[ci.jenkins.io] Enforced authentication and user / API token cleanup

7 views
Skip to first unread message

Damien Duportal

unread,
Jan 28, 2026, 1:06:20 PM (2 days ago) Jan 28
to Jenkins Developers
Hello dear contributors,

As detailed in https://github.com/jenkins-infra/helpdesk/issues/4971, we're going to perform an operation, today, on ci.jenkins.io which will:
- Enforce authentication to access build pages/logs with your Jenkins LDAP account
- Clean up the user directory, wiping out all settings (API tokens, appearance, etc.).

Enforcing authentication comes as a direct consequence of many abusive usages from content scrappers in the past weeks (if not months) which are threatening the ci.jenkins.io service itself, its usage and also the platform. It's the only way to keep ci.jenkins.io running and sustainable while allowing the Jenkins infrastructure team not to waste our time on playing cat and mouse with script kiddies or careless LLM users.

On the user directory wiping out, it's an opportunity to get rid of literally thousands of inactive accounts (older ones are from 2017) and avoid putting too much strain on the controller restarts (failed migration of user format since 2.528.1).

Thanks for your understanding.

For the Jenkins infra team, 
Damien Duportal

Reply all
Reply to author
Forward
0 new messages