spk-logo-white-text-short2
0%
1-888-310-4540 (main) / 1-888-707-6150 (support) info@spkaa.com
Select Page

Using Credentials In Code In CloudBees SDA

Using-Credentials-in-Code
Written by Joshua Kling
Published on February 1, 2022

Credentials Are Tough By Design

Credentials in Cloudbees SDA are admittedly a little tricky to get to. This is by design.  If it were any easier, it could be a potential security risk. There is really just one way to use credentials in code, and it’s a multi-step process. Here are the steps:

  1. Set the credential.
  2. Attach it to a step.
  3. Use it.

Careful manipulation is required here, as the software requires very exact definitions to get to this information. Any single missed parameter or missing ACL will return an error code.

How To Set The Credential

It is very simple to set a credential in CloudBees SDA.  First, start at the project level, or go to the credential screen, and add a new cred. You’ll be able to add a name, description, username, password, and set it to a local or external credential. Once it’s set, hit OK and head to the location where you intend to use it.

where to edit credentials

Attachment

Once a credential is set, it’s available in any pipeline or procedure that can access that project. However, you will need to grant explicit access permission for the pipeline or procedure that will use it.  You do this through the attaching feature. From within a pipeline, the code for this command looks like this:

ectool attachCredential "<project name>" "<credential name>" --pipelineName $[/myPipeline] 
--stageName $[/myStage] --taskName $[/myTask]

In this case, all of these flags are important. Please note that if you call it from a procedure context, you’ll need to use –stepName instead of –taskName, as these are different from pipeline tasks.

Using The Credential

Once the credential is attached to a task or step, using it is a simple matter. Use these two lines of code to pull the username or password into any script or bash command:

ectool getFullCredential "/projects/<project name>/credentials/<credential name>" --value password
ectool getFullCredential "/projects/<project name>/credentials/<credential name>" --value userName

They can be set to variables or used inline, depending on the context, such as an API call to a third party tool. Credentials are a powerful tool in CloudBees SDA — they can be used for more than just basic authentication. You can save any kind of secret in the password field, including tokens, making them a convenient way to hide secure information with confidence.

If you have any questions about credentials in SDA, or need help getting started, reach out to us and we’d be happy to help.

Latest White Papers

Atlassian and AWS: Supercharging the Future of Work for Enterprise

Atlassian and AWS: Supercharging the Future of Work for Enterprise

Adopting cloud technologies can lead to benefits such as enhanced collaboration or expedited decision-making. Explore how the collaboration between Atlassian and AWS achieves these results.What You Will Learn In this eBook, you will discover: Key benefits of cloud...

Related Resources

Continuous Compliance for Automotive Software Updates

Continuous Compliance for Automotive Software Updates

Key Takeaways Automotive compliance must be continuous. Regulations such as UNECE R155 and R156 require teams to manage cybersecurity risks and software updates throughout the vehicle lifecycle, not just at audit time. Disconnected tools make compliance difficult....

What Is an AI Agent Really?

What Is an AI Agent Really?

Key Takeaways AI agents go beyond generating responses. They can gather context, use tools, take actions, and work through multiple steps toward a defined goal. A model provides intelligence, while an agent puts that intelligence to work. Agents combine models with...