Sign inSign up

zaysahq/jenkins-agent

By zaysahq

•Updated 2 days ago

Attach-once Jenkins agent with docker + every cloud CLI — InfraHQ's build worker.

Image
Integration & delivery
Developer tools
0

536

zaysahq/jenkins-agent repository overview

Zaysa

⁠Zaysa Jenkins build agent

Attach once, never install a build tool again. A Jenkins inbound (JNLP) agent with the whole cross-provider CI/CD toolchain baked in — so Zaysa-generated pipelines (build → push → deploy, to any cloud) just work. This is Zaysa's equivalent of a Harness Delegate or a GitHub-hosted runner.

⁠Supported tags

TagDescription
1.1.0Isolated mode (default): agent runs its own rootless BuildKit (no host socket). Host-Docker mode is now an explicit opt-in.
1.0.1Agent hardening: pinned tool versions, SHA-256 checks, Microsoft signed repo for Azure CLI, secret file mount (no env var secret), base image digest pin.
1.0.0, latestFirst release on zaysahq. Java 21 base (current Jenkins LTS controllers), includes opa (pinned, SHA-256 verified) for the policy gate.

⁠Quick start

Zaysa generates the exact command for you (with the connection secret pre-filled) under Pipeline → Jenkins → Set up build agent. It looks like this:

(umask 077 && mkdir -p "$HOME/.zaysa" && printf '%s' '<secret from Zaysa>' > "$HOME/.zaysa/jenkins-agent-secret") && docker run -d --restart unless-stopped --name infrahq-agent \
  --security-opt seccomp=unconfined \
  --security-opt apparmor=unconfined \
  -v "$HOME/.zaysa/jenkins-agent-secret:/run/secrets/jenkins_secret:ro" \
  -e JENKINS_URL="https://your-jenkins.example.com" \
  -e JENKINS_AGENT_NAME="infrahq" \
  -e JENKINS_SECRET_FILE=/run/secrets/jenkins_secret \
  -e JENKINS_WEB_SOCKET=true \
  zaysahq/jenkins-agent:1.1.0@sha256:<digest>

Run it on any host that has Docker. The agent connects to your controller, labels itself infrahq, and every Zaysa pipeline targets it automatically.

⁠Environment variables

VariableRequiredDescription
JENKINS_URLyesYour Jenkins controller URL
JENKINS_AGENT_NAMEyesThe agent node name (Zaysa uses infrahq)
JENKINS_SECRET_FILEyesJNLP connection secret file path

By default, the agent runs in isolated mode, spinning up its own rootless BuildKit daemon for image builds. You can opt-in to legacy host-Docker mode by mounting -v /var/run/docker.sock:/var/run/docker.sock instead of using the --security-opt flags. Warning: Mounting the socket means pipeline steps run as root on the customer host.

⁠What's inside

ToolUsed for
docker CLI + buildxbuild & push container images
aws CLI v2ECR login · ECS / Lambda / App Runner / EKS
az CLIACR login · ACA / Web App / Functions / AKS
gcloud + GKE auth pluginGAR login · Cloud Run / App Engine / Cloud Functions / GKE
doctlDOCR login · DO App Platform
kubectlKubernetes rollouts
terraformthe provision stage (build NEW infra, then deploy)
git · openssh · jqcheckout · vm-ssh deploys · JSON

⁠Verify it connected

In Jenkins: Manage Jenkins → Nodes → the infrahq agent shows online. In Zaysa the Set up build agent panel flips to Connected ✓.

⁠Why this exists

You can't build a container image without a builder (a Docker daemon, or Kaniko/BuildKit) present somewhere — no CI platform removes that, Harness included. What a good platform removes is the per-CLI manual install and the cryptic mid-run failure. This image is that removal: one attach, full toolchain, every provider.

— Maintained by Zaysa⁠

Tag summary

Content type

Image

Digest

sha256:e68c8278c…

Size

731.8 MB

Last updated

2 days ago

docker pull zaysahq/jenkins-agent