Skip to content

SPIRE Agent

Image: ghcr.io/parlesec/protocolsoup-spire-agent

Use SPIRE agent to provide Workload API sockets (agent.sock) to SPIFFE-enabled services.

PropertyValue
TCP portNone (Unix socket only)
Workload API/run/spire/sockets/agent.sock
Depends onSPIRE server socket
Mount PathPurpose
/run/spire/sockets/server (read-only)SPIRE server socket
/run/spire/socketsAgent socket output
/opt/spire/data/agentAgent state
Terminal window
docker run -d --name spire-agent \
-v spire-server-socket:/run/spire/sockets/server:ro \
-v spire-agent-socket:/run/spire/sockets \
-v spire-agent-data:/opt/spire/data/agent \
ghcr.io/parlesec/protocolsoup-spire-agent:latest
  • Only trusted workloads should mount agent.sock.
  • If agent startup loops, verify SPIRE server socket availability first.
  • Start SPIRE server before starting the agent.