Skip to main content

Connector configuration

The connector keeps one configuration file on the host it runs on. The installer writes it, and after that it is yours to edit: where the gateway is, where the connector keeps its identity, how often it reports, and the switches that decide what this host accepts from Fleet. Nothing in it is about the Wazuh deployment, because the connector reads nothing from Wazuh. The one Wazuh login Fleet handles on a host is the one the installer finds, and it is kept in a file of its own, described in The Wazuh login the installer finds. None of this file reaches Fleet, and Fleet cannot change it. Install the connector writes the file, and The connector is the shape around it.

Where the file is​

/etc/fleet-connector/connector.yaml, mode 0600, owned by root, and named explicitly by the systemd unit. The daemon reads it once, at start, and never writes to it. A missing file is not an error: the defaults are the shipped gateway and the shipped data directory. A file it cannot parse is an error, and a fatal one.

The pre-rename path is read only while the new file is absent

Hosts installed before the rename keep their configuration at /etc/mobius/connector.yaml. It is still read, but only while /etc/fleet-connector/connector.yaml does not exist, and the log says so. The installer copies it across rather than moving it, so the original stays where a pre-move unit still points, and it leaves the old file alone on a host that also runs a mobius-connector binary or unit, where that file is the other product's. A --config pointing anywhere else never falls back.

What the installer writes​

A host installed with --connect. Nothing else is written; the rest of the table below is yours to add, and the file is the same on every host whatever Wazuh runs beside it.

# Wazuh Fleet connector configuration.
# Written by `fleet-connector provision`. The connector reads nothing from
# Wazuh, so this file names no Wazuh address and no login.
connect_url: "wss://connect.fleet.wazuh.com" # only when --connect was given
data_dir: "/var/lib/fleet-connector" # identity, gateway CA, staged updates
heartbeat_seconds: 30
request_timeout_seconds