如何通过Jenkins EC2插件在AWS启动Windows代理节点?JNLP密钥问题求助
Hey there, you’ve nailed the root cause—hardcoding a static JNLP secret into your AMI is exactly why your dynamic agents are hijacking the static node instead of registering as new ones. The EC2 Plugin needs to generate unique, per-agent JNLP credentials on the fly, so here’s how to fix this step by step:
1. Strip Static JNLP Config from Your AMI
First, modify your Windows AMI to remove all pre-configured JNLP settings—any hardcoded secrets, fixed agent names, or auto-start scripts that connect to the static node. Make sure the instance boots up without automatically trying to connect using old credentials.
2. Use EC2 User Data to Inject Dynamic JNLP Params
The EC2 Plugin lets you pass dynamically generated JNLP parameters via User Data, which the Windows instance will run on boot to register as a fresh dynamic agent. Here’s how to set this up:
Windows PowerShell User Data Script
Add this script to your EC2 Plugin’s AMI template configuration (replace <your-jenkins-url> with your actual master URL):
# Download Jenkins agent JAR Invoke-WebRequest -Uri "http://<your-jenkins-url>/jnlpJars/agent.jar" -OutFile "C:\agent.jar" # Grab dynamic params injected by EC2 Plugin (these are auto-set as env vars) $jenkinsUrl = $env:JENKINS_URL $jenkinsSecret = $env:JENKINS_SECRET $jenkinsAgentName = $env:JENKINS_AGENT_NAME # Launch the agent with dynamic credentials java -jar C:\agent.jar -jnlpUrl "$jenkinsUrl/computer/$jenkinsAgentName/slave-agent.jnlp" -secret $jenkinsSecret -workDir "C:\jenkins_workspace"
Configure EC2 Plugin for Dynamic Injection
In your Jenkins EC2 Plugin settings, for the Windows AMI template:
- Check "Use JNLP" (this is the default for dynamic agents)
- Paste the above script into the "User Data" field
- Ensure the "Remote FS root" in the plugin matches the
workDirin your script (e.g.,C:\jenkins_workspace)
3. Verify Network Permissions
- Your Windows agents need outbound access to your Jenkins master’s JNLP port (default is 50000, or your custom port)
- If your master is in a VPC, make sure the agent’s security group allows outbound traffic to that port
- The master’s security group should allow inbound JNLP connections from the agent’s security group
4. Test the Dynamic Agent Flow
Trigger a provision (either via a build that requires the agent, or manually from the EC2 Plugin page):
- The plugin spins up a new Windows instance
- On boot, the user data script downloads the agent JAR
- It uses the plugin-generated
JENKINS_SECRETandJENKINS_AGENT_NAMEto connect to the master - The master recognizes this as a new dynamic agent, not the static one you had before
Bonus: Run Agent as a Windows Service
If you want the agent to persist as a service (so it restarts with the instance), update the user data script to register it:
# Register Jenkins Agent as a Windows Service New-Service -Name "JenkinsAgent" -BinaryPathName "java -jar C:\agent.jar -jnlpUrl `"$jenkinsUrl/computer/$jenkinsAgentName/slave-agent.jnlp`" -secret $jenkinsSecret -workDir `"C:\jenkins_workspace`"" -DisplayName "Jenkins Agent" -StartupType Automatic # Start the service Start-Service JenkinsAgent
That should get your dynamic Windows agents working without conflicting with your static node.
内容的提问来源于stack exchange,提问作者Dzerlig

