Non-KYC Huawei Cloud Account Huawei Cloud Jenkins Integration Deployment Guide
Huawei Cloud Jenkins Integration Deployment Guide
In modern teams, CI/CD is no longer a “nice to have”. It’s the difference between shipping changes safely and shipping surprises. Jenkins is often chosen because it’s flexible, widely adopted, and supported by a huge ecosystem of plugins. The missing piece is usually integration: how to connect Jenkins with Huawei Cloud services, how to authenticate, how to deploy reliably, and how to handle rollbacks when something goes wrong.
This guide is written as a deployment playbook. It assumes you want a practical route to integrate Jenkins with Huawei Cloud and automate application delivery. You’ll see recommended architecture, setup steps, pipeline design patterns, security considerations, and deployment strategies that work in day-to-day operations.
1. Target Architecture: What “Integration” Should Mean
Before touching configuration files, decide what “integration” should accomplish. In most projects, Jenkins needs to perform four jobs:
- Build: compile code, run tests, build artifacts (Docker images, binaries, packages).
- Store artifacts: push images or packages to Huawei Cloud registries/storage.
- Deploy: update a runtime environment (VMs, Kubernetes, or other compute services).
- Operate safely: record deployments, verify health, and roll back when necessary.
A clean approach is to split responsibilities:
- Jenkins orchestrates the pipeline and triggers stages.
- Huawei Cloud services provide storage, compute, networking, and security.
- Infrastructure definitions (IaC) and deployment scripts remain versioned with the codebase.
This keeps pipelines repeatable and reduces “works on my machine” incidents.
2. Prerequisites You Should Confirm First
Integration and deployment fail most often due to missing prerequisites rather than incorrect commands. Validate the following early:
- Access to Huawei Cloud: an account with permissions to create or use the target services.
- Region and project alignment: the Jenkins deployment targets must live in the same region/project context you intend.
- Compute target readiness: whether you deploy to VMs or Kubernetes, the target environment must already be reachable and configured.
- Network reachability: Jenkins must be able to reach Huawei Cloud endpoints (directly or through VPN/bastion).
- Non-KYC Huawei Cloud Account Secrets management plan: Jenkins credentials should be created for keys/tokens instead of hardcoding.
If any of these are shaky, pause and fix the foundation. A pipeline can’t reliably deploy over a network that drops half the requests.
3. Choose the Right Jenkins Deployment Style
There are two common ways to run Jenkins: managed service vs. self-managed. Since this guide is practical, the recommendations apply regardless of hosting model, but you must align them with how you control networking and credentials.
3.1 Jenkins runs inside Huawei Cloud
If Jenkins is hosted on Huawei Cloud compute, integration tends to be smoother because network routes and security groups are easier to reason about. You still need correct authentication to Huawei Cloud APIs or registries.
3.2 Jenkins runs outside Huawei Cloud
If Jenkins is self-hosted in an on-prem data center or another cloud, you’ll typically rely on VPN, dedicated links, or careful firewall rules. The rest of the workflow stays similar, but you must be more careful with endpoints, DNS, and certificate trust.
4. Authentication and Credentials: The Core of Integration
Non-KYC Huawei Cloud Account To call Huawei Cloud APIs (for deployments, container pushes, and resource management), Jenkins needs credentials. The right way is to use short-lived scoped permissions where possible, and store them as Jenkins credentials.
4.1 Create an API access identity with least privilege
Create an IAM user (or an application credential equivalent in your setup) specifically for CI/CD. Grant only the permissions needed to:
- Push images to the container registry (if you use one)
- Deploy or update the target environment
- Read required configuration (like cluster access details)
- Optionally manage secrets used by your deployment tooling
A practical habit is to start with broad permissions during initial integration, then reduce them after you confirm which APIs are used.
4.2 Register credentials in Jenkins
In Jenkins, credentials should be stored in its credential store (not in the pipeline script). Use different entries for different purposes:
- API keys / access tokens for Huawei Cloud calls
- Registry username/password or access token
- SSH keys or bastion credentials (if deploying to VMs)
- Kubernetes config data (if deploying to Kubernetes)
Then reference these credentials in pipeline steps using Jenkins credential IDs.
