The Matrix Authorization Strategy grants individual permissions (Overall/Read, Job/Build, Credentials/View and 35 others on this controller) to users and groups; its project-based variant also lets a folder or job add grants of its own. This JCasC 2,791 fragment (JCasC) gives admin everything, every logged-in user read access, and anonymous users nothing:
jenkins:
authorizationStrategy:
projectMatrix:
entries:
- user:
name: admin
permissions: [Overall/Administer]
- group:
name: authenticated
permissions: [Overall/Read, Job/Read]Applied to l2-jenkins, it replaced the wizard's strategy. Of two small jobs, only sec-hello enables project-based security, granting developer Job/Build and Job/Cancel:
DEV="developer:$DEV_TOKEN"
for who in VIEWER DEV; do
for job in sec-hello sec-other; do
printf '%-6s %-9s ' $who $job
curl -s -u "${!who}" -X POST -o /dev/null -w '%{http_code}\n' $J/job/$job/build
done
done
curl -s -u "$VIEWER" -X POST $J/job/sec-hello/build | grep -o 'viewer is missing[^<]*'VIEWER sec-hello 403 VIEWER sec-other 403 DEV sec-hello 201 DEV sec-other 403 viewer is missing the Job/Build permission
A job's grants add to the global ones; they never take any away. Grant to groups, not people, and keep Overall/Administer to a few accounts: it includes the Script Console, and so the whole controller. The Role-based Authorization Strategy plugin (about 87,000 installations) suits controllers shared by many teams: you define global roles, item roles matched by a regular expression on job names (booknest-.*) and agent roles, then assign groups to them.