PremiumCloud PremiumCloud Contact Us

Non-KYC Huawei Cloud Account Huawei Cloud Jenkins Integration Deployment Guide

Huawei Cloud / 2026-06-30 16:19:38

Huawei Cloud Jenkins Integration Deployment Guide

In modern teams, CI/CD is no longer a “nice to have”. It’s the difference between shipping changes safely and shipping surprises. Jenkins is often chosen because it’s flexible, widely adopted, and supported by a huge ecosystem of plugins. The missing piece is usually integration: how to connect Jenkins with Huawei Cloud services, how to authenticate, how to deploy reliably, and how to handle rollbacks when something goes wrong.

This guide is written as a deployment playbook. It assumes you want a practical route to integrate Jenkins with Huawei Cloud and automate application delivery. You’ll see recommended architecture, setup steps, pipeline design patterns, security considerations, and deployment strategies that work in day-to-day operations.

1. Target Architecture: What “Integration” Should Mean

Before touching configuration files, decide what “integration” should accomplish. In most projects, Jenkins needs to perform four jobs:

  • Build: compile code, run tests, build artifacts (Docker images, binaries, packages).
  • Store artifacts: push images or packages to Huawei Cloud registries/storage.
  • Deploy: update a runtime environment (VMs, Kubernetes, or other compute services).
  • Operate safely: record deployments, verify health, and roll back when necessary.

A clean approach is to split responsibilities:

  • Jenkins orchestrates the pipeline and triggers stages.
  • Huawei Cloud services provide storage, compute, networking, and security.
  • Infrastructure definitions (IaC) and deployment scripts remain versioned with the codebase.

This keeps pipelines repeatable and reduces “works on my machine” incidents.

2. Prerequisites You Should Confirm First

Integration and deployment fail most often due to missing prerequisites rather than incorrect commands. Validate the following early:

  • Access to Huawei Cloud: an account with permissions to create or use the target services.
  • Region and project alignment: the Jenkins deployment targets must live in the same region/project context you intend.
  • Compute target readiness: whether you deploy to VMs or Kubernetes, the target environment must already be reachable and configured.
  • Network reachability: Jenkins must be able to reach Huawei Cloud endpoints (directly or through VPN/bastion).
  • Non-KYC Huawei Cloud Account Secrets management plan: Jenkins credentials should be created for keys/tokens instead of hardcoding.

If any of these are shaky, pause and fix the foundation. A pipeline can’t reliably deploy over a network that drops half the requests.

3. Choose the Right Jenkins Deployment Style

There are two common ways to run Jenkins: managed service vs. self-managed. Since this guide is practical, the recommendations apply regardless of hosting model, but you must align them with how you control networking and credentials.

3.1 Jenkins runs inside Huawei Cloud

If Jenkins is hosted on Huawei Cloud compute, integration tends to be smoother because network routes and security groups are easier to reason about. You still need correct authentication to Huawei Cloud APIs or registries.

3.2 Jenkins runs outside Huawei Cloud

If Jenkins is self-hosted in an on-prem data center or another cloud, you’ll typically rely on VPN, dedicated links, or careful firewall rules. The rest of the workflow stays similar, but you must be more careful with endpoints, DNS, and certificate trust.

4. Authentication and Credentials: The Core of Integration

Non-KYC Huawei Cloud Account To call Huawei Cloud APIs (for deployments, container pushes, and resource management), Jenkins needs credentials. The right way is to use short-lived scoped permissions where possible, and store them as Jenkins credentials.

4.1 Create an API access identity with least privilege

Create an IAM user (or an application credential equivalent in your setup) specifically for CI/CD. Grant only the permissions needed to:

  • Push images to the container registry (if you use one)
  • Deploy or update the target environment
  • Read required configuration (like cluster access details)
  • Optionally manage secrets used by your deployment tooling

A practical habit is to start with broad permissions during initial integration, then reduce them after you confirm which APIs are used.

4.2 Register credentials in Jenkins

In Jenkins, credentials should be stored in its credential store (not in the pipeline script). Use different entries for different purposes:

  • API keys / access tokens for Huawei Cloud calls
  • Registry username/password or access token
  • SSH keys or bastion credentials (if deploying to VMs)
  • Kubernetes config data (if deploying to Kubernetes)

Then reference these credentials in pipeline steps using Jenkins credential IDs.