4.3 Avoid secrets in logs
Many teams inadvertently print secrets by enabling verbose output or echoing environment variables. When testing, confirm that pipeline logs do not reveal token values, private keys, or registry passwords.
5. Pipeline Design: A Simple, Reliable CI/CD Flow
A robust Jenkins pipeline for Huawei Cloud integration typically follows a predictable pattern:
- Checkout source code
- Build artifacts
- Test and quality checks
- Package artifacts (Docker image or deployment bundle)
- Publish to Huawei Cloud registry/storage
- Non-KYC Huawei Cloud Account Deploy to target environment
- Verify health and optionally run smoke tests
- Record version and provide rollback data
When you design stages this way, debugging becomes easier because failures are isolated.
6. Integrating Container Images with Huawei Cloud
If your application is containerized, container registry integration is usually the cleanest path: Jenkins builds a Docker image and pushes it, and deployment pulls that immutable image tag.
6.1 Build with a unique tag per commit
Use tags such as commit SHA, build number, or a combination:
- Example idea:
myapp:${GIT_COMMIT[0..8]}-${BUILD_NUMBER}
This prevents “latest drift” and makes rollbacks reliable.
6.2 Push to registry using Jenkins credentials
In the pipeline, authenticate to the Huawei Cloud container registry using the Jenkins-stored credentials. Then run the standard Docker build and push flow.
Key points:
- Use BuildKit or caching if you want speed, but don’t sacrifice reproducibility.
- Ensure image tags are consistent across pipeline stages.
- Verify that the push succeeded before triggering deployment.
6.3 Keep deployment pull behavior deterministic
When Kubernetes (or other orchestration) pulls the image, ensure it references the exact tag you pushed. Avoid using mutable tags like latest for production deployments.
7. Deploying to Kubernetes in Huawei Cloud
For teams using Kubernetes, the deployment step typically updates a deployment object to use the new image tag. Your pipeline should apply changes and then verify application readiness.
7.1 Prepare kubeconfig or cluster access
Non-KYC Huawei Cloud Account Jenkins needs a way to authenticate to the Kubernetes API server. You can provide kubeconfig content as a Jenkins credential, or use a dedicated service account mechanism.
Whichever approach you use, confirm:
- Jenkins agents can reach the Kubernetes API endpoint.
- RBAC permissions allow updating only what’s needed (deployments, services, rollbacks if required).
7.2 Update manifests with image tag substitution
A common approach is to keep Kubernetes YAML templates in the repository and replace image tags at build time. You then apply the updated YAML.
Prefer one of these patterns:
- Template + substitution: use environment variables to patch image fields.
- Kustomize: generate overlays per environment.
- Helm: pass values like image tag during
helm upgrade.
Non-KYC Huawei Cloud Account Pick one pattern and standardize across teams; mixing too many approaches increases cognitive load.
7.3 Add health checks and smoke tests
Deployment isn’t finished when the YAML is applied. Add verification:
- Wait for rollout completion
- Check readiness and liveness probes
- Optionally run a lightweight smoke test endpoint call
If verification fails, treat it as a deployment failure, not a warning.
7.4 Rollback strategy: use immutable image tags
Kubernetes supports rollbacks to previous ReplicaSets. However, having immutable image tags makes this safer:
- Record the previous known-good tag (or deployment revision)
- On failure, roll back and verify readiness again
This prevents cascading failures caused by guessing which image version was actually deployed previously.
8. Deploying to VMs: SSH, Scripts, and Configuration Management
If your target environment is a set of VMs, your pipeline will likely use SSH-based deployment. A good VM deployment pipeline is careful about idempotency and configuration drift.
8.1 Use SSH keys stored in Jenkins credentials
Create a Jenkins credential for SSH authentication. Then use it to execute controlled deployment scripts.
Avoid running one-off commands directly in pipeline code. Instead:
- Version deployment scripts alongside the application
- Keep scripts idempotent (safe to run multiple times)
- Log meaningful output without exposing secrets
8.2 Use a deployment bundle and restart strategy
A typical flow:
- Non-KYC Huawei Cloud Account Copy artifact to VM
- Stop current service gracefully
- Deploy new artifact
- Start service
- Run health checks
If you rely on Docker on the VM, you can also use image pull + restart semantics, which tends to be cleaner than copying binaries.
