Install the CloudGrange Relay

The CloudGrange Relay is a container that runs on a host inside your network, one per site. It maintains a persistent outbound connection to the CloudGrange control plane and routes jobs to the agents running on your managed Hyper-V hosts. The relay host needs only outbound access to the control plane — no inbound internet access is required.

CloudGrange is in active development and is not GA. The relay code lives in cloudgrange-runtime-relay. See current product and release status.

One relay per site

Deploy one relay per physical site or network segment — anywhere you have a group of Hyper-V hosts on the same LAN. A single site can hold multiple clusters and any number of hosts; all of them enroll with that site's relay. One CloudGrange instance manages any number of sites, each with its own relay.

Traffic flow

CloudGrange control plane
        │  outbound HTTPS/WSS (443) from relay
        ▼
   Relay host            (container, inside your network)
        │  inbound TCP 8443 from Hyper-V hosts
        ▼
   Hyper-V hosts running the CloudGrange agent

Security note: the relay's agent listener is plain HTTP inside the trusted cluster network; only the agent routes are exposed over TLS on port 8443. Per-agent mTLS is planned but not yet implemented.

Prerequisites

  • A Linux or container-capable host with Docker, or a Kubernetes cluster (the on-premises install already includes a relay)
  • Outbound HTTPS (443) from the relay host to the control plane
  • Inbound TCP 8443 (TLS) from managed Hyper-V hosts to the relay
  • For agentless (PSRemoting) inventory: outbound TCP 5986 from the relay to managed Windows hosts
  • A persistent volume/directory for the relay identity (RELAY_IDENTITY_DIR)

Deployment model

In every on-premises install the relay ships inside the deployment and is wired up automatically — you do not deploy it separately for the first site. On the Kubernetes/Helm paths it is the cloudgrange-relay Deployment in the chart; on the legacy Compose path it is a container in the stack. A standalone relay is only needed for additional sites.

Confirm the built-in relay is running:

# Kubernetes/Helm (appliance, Windows-orchestrated, native Linux, your own cluster)
sudo k3s kubectl get pods -l app.kubernetes.io/name=cloudgrange-relay
sudo k3s kubectl logs -l app.kubernetes.io/name=cloudgrange-relay --tail=50

# Legacy Compose
sudo docker compose -f /opt/cloudgrange/docker-compose.yml ps cloudgrange-relay

An additional site on Kubernetes

Deploy the relay subchart on its own with the site's values:

helm install cloudgrange-relay oci://ghcr.io/cloudgrange/charts/cloudgrange \
  --version 2609.0.0-preview.7 \
  --set api.enabled=false --set portal.enabled=false \
  --set postgres.enabled=false --set keycloak.enabled=false \
  --set observability.enabled=false \
  --set relay.env.RELAY_PAAS_URL=https://<control-plane-host> \
  --set relay.env.RELAY_ENROLLMENT_TOKEN=<one-time-token-from-portal>

Generate the one-time enrollment token in the portal under Sites → add site → generate token.

A relay is configured by environment variables (see Variables Registry for the full list). The key ones:

Variable Description
RELAY_PAAS_URL Upstream control-plane URL.
RELAY_ENROLLMENT_TOKEN One-time token for the relay to enroll with the control plane. Minted per site in the portal.
RELAY_AGENT_ENROLLMENT_TOKEN Shared secret agents present on first enrollment. You choose this value.
RELAY_ADMIN_TOKEN Token required to approve re-enrollment of an already-enrolled host.
RELAY_SITE_ID / RELAY_CLUSTER_ID Site and cluster the relay serves.

Enrollment security

  • A relay enrolls with the control plane once, using a one-time enrollment token generated in the portal (Sites → add site → generate token). The token is time-limited and single-use.
  • Agents enroll with the relay using the shared RELAY_AGENT_ENROLLMENT_TOKEN.
  • Re-enrolling a host that is already enrolled requires admin approval via RELAY_ADMIN_TOKEN, with a time-limited, single-use approval. This is an interim control until mTLS lands.

Next step

Install the CloudGrange Agent on each Hyper-V host at the site.

See current product and release status.