4.3 Avoid secrets in logs

Many teams inadvertently print secrets by enabling verbose output or echoing environment variables. When testing, confirm that pipeline logs do not reveal token values, private keys, or registry passwords.

5. Pipeline Design: A Simple, Reliable CI/CD Flow

A robust Jenkins pipeline for Huawei Cloud integration typically follows a predictable pattern:

  • Checkout source code
  • Build artifacts
  • Test and quality checks
  • Package artifacts (Docker image or deployment bundle)
  • Publish to Huawei Cloud registry/storage
  • Non-KYC Huawei Cloud Account Deploy to target environment
  • Verify health and optionally run smoke tests
  • Record version and provide rollback data

When you design stages this way, debugging becomes easier because failures are isolated.

6. Integrating Container Images with Huawei Cloud

If your application is containerized, container registry integration is usually the cleanest path: Jenkins builds a Docker image and pushes it, and deployment pulls that immutable image tag.

6.1 Build with a unique tag per commit

Use tags such as commit SHA, build number, or a combination:

  • Example idea: myapp:${GIT_COMMIT[0..8]}-${BUILD_NUMBER}

This prevents “latest drift” and makes rollbacks reliable.

6.2 Push to registry using Jenkins credentials

In the pipeline, authenticate to the Huawei Cloud container registry using the Jenkins-stored credentials. Then run the standard Docker build and push flow.

Key points:

  • Use BuildKit or caching if you want speed, but don’t sacrifice reproducibility.
  • Ensure image tags are consistent across pipeline stages.
  • Verify that the push succeeded before triggering deployment.

6.3 Keep deployment pull behavior deterministic

When Kubernetes (or other orchestration) pulls the image, ensure it references the exact tag you pushed. Avoid using mutable tags like latest for production deployments.

7. Deploying to Kubernetes in Huawei Cloud

For teams using Kubernetes, the deployment step typically updates a deployment object to use the new image tag. Your pipeline should apply changes and then verify application readiness.

7.1 Prepare kubeconfig or cluster access

Non-KYC Huawei Cloud Account Jenkins needs a way to authenticate to the Kubernetes API server. You can provide kubeconfig content as a Jenkins credential, or use a dedicated service account mechanism.

Whichever approach you use, confirm:

  • Jenkins agents can reach the Kubernetes API endpoint.
  • RBAC permissions allow updating only what’s needed (deployments, services, rollbacks if required).

7.2 Update manifests with image tag substitution

A common approach is to keep Kubernetes YAML templates in the repository and replace image tags at build time. You then apply the updated YAML.

Prefer one of these patterns:

  • Template + substitution: use environment variables to patch image fields.
  • Kustomize: generate overlays per environment.
  • Helm: pass values like image tag during helm upgrade.

Non-KYC Huawei Cloud Account Pick one pattern and standardize across teams; mixing too many approaches increases cognitive load.

7.3 Add health checks and smoke tests

Deployment isn’t finished when the YAML is applied. Add verification:

  • Wait for rollout completion
  • Check readiness and liveness probes
  • Optionally run a lightweight smoke test endpoint call

If verification fails, treat it as a deployment failure, not a warning.

7.4 Rollback strategy: use immutable image tags

Kubernetes supports rollbacks to previous ReplicaSets. However, having immutable image tags makes this safer:

  • Record the previous known-good tag (or deployment revision)
  • On failure, roll back and verify readiness again

This prevents cascading failures caused by guessing which image version was actually deployed previously.

8. Deploying to VMs: SSH, Scripts, and Configuration Management

If your target environment is a set of VMs, your pipeline will likely use SSH-based deployment. A good VM deployment pipeline is careful about idempotency and configuration drift.

8.1 Use SSH keys stored in Jenkins credentials

Create a Jenkins credential for SSH authentication. Then use it to execute controlled deployment scripts.

Avoid running one-off commands directly in pipeline code. Instead:

  • Version deployment scripts alongside the application
  • Keep scripts idempotent (safe to run multiple times)
  • Log meaningful output without exposing secrets

8.2 Use a deployment bundle and restart strategy

A typical flow:

  • Non-KYC Huawei Cloud Account Copy artifact to VM
  • Stop current service gracefully
  • Deploy new artifact
  • Start service
  • Run health checks

If you rely on Docker on the VM, you can also use image pull + restart semantics, which tends to be cleaner than copying binaries.

