CloudrawSetup guides
Download PDF
Integrations · For IT admins

Install a Cloudraw connector

Put an outbound-only connector in your network on Windows, Linux or Docker, keep it updated, and run more than one for failover.

Last updated 7 October 2026 · Download this guide as PDF

Overview

A connector is a small service that runs on a machine in your network. It connects your applications, file servers and private networks to the Cloudraw network, so the people you allow can reach them from anywhere.

  • Outbound only. The connector makes outgoing connections on TCP 443. You do not open any inbound port, and your applications are never exposed to the internet.
  • Deny by default. Installing a connector gives nobody access. You publish an application, choose the connector that hosts it, and then add an access rule.
  • Host only. The connector does not change the machine's routes or DNS. It only forwards the connections that Cloudraw sends to it.

Where to put it

  • On a machine that is always on, inside the network where your applications live.
  • The machine must reach the applications by the same names and addresses you will publish. If it can open the application, the connector can too.
  • A small virtual machine is enough. One connector can host many applications.
  • For a SaaS app locked to your IP, use a machine with a fixed public IP. The SaaS sees that IP.
  • For RemoteApps, a Windows connector on the RDP server itself can publish them for you. See RemoteApp helper.
  • Plan for a second connector on another machine. See High availability.

You need

  • The Owner, Security admin or Connector operator role in the Cloudraw admin console.
  • Administrator rights on the machine (an Administrator PowerShell on Windows, sudo on Linux).

Requirements

ItemWindowsLinuxDocker
Operating system64-bit Windows or Windows Server (x64)Any 64-bit x86 (x86_64) distribution with systemd. ARM is not supported yet.A Linux host with Docker. The container uses the host's network.
RightsAdministrator PowerShellsudo (or root)A user who can run docker
ToolsWindows PowerShell 5.1 or later. TLS 1.2 is turned on by the installer.curl, tar. For automatic updates also openssl, sha256sum and python3 (or Node.js).Docker Engine
Inbound portsNone

Outbound connections

Allow these from the connector machine. If your firewall filters by name, allow the names, not today's IP addresses.

DestinationPortUsed for
ctrl1.cloudraw.comTCP 443The Cloudraw network (control)
il1.edge.cloudraw.comTCP 443The Cloudraw network (traffic)
orchestrator-stg.cloudraw.comTCP 443Install link, downloads, update checks and the connector's status reports
docker.io (Docker Hub)TCP 443Docker only: pulling the connector image
  • Web proxy (Windows). Downloads and update checks use the machine's system proxy with the machine's credentials. The connector's own connections to the Cloudraw network go out directly on TCP 443, so allow those even if web browsing goes through a proxy.
  • SSL inspection. Do not decrypt traffic to *.cloudraw.com. The connector checks the Cloudraw certificates itself.
  • Antivirus and EDR. Some products block or quarantine new network services. If yours does, allow C:\Program Files\Cloudraw Connector\cloudraw-connector.exe. The Windows installer detects this and tells you (see Troubleshooting).

Install on Windows

  1. Add the connector in CloudrawIn the admin console open Connectors and click Add connector. Give it a name, for example office-connector-1, and choose Windows.
  2. Copy the install commandIt is one short line that looks like this: irm https://orchestrator-stg.cloudraw.com/c/<code> | iex Always copy it from your console. The link is for this one connector only. It works for 24 hours.
  3. Run it as administratorOn the connector machine, right-click Windows PowerShell, choose Run as administrator, paste the command and press Enter.
  4. Wait for "Online"The installer prints "connector is running and connecting". Within a few seconds the connector shows Online in the console.

What the installer sets up

ItemWhere
Windows service Cloudraw Connector (cloudraw-connector), starts automatically and restarts on failureC:\Program Files\Cloudraw Connector
The connector's identity (its private key) and logs. Only SYSTEM and Administrators can read this folder.C:\ProgramData\cloudraw-connector
Scheduled task Cloudraw Connector Update (see Updates)Task Scheduler
Status icon for administrators in the notification area, with Reconnect, Disconnect and Open logs. It starts when an administrator signs in.Start menu: Cloudraw Connector
An entry to remove it the normal waySettings→Apps (or Programs and Features): Cloudraw Connector
Note

The installer adds no certificate to the Windows certificate store. On a server without a desktop session the status icon is skipped. The service runs either way.

