# Oidc-provider plugin not picking up all envvars

**URL:** <https://community.jenkins.io/t/oidc-provider-plugin-not-picking-up-all-envvars/15239>\
**Category:** Using Jenkins\
**Tags:** question\
**Created:** [May 17, 2024, 10:48am UTC](https://community.jenkins.io/t/oidc-provider-plugin-not-picking-up-all-envvars/15239 "2024-05-17T10:48:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gczuczy](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/gczuczy/32/8272_2.png) [@gczuczy](https://community.jenkins.io/u/gczuczy)\
**Post date:** [May 17, 2024, 10:48am UTC](https://community.jenkins.io/t/oidc-provider-plugin-not-picking-up-all-envvars/15239/1 "2024-05-17T10:48:12Z")

</div>

Hello,

I would like to ask for a bit of help. I’m trying to figure out why the [oidc-provider](https://github.com/jenkinsci/oidc-provider-plugin) plugin is not picking up the `GIT_` envvars, i would need it to put the commit sha and repourl into the claim. I’ve checked the plugin out, and some debugging told me it’s only picking up the following envvars:

```auto
BRANCH_IS_PRIMARY,BRANCH_NAME,BUILD_DISPLAY_NAME,BUILD_ID,BUILD_NUMBER,BUILD_TAG,BUILD_URL,CI,CLASSPATH,HUDSON_HOME,HUDSON_SERVER_COOKIE,HUDSON_URL,JENKINS_HOME,JENKINS_SERVER_COOKIE,JENKINS_URL,JOB_BASE_NAME,JOB_DISPLAY_URL,JOB_NAME,JOB_URL,RUN_ARTIFACTS_DISPLAY_URL,RUN_CHANGES_DISPLAY_URL,RUN_DISPLAY_URL,RUN_TESTS_DISPLAY_URL

```

And the plugin is fetching the envvars [here](https://github.com/jenkinsci/oidc-provider-plugin/blob/caff89837ec659600e08245635d2bea5e53a3ed8/src/main/java/io/jenkins/plugins/oidc_provider/IdTokenCredentials.java#L195).  
are there any docs which are explaining how envvar propagation is working among plugins, how to query more envvars, etc. Basically how the plugin architecture isworking?

