An inbound agent opens the connection itself, so it works from networks the controller cannot reach. The classic transport is TCP port 50000 (published here as 32500), which firewalls often block; the WebSocket transport upgrades an ordinary request on the controller's web port instead, through the same proxy and TLS. agent-ws was defined like agent-1, with Use WebSocket ticked, and started with only the web URL:
docker run -d --name l2-agent-ws --init --network l2-jenkins-net --cpus 1 --memory 1g \
jenkins/inbound-agent:latest-jdk21 -url http://l2-jenkins:8080/ -webSocket \
-name agent-ws -secret "$SECRET" -workDir /home/jenkins/agent
docker logs l2-agent-ws 2>&1 | grep -E 'INFO: (Setting up|Using Remoting|WebSocket|Connected)'INFO: Setting up agent: agent-ws INFO: Using Remoting version: 3391.va_37fa_a_305d6d INFO: WebSocket connection open INFO: Connected
The image's Remoting (3391) is newer than the controller's (3355); they interoperate, but keep images updated. The firewall needs only outbound HTTPS from agents to the controller. The controller cannot restart an inbound agent, so run it under systemd 142,543 , a Windows service or docker run --restart.