Theme
Enroll to your site
Enrollment binds this Connector to one site. It gives the Connector its identity, tells it which site it serves, and brings up the secure link to that site.
It takes one code and about a minute.
Where the code comes from
In the Portal: open your site, choose Storage, then Connect your storage. The wizard mints a single use enrollment code and shows it once.
Codes are single use and expire, by default after 24 hours. If yours was lost, cancel it in the Portal and mint a new one.
Enrolling with a code
In the Connector's admin console:
- Choose the Enrollment code method.
- Leave Portal address as
https://portal.sftp.cloudunless you were told otherwise. It only changes in development and testing setups. - Paste the code, in the form
XXXXX-XXXXX-XXXXX-XXXXX. - Choose Connect.
The Connector contacts the Portal directly, not through your site, and verifies what comes back against a Portal key built into the Connector software itself.
On success you see Connected, along with the site it bound to, its own connector id, the site server it connects to, and whether the secure link is running.
If the enrollment saved but the secure link did not start, restart the Connector service.
Enrolling from the command line
For scripted installs, or for recovery while the service is stopped:
sh
sc-conn enroll --portal https://portal.sftp.cloud --code XXXXX-XXXXX-XXXXX-XXXXX--portal defaults to https://portal.sftp.cloud, so it can be omitted on any production Connector.
If the Connector service is running, it notices the enrollment by itself within moments and starts the enforcement plane; opening the admin console shows it enrolled. With the service stopped, simply start it:
sh
sudo sc-conn svc startAir gapped enrollment
For a Connector that must not contact the Portal at all, use the Bundle file method: paste the signed enrollment bundle exactly as the Portal produced it, or:
sh
sc-conn enroll --bundle ./enrollment-bundle.jsonThe bundle is signed, and the Connector verifies it against the same baked in key. Use either --code or --bundle, never both.
Why this path bypasses your site
The Connector's trust root is the Portal, not your site.
Enrollment is delivered without your site's involvement, and the anchor that lets the Connector verify things arrives inside the Connector binary itself. That is what makes it possible for the Connector to refuse an instruction from a site that has been taken over: it is not asking the site whether the site is telling the truth.
Common errors
| The console says | What it means |
|---|---|
| The enrollment code is not valid | A typo, or the code has already been used. Codes are single use |
| The enrollment code has expired | Mint a fresh one in the Portal |
| This Connector is already enrolled | Use re-enrollment instead, below |
| The baked Portal anchor is damaged | Reinstall from a correctly built package. A release Connector refuses to start in this state |
Re-enrollment
Re-enrollment is for a Connector that is fine but whose binding to your site is not. The dashboard shows a banner when this is the case, and the Portal's Storage page says Your storage needs to be reconnected.
The usual causes: your site was moved to a dedicated server, or your site's server was replaced or re-enrolled.
- In the Portal, on the site's Storage page, choose Generate re-enrollment code.
- In the Connector's admin console, open the dashboard and choose Re-enroll.
- Paste the code.
Nothing else changes: the same storage stays bound to the same site, with the same virtual file systems, the same permissions and the same encryption keys.
Errors here are specific:
| The console says | What it means |
|---|---|
| That code is for a different site or connector | Use the code generated for this storage |
| This Connector is not enrolled yet | Use first time enrollment instead |
The one symptom worth recognizing
The link is up, but every session on a folder set is refused, and the dashboard says the site's voucher key no longer matches this Connector's enrollment.
That means the site was re-enrolled without re-enrolling this Connector. Re-enroll the Connector against the site's current identity and service resumes.
Starting over: reset pairing
A Connector that was disconnected in the customer portal is refused by every Head from then on, and it cannot simply be enrolled again: a first enrollment is refused on an enrolled Connector, and a re-enrollment code can no longer be minted for its old identity.
The way back is Reset pairing, on the dashboard, offered once no Head accepts this Connector any more. The Connector notices the disconnect on its own within a couple of minutes and shows its links as refused; no restart is needed. Reset pairing forgets the Connector's identity and nothing else: the virtual file systems, permissions, scripts, secrets and encryption keys stay. You retype the connector id to confirm, the console returns to the enrollment wizard, and you enroll with a new code from the customer portal. The storage keeps its identity, so the users' removed folders can then be restored from the customer portal's user editor.
With the service stopped, sc-conn enroll reset --yes does the same from the command line.
Waiting to be admitted
Just after enrolling you may see that your site has not admitted this Connector yet. That normally resolves by itself within a few minutes.
If it does not, disconnect the storage in the customer portal, choose Reset pairing on this Connector's dashboard, and enroll it again with a fresh code.