## Jenkins setup: Jenkins: 2.440.2 OS: Linux - 5.15.133+ Java: 17.0.10 - Eclipse Adoptium (OpenJDK 64-Bit Server VM)

Parameterized-Remote-Trigger:3.2.0  
ace-editor:1.1  
active-directory:2.35  
analysis-model-api:12.3.3  
ansicolor:1.0.4  
ant:497.v94e7d9fffa\_b\_9  
antisamy-markup-formatter:162.v0e6ec0fcfcf6  
apache-httpcomponents-client-4-api:4.5.14-208.v438351942757  
apache-httpcomponents-client-5-api:5.3.1-1.0  
artifactory:4.0.6  
asm-api:9.7-33.v4d23ef79fcc8  
audit-trail:361.v82cde86c784e  
authentication-tokens:1.53.v1c90fd9191a\_b\_  
aws-credentials:231.v08a\_59f17d742  
aws-java-sdk-ec2:1.12.696-451.v0651a\_da\_9ca\_ec  
aws-java-sdk-minimal:1.12.696-451.v0651a\_da\_9ca\_ec  
badge:1.9.1  
basic-branch-build-strategies:81.v05e333931c7d  
blackduck-detect:9.0.0  
blueocean:1.27.12  
blueocean-autofavorite:1.2.5  
blueocean-bitbucket-pipeline:1.27.12  
blueocean-commons:1.27.12  
blueocean-config:1.27.12  
blueocean-core-js:1.27.12  
blueocean-dashboard:1.27.12  
blueocean-display-url:2.4.2  
blueocean-events:1.27.12  
blueocean-git-pipeline:1.27.12  
blueocean-github-pipeline:1.27.12  
blueocean-i18n:1.27.12  
blueocean-jwt:1.27.12  
blueocean-personalization:1.27.12  
blueocean-pipeline-api-impl:1.27.12  
blueocean-pipeline-editor:1.27.12  
blueocean-pipeline-scm-api:1.27.12  
blueocean-rest:1.27.12  
blueocean-rest-impl:1.27.12  
blueocean-web:1.27.12  
bootstrap4-api:4.6.0-6  
bootstrap5-api:5.3.3-1  
bouncycastle-api:2.30.1.77-225.v26ea\_c9455fd9  
branch-api:2.1163.va\_f1064e4a\_a\_f3  
build-timestamp:1.0.3  
caffeine-api:3.1.8-133.v17b\_1ff2e0599  
checkmarx:2024.2.3  
checks-api:2.2.0  
cloud-stats:336.v788e4055508b\_  
cloudbees-bitbucket-branch-source:883.v041fa\_695e9c2  
cloudbees-folder:6.901.vb\_4c7a\_da\_75da\_3  
cobertura:1.17  
code-coverage-api:4.99.0  
command-launcher:107.v773860566e2e  
commons-lang3-api:3.13.0-62.v7d18e55f51e2  
commons-text-api:1.11.0-109.vfe16c66636eb\_  
config-file-provider:973.vb\_a\_80ecb\_9a\_4d0  
configuration-as-code:1775.v810dc950b\_514  
copyartifact:722.v0662a\_9b\_e22a\_c  
coverage:1.14.0  
credentials:1337.v60b\_d7b\_c7b\_c9f  
credentials-binding:657.v2b\_19db\_7d6e6d  
dashboard-view:2.508.va\_74654f026d1  
data-tables-api:2.0.5-1  
dependency-check-jenkins-plugin:5.5.0  
dependency-track:4.3.1  
disk-usage:1.2  
display-url-api:2.200.vb\_9327d658781  
docker-commons:439.va\_3cb\_0a\_6a\_fb\_29  
docker-workflow:572.v950f58993843  
durable-task:555.v6802fe0f0b\_82  
echarts-api:5.5.0-1  
email-ext:1806.v856a\_01a\_fa\_39a\_  
embeddable-build-status:487.va\_0ef04c898a\_2  
envinject:2.908.v66a\_774b\_31d93  
envinject-api:1.199.v3ce31253ed13  
extended-read-permission:53.v6499940139e5  
external-monitor-job:215.v2e88e894db\_f8  
favorite:2.208.v91d65b\_7792a\_c  
font-awesome-api:6.5.2-1  
forensics-api:2.4.0  
generic-webhook-trigger:2.2.0  
git:5.2.1  
git-client:4.7.0  
git-server:114.v068a\_c7cc2574  
git-tag-message:1.7.1  
github:1.38.0  
github-api:1.318-461.v7a\_c09c9fa\_d63  
github-autostatus:3.6.2  
github-branch-source:1787.v8b\_8cd49a\_f8f1  
github-label-filter:1.0.0  
github-oauth:597.ve0c3480fcb\_d0  
github-pr-comment-build:103.vc8919acf2a6b  
global-slack-notifier:1.5  
golang:1.4  
google-metadata-plugin:0.5  
google-oauth-plugin:1.330.vf5e86021cb\_ec  
google-storage-plugin:1.360.v6ca\_38618b\_41f  
gradle:2.11  
greenballs:1.15.1  
groovy-postbuild:228.vcdb\_cf7265066  
gson-api:2.10.1-15.v0d99f670e0a\_7  
h2-api:11.1.4.199-12.v9f4244395f7a\_  
handlebars:3.0.8  
handy-uri-templates-2-api:2.1.8-30.v7e777411b\_148  
hashicorp-vault-plugin:367.v8a\_1ee1cccf3a  
htmlpublisher:1.33  
http\_request:1.18  
influxdb:3.6.1  
instance-identity:185.v303dc7c645f9  
ionicons-api:70.v2959a\_b\_74e3cf  
ivy:2.5  
jackson2-api:2.17.0-379.v02de8ec9f64c  