8.3 Rollback on VM deployments
VM rollbacks must be deliberate:
- Store previous artifact versions (or keep old Docker images available)
- On failure, revert to the last known-good version
- Verify service health after rollback
Without version retention, rollback becomes guesswork.
9. Environment Strategy: Dev, Staging, and Production
Most Jenkins setups fail because everything deploys the same way to every environment. You want a consistent pipeline with environment-specific configuration.
9.1 Separate credentials per environment
Use different Jenkins credentials or access scopes for dev, staging, and production. The same pipeline can run for all environments, but it must not share privileges.
9.2 Use branch and approval gates
A common pattern:
- Push to
maintriggers staging deployment - Production deployment requires approval (manual gate)
Approval gates reduce accidental production releases.
9.3 Track what was deployed where
Record the image tag or artifact version in each deployment stage. Even a simple annotation or metadata file can help audits and troubleshooting.
10. Observability: What to Log and What to Measure
CI/CD should generate signals, not noise. For integration deployments, focus on:
- Build duration and test results
- Image build and push success
- Deployment rollout time
- Smoke test success/failure
- Rollback events and reasons
Also ensure your application exposes health endpoints or readiness checks so the pipeline can verify outcomes.
11. Troubleshooting: Common Failure Patterns
When pipelines break, the right troubleshooting approach is to identify the stage where the truth first diverges.
11.1 Authentication errors
Symptoms: registry login fails, API calls return unauthorized, Kubernetes apply is forbidden.
Fix checklist:
- Confirm the correct Jenkins credential ID is used
- Verify account/role has the required permissions
- Non-KYC Huawei Cloud Account Check region mismatch between credential scope and target resources
11.2 Image not found
Symptoms: deployment references an image tag that doesn’t exist in the registry.
Fix checklist:
- Ensure the pipeline uses the same tag during push and deploy
- Confirm the push stage completed successfully
- Check for whitespace or string substitution mistakes in manifests
11.3 Rollout stuck in Kubernetes
Symptoms: rollout doesn’t finish, pods remain unready.
Fix checklist:
- Inspect pod events and readiness probe failures
- Verify resource requests/limits and configuration values
- Confirm image startup environment variables are correct
11.4 Network timeouts between Jenkins and Huawei Cloud
Symptoms: API calls time out or push takes too long.
Fix checklist:
- Verify security group rules and outbound access from Jenkins host
- Check DNS resolution
- Consider enabling retry logic for transient API failures
12. A Practical End-to-End Checklist
Use this as your final verification before running a full deployment.
- Credentials: Jenkins has the right Huawei Cloud API/registry/cluster credentials.
- Permissions: least privilege is sufficient for all pipeline stages.
- Non-KYC Huawei Cloud Account Connectivity: Jenkins can reach registry and deployment targets.
- Build reproducibility: artifact tagging is deterministic and immutable.
- Deployment templating: manifest templates correctly reference the chosen tag.
- Verification: pipeline waits for rollout and runs smoke checks.
- Rollback: rollback uses known-good image tags or previous revisions.
- Audit trail: deployment version is recorded for traceability.
Non-KYC Huawei Cloud Account 13. Recommended Pipeline Patterns (Without Overcomplicating)
You don’t need a complex pipeline to get reliable deployments. These patterns are widely useful:
- Single source of truth: store deployment templates and scripts in the same repo as application code.
- Immutable artifacts: build once, deploy the same artifact.
- Fail fast: stop pipeline immediately on build/test failures.
- Clear stage boundaries: each stage has explicit success and failure criteria.
- Environment gates: require approval before production.
When you follow these, you’ll spend less time interpreting logs and more time delivering value.
14. Closing Thoughts: Make CI/CD Boring
Non-KYC Huawei Cloud Account The best CI/CD system feels almost boring: it runs predictably, failures happen rarely, and when they do, the pipeline tells you exactly where the problem started. Huawei Cloud Jenkins integration should aim for that same outcome. Start with a working skeleton pipeline, secure it with least privilege credentials, standardize deployment templates, and add rollout verification and rollback mechanisms early.
Non-KYC Huawei Cloud Account If you build it this way, you get more than automation—you get confidence. And confidence is what teams actually need to ship continuously.

