The Kubernetes 5,150 plugin (4557.ve746270f672f) treats a cluster as a cloud: for each build it creates a pod whose jnlp container runs the inbound agent, then deletes it. Here a one-node kind cluster, l2-agents, runs only agent pods, with Kubernetes's RBAC for Jenkins 8,793 (a jenkins namespace, a ServiceAccount and a Role limited to pods there); docker network connect kind l2-jenkins joins the controller to its network. The cloud uses a kubeconfig with the ServiceAccount's token (a Secret file credential), namespace jenkins, Jenkins URL http://l2-jenkins:8080/, WebSocket and at most two pods. The pod template lives in the Jenkinsfile:
pipeline {
agent {
kubernetes {
cloud 'l2-agents'
defaultContainer 'node'
yaml '''
spec:
containers:
- name: jnlp
image: jenkins/inbound-agent:latest-jdk21
resources: {requests: {cpu: 100m, memory: 256Mi}, limits: {memory: 512Mi}}
- name: node
image: node:24-alpine
command: [sleep, infinity]
resources: {requests: {cpu: 250m, memory: 256Mi}, limits: {cpu: 1, memory: 768Mi}}
'''
}
}
stages {
stage('Install') {
steps {
container('jnlp') {
git url: 'https://github.com/binarybehemoth/booknest-jenkins.git', branch: 'main'
}
sh 'echo "$NODE_NAME: node $(node --version)" && npm ci --no-audit --no-fund'
}
}
}
}Created Pod: l2-agents jenkins/k8s-pod-7-14859-b6hrr-0dkxl ... k8s-pod-7-14859-b6hrr-0dkxl: node v24.21.0 ... added 82 packages in 3s
defaultContainer 'node' sends each sh to the Node.js 2,131 container, which shares the workspace with jnlp; Git 1,932 runs in jnlp because Alpine 13,255 's Node image lacks it. The pod agent exists only while its build runs:

Build 7 took 17 seconds, pod creation included (the very first pod took four minutes to connect). kind load docker-image failed here ("content digest ... not found"), so docker save --platform linux/amd64 ... | ctr images import loaded the images instead.