You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于将Jenkins流水线中Hudson密码参数替换为密码参数或凭证参数的技术咨询

Alright, let's tackle this problem of replacing those deprecated Hudson password parameters in your Jenkins pipeline. Since Hudson's hudson.model.PasswordParameterValue is no longer supported, we've got two reliable alternatives to choose from depending on your downstream job setup:

1. Use Jenkins Native PasswordParameterValue (For Standard Password Parameters)

If your downstream job uses regular Password Parameters, swap out the old Hudson class with Jenkins' officially supported jenkins.model.PasswordParameterValue. You don't need to manually handle hudson.util.Secret either—withCredentials already provides the password as a secure string variable, and Jenkins' native parameter class will handle encryption automatically.

Here's the modified parameter section:

build job: 'DBA-TSS/db_aurora-mysql_DEPLOY/', parameters: [
    string(name: 'INSTALL_TYPE', value: "${INSTALL_TYPE}"),
    string(name: 'SDLC', value: "${SDLC}"),
    string(name: 'DB_ARTIFACT', value: "${DB_ARTIFACT}"),
    string(name: 'DEV_NEXUS_ID', value: NEXUS_APPTEAM_USER),
    // Replace deprecated Hudson class with Jenkins' native one
    jenkins.model.PasswordParameterValue(name: 'DEV_NEXUS_PASSWORD', value: NEXUS_APPTEAM_PASS),
    string(name: 'DEV_NEXUS_REPO', value: "${DEV_NEXUS_REPO}"),
    string(name: 'DB_USERNAME', value: DB_APPTEAM_USER),
    jenkins.model.PasswordParameterValue(name: 'DB_PASSWORD', value: DB_APPTEAM_PASS),
    string(name: 'REQUESTER_EMAIL', value: "${REQUESTER_EMAIL}")
]

2. Use CredentialsParameterValue (For Credential Parameters)

If your downstream job is configured to use Credential Parameters (the more secure option), you can pass the credential IDs directly from upstream to downstream. This avoids passing raw password variables entirely—let the downstream job fetch the credentials itself using the ID.

First, make sure your downstream job has Credential Parameters defined (e.g., named DEV_NEXUS_CREDENTIALS and DB_ADMIN_CREDENTIALS). Then update the parameter section like this:

build job: 'DBA-TSS/db_aurora-mysql_DEPLOY/', parameters: [
    string(name: 'INSTALL_TYPE', value: "${INSTALL_TYPE}"),
    string(name: 'SDLC', value: "${SDLC}"),
    string(name: 'DB_ARTIFACT', value: "${DB_ARTIFACT}"),
    // Pass credential IDs directly to downstream's credential parameters
    [$class: 'CredentialsParameterValue', name: 'DEV_NEXUS_CREDENTIALS', credentialsId: 'nexus_download_user', description: 'Nexus download credentials'],
    string(name: 'DEV_NEXUS_REPO', value: "${DEV_NEXUS_REPO}"),
    [$class: 'CredentialsParameterValue', name: 'DB_ADMIN_CREDENTIALS', credentialsId: 'RUNBOOK_RDS_DBADMIN', description: 'RDS DB admin credentials'],
    string(name: 'REQUESTER_EMAIL', value: "${REQUESTER_EMAIL}")
]

Note: With this approach, you can remove the separate DEV_NEXUS_ID, DEV_NEXUS_PASSWORD, DB_USERNAME, and DB_PASSWORD parameters from the downstream job. The downstream can use withCredentials directly with the passed credential ID to retrieve the username and password.

Full Updated Pipeline Script (Option 1 Example)

Here's the complete pipeline using the first approach (for standard password parameters):

pipeline {
    agent any
    stages {
        stage('Runbook database deploy job') {
            steps {
                withCredentials([
                    usernamePassword(credentialsId: 'RUNBOOK_RDS_DBADMIN', passwordVariable: 'DB_APPTEAM_PASS', usernameVariable: 'DB_APPTEAM_USER'),
                    usernamePassword(credentialsId: 'nexus_download_user', passwordVariable: 'NEXUS_APPTEAM_PASS', usernameVariable: 'NEXUS_APPTEAM_USER')
                ]) {
                    build job: 'DBA-TSS/db_aurora-mysql_DEPLOY/', parameters: [
                        string(name: 'INSTALL_TYPE', value: "${INSTALL_TYPE}"),
                        string(name: 'SDLC', value: "${SDLC}"),
                        string(name: 'DB_ARTIFACT', value: "${DB_ARTIFACT}"),
                        string(name: 'DEV_NEXUS_ID', value: NEXUS_APPTEAM_USER),
                        jenkins.model.PasswordParameterValue(name: 'DEV_NEXUS_PASSWORD', value: NEXUS_APPTEAM_PASS),
                        string(name: 'DEV_NEXUS_REPO', value: "${DEV_NEXUS_REPO}"),
                        string(name: 'DB_USERNAME', value: DB_APPTEAM_USER),
                        jenkins.model.PasswordParameterValue(name: 'DB_PASSWORD', value: DB_APPTEAM_PASS),
                        string(name: 'REQUESTER_EMAIL', value: "${REQUESTER_EMAIL}")
                    ]
                }
            }
        }
    }
}

内容的提问来源于stack exchange,提问作者sandeep

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 17:57:34