Important

One connector per machine. If the installer says "a Cloudraw Connector is already installed and running on this machine", it is already there. To move a connector to a different machine, add a new connector in the console and remove the old one.

Install on Linux

  1. Add the connector in CloudrawIn Connectors click Add connector, name it and choose Linux.
  2. Copy the install commandIt looks like this: curl -fsSL https://orchestrator-stg.cloudraw.com/c/<code> | sh The link works for 24 hours.
  3. Run it on the connector machineRun it as a user who can use sudo. The script asks for sudo itself.
  4. Wait for "Online"The script prints "connector is running" and the console shows the connector Online.

What the installer sets up

ItemWhere
The connector program/opt/cloudraw-connector
The connector's identity (mode 600, folder mode 700)/etc/cloudraw-connector
systemd service, starts at boot and restarts on failurecloudraw-connector.service
Update timer and updater (see Updates)cloudraw-connector-update.timer, /usr/local/sbin/cloudraw-connector-update

Check it with:

systemctl status cloudraw-connector
journalctl -u cloudraw-connector -n 50

Install with Docker

  1. Add the connector in CloudrawIn Connectors click Add connector, name it and choose Docker.
  2. Copy the docker run commandCopy it exactly as the console shows it. It starts a container named cloudraw-connector-<name> that uses the host's network, restarts by itself (--restart unless-stopped), and keeps the connector's identity in a Docker volume with the same name.
  3. Run it on a Linux Docker hostThe host must reach your applications, just like a Linux connector.
  4. Wait for "Online"Check the container with docker ps and docker logs cloudraw-connector-<name>.
Warning

Do not delete the container's volume. It holds the connector's identity. Without it the connector cannot sign in again, and you must add a new connector.

Important

The Docker command does not set up automatic updates. The console shows the connector as a manual update. If you want automatic updates, use the Linux install instead.

Updates

Connectors installed with the current Windows or Linux command update themselves. Cloudraw decides when. The connector checks every 15 minutes.

When updates install

Connectors follow your workspace update policy, the same one your desktop clients use.

OptionWhat happens
In the maintenance window (default)A new version installs during your window. The default window is every day, 02:00–05:00 UTC. You can change the days, the hours and the time zone.
Manual onlyNothing installs until you click Update now.
As soon as releasedA new version installs at the next check.

Update now

In Connectors, click Update now on a connector. It updates at its next check, within 15 minutes, even outside the window. If the connector is the only one hosting an application, people lose that application for a few seconds while the service restarts. With two connectors there is no interruption.

How an update is applied

  1. The connector downloads the new version from Cloudraw.
  2. It checks Cloudraw's signature and the file's checksum. If either is wrong, it installs nothing.
  3. It replaces the files, restarts the service and checks that it runs.
  4. If the check fails, it puts the previous version back by itself.
  5. It reports the result to the console.

Versions

A connector version looks like 1.18.7-b9c: the base version (1.18.7) followed by the Cloudraw build (b9c). Builds are in order: 1.18.7, 1.18.7-b9, 1.18.7-b9c, 1.18.7-b10, then 1.18.8.

The console showsMeaning
up to dateNothing to do.
An old and a new version, in the windowThe update installs in the next maintenance window. Click Update now to do it sooner.
update requestedYou clicked Update now. It installs within 15 minutes.
update failed: …The update did not install, or it was rolled back. The connector keeps running its previous version. See Troubleshooting.
Build unknownThe connector was installed before builds were tracked. It is never updated on its own. Click Update now once.
Manual update / automatic updates offAn older install, or a Docker connector, without the updater. Install the connector again with a fresh link to turn automatic updates on.

Update logs

  • Windows: C:\ProgramData\cloudraw-connector\update.log
  • Linux: /var/log/cloudraw-connector-update.log. To check the update feed and its signature without installing anything, run sudo cloudraw-connector-update --verify.

High availability

An application can be hosted by up to 5 connectors. While at least one of them is online, people can reach the application. If one connector stops, the next connection goes through another one. Nobody needs to do anything.