8.3 Rollback on VM deployments

VM rollbacks must be deliberate:

  • Store previous artifact versions (or keep old Docker images available)
  • On failure, revert to the last known-good version
  • Verify service health after rollback

Without version retention, rollback becomes guesswork.

9. Environment Strategy: Dev, Staging, and Production

Most Jenkins setups fail because everything deploys the same way to every environment. You want a consistent pipeline with environment-specific configuration.

9.1 Separate credentials per environment

Use different Jenkins credentials or access scopes for dev, staging, and production. The same pipeline can run for all environments, but it must not share privileges.

9.2 Use branch and approval gates

A common pattern:

  • Push to main triggers staging deployment
  • Production deployment requires approval (manual gate)

Approval gates reduce accidental production releases.

9.3 Track what was deployed where

Record the image tag or artifact version in each deployment stage. Even a simple annotation or metadata file can help audits and troubleshooting.

10. Observability: What to Log and What to Measure

CI/CD should generate signals, not noise. For integration deployments, focus on:

  • Build duration and test results
  • Image build and push success
  • Deployment rollout time
  • Smoke test success/failure
  • Rollback events and reasons

Also ensure your application exposes health endpoints or readiness checks so the pipeline can verify outcomes.

11. Troubleshooting: Common Failure Patterns

When pipelines break, the right troubleshooting approach is to identify the stage where the truth first diverges.

11.1 Authentication errors

Symptoms: registry login fails, API calls return unauthorized, Kubernetes apply is forbidden.

Fix checklist:

  • Confirm the correct Jenkins credential ID is used
  • Verify account/role has the required permissions
  • Non-KYC Huawei Cloud Account Check region mismatch between credential scope and target resources

11.2 Image not found

Symptoms: deployment references an image tag that doesn’t exist in the registry.

Fix checklist:

  • Ensure the pipeline uses the same tag during push and deploy
  • Confirm the push stage completed successfully
  • Check for whitespace or string substitution mistakes in manifests

11.3 Rollout stuck in Kubernetes

Symptoms: rollout doesn’t finish, pods remain unready.

Fix checklist:

  • Inspect pod events and readiness probe failures
  • Verify resource requests/limits and configuration values
  • Confirm image startup environment variables are correct

11.4 Network timeouts between Jenkins and Huawei Cloud

Symptoms: API calls time out or push takes too long.

Fix checklist:

  • Verify security group rules and outbound access from Jenkins host
  • Check DNS resolution
  • Consider enabling retry logic for transient API failures

12. A Practical End-to-End Checklist

Use this as your final verification before running a full deployment.

  • Credentials: Jenkins has the right Huawei Cloud API/registry/cluster credentials.
  • Permissions: least privilege is sufficient for all pipeline stages.
  • Non-KYC Huawei Cloud Account Connectivity: Jenkins can reach registry and deployment targets.
  • Build reproducibility: artifact tagging is deterministic and immutable.
  • Deployment templating: manifest templates correctly reference the chosen tag.
  • Verification: pipeline waits for rollout and runs smoke checks.
  • Rollback: rollback uses known-good image tags or previous revisions.
  • Audit trail: deployment version is recorded for traceability.

Non-KYC Huawei Cloud Account 13. Recommended Pipeline Patterns (Without Overcomplicating)

You don’t need a complex pipeline to get reliable deployments. These patterns are widely useful:

  • Single source of truth: store deployment templates and scripts in the same repo as application code.
  • Immutable artifacts: build once, deploy the same artifact.
  • Fail fast: stop pipeline immediately on build/test failures.
  • Clear stage boundaries: each stage has explicit success and failure criteria.
  • Environment gates: require approval before production.

When you follow these, you’ll spend less time interpreting logs and more time delivering value.

14. Closing Thoughts: Make CI/CD Boring

Non-KYC Huawei Cloud Account The best CI/CD system feels almost boring: it runs predictably, failures happen rarely, and when they do, the pipeline tells you exactly where the problem started. Huawei Cloud Jenkins integration should aim for that same outcome. Start with a working skeleton pipeline, secure it with least privilege credentials, standardize deployment templates, and add rollout verification and rollback mechanisms early.

Non-KYC Huawei Cloud Account If you build it this way, you get more than automation—you get confidence. And confidence is what teams actually need to ship continuously.

TelegramContact Us
CS ID
@cloudcup
TelegramSupport
CS ID
@yanhuacloud