Attach-once Jenkins agent with docker + every cloud CLI — InfraHQ's build worker.
536
Attach once, never install a build tool again. A Jenkins inbound (JNLP) agent with the whole cross-provider CI/CD toolchain baked in — so Zaysa-generated pipelines (build → push → deploy, to any cloud) just work. This is Zaysa's equivalent of a Harness Delegate or a GitHub-hosted runner.
| Tag | Description |
|---|---|
1.1.0 | Isolated mode (default): agent runs its own rootless BuildKit (no host socket). Host-Docker mode is now an explicit opt-in. |
1.0.1 | Agent hardening: pinned tool versions, SHA-256 checks, Microsoft signed repo for Azure CLI, secret file mount (no env var secret), base image digest pin. |
1.0.0, latest | First release on zaysahq. Java 21 base (current Jenkins LTS controllers), includes opa (pinned, SHA-256 verified) for the policy gate. |
Zaysa generates the exact command for you (with the connection secret pre-filled) under Pipeline → Jenkins → Set up build agent. It looks like this:
(umask 077 && mkdir -p "$HOME/.zaysa" && printf '%s' '<secret from Zaysa>' > "$HOME/.zaysa/jenkins-agent-secret") && docker run -d --restart unless-stopped --name infrahq-agent \
--security-opt seccomp=unconfined \
--security-opt apparmor=unconfined \
-v "$HOME/.zaysa/jenkins-agent-secret:/run/secrets/jenkins_secret:ro" \
-e JENKINS_URL="https://your-jenkins.example.com" \
-e JENKINS_AGENT_NAME="infrahq" \
-e JENKINS_SECRET_FILE=/run/secrets/jenkins_secret \
-e JENKINS_WEB_SOCKET=true \
zaysahq/jenkins-agent:1.1.0@sha256:<digest>
Run it on any host that has Docker. The agent connects to your controller, labels itself infrahq,
and every Zaysa pipeline targets it automatically.
| Variable | Required | Description |
|---|---|---|
JENKINS_URL | yes | Your Jenkins controller URL |
JENKINS_AGENT_NAME | yes | The agent node name (Zaysa uses infrahq) |
JENKINS_SECRET_FILE | yes | JNLP connection secret file path |
By default, the agent runs in isolated mode, spinning up its own rootless BuildKit daemon for image builds. You can opt-in to legacy host-Docker mode by mounting -v /var/run/docker.sock:/var/run/docker.sock instead of using the --security-opt flags. Warning: Mounting the socket means pipeline steps run as root on the customer host.
| Tool | Used for |
|---|---|
| docker CLI + buildx | build & push container images |
| aws CLI v2 | ECR login · ECS / Lambda / App Runner / EKS |
| az CLI | ACR login · ACA / Web App / Functions / AKS |
| gcloud + GKE auth plugin | GAR login · Cloud Run / App Engine / Cloud Functions / GKE |
| doctl | DOCR login · DO App Platform |
| kubectl | Kubernetes rollouts |
| terraform | the provision stage (build NEW infra, then deploy) |
| git · openssh · jq | checkout · vm-ssh deploys · JSON |
In Jenkins: Manage Jenkins → Nodes → the infrahq agent shows online. In Zaysa the
Set up build agent panel flips to Connected ✓.
You can't build a container image without a builder (a Docker daemon, or Kaniko/BuildKit) present somewhere — no CI platform removes that, Harness included. What a good platform removes is the per-CLI manual install and the cryptic mid-run failure. This image is that removal: one attach, full toolchain, every provider.
— Maintained by Zaysa
Content type
Image
Digest
sha256:e68c8278c…
Size
731.8 MB
Last updated
2 days ago
docker pull zaysahq/jenkins-agent