Overview
A connector is a small service that runs on a machine in your network. It connects your applications, file servers and private networks to the Cloudraw network, so the people you allow can reach them from anywhere.
- Outbound only. The connector makes outgoing connections on TCP 443. You do not open any inbound port, and your applications are never exposed to the internet.
- Deny by default. Installing a connector gives nobody access. You publish an application, choose the connector that hosts it, and then add an access rule.
- Host only. The connector does not change the machine's routes or DNS. It only forwards the connections that Cloudraw sends to it.
Where to put it
- On a machine that is always on, inside the network where your applications live.
- The machine must reach the applications by the same names and addresses you will publish. If it can open the application, the connector can too.
- A small virtual machine is enough. One connector can host many applications.
- For a SaaS app locked to your IP, use a machine with a fixed public IP. The SaaS sees that IP.
- For RemoteApps, a Windows connector on the RDP server itself can publish them for you. See RemoteApp helper.
- Plan for a second connector on another machine. See High availability.
You need
- The Owner, Security admin or Connector operator role in the Cloudraw admin console.
- Administrator rights on the machine (an Administrator PowerShell on Windows,
sudoon Linux).
Requirements
| Item | Windows | Linux | Docker |
|---|---|---|---|
| Operating system | 64-bit Windows or Windows Server (x64) | Any 64-bit x86 (x86_64) distribution with systemd. ARM is not supported yet. | A Linux host with Docker. The container uses the host's network. |
| Rights | Administrator PowerShell | sudo (or root) | A user who can run docker |
| Tools | Windows PowerShell 5.1 or later. TLS 1.2 is turned on by the installer. | curl, tar. For automatic updates also openssl, sha256sum and python3 (or Node.js). | Docker Engine |
| Inbound ports | None | ||
Outbound connections
Allow these from the connector machine. If your firewall filters by name, allow the names, not today's IP addresses.
| Destination | Port | Used for |
|---|---|---|
ctrl1.cloudraw.com | TCP 443 | The Cloudraw network (control) |
il1.edge.cloudraw.com | TCP 443 | The Cloudraw network (traffic) |
orchestrator-stg.cloudraw.com | TCP 443 | Install link, downloads, update checks and the connector's status reports |
docker.io (Docker Hub) | TCP 443 | Docker only: pulling the connector image |
- Web proxy (Windows). Downloads and update checks use the machine's system proxy with the machine's credentials. The connector's own connections to the Cloudraw network go out directly on TCP 443, so allow those even if web browsing goes through a proxy.
- SSL inspection. Do not decrypt traffic to
*.cloudraw.com. The connector checks the Cloudraw certificates itself. - Antivirus and EDR. Some products block or quarantine new network services. If yours does, allow
C:\Program Files\Cloudraw Connector\cloudraw-connector.exe. The Windows installer detects this and tells you (see Troubleshooting).
Install on Windows
- Add the connector in CloudrawIn the admin console open Connectors and click Add connector. Give it a name, for example
office-connector-1, and choose Windows. - Copy the install commandIt is one short line that looks like this: irm https://orchestrator-stg.cloudraw.com/c/<code> | iex Always copy it from your console. The link is for this one connector only. It works for 24 hours.
- Run it as administratorOn the connector machine, right-click Windows PowerShell, choose Run as administrator, paste the command and press Enter.
- Wait for "Online"The installer prints "connector is running and connecting". Within a few seconds the connector shows Online in the console.
What the installer sets up
| Item | Where |
|---|---|
Windows service Cloudraw Connector (cloudraw-connector), starts automatically and restarts on failure | C:\Program Files\Cloudraw Connector |
| The connector's identity (its private key) and logs. Only SYSTEM and Administrators can read this folder. | C:\ProgramData\cloudraw-connector |
| Scheduled task Cloudraw Connector Update (see Updates) | Task Scheduler |
| Status icon for administrators in the notification area, with Reconnect, Disconnect and Open logs. It starts when an administrator signs in. | Start menu: Cloudraw Connector |
| An entry to remove it the normal way | Settings→Apps (or Programs and Features): Cloudraw Connector |
The installer adds no certificate to the Windows certificate store. On a server without a desktop session the status icon is skipped. The service runs either way.
