在 Debian 上给 Jenkins 加证书,通常有两种常见场景:
下面分别说明。
最简单、最安全。
sudo apt update
sudo apt install nginx
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d jenkins.example.com
server {
listen 80;
server_name jenkins.example.com;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
sudo systemctl restart nginx
✅ Jenkins 本身仍用 HTTP(8080),由 Nginx 提供 HTTPS。
编辑:
sudo nano /etc/default/jenkins
修改:
JENKINS_ARGS="--httpsPort=8443 --httpsCertificate=/etc/ssl/jenkins/jenkins.crt --httpsPrivateKey=/etc/ssl/jenkins/jenkins.key"
重启:
sudo systemctl restart jenkins
⚠️ 证书必须是 Jenkins 能读取的格式(PEM)。
如果你访问 Git / Harbor / 私有 HTTPS 报:
sun.security.validator.ValidatorException: PKIX path building failed
which java
# 或
readlink -f $(which java)
sudo keytool -import -trustcacerts \
-alias myca \
-file /path/to/ca.crt \
-keystore $JAVA_HOME/lib/security/cacerts \
-storepass changeit
sudo systemctl restart jenkins
如果是 Docker 启动:
docker run -d \
-p 8080:8080 \
-v /path/cacerts:/etc/ssl/certs \
jenkins/jenkins
或在 Dockerfile 里导入 CA。
ufw allow 443chmod 644journalctl -u jenkins如果你能告诉我:
我可以给你精确步骤。