Upgrade Notes
- CloudBees CI now requires Red Hat OpenShift 4.19+
-
Starting with this release, support for Red Hat OpenShift 4.22 has been added and support for Red Hat OpenShift 4.17 and 4.18 have been removed. If you are using Red Hat OpenShift 4.17 or earlier, you must upgrade to Red Hat OpenShift 4.19 or later before upgrading to this CloudBees CI release.
- Operations center CloudBees Assurance Program plugin changes since 2.568.3.37913
-
The following plugins have been added to the operations center CloudBees Assurance Program since 2.568.3.37913:
-
CloudBees OAuth Resource Server Plugin (
cloudbees-oauth-resource) -
CloudBees OAuth Authorization Server Plugin (
cloudbees-oauth-server) -
MCP Server Plugin (
mcp-server)
-
The following plugins have been removed from the operations center CloudBees Assurance Program since 2.568.3.37913:
-
CloudBees Platform Insights Plugin (
cloudbees-platform-insights)
- Controller CloudBees Assurance Program plugin changes since 2.568.3.37913
-
The following plugins have been added to the controller CloudBees Assurance Program since 2.568.3.37913:
-
CloudBees OAuth Resource Server Plugin (
cloudbees-oauth-resource)
-
The following plugins have been removed from the controller CloudBees Assurance Program since 2.568.3.37913:
-
CloudBees Platform Insights Plugin (
cloudbees-platform-insights)
- Windows LTSC 2019 agent images removed and LTSC 2025 added
-
As announced in the Windows Server 2019 Agent Containers End of Life, the Jenkins project is dropping inbound agent image builds for the end-of-life Windows LTSC 2019, while adding support for LTSC 2025. CloudBees CI Windows agent images are derived from the Jenkins versions, and are now aligned. Customers who cannot yet upgrade from LTSC 2019 Kubernetes node pools may temporarily pin older agent images.
New Features
- CloudBees Mask Secrets is now generally available
-
Support for masking ephemeral credentials in Pipeline build logs and step arguments is now generally available (GA). Configure stock patterns for common ephemeral credential formats such as AWS STS tokens and JWTs, or define custom regular expression patterns for token formats specific to your environment. Optionally configure patterns to fail the build when a secret is detected, signaling to Pipeline authors to fix their Pipelines rather than relying on masking as a permanent solution.
For more information, refer to Mask ephemeral secrets in Pipeline build logs.
- CloudBees CI MCP Router: Helm chart integration and OAuth authentication
-
The CloudBees CI MCP Router can now be deployed as an optional service in the CloudBees CI Helm chart. The CloudBees CI MCP Router also now supports OAuth authentication; rather than relying on one shared token, each request carries the identity of the person or tool that made it. To use OAuth authentication, install the required OAuth plugins on your operations center and controllers:
-
Operations center: CloudBees OAuth Authorization Server (
cloudbees-oauth-server) and CloudBees OAuth Resource Server (cloudbees-oauth-resource) -
Controllers: CloudBees OAuth Resource Server (
cloudbees-oauth-resource)
-
Resolved Issues
- Script Security plugin sandbox no longer rejects
nullstring concatenation in Pipeline scripts -
The Script Security plugin (
script-security) sandbox incorrectly rejected operations performed on anullreceiver as part of the SECURITY-3931 fix, causing sandboxed Pipeline scripts that concatenate a string onto anullvalue to fail. This has been resolved in Script Security plugin 1429.v0810f1b_530f5.
- Controllers with long root URLs now connect successfully to the operations center
-
In environments where a controller’s root URL exceeded 64 characters, such as clusters with long hostnames or controllers with long names, the controller would start successfully but never reach a Connected state in the operations center. This affected all cluster types, including OpenShift, GKE, EKS, AKS, and kind. The controller now establishes its connection to the operations center regardless of root URL length.
- Move/Copy/Promote destination autocomplete now filters suggestions correctly
-
When using Move/Copy/Promote, typing a partial path like
cjp:///Tforcjp:///Tasksin the destination field returned no suggestions, even though typingcjp:///alone showed all available items. This made it appear as if the destination did not exist. The destination dropdown now correctly filters suggestions as you type.
- Adopting a Pipeline build that has not yet started no longer leaves a High Availability (HA) controller in a corrupt state
-
A Pipeline build has an initial phase during which its definition is being loaded, before the Groovy logic is interpreted and the program state is recorded. This phase can include retrieving a
Jenkinsfilefrom SCM, cloning libraries, or similar operations, and might run for a significant amount of time if SCM access is slow. If the owning replica exited during this phase, other replicas would attempt to adopt and resume the build but failed to do so, leaving the build recorded as running but not making progress, and potentially blocking subsequent builds. This fix also addresses related problems that could affect non-HA controllers.
- Anonymized support bundles no longer include references to deleted or renamed items
-
When anonymization was enabled, support bundles retained references to deleted or renamed items, leading to increased support bundle size. Anonymized support bundles now correctly exclude these stale references.
- Reduced CPU consumption for controllers during agent connection
-
CloudBees CI now caches JAR checksums, reducing CPU and I/O load on the controller when agents connect.