Ansible and Jenkins in October 2026: ansible-core 2.21 and Jenkins LTS 2.580

Published 2 October 2026 · Updated 2 October 2026

In short. ansible-core 2.21 (May 2026) requires Python 3.12-3.14 on the controller and removes the paramiko plugin. Jenkins LTS 2.580.1 (30 September 2026) requires Java 21 or 25 and no longer bundles many legacy plugins. The risk lies in the dependencies: upgrade after an inventory and a trial on a copy.

Two very widely used automation tools have had changes that affect their dependencies: ansible-core 2.21 and Jenkins LTS 2.580.1. In both cases the upgrade is simple only if you take an inventory first.

ansible-core 2.21

Released on 18 May 2026 (latest confirmed patch: 2.21.3 of 10 August). Source: changelog and maintenance cycle.

  • Python on the controller: 3.12-3.14. On managed nodes: 3.9-3.14.
  • Support: critical fixes until November 2026, security until May 2027, end of support in November 2027. 2.20 ends in May 2027.
  • New features: variables registered with “projections” (fewer set_fact), a new implicit _task object, PowerShell 7 modules on POSIX hosts.
  • Breaking change: the default PSRP negotiate service changes from WSMAN to host; to revert, set ansible_psrp_negotiate_service=WSMAN.
  • Removed: the paramiko connection plugin and some interpreter discovery options (auto_legacy).
  • Deprecated: ansible.module_utils.six, the apt_key and apt_repository modules (replaced by deb822_repository) and inferring failure from the return code without a failed key.
  • Security (2.21.1): ansible-galaxy install passes role requirements as positional arguments to prevent injection through malicious git configurations.
  • Collections: the Ansible 14 community package is based on 2.21; Galaxy excludes collections with an incompatible requires_ansible by default. community.general no longer supports 2.17.

The migration guide for playbooks and the command line reports no significant changes. It has not been verified whether ansible-lint and ansible-navigator are compatible with 2.21 and Python 3.12-3.14: test them in your own workflow.

Jenkins LTS 2.580.1

Released on 30 September 2026; it requires Java 21 or 25. Java 17 has not been valid since the 2.555 line (April 2026). Source: LTS changelog and Java policy.

  • Main risk: nine plugins are no longer bundled in the controller package (including BouncyCastle API, JAXB, SSH server, JavaMail) and, when jumping from very old versions, also JUnit, Mailer, Matrix Authorization Strategy, Matrix Project and OWASP Markup Formatter. Configurations that use them (matrix security, multi-configuration jobs, test results, email) may fail to load. Source: 2.580 upgrade guide.
  • With access to the update centre, missing plugins are resolved as dependencies; without it, they must be copied manually before the upgrade.
  • Security: the September 2026 advisories (2 and 16) concern the core and many plugins, with issues such as sandbox bypass, XSS and exposed credentials. Stay on a recent LTS with up-to-date plugins.

Upgrade best practices

  1. Inventory: Jenkins version, Java on the controller and agents, installed plugins, ansible-core and Python versions, collections in use.
  2. Back up JENKINS_HOME and test the upgrade on a copy.
  3. Order for Jenkins: install the new Java, upgrade the controller, then the plugins; agents must have at least the controller’s minimum Java.
  4. Order for Ansible: upgrade Python on the controller, then ansible-core, then the collections; run the playbooks in check mode.
  5. Version jumps: read the guides for all the LTS versions skipped.
  6. Rollback: keep the backup and the previous version ready.

What has not been verified

The exact number of plugins and vulnerabilities in the advisories, the compatibility of ansible-lint and ansible-navigator, the date of ansible-core 2.21.4 and any LTS 2.580.2 have not been confirmed.

To put pipelines in code and automate releases, see Orchestration and automation.

Need a hand?

If you want to apply these points to your case, tell me in a few lines.

Let's talk