Access Control

Matrix-Based and Role-Based Access Control

The Matrix Authorization Strategy grants individual permissions (Overall/Read, Job/Build, Credentials/View and 35 others on this controller) to users and groups; its project-based variant also lets a folder or job add grants of its own. This JCasC 2,791 fragment (JCasC) gives admin everything, every logged-in user read access, and anonymous users nothing:

matrix.yaml: project-based matrix authorization as codeYAML
jenkins:
  authorizationStrategy:
    projectMatrix:
      entries:
        - user:
            name: admin
            permissions: [Overall/Administer]
        - group:
            name: authenticated
            permissions: [Overall/Read, Job/Read]

Applied to l2-jenkins, it replaced the wizard's strategy. Of two small jobs, only sec-hello enables project-based security, granting developer Job/Build and Job/Cancel:

Who may start which job?Groovy
DEV="developer:$DEV_TOKEN"
for who in VIEWER DEV; do
  for job in sec-hello sec-other; do
    printf '%-6s %-9s ' $who $job
    curl -s -u "${!who}" -X POST -o /dev/null -w '%{http_code}\n' $J/job/$job/build
  done
done
curl -s -u "$VIEWER" -X POST $J/job/sec-hello/build | grep -o 'viewer is missing[^<]*'
Output
VIEWER sec-hello 403
VIEWER sec-other 403
DEV    sec-hello 201
DEV    sec-other 403
viewer is missing the Job/Build permission

A job's grants add to the global ones; they never take any away. Grant to groups, not people, and keep Overall/Administer to a few accounts: it includes the Script Console, and so the whole controller. The Role-based Authorization Strategy plugin (about 87,000 installations) suits controllers shared by many teams: you define global roles, item roles matched by a regular expression on job names (booknest-.*) and agent roles, then assign groups to them.