Integration · CI/CD
Jenkins + OrchestrAI
Catalog exported 2026-09-02 · Jenkins website
Trigger Jenkins builds, read build status and logs, and create freestyle or pipeline jobs from chat.
OrchestrAI exposes 4 Jenkins operations: 2 are low-risk (read-only or low-impact), and 2 create or modify resources and run only after you confirm the plan. 2 of them also carry a step-level approval gate.
What teams use it for
Teams with a long-lived Jenkins controller use OrchestrAI to kick off a build with parameters, watch its status, and read the console log when it fails. Build status and logs are low risk, while triggering a build and creating a job are medium risk and each waits for confirmation. There is no operation to abort a running build, delete a job, or manage credentials and plugins, so those still happen in the Jenkins UI.
Every Jenkins operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Get Jenkins Build Logs |
Get Jenkins build logs | Low risk | No |
Get Jenkins Build Status |
Get Jenkins build status | Low risk | No |
Create Jenkins Job |
Create Jenkins job (freestyle or pipeline) | Creates resources | Yes |
Trigger Jenkins Build |
Trigger Jenkins build | Creates resources | Yes |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
What you connect
A Jenkins credential (stored as jenkins).
Connected-service tokens are envelope-encrypted with a per-record key wrapped by a cloud KMS.
Prompts that work
- Trigger the deploy-staging job in Jenkins with BRANCH=release/3.2
- Get the console log for build #214 of backend-tests and explain the failure
- Create a Jenkins pipeline job called nightly-regression that uses the Jenkinsfile in the qa-suite repo
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Can OrchestrAI stop a running Jenkins build?
- No. Coverage includes triggering builds, reading status and logs, and creating jobs, but aborting a build is not available yet.
- Does OrchestrAI ask before triggering a Jenkins build?
- Yes. Triggering a build is medium risk and marked for confirmation, so OrchestrAI shows the job and parameters and waits for approval.
- How does OrchestrAI authenticate to Jenkins?
- You add a Jenkins credential once in the connections screen. It is envelope-encrypted with a per-record key wrapped by a cloud KMS and is only decrypted inside the run that needs it.
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.