如何修改AWS EC2实例上Jenkins的访问URL?
Hey there! Since you're new to setting up custom URLs and public access for Jenkins, let's walk through this step by step—yes, you will need a reverse proxy (like Nginx) to make this work, and I'll break down every part so it's easy to follow.
- First, you need to register your desired domain:
jenkins-myjob-myproject.com. Pick any domain registrar (they're all pretty straightforward) and complete the registration process. - Next, point your domain to your Jenkins server's public IP address:
- If your Jenkins is running on a cloud server (like AWS, DigitalOcean), you already have a public IP—go to your domain registrar's DNS settings and add an
Arecord pointing that domain to your server's public IP. - If your Jenkins is on an internal network (home/office LAN), you'll need to set up port forwarding on your router: forward incoming traffic on port 80 to your Jenkins server's local IP and port 8080. For testing, you could also use an internal tunneling tool like frp or ngrok, but those are better for short-term use—long-term, port forwarding + your own domain is the way to go.
- If your Jenkins is running on a cloud server (like AWS, DigitalOcean), you already have a public IP—go to your domain registrar's DNS settings and add an
A reverse proxy acts as a middleman: it takes requests to your custom domain and sends them to Jenkins' 8080 port. Here's how to set it up with Nginx:
- Install Nginx on your Jenkins server:
- For Ubuntu/Debian:
sudo apt update && sudo apt install nginx - For CentOS/RHEL:
sudo dnf install nginx
- For Ubuntu/Debian:
- Create a custom Nginx configuration file for Jenkins:
sudo nano /etc/nginx/sites-available/jenkins - Paste this configuration into the file (replace
jenkins-myjob-myproject.comwith your actual domain):server { listen 80; server_name jenkins-myjob-myproject.com; location / { proxy_pass http://localhost:8080; # These headers make sure Jenkins knows the correct source of requests proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } - Enable the configuration and restart Nginx:
# Link the config to the enabled sites directory sudo ln -s /etc/nginx/sites-available/jenkins /etc/nginx/sites-enabled/ # Test for config errors sudo nginx -t # Restart Nginx to apply changes sudo systemctl restart nginx
Jenkins needs to know its own public URL to generate correct links (like in emails or build notifications):
- Log into your Jenkins instance (still accessible via
IP_address:8080for now) - Click Manage Jenkins on the left sidebar, then select Configure System
- Scroll down to the Jenkins Location section
- Update the Jenkins URL field to
http://jenkins-myjob-myproject.com(match your domain exactly) - Save the changes, then restart Jenkins to apply them:
sudo systemctl restart jenkins
- Add HTTPS for safety: You should use
https://instead ofhttp://to encrypt traffic. The easiest way is to use Let's Encrypt's free certificates with Certbot:
Follow the prompts, and Certbot will automatically update your Nginx config to use HTTPS.sudo apt install certbot python3-certbot-nginx # For Ubuntu/Debian # Or for CentOS/RHEL: sudo dnf install certbot python3-certbot-nginx sudo certbot --nginx - Lock down your firewall: Make sure only necessary ports are open. For Nginx + Jenkins, you need ports 80 (HTTP) and 443 (HTTPS):
sudo ufw allow 80/tcp && sudo ufw allow 443/tcp && sudo ufw reload # Ubuntu/Debian # For CentOS/RHEL: sudo firewall-cmd --add-service=http --permanent && sudo firewall-cmd --add-service=https --permanent && sudo firewall-cmd --reload - Don't expose port 8080 directly: Keep port 8080 restricted to your internal network (or only allow loopback access) so traffic only goes through the Nginx proxy—this adds an extra layer of security.
Now you should be able to access Jenkins at http://jenkins-myjob-myproject.com (or https:// if you set up HTTPS) from anywhere on the public internet!
内容的提问来源于stack exchange,提问作者Namrata Shilpi