jacoco:3.3.6  
jakarta-activation-api:2.1.3-1  
jakarta-mail-api:2.1.3-1  
javadoc:243.vb\_b\_503b\_b\_45537  
javax-activation-api:1.2.0-6  
javax-mail-api:1.6.2-9  
jaxb:2.3.9-1  
jdk-tool:73.vddf737284550  
jenkins-design-language:1.27.12  
jersey2-api:2.42-147.va\_28a\_44603b\_d5  
jira:3.13  
jjwt-api:0.11.5-112.ve82dfb\_224b\_a\_d  
job-dsl:1.87  
joda-time-api:2.12.7-29.v5a\_b\_e3a\_82269a\_  
jquery-detached:1.2.1  
jquery3-api:3.7.1-2  
jsch:0.2.16-86.v42e010d9484b\_  
json-api:20240303-41.v94e11e6de726  
json-path-api:2.9.0-58.v62e3e85b\_a\_655  
junit:1265.v65b\_14fa\_f12f0  
kubernetes:4203.v1dd44f5b\_1cf9  
kubernetes-client-api:6.10.0-240.v57880ce8b\_0b\_2  
kubernetes-credentials:0.11  
ldap:725.v3cb\_b\_711b\_1a\_ef  
lockable-resources:1255.vf48745da\_35d0  
mailer:472.vf7c289a\_4b\_420  
mask-passwords:173.v6a\_077a\_291eb\_5  
matrix-auth:3.2.2  
matrix-project:822.824.v14451b\_c0fd42  
maven-plugin:3.23  
mercurial:1260.vdfb\_723cdcc81  
metrics:4.2.21-449.v6960d7c54c69  
mina-sshd-api-common:2.12.1-101.v85b\_e08b\_780dd  
mina-sshd-api-core:2.12.1-101.v85b\_e08b\_780dd  
momentjs:1.1.1  
multibranch-build-strategy-extension:51.v88f14e2a\_4075  
naginator:1.449.ve19751d70eb\_0  
nodejs:1.6.1  
oauth-credentials:0.646.v02b\_66dc03d2e  
oidc-provider:62.vd67c19f76766  
okhttp-api:4.11.0-172.vda\_da\_1feeb\_c6e  
openstack-cloud:2.65  
pam-auth:1.10  
parameterized-scheduler:262.v00f3d90585cc  
parameterized-trigger:787.v665fcf2a\_830b\_  
percentage-du-node-column:0.1.0  
performance:957.v658a\_7065b\_92a\_  
pipeline-build-step:540.vb\_e8849e1a\_b\_d8  
pipeline-github:2.8-159.09e4403bc62f  
pipeline-githubnotify-step:49.vf37bf92d2bc8  
pipeline-graph-analysis:216.vfd8b\_ece330ca\_  
pipeline-groovy-lib:704.vc58b\_8890a\_384  
pipeline-input-step:495.ve9c153f6067b\_  
pipeline-maven:1396.veb\_f07b\_2fc1d8  
pipeline-maven-api:1396.veb\_f07b\_2fc1d8  
pipeline-milestone-step:119.vdfdc43fc3b\_9a\_  
pipeline-model-api:2.2198.v41dd8ef6dd56  
pipeline-model-definition:2.2198.v41dd8ef6dd56  
pipeline-model-extensions:2.2198.v41dd8ef6dd56  
pipeline-rest-api:2.34  
pipeline-stage-step:312.v8cd10304c27a\_  
pipeline-stage-tags-metadata:2.2198.v41dd8ef6dd56  
pipeline-stage-view:2.34  
pipeline-utility-steps:2.16.2  
plain-credentials:179.vc5cb\_98f6db\_38  
plugin-util-api:4.1.0  
popper-api:1.16.1-3  
popper2-api:2.11.6-4  
prism-api:1.29.0-13  
pubsub-light:1.18  
rebuild:332.va\_1ee476d8f6d  
resource-disposer:0.23  
robot:3.5.1  
role-strategy:717.v6a\_69a\_fe98974  
run-condition:1.7  
saferestart:0.7  
saml:4.464.vea\_cb\_75d7f5e0  
scm-api:690.vfc8b\_54395023  
script-security:1335.vf07d9ce377a\_e  
sidebar-link:2.4.1  
simple-theme-plugin:176.v39740c03a\_a\_f5  
slack:684.v833089650554  
snakeyaml-api:2.2-111.vc6598e30cc65  
sonar:2.17.2  
sse-gateway:1.26  
ssh-agent:367.vf9076cd4ee21  
ssh-credentials:337.v395d2403ccd4  
ssh-slaves:2.948.vb\_8050d697fec  
sshd:3.322.v159e91f6a\_550  
startup-trigger-plugin:2.9.4  
strict-crumb-issuer:2.1.1  
structs:337.v1b\_04ea\_4df7c8  
timestamper:1.26  
token-macro:400.v35420b\_922dcb\_  
trilead-api:2.142.v748523a\_76693  
variant:60.v7290fc0eb\_b\_cd  
view-job-filters:369.ve0513a\_a\_f5524  
warnings-ng:11.3.0  
webhook-step:342.v620877effe14  
windows-slaves:1.8.1  
workflow-aggregator:596.v8c21c963d92d  
workflow-api:1291.v51fd2a\_625da\_7  
workflow-basic-steps:1058.vcb\_fc1e3a\_21a\_9  
workflow-cps:3894.vd0f0248b\_a\_fc4  
workflow-cps-global-lib:612.v55f2f80781ef  
workflow-cps-global-lib-http:2.48.0  
workflow-durable-task-step:1336.v768003e07199  
workflow-job:1400.v7fd111b\_ec82f  
workflow-multibranch:773.vc4fe1378f1d5  
workflow-scm-step:427.v4ca\_6512e7df1  
workflow-step-api:657.v03b\_e8115821b\_  
workflow-support:896.v175a\_a\_9c5b\_78f  
ws-cleanup:0.45

