Jenkins主从集群从节点自动注册配置问题求助
Hey there, let’s fix that Jenkins slave auto-registration headache—manual setup after Terraform provisioning is such a tedious waste of time, right? I’ve solved this exact scenario before, so here’s a step-by-step breakdown to automate the whole process:
First, configure the master to accept automated agent connections without manual node creation hoops:
- Go to Manage Jenkins > Configure Global Security
- Under Agents, enable TCP port for inbound agents (set a fixed port like 50000 instead of random)
- Scroll down to Agent Registration and generate a fixed secret (save this somewhere safe—you’ll need it in Terraform)
- Ensure CSRF protection is configured to allow agent connections (if you have strict settings, add the slave IP range to the allowed list)
Instead of manually creating nodes in the UI, use the Jenkins API to create all 5 slave nodes directly from Terraform. Add this null_resource to your config:
# Fetch Jenkins Master details (adjust filter to match your master's tags) data "aws_instance" "jenkins_master" { filter { name = "tag:Name" values = ["jenkins-master"] } } # Auto-create Jenkins slave nodes via API resource "null_resource" "jenkins_slave_nodes" { count = 5 provisioner "local-exec" { command = <<EOF curl -X POST "http://${data.aws_instance.jenkins_master.public_ip}:8080/createItem?name=jenkins-slave-${count.index}" \ -u "${var.jenkins_admin_username}:${var.jenkins_admin_password}" \ -H "Content-Type: application/xml" \ -d '<slave> <name>jenkins-slave-${count.index}</name> <remoteFS>C:\\Jenkins</remoteFS> <!-- Use /var/lib/jenkins for Linux slaves --> <numExecutors>2</numExecutors> <mode>NORMAL</mode> <retentionStrategy class="hudson.slaves.RetentionStrategy$Always"/> <launcher class="hudson.slaves.JNLPLauncher"> <workDirSettings> <disabled>false</disabled> <workDirPath>C:\\Jenkins\\work</workDirPath> <!-- Match remoteFS structure --> <internalDir>remoting</internalDir> <failIfWorkDirIsMissing>true</failIfWorkDirIsMissing> </workDirSettings> </launcher> <label>windows-slave</label> <!-- Update tag based on your slave OS --> <nodeProperties/> </slave>' EOF } depends_on = [aws_instance.jenkins_master] }
Use Terraform’s remote-exec provisioner to automatically download the agent JAR and start the agent on each slave right after creation. Add this to your slave instance resource:
resource "aws_instance" "jenkins_slave" { count = 5 ami = var.slave_ami_id instance_type = var.slave_instance_type tags = { Name = "jenkins-slave-${count.index}" } # Remote provisioning for Windows slaves (adjust connection type for Linux) provisioner "remote-exec" { inline = [ # Download agent.jar from Jenkins Master "Invoke-WebRequest -Uri http://${data.aws_instance.jenkins_master.private_ip}:8080/jnlpJars/agent.jar -OutFile C:\\Jenkins\\agent.jar", # Start agent in background with nohup equivalent (PowerShell) "Start-Process java -ArgumentList '-jar C:\\Jenkins\\agent.jar -jnlpUrl http://${data.aws_instance.jenkins_master.private_ip}:8080/computer/jenkins-slave-${count.index}/slave-agent.jnlp -secret ${var.jenkins_agent_secret} -workDir C:\\Jenkins' -WindowStyle Hidden" ] connection { type = "rdp" user = var.slave_admin_username password = var.slave_admin_password host = self.public_ip } } depends_on = [null_resource.jenkins_slave_nodes] }
- Network Access: Ensure your security groups allow inbound traffic from slaves to master on ports 8080 (Jenkins UI) and 50000 (inbound agent port)
- Persistent Agent Startup: For long-term reliability, set up the agent as a service:
- On Windows: Use NSSM (Non-Sucking Service Manager) to wrap the agent command into a Windows service
- On Linux: Create a systemd service file that starts the agent on boot
- Secret Management: Never hardcode the Jenkins agent secret or admin credentials—use Terraform variables with sensitive flags, or integrate with a secrets manager like AWS Secrets Manager
This workflow eliminates all manual steps: Terraform creates the master and slaves, auto-creates the slave nodes in Jenkins, and starts the agents automatically. I’ve used this exact setup for scaling Jenkins clusters to 20+ nodes without any manual intervention.
内容的提问来源于stack exchange,提问作者aloisbarreras