  1. Install a second connectorPut it on a different machine, ideally on a different host or in another site, that can also reach the application.
  2. Add it to the applicationOpen the application and, under Hosted by, select both connectors. The application shows an HA badge and "Hosted by 2 connectors — keeps working if one fails".
  • Private networks can also be hosted by several connectors.
  • The connector page lists what each connector hosts, and which of those have no second connector.
  • To remove a connector that is one of several hosts of an application or a private network, first take it out of Hosted by there.
  • For a SaaS app locked to your IP, each connector leaves from its own public IP. Allow all of them at the SaaS. See Lock a SaaS app to your connector's IP.
Tip

Two connectors also make updates invisible. With one connector, an update briefly interrupts its applications. With two, people keep working.

RemoteApp helper

If the Windows connector runs on the RDP server itself, it publishes your RemoteApps there for you. You do not need to edit the server's RemoteApp list by hand.

  • It works for RDP applications whose server address is the connector's own machine: localhost, 127.0.0.1, or the server's own name.
  • It needs connector build b11 or newer.
  • It only adds and removes its own entries. It does not touch RemoteApps that someone else set up.
  • It lists the programs installed on the server, so you can pick the program from a list when you publish. The list appears within a few minutes.
  • It is on by default. You can turn it off per connector on the connector's page.

See Publish a RemoteApp for the full steps.

Troubleshooting

On Windows, when the connector does not come online, the installer runs a check and prints the cause and the fix. It also saves a report to C:\ProgramData\cloudraw-connector\cloudraw-diagnostics.txt. Send that file to support if you are stuck.

Message or symptomCause and fix
"invalid or expired install code"The install link is older than 24 hours or was used too many times. Open the connector in the console and get the install command again.
"enrollment failed - the code may have expired"The connector's one-time enrolment has expired (after 7 days) or was already used. Remove the connector in the console and add a new one.
"please run from an Administrator PowerShell"Open PowerShell with Run as administrator and run the command again.
"please run with sudo" or "this installer currently supports x86_64"Use a user with sudo. ARM machines are not supported yet. Use an x86_64 machine.
"a Cloudraw Connector identity already exists in /etc/cloudraw-connector"This Linux machine is already enrolled. To enrol it again as a new connector, run the same command with CLOUDRAW_REPLACE=1 in front. The old identity is kept as a backup in that folder.
Windows: "an AV/EDR quarantined the connector binary"Allow C:\Program Files\Cloudraw Connector\cloudraw-connector.exe in your security product, then run the install command again.
Windows: "a security product is blocking THIS executable's network access"The machine can reach Cloudraw but the connector cannot. Add an application or path exclusion for cloudraw-connector.exe in your EDR (for example SentinelOne, CrowdStrike or Microsoft Defender for Endpoint).
"this machine cannot reach Cloudraw on tcp/443"A firewall or EDR network rule blocks it. Allow the outbound connections. Test with Test-NetConnection ctrl1.cloudraw.com -Port 443 (Windows) or curl -v https://ctrl1.cloudraw.com (Linux).
Windows: "connector came up in FULL-TUNNEL mode … Aborted"The installer stopped the connector to protect the machine's network settings. Do not retry. Contact support with the diagnostics report.
The connector was online and is now offlineIt is already installed. Installing again does not help. Check that the machine is running, the service is started, and outbound TCP 443 is still allowed. Windows: Get-Service cloudraw-connector, logs in C:\ProgramData\cloudraw-connector. Linux: journalctl -u cloudraw-connector -n 50.
The connector shows Pending approval or BlockedYour workspace requires approval for new connectors, or someone blocked it. Approve it on the connector page. A blocked connector hosts nothing.
update failed: …The connector went back to its previous version and keeps running. Read the update log (Updates). Fix the cause, for example a blocked download, and click Update now.
Public IP is empty on the connector pageThe connector reports its public IP with its update checks. Wait 15 minutes after installing. Connectors without automatic updates do not report it.

To remove a Windows connector, use Settings→Apps→Cloudraw Connector→Uninstall. It removes the service, the scheduled tasks, the data folder and the program folder. Then remove the connector in the Cloudraw console.