SSH Agents

Connecting a Permanent Agent over SSH

With an SSH agent, the controller logs in with a key, copies remoting.jar over SFTP and starts it, so the machine needs only sshd, Java and a user, all of which the official jenkins/ssh-agent image (github.com/jenkinsci/docker-ssh-agent (https://github.com/jenkinsci/docker-ssh-agent 208 )) provides. BookNest's image adds the Docker 514 CLI and its plugins, and a docker group matching the host socket's group ID:

agents/docker-agent/DockerfileDockerfile
FROM jenkins/ssh-agent:latest-jdk21
COPY --from=docker:29.8.1-cli /usr/local/bin/docker /usr/local/bin/docker
COPY --from=docker:29.8.1-cli /usr/local/libexec/docker/cli-plugins \
     /usr/local/libexec/docker/cli-plugins
ARG DOCKER_GID=986
RUN groupadd -g "${DOCKER_GID}" docker && usermod -aG docker jenkins
Building and starting the SSH agent with its public keyGroovy
ssh-keygen -q -t ed25519 -N '' -C jenkins-agent-ssh -f ssh/agent_key
docker build -q -t l2-agent-docker:1 \
  --build-arg DOCKER_GID=$(stat -c %g /var/run/docker.sock) docker-agent
docker run -d --name l2-agent-ssh --network l2-jenkins-net --cpus 2 --memory 2g \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v /var/lib/l2-agent-ssh:/var/lib/l2-agent-ssh \
  -e "JENKINS_AGENT_SSH_PUBKEY=$(cat ssh/agent_key.pub)" l2-agent-docker:1

The private key became the credential agent-ssh-key (user jenkins) in the System scope, usable for launching agents but invisible to jobs. The node agent-ssh (two executors, labels linux docker, Exclusive) pins the container's host key (Manually provided key), and its launch log reads "SSH host key matched", "Authentication successful", "Copied 1,407,938 bytes" (remoting.jar) and "Agent successfully connected and online".