← Jenkins Engineer: pipelines and operations
05 / 7 · 50 MIN

Libraries, CPS, and configuration

Control reuse while retaining security, performance, and compatibility.

Concept and mechanism

Shared libraries reduce repetition, but their trust model matters. A global trusted library can use APIs outside the sandbox; write access to its repository is a privileged capability. Folder libraries are untrusted. Define owners, review, and versions suitable for the consumer population. A shared change can affect many applications simultaneously, so pin validated revisions and trial updates before broad adoption. Pipeline Groovy also uses a CPS model enabling execution persistence. A NonCPS function must not call CPS Pipeline steps such as sh. The annotation does not move computation to an agent or replace design review. Keep privileged wrappers narrow enough for their behavior to be understood.

Guided application

In a fictional team, parsing a huge report in Groovy degrades the controller. Move heavy processing into an agent-side tool and return only the small information needed for the decision. Avoid retaining large objects in pipeline state. With JCasC, keep declarative configuration under review but manage plugin installation and compatibility separately. Supply secrets through suitable mechanisms without exposing values in Git. Valid YAML can still reference missing components or incompatible settings. Rehearsing configuration, startup, and representative jobs reveals these dependencies. For a shared deployment library, document its contract, version policy, and recovery so each team knows when and how to upgrade.

IN PRACTICE

Trusted library changed on a shared branch: assess reach and contain the version before further rollout.

Common pitfalls

Trusted as convenience; NonCPS as agent execution; valid YAML as complete installation; main as stable version.

Related topics: Architecture, agents, and traceability · Credentials and trust boundaries · Pipeline: scope, timing, and evidence

Take this idea with you

Version contracts and control who can change code executed with elevated trust.

Create account

Reference: Shared libraries and trust · Jenkins LTS 2.568.3; Java 21 or 25 runtime