JCasC

Defining Jenkins Configuration in YAML with JCasC

The Configuration as Code 2,791 plugin (2121.v86fe99d4b_b_a_b_) maps YAML onto the objects the configuration pages edit, under top-level keys such as jenkins, credentials, unclassified (plugin settings), tool and jobs. Installed on the existing controller, its Export configuration action dumps the running setup, including the library configured by hand in Loading Libraries:

Exporting the running controller's library settingsShell
curl -s -u "admin:$JENKINS_TOKEN" -X POST http://localhost:32080/configuration-as-code/export \
  | sed -n '/^  globalLibraries:/,/remote:/p'
Output
  globalLibraries:
    libraries:
    - defaultVersion: "v1.1.0"
      includeInChangesets: false
      name: "booknest-lib"
...
              remote: "https://github.com/binarybehemoth/booknest-jenkins-lib.git"

The full export ran to 323 lines, with defaults and five secrets encrypted by this controller's own key. Use it as a dictionary, keep what matters and replace each secret with a ${VARIABLE}:

ci/jenkins/casc.yamlYAML
# BookNest's Jenkins, as code. Secrets come from /run/secrets/<NAME>, never from this file.
jenkins:
  systemMessage: "BookNest CI, configured from ci/jenkins/casc.yaml"
  numExecutors: 0
  securityRealm:
    local:
      allowsSignup: false
      users:
        - id: admin
          name: BookNest Admin
          password: "${JENKINS_ADMIN_PASSWORD}"
  authorizationStrategy:
    loggedInUsersCanDoAnything:
      allowAnonymousRead: false
  nodes:
    - permanent:
        name: agent-1
        labelString: "linux booknest"
        remoteFS: /home/jenkins/agent
        numExecutors: 1
        launcher: inbound
credentials:
  system:
    domainCredentials:
      - credentials:
          - usernamePassword:
              scope: GLOBAL
              id: github-booknest
              username: binarybehemoth
              password: "${GITHUB_TOKEN}"
unclassified:
  location:
    url: http://localhost:32081/
    adminAddress: Jenkins <jenkins@example.com>
  mailer:
    smtpHost: l2-mailpit
    smtpPort: "1025"
  globalLibraries:
    libraries:
      - name: booknest-lib
        defaultVersion: v1.2.0
        allowVersionOverride: true
        retriever:
          modernSCM:
            scm:
              git:
                remote: https://github.com/binarybehemoth/booknest-jenkins-lib.git
jobs:
  - file: /var/jenkins_conf/jobs.groovy

JCasC resolves ${NAME} from a file named NAME in /run/secrets (where Docker 514 and Kubernetes 5,150 mount secrets) or from the environment, so the YAML itself can be public. Manage Jenkins 8,793 > Configuration as Code documents every key the installed plugins support.