One connector per machine. If the installer says "a Cloudraw Connector is already installed and running on this machine", it is already there. To move a connector to a different machine, add a new connector in the console and remove the old one.
Install on Linux
- Add the connector in CloudrawIn Connectors click Add connector, name it and choose Linux.
- Copy the install commandIt looks like this: curl -fsSL https://orchestrator-stg.cloudraw.com/c/<code> | sh The link works for 24 hours.
- Run it on the connector machineRun it as a user who can use
sudo. The script asks forsudoitself. - Wait for "Online"The script prints "connector is running" and the console shows the connector Online.
What the installer sets up
| Item | Where |
|---|---|
| The connector program | /opt/cloudraw-connector |
| The connector's identity (mode 600, folder mode 700) | /etc/cloudraw-connector |
| systemd service, starts at boot and restarts on failure | cloudraw-connector.service |
| Update timer and updater (see Updates) | cloudraw-connector-update.timer, /usr/local/sbin/cloudraw-connector-update |
Check it with:
systemctl status cloudraw-connectorjournalctl -u cloudraw-connector -n 50
Install with Docker
- Add the connector in CloudrawIn Connectors click Add connector, name it and choose Docker.
- Copy the
docker runcommandCopy it exactly as the console shows it. It starts a container namedcloudraw-connector-<name>that uses the host's network, restarts by itself (--restart unless-stopped), and keeps the connector's identity in a Docker volume with the same name. - Run it on a Linux Docker hostThe host must reach your applications, just like a Linux connector.
- Wait for "Online"Check the container with
docker psanddocker logs cloudraw-connector-<name>.
Do not delete the container's volume. It holds the connector's identity. Without it the connector cannot sign in again, and you must add a new connector.
The Docker command does not set up automatic updates. The console shows the connector as a manual update. If you want automatic updates, use the Linux install instead.
Updates
Connectors installed with the current Windows or Linux command update themselves. Cloudraw decides when. The connector checks every 15 minutes.
When updates install
Connectors follow your workspace update policy, the same one your desktop clients use.
| Option | What happens |
|---|---|
| In the maintenance window (default) | A new version installs during your window. The default window is every day, 02:00–05:00 UTC. You can change the days, the hours and the time zone. |
| Manual only | Nothing installs until you click Update now. |
| As soon as released | A new version installs at the next check. |
Update now
In Connectors, click Update now on a connector. It updates at its next check, within 15 minutes, even outside the window. If the connector is the only one hosting an application, people lose that application for a few seconds while the service restarts. With two connectors there is no interruption.
How an update is applied
- The connector downloads the new version from Cloudraw.
- It checks Cloudraw's signature and the file's checksum. If either is wrong, it installs nothing.
- It replaces the files, restarts the service and checks that it runs.
- If the check fails, it puts the previous version back by itself.
- It reports the result to the console.
Versions
A connector version looks like 1.18.7-b9c: the base version (1.18.7) followed by the Cloudraw build (b9c). Builds are in order: 1.18.7, 1.18.7-b9, 1.18.7-b9c, 1.18.7-b10, then 1.18.8.
| The console shows | Meaning |
|---|---|
| up to date | Nothing to do. |
| An old and a new version, in the window | The update installs in the next maintenance window. Click Update now to do it sooner. |
| update requested | You clicked Update now. It installs within 15 minutes. |
| update failed: … | The update did not install, or it was rolled back. The connector keeps running its previous version. See Troubleshooting. |
| Build unknown | The connector was installed before builds were tracked. It is never updated on its own. Click Update now once. |
| Manual update / automatic updates off | An older install, or a Docker connector, without the updater. Install the connector again with a fresh link to turn automatic updates on. |
Update logs
- Windows:
C:\ProgramData\cloudraw-connector\update.log - Linux:
/var/log/cloudraw-connector-update.log. To check the update feed and its signature without installing anything, runsudo cloudraw-connector-update --verify.
High availability
An application can be hosted by up to 5 connectors. While at least one of them is online, people can reach the application. If one connector stops, the next connection goes through another one. Nobody needs to do anything.
- Install a second connectorPut it on a different machine, ideally on a different host or in another site, that can also reach the application.
- Add it to the applicationOpen the application and, under Hosted by, select both connectors. The application shows an HA badge and "Hosted by 2 connectors — keeps working if one fails".
- Private networks can also be hosted by several connectors.
- The connector page lists what each connector hosts, and which of those have no second connector.
- To remove a connector that is one of several hosts of an application or a private network, first take it out of Hosted by there.
- For a SaaS app locked to your IP, each connector leaves from its own public IP. Allow all of them at the SaaS. See Lock a SaaS app to your connector's IP.
Two connectors also make updates invisible. With one connector, an update briefly interrupts its applications. With two, people keep working.
RemoteApp helper
If the Windows connector runs on the RDP server itself, it publishes your RemoteApps there for you. You do not need to edit the server's RemoteApp list by hand.
- It works for RDP applications whose server address is the connector's own machine:
localhost,127.0.0.1, or the server's own name. - It needs connector build
b11or newer. - It only adds and removes its own entries. It does not touch RemoteApps that someone else set up.
- It lists the programs installed on the server, so you can pick the program from a list when you publish. The list appears within a few minutes.
- It is on by default. You can turn it off per connector on the connector's page.
See Publish a RemoteApp for the full steps.
Troubleshooting
On Windows, when the connector does not come online, the installer runs a check and prints the cause and the fix. It also saves a report to C:\ProgramData\cloudraw-connector\cloudraw-diagnostics.txt. Send that file to support if you are stuck.
| Message or symptom | Cause and fix |
|---|---|
| "invalid or expired install code" | The install link is older than 24 hours or was used too many times. Open the connector in the console and get the install command again. |
| "enrollment failed - the code may have expired" | The connector's one-time enrolment has expired (after 7 days) or was already used. Remove the connector in the console and add a new one. |
| "please run from an Administrator PowerShell" | Open PowerShell with Run as administrator and run the command again. |
| "please run with sudo" or "this installer currently supports x86_64" | Use a user with sudo. ARM machines are not supported yet. Use an x86_64 machine. |
| "a Cloudraw Connector identity already exists in /etc/cloudraw-connector" | This Linux machine is already enrolled. To enrol it again as a new connector, run the same command with CLOUDRAW_REPLACE=1 in front. The old identity is kept as a backup in that folder. |
| Windows: "an AV/EDR quarantined the connector binary" | Allow C:\Program Files\Cloudraw Connector\cloudraw-connector.exe in your security product, then run the install command again. |
| Windows: "a security product is blocking THIS executable's network access" | The machine can reach Cloudraw but the connector cannot. Add an application or path exclusion for cloudraw-connector.exe in your EDR (for example SentinelOne, CrowdStrike or Microsoft Defender for Endpoint). |
| "this machine cannot reach Cloudraw on tcp/443" | A firewall or EDR network rule blocks it. Allow the outbound connections. Test with Test-NetConnection ctrl1.cloudraw.com -Port 443 (Windows) or curl -v https://ctrl1.cloudraw.com (Linux). |
| Windows: "connector came up in FULL-TUNNEL mode … Aborted" | The installer stopped the connector to protect the machine's network settings. Do not retry. Contact support with the diagnostics report. |
| The connector was online and is now offline | It is already installed. Installing again does not help. Check that the machine is running, the service is started, and outbound TCP 443 is still allowed. Windows: Get-Service cloudraw-connector, logs in C:\ProgramData\cloudraw-connector. Linux: journalctl -u cloudraw-connector -n 50. |
| The connector shows Pending approval or Blocked | Your workspace requires approval for new connectors, or someone blocked it. Approve it on the connector page. A blocked connector hosts nothing. |
| update failed: … | The connector went back to its previous version and keeps running. Read the update log (Updates). Fix the cause, for example a blocked download, and click Update now. |
| Public IP is empty on the connector page | The connector reports its public IP with its update checks. Wait 15 minutes after installing. Connectors without automatic updates do not report it. |
To remove a Windows connector, use Settings→Apps→Cloudraw Connector→Uninstall. It removes the service, the scheduled tasks, the data folder and the program folder. Then remove the connector in the Cloudraw console.