Upgrade Notes

CloudBees CI now requires Red Hat OpenShift 4.19+

Starting with this release, support for Red Hat OpenShift 4.22 has been added and support for Red Hat OpenShift 4.17 and 4.18 have been removed. If you are using Red Hat OpenShift 4.17 or earlier, you must upgrade to Red Hat OpenShift 4.19 or later before upgrading to this CloudBees CI release.


Operations center CloudBees Assurance Program plugin changes since 2.568.3.37913

The following plugins have been added to the operations center CloudBees Assurance Program since 2.568.3.37913:

  • CloudBees OAuth Resource Server Plugin (cloudbees-oauth-resource)

  • CloudBees OAuth Authorization Server Plugin (cloudbees-oauth-server)

  • MCP Server Plugin (mcp-server)

The following plugins have been removed from the operations center CloudBees Assurance Program since 2.568.3.37913:

  • CloudBees Platform Insights Plugin (cloudbees-platform-insights)


Controller CloudBees Assurance Program plugin changes since 2.568.3.37913

The following plugins have been added to the controller CloudBees Assurance Program since 2.568.3.37913:

  • CloudBees OAuth Resource Server Plugin (cloudbees-oauth-resource)

The following plugins have been removed from the controller CloudBees Assurance Program since 2.568.3.37913:

  • CloudBees Platform Insights Plugin (cloudbees-platform-insights)


Windows LTSC 2019 agent images removed and LTSC 2025 added

As announced in the Windows Server 2019 Agent Containers End of Life, the Jenkins project is dropping inbound agent image builds for the end-of-life Windows LTSC 2019, while adding support for LTSC 2025. CloudBees CI Windows agent images are derived from the Jenkins versions, and are now aligned. Customers who cannot yet upgrade from LTSC 2019 Kubernetes node pools may temporarily pin older agent images.


New Features

CloudBees Mask Secrets is now generally available

Support for masking ephemeral credentials in Pipeline build logs and step arguments is now generally available (GA). Configure stock patterns for common ephemeral credential formats such as AWS STS tokens and JWTs, or define custom regular expression patterns for token formats specific to your environment. Optionally configure patterns to fail the build when a secret is detected, signaling to Pipeline authors to fix their Pipelines rather than relying on masking as a permanent solution.

For more information, refer to Mask ephemeral secrets in Pipeline build logs.


CloudBees CI MCP Router: Helm chart integration and OAuth authentication

The CloudBees CI MCP Router can now be deployed as an optional service in the CloudBees CI Helm chart. The CloudBees CI MCP Router also now supports OAuth authentication; rather than relying on one shared token, each request carries the identity of the person or tool that made it. To use OAuth authentication, install the required OAuth plugins on your operations center and controllers:

  • Operations center: CloudBees OAuth Authorization Server (cloudbees-oauth-server) and CloudBees OAuth Resource Server (cloudbees-oauth-resource)

  • Controllers: CloudBees OAuth Resource Server (cloudbees-oauth-resource)

Feature Enhancements

Software bill of materials for CloudBees CI on modern cloud platforms Docker images

The cloudbees-cloud-core-oc and cloudbees-core-mm Docker images include a software bill of materials (SBOM) in CycloneDX JSON format, available as an attestation alongside every image tag on Docker Hub for CloudBees CI on modern cloud platforms 2.568.1.37445 and later. You can download the SBOM to review software composition for compliance or risk assessment purposes. For more information, refer to the documentation for your platform:

Resolved Issues

Managed controller creation no longer fails on recent versions of OpenShift due to fsGroup

On recent versions of OpenShift, managed controller creation could fail with the error: provider restricted-v2: .spec.securityContext.fsGroup: Invalid value: []int64{1000}: 1000 is not an allowed group This has been resolved; managed controllers are now created successfully on recent versions of OpenShift.


Script Security plugin sandbox no longer rejects null string concatenation in Pipeline scripts

The Script Security plugin (script-security) sandbox incorrectly rejected operations performed on a null receiver as part of the SECURITY-3931 fix, causing sandboxed Pipeline scripts that concatenate a string onto a null value to fail. This has been resolved in Script Security plugin 1429.v0810f1b_530f5.


Controllers with long root URLs now connect successfully to the operations center

In environments where a controller’s root URL exceeded 64 characters, such as clusters with long hostnames or controllers with long names, the controller would start successfully but never reach a Connected state in the operations center. This affected all cluster types, including OpenShift, GKE, EKS, AKS, and kind. The controller now establishes its connection to the operations center regardless of root URL length.


Move/Copy/Promote destination autocomplete now filters suggestions correctly

When using Move/Copy/Promote, typing a partial path like cjp:///T for cjp:///Tasks in the destination field returned no suggestions, even though typing cjp:/// alone showed all available items. This made it appear as if the destination did not exist. The destination dropdown now correctly filters suggestions as you type.


Adopting a Pipeline build that has not yet started no longer leaves a High Availability (HA) controller in a corrupt state

A Pipeline build has an initial phase during which its definition is being loaded, before the Groovy logic is interpreted and the program state is recorded. This phase can include retrieving a Jenkinsfile from SCM, cloning libraries, or similar operations, and might run for a significant amount of time if SCM access is slow. If the owning replica exited during this phase, other replicas would attempt to adopt and resume the build but failed to do so, leaving the build recorded as running but not making progress, and potentially blocking subsequent builds. This fix also addresses related problems that could affect non-HA controllers.


Anonymized support bundles no longer include references to deleted or renamed items

When anonymization was enabled, support bundles retained references to deleted or renamed items, leading to increased support bundle size. Anonymized support bundles now correctly exclude these stale references.


Reduced CPU consumption for controllers during agent connection

CloudBees CI now caches JAR checksums, reducing CPU and I/O load on the controller when agents connect.

Known Issues

git-lfs removed from the default Linux agent image

Starting with the October 2026 CloudBees CI release, the default CloudBees CI Linux agent image will no longer include git-lfs. This change addresses frequent false-positive vulnerability scan findings caused by git-lfs in the default image.

Who is affected:

  • Linux agent users whose pipelines depend on git-lfs (for example, to pull or push Git LFS-tracked assets).

  • Windows agent images are not affected.

How to prepare:

  • No action is required if your pipelines do not use git-lfs.

  • Identify whether any of your pipelines depend on git-lfs.

  • If you need git-lfs, you will need to opt into an alternative image when this change is released. Instructions will be provided in the release documentation.


Java 25 becomes the default runtime for CloudBees CI Docker images

Starting with the October 2026 release, all CloudBees CI Docker images without a suffix will use Java 25 as the default runtime (equivalent to using the -jdk25 suffix). A Java 21 fallback image will remain available if you are not yet ready to migrate (equivalent to using the -jdk21 suffix). No action is required before the October 2026 release, but you should review your Java version requirements ahead of the upgrade. An administrative monitor has been added to notify you of this upcoming change.


Duplicate plugins in the Operations center Plugin Manager UI

When you search for a specific plugin under the Available tab in the Operations center Plugin Manager, the search results show duplicate entries for the plugin.