Jenkins - DSL / pipeline password Parameter problem

Viewed 186

We have a been using a particular password parameter in our Jenkins Job DSL and pipelines (passwordParameterDefinition). But after upgrading to Jenkins 2.249.x we can no longer use that parameter due to an unresolved issue LINK1 LINK2

All of our jobs are created using jbd-dsl and groovy files and for reasons I will not get into now, I am updating a few of these jobs to use the nonStoredPasswordParam with the mask-passwords plugin.

THE CODE Here is an example of a pipeline definition that is using this parameter.

pipelineJob('job/path/deployment/aws-parameter-store-job') {
  parameters {
      choiceParam('ACTION', ['Create', 'Update', 'Delete', 'Get'])
      stringParam('AppName', '', 'Enter the application')
      stringParam('AppEnv', '', 'Enter environment') 
      stringParam('Name', '', 'Enter Parameter Name')
      choiceParam('Account', ['sandbox','nonProd'], "Choose an AWS Account.")
      nonStoredPasswordParam('PASSWORD', 'Enter the password')
      // NOTE: the parameter below is being replaced 
      // by the nonStoredPasswordParam above ^^
      // passwordParameterDefinition {
      //   name('SECRET')
      //   defaultValue(null)
      //   description('SECRET')
      // }
    }
  environmentVariables {
      env('REGION', 'us-west-1')
  } 
  definition {
    cpsScm {
      scm {
        git {
            remote {
                url('git@my.gitserver.com:Automation/aws-parameter-store.git')
                credentials('creds')
            } 
            branch('development')
            extensions {
            cleanBeforeCheckout()
            }
         }
      }
      scriptPath("jenkinsfile")
    }
  }
}

And Here is a jenkinsfile for the pipeline that uses this parameter for in this job:

pipeline {
    agent any
    stages {
        stage('encrypt') {
            steps {
                withCredentials([[$class: 'AmazonWebServicesCredentialsBinding', credentialsId: "awskey-${env.Account}"]]) {
                sh script: "set +x; aws --region us-east-1 ssm put-parameter --name '/deployment/${Account}/${AppName}/${AppEnv}/${Name}' --type 'SecureString' --value '${PASSWORD}'"
                }
            }
        }
    }
}

NOTE: I have also tried --value '${params.PASSWORD} and --value '${env.PASSWORD}

THE RESULT The job runs without error, but the parameter being passed is not the PASSWORD, but null.

There are no good examples of using the nonStoredPasswordParam in a pipeline. I have been working on this for DAYS.

TL;DR Why is my nonStorePasswordParam returning null?

0 Answers
Related