Complete Jenkins CI/CD Capstone from Commit to Recovery
Anil Jalela · Published · 6 min read
This final guide assembles the series into one delivery path. A GitHub change is discovered by a Multibranch Pipeline, validated on an isolated agent, packaged once, fingerprinted, approved by immutable identity, deployed through a restricted account, tested for health and rolled back when acceptance fails.
Define the delivery contract
Gate
Input
Evidence
Source
Reviewed commit
Commit SHA and pull request
Validation
Clean checkout
Tests, lint, security results
Package
Validated tree
Immutable artifact and SHA-256
Approval
Artifact digest and staging result
Approver and time
Production
Same artifact
Release ID, health and rollback state
Required Jenkins configuration
Multibranch project with GitHub App credential and webhook.
linux nodejs build agents isolated from deployment agents.
Folder-scoped myapp-staging-ssh and myapp-production-ssh credentials.
Verified known_hosts entries on the deployment agent.
Artifact repository or Jenkins artifact retention sized for promotion and rollback.
Protected main branch and separate policy for untrusted pull requests.
Untrusted pull requests run validation without publish or deploy credentials.
Production deploy keys cannot log into unrelated hosts and cannot run arbitrary privileged commands.
Approval shows commit, build, artifact checksum and staging result.
Logs do not echo secrets; artifact and release retention meet rollback needs.
Controller, plugins, credentials, agents, backups and restore tests have named owners.
Unsafe shortcuts
Unsafe: rebuilding after production approval breaks the evidence chain. Promote the archived digest. Unsafe: deploying with scp directly into the live directory exposes partial files. Transfer to a temporary location and switch an atomic release link. Unsafe: suppressing a failed health check with || true records a false success.
Production acceptance checklist
GitHub event, commit, tests, artifact checksum, approval, release and health result are linked.
The same artifact passes staging and reaches production.
Credentials and agents are separated by trust and environment.
Timeout, failure, rollback and notification paths have been exercised.
A controller restore and agent replacement rehearsal has passed.
Choose a Pipeline topology before combining everything
Topology
Use
Trade-off
Single repository Pipeline
One application and one release artifact
Simple traceability; can grow large
Build Pipeline plus promotion Pipeline
Build once, deploy the same digest many times
Requires durable release manifest and authorization between jobs
Monorepo orchestrator plus component Pipelines
Independent components in one repository
Must aggregate downstream status and pass exact commit
A downstream deployment job receives the manifest location or digest, not a workspace path and not “last successful build.” “Last successful” can change between approval and execution.
Handle partial failure explicitly
Failure point
System state
Next action
Checkout/test
No release
Fix source and rerun
Artifact upload
Possibly incomplete release
Verify repository; never publish manifest until digest exists
Staging deployment
Staging may be partial
Reconcile or rollback staging; block production
Approval timeout
Production unchanged
Create new approval against same valid digest or expire release
Production health
New release may be active
Redeploy recorded previous digest and keep build failed
Notification
Deployment result already decided
Record notification failure without changing deployment truth
Operational evidence for every deployment
Repository, branch/tag, commit and Jenkinsfile/library version
Build URL, agent image, dependency lockfiles and test/security reports
Artifact URI, checksum/digest and signature/provenance status
Environment, approver, deployment identity, start/end time and change record
Health checks, monitoring window, current release and previous release
Rollback execution and final environment state
Capstone exercises
Convert the example to a Multibranch Pipeline and prove pull requests cannot access deployment credentials.
Move build and deploy to different labeled agents and transfer only the release manifest.
Trigger a tag build, deploy it to staging, approve the digest and promote it to production.
Break the production health endpoint and verify automatic redeployment of the recorded previous digest.
Restart Jenkins after packaging and confirm the Pipeline can continue from durable artifacts.
Trigger two production requests concurrently and prove the environment lock serializes them.