Class SshLaunchStrategy

All Implemented Interfaces:
ExtensionPoint, Describable<AgentLaunchStrategy>

public class SshLaunchStrategy extends AgentLaunchStrategy
Connects by SSH from the controller into the instance.

Use this when the agent cannot dial out to Jenkins. The controller must be able to reach Namespace's regional ingress, and the token additionally needs the instance:ssh and ingress:access grants.

Namespace authorises SSH against public keys injected at instance creation. Those are computed from the configured private-key credential rather than configured alongside it: a separately stored public key silently stops matching the moment the credential is rotated, and the failure surfaces only as an agent that cannot be reached.