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [May 20, 2024, 10:09am UTC](https://community.jenkins.io/t/oidc-provider-plugin-not-picking-up-all-envvars/15239/2 "2024-05-20T10:09:04Z")

</div>

Hello and welcome to this community, @gczuczy . 👋

In Jenkins, environment variables are typically made available to plugins through the [`EnvVars`](https://javadoc.jenkins-ci.org/hudson/EnvVars.html) class, which provides a map-like interface to access the variables.

The [oidc-provider plugin](https://plugins.jenkins.io/oidc-provider/), like many other Jenkins plugins, likely uses this class to access environment variables (I haven’t [checked](https://github.com/jenkinsci/oidc-provider-plugin/blob/caff89837ec659600e08245635d2bea5e53a3ed8/src/main/java/io/jenkins/plugins/oidc_provider/IdTokenCredentials.java#L200) thoroughly, though).

The list of environment variables you provided seems to be the standard set of variables that Jenkins provides for each build.  
These include information about the build itself, the job that triggered the build, and the Jenkins instance.

If you want to make additional environment variables available to the `oidc-provider` plugin, you would typically do this in your pipeline script or job configuration. 🤔

For example, you could use the [`withEnv`](https://www.jenkins.io/doc/pipeline/steps/workflow-basic-steps/#withenv-set-environment-variables) step in a pipeline script to set environment variables for a block of steps:

```auto
withEnv(['GIT_COMMIT_SHA=${GIT_COMMIT}', 'GIT_REPO_URL=${GIT_URL}']) {
    // Steps that need the GIT_COMMIT_SHA and GIT_REPO_URL variables
}

```

In this example, `GIT_COMMIT` and `GIT_URL` are built-in Jenkins environment variables that contain the commit SHA and repository URL for the current build. The `withEnv` step makes these values available as `GIT_COMMIT_SHA` and `GIT_REPO_URL` for the steps inside the block.

However, whether the oidc-provider plugin can actually use these variables depends on how the plugin is implemented. 🤷  
If the plugin only reads environment variables at the start of the build, then setting variables in the pipeline script might not have any effect. 🤔

As for your question about how environment variable propagation works among plugins, there isn’t a general answer because it depends on how each plugin is implemented. Some plugins might read environment variables directly from the [`EnvVars`](https://github.com/search?q=org%3Ajenkinsci+EnvVars&type=code) class, while others might require you to configure the variables in the Jenkins UI or in a pipeline script.

For more detailed information about how the oidc-provider plugin works with environment variables, I would recommend looking at the [plugin’s documentation](https://plugins.jenkins.io/oidc-provider/) or [source code](https://github.com/jenkinsci/oidc-provider-plugin).

Regarding the plugin architecture in Jenkins, it’s a broad topic I don’t mаster, but here are some key points to me:

- Jenkins plugins are written in Java and packaged as `.hpi` files.
- Each plugin provides an extension point, which is a Java interface that other plugins can implement to extend Jenkins’ functionality.
- Plugins can also contribute to the Jenkins UI by adding new pages, menu items, etc.
- Jenkins provides a number of core APIs and services that plugins can use, such as the `EnvVars` class for accessing environment variables.

For a more in-depth understanding, you might want to check out the [Jenkins plugin tutorial](https://www.jenkins.io/doc/developer/tutorial/) and [developer documentation](https://www.jenkins.io/doc/developer/), which provide a lot of information about how to create and work with Jenkins plugins.

---

<div class="post-metadata">

**Author:** ![gczuczy](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/gczuczy/32/8272_2.png) [@gczuczy](https://community.jenkins.io/u/gczuczy)\
**Post date:** [May 21, 2024, 8:45am UTC](https://community.jenkins.io/t/oidc-provider-plugin-not-picking-up-all-envvars/15239/3 "2024-05-21T08:45:16Z")

</div>

Thank you, unfortunately this did not bring any improvements. With `withEnv` the claim has the raw strings (I’ve replaced it with double quotes, since singles do not do variable replacement):

```auto
     "git_commit": "${GIT_COMMIT}",
10:39:35 "git_commit_sha": "${GIT_COMMIT_SHA}",
10:39:35 "git_repo_url": "${GIT_REPO_URL}",
10:39:35 "git_url": "${GIT_URL}",
10:39:35 "github_repo": "${GITHUB_REPO}",

```

In the original post I’ve linked the exact line of the source (so I came here asking, after I’ve gone through most of the resources you’ve linked, and reading and locally debugging the source of the plugin), but here it is:

```auto
 env = build.getEnvironment(TaskListener.NULL);

```

This is how the plugin is getting its envvars. What I wasn’t able to find, is how the `build` variable is “there”, it’s just here, and what’s the effect of the NULL tasklistener. Also, how does this relate to a job itself (versus global environment variables)?
