Inbound Agents

Inbound Agents Behind a Firewall

An inbound agent opens the connection itself, so it works from networks the controller cannot reach. The classic transport is TCP port 50000 (published here as 32500), which firewalls often block; the WebSocket transport upgrades an ordinary request on the controller's web port instead, through the same proxy and TLS. agent-ws was defined like agent-1, with Use WebSocket ticked, and started with only the web URL:

An inbound agent that needs only the controller's HTTP portShell
docker run -d --name l2-agent-ws --init --network l2-jenkins-net --cpus 1 --memory 1g \
  jenkins/inbound-agent:latest-jdk21 -url http://l2-jenkins:8080/ -webSocket \
  -name agent-ws -secret "$SECRET" -workDir /home/jenkins/agent
docker logs l2-agent-ws 2>&1 | grep -E 'INFO: (Setting up|Using Remoting|WebSocket|Connected)'
Output
INFO: Setting up agent: agent-ws
INFO: Using Remoting version: 3391.va_37fa_a_305d6d
INFO: WebSocket connection open
INFO: Connected

The image's Remoting (3391) is newer than the controller's (3355); they interoperate, but keep images updated. The firewall needs only outbound HTTPS from agents to the controller. The controller cannot restart an inbound agent, so run it under systemd 142,543 , a Windows service or docker run --restart.