Q: Your legacy Jenkins master maintains 40 static EC2 build worker VMs running 24/7, costing $18,000/month. Build queues stall during peak hours, and VMs accumulate corrupted dependency caches and disk-full errors. How do you re-architect Jenkins to dynamically spawn single-use, ephemeral build agent pods on Kubernetes that terminate immediately after job completion?
Step-by-step engineering runbook for replacing static, expensive Jenkins VM build slaves with dynamic, on-demand ephemeral Kubernetes agent pods using the Kubernetes Cloud Plugin and JNLP.
Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Configure Jenkins Kubernetes Cloud Plugin & ServiceAccount
Establish communication between the Jenkins controller and the Kubernetes API server:
- RBAC Permissions: Granted Jenkins controller ServiceAccount permissions to create, get, and delete Pods and Secrets in the
jenkins-agentsnamespace. - Cloud Configuration: Configured Kubernetes Cloud in Jenkins Manage Nodes settings: Kubernetes URL
https://kubernetes.default.svc, Jenkins URLhttp://jenkins.jenkins.svc.cluster.local:8080, and JNLP Tunneljenkins-agent.jenkins.svc.cluster.local:50000.
Define Declarative Pod Templates with Specialized Build Containers
Structure multi-container build agent pods with dedicated toolchains:
- Declarative Pod Template: Declared pod template in Jenkinsfile:
podTemplate(containers: [ containerTemplate(name: 'golang', image: 'golang:1.22', command: 'sleep', args: '99d'), containerTemplate(name: 'helm', image: 'alpine/helm:3.14', command: 'sleep', args: '99d') ]). - Resource Limits: Enforced CPU/memory requests and limits on every container to prevent runaway builds from starving cluster worker nodes.
Establish High-Speed JNLP Agent Pod Communication
Ensure reliable communication between dynamic worker pods and the Jenkins controller:
- Inbound Agent Container: The
jenkins/inbound-agentJNLP sidecar boots automatically, connecting to Jenkins port 50000 over TCP. - Pipeline Execution: Steps execute inside specified containers using
container('golang') { sh 'go test ./...' }. - Instant Teardown: Upon pipeline completion, the Kubernetes API server deletes the agent pod immediately, releasing all compute memory and CPU.
Target Kubernetes Spot Nodes & Measure Cost Savings
Schedule agent pods onto elastic Spot instance compute pools:
- Node Tolerations: Configured pod templates with tolerations and node selectors targeting Spot instances.
- Financial Impact: Monthly CI infrastructure spend dropped from $18,000/month to $3,200/month (82% cost reduction).
- Zero Queue Latency: Agent capacity scales elastically from 0 to 200 concurrent pods in 15 seconds during peak morning commit surges.
- Configure the Jenkins Kubernetes Cloud plugin with least-privilege RBAC in the agent namespace.
- Define multi-container pod templates directly in Jenkinsfiles for Go, Java, and Helm runtimes.
- Connect agents over internal JNLP port 50000 and terminate pods immediately after build completion.
- Target Kubernetes Spot nodes to slash monthly CI compute expenses by over 80%.