Theme
Storage and connectors
The Storage page on a site lists the Storage Connectors linked to it. Connecting the first one is covered in Connect your storage; this page is what you need afterwards.
Each row shows the machine's hostname with its connector id beneath it. The same pair appears on that Connector's own dashboard, under Node health, so with several Connectors on one site you can always tell which row is which machine before acting on it.
Reading the health line
| State | What it means | What your users see |
|---|---|---|
| Connected | Seen recently, serving your site | Everything works |
| Not seen recently | Quiet longer than expected | Sign in still works. A Custom folder on this Connector still shows and refuses to open until it is back; an Automatic one is absent until then |
| Not seen yet | Enrolled, never linked | The same. It has nothing to serve yet |
| Re-enroll needed | The link is broken and a fresh code is required | The same |
A Connector that has never linked usually just has no virtual file system yet. Create one in its own admin console and it links within moments. See Virtual file systems.
An unreachable Connector is not an SFTP.cloud outage
Connector reachability depends on your network, your machine and your storage. Your site's Overview shows it separately from our platform for exactly that reason, and it is not counted against the service level.
Slots
Every enrolled Connector claims one connector slot on your plan. The slot is claimed at enrollment and released when you disconnect.
If minting a code is refused for want of a slot, you have two options: disconnect a Connector you no longer use, or add connectors on Plan and billing.
Running more than one Connector
You can enroll several Connectors on one site. Each one is a separate machine with its own storage and its own permissions.
A user's What they see list can mix them: / on one Connector and /archive on another. Each Connector answers for its own part of the namespace, and grants the permissions for its own folders.
Two consequences worth planning around:
- A move never crosses a virtual file system. Renaming or moving a file from one virtual file system to another is refused, including between two virtual file systems on the same Connector. Clients fall back to copy and delete, which is slower but correct. See Permissions.
- If one Connector is offline, only its part of the namespace is affected. The user still signs in as long as the Connector behind their starting folder is reachable, the rest of the session keeps working, and the offline folder comes back by itself, in that same session, when its Connector links again. A user whose starting folder is on the offline Connector is refused until it returns.
Disconnecting
Choose Disconnect.
- The Connector is refused from then on, and nothing is read from or written to it any more, even if its machine is still running.
- Sessions using it end at once. Any user signed in with a Custom folder on this Connector is disconnected and can sign in again immediately, without that folder. Users whose folders never named it are not affected.
- Folders on it are removed from your users. Every user whose Custom folders named storage on this Connector loses those rows; they are kept as Removed folders on the user, so you can restore them later. A user whose starting folder was on it goes back to Automatic folders. The confirmation says how many users were affected, and Activity records each one.
- Users on Automatic folders are not touched: their folders only ever come from connected storage.
- Files are not touched. They stay exactly where they are.
- The slot is freed immediately.
To connect the same machine again later, open the Connector's admin console and choose Reset pairing on its dashboard. The Connector notices the disconnect on its own within a couple of minutes, shows its links as refused, and offers the action; no restart is needed. Then mint a new enrollment code here and enroll it. Its virtual file systems, permissions, scripts, secrets and encryption keys are all still there, and because the storage keeps its identity, the users' removed folders can be restored from the user editor. See Enroll to your site.
Re-enrolling
Re-enrollment is for a Connector that is fine but whose binding to your site is not: after a move to a dedicated server, or after the site's server was replaced.
The Storage page shows Your storage needs to be reconnected when this is the case.
- Choose Generate re-enrollment code.
- In the Connector's admin console, open the dashboard and choose Re-enroll.
- Paste the code together with your portal address.
Nothing else changes: same identity, same virtual file systems, same permissions, same encryption keys.
If the site has more than one Connector, the Portal cannot tell which one needs the code. Contact support rather than guessing.
When a Connector cannot renew its certificate
Each Connector presents a certificate to your site that lasts thirty days, and renews it by itself over a connection to the Portal. The Storage page shows A Connector could not renew its certificate, naming the machine and the date the certificate ends, when one of your Connectors is in service and has gone three quarters of that time without renewing.
Nothing is broken yet when you see it: the Connector is linked and transfers work. If nothing is done, your site stops admitting that Connector the next time it reconnects after the date shown, and the files on it become unreachable. The notice then reads A Connector's certificate has ended.
The usual cause is a firewall rule that allowed the Portal for enrollment and was closed afterwards. Allow that machine to reach portal.sftp.cloud on port 443. The Connector retries every hour, renews by itself, and the notice clears on your next visit. Nothing is re-enrolled, even after the certificate has ended. The Connector's own dashboard shows the same warning. See Before you install.
When the Connector clock is off
The Storage page shows Your Connector's clock is off when the storage is linked but the machine that runs your Connector has a clock more than five minutes away from ours. While that lasts the Connector refuses every session, so your users sign in and nothing opens.
This is not a re-enrollment case, and there is no code to generate. Correct the time on that machine and turn on automatic time synchronization. Transfers resume at the next sign in and the notice clears by itself. The Connector's own dashboard names the same problem and, when it can, says how far ahead or behind the clock is. See Before you install.
Pending codes
An enrollment code that has been minted but not yet used appears under Waiting to connect, with its expiry. Choose Cancel code to invalidate it.
Cancel a code you did not just create yourself. A code is a bearer credential: whoever holds it can attach a Connector to your site until it expires or is used.
What lives on the Connector, not here
The Portal never sees, and cannot change:
- What storage a Connector actually serves.
- What any user may do inside a folder.
- Your at rest encryption keys.
All three are in the Connector's own admin console. See What the Connector is.