-Proto https
  # Missing Upgrade / Connection for WebSocket agents
}

Likely evidence includes the Jenkins reverse-proxy administrative monitor, redirects or absolute URLs using http://, and WebSocket-agent connection failures. Do not conclude “CSRF is broken” merely because a state-changing browser request later fails; first prove scheme/host/session continuity.

Repair

location / {
  proxy_pass http://jenkins:8080;
  proxy_http_version 1.1;
  proxy_set_header Host $http_host;
  proxy_set_header X-Forwarded-Proto https;
  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  proxy_set_header Upgrade $http_upgrade;
  proxy_set_header Connection $connection_upgrade;
}

Re-test the same URL and agent connection. Do not change authentication, CSRF or Jenkinsfile state unless their own evidence shows a separate failure.

3. Five common hardening failures

Symptom Likely layer Evidence Smallest safe correction
403 POST from password client CSRF/session or authorization Response body, crumb/session cookie, permission check Use matching crumb/session or API token; keep CSRF enabled
Build ran on built-in node Controller/node configuration Build node name + executor count Set built-in executors 0; provide eligible agent
Sandboxed script unexpectedly powerful Script Security/plugin Plugin version, approval list, source revision Update to 1422+, revoke only unjustified approval after clone test
HTML report needs unsafe scripts User content/CSP CSP violation + report source Use compatible report/Resource Root URL; do not empty CSP
Wrong http redirect through HTTPS proxy Reverse proxy Location headers, forwarded scheme, Jenkins URL Fix proxy headers/context; preserve TLS

4. Failure: “temporary” controller execution becomes permanent

An agent outage causes a team to add a generic label to the built-in node or raise its executor count. The immediate queue clears, but repository-controlled build code now runs within the controller host trust boundary. Preserve the affected build IDs and node names. Restore eligible agent capacity, return the built-in executor count to zero, and rerun only jobs whose evidence requires it.

5. Failure: broad script approvals

A developer asks an administrator to approve several methods “until the Pipeline turns green.” The correct question is not whether the method appears harmless in isolation; it is which source can invoke it and what controller object it reaches. Record the exact pending signature, job/library revision and use case. Prefer a maintained step/API or a narrower design. Never approve entire mutable scripts or classpaths merely to suppress prompts.

If an existing approval is suspected unsafe, test removal in a clone first. A mass-clear can break unrelated jobs and destroys useful ownership evidence.

6. Failure: attacker-controlled HTML rendered on the Jenkins origin

A report publisher produces HTML with inline script. A team weakens the user-content CSP until it renders. That converts attacker-influenced artifact content into same-origin browser code. Preserve the report artifact/build ID and CSP violation, then move to a compatible report format or Resource Root URL. General UI CSP is not a substitute for isolating user content.

7. Never troubleshoot by removing the boundary

Prohibited shortcuts: disable CSRF, turn off TLS verification, grant anonymous/admin access, run untrusted code on the controller, disable Script Security, attempt legacy agent→controller kill-switches, use permissive SSH host-key checking, or install broad plugins blindly.

These actions usually replace a diagnosable integration error with an invisible privilege-escalation path.

8. Security and performance: measure instead of guessing

CSP reporting, TLS and proxies add processing, but the largest Jenkins controller risks usually come from workload and plugin design rather than cryptography itself. Capture response latency, controller CPU/heap, queue time and plugin behavior before optimizing. Do not trade away TLS or isolation to recover a few milliseconds.

Next lesson

Checkpoint hardening lab

Apply the chapter as a controlled before/after exercise: harden a local-only controller, prove each boundary independently, capture evidence and document rollback without ever turning core security features off.

Knowledge check

Answer before revealing the explanation.

1. A reverse-proxied Jenkins redirects to http:// after an HTTPS login. Which layer should you inspect first?

2. A build used the built-in node because all agents were busy. What should be fixed?

3. Why can blindly approving signatures be a controller-security problem?

4. An archived HTML report needs inline JavaScript. Is weakening CSP globally the safest repair?

5. What does a 403 prove by itself?

Official references and version notes

Verified baseline — 17 September 2026. Labs target Jenkins 2.568.3 LTS with Java 21 (Jenkins 2.568.3 is tested with Java 21 and 25) and Script Security 1422.v06869826dd9b_. Script Security 1415.v9a_f9b_3a_c253d and earlier are affected by multiple sandbox vulnerabilities disclosed 16 September 2026. General Jenkins UI CSP is a core feature in Jenkins 2.539+ but is disabled by default because plugin compatibility varies; introduce it using report evidence and testing. Re-check Jenkins core/plugin advisories before applying these patterns to a long-lived controller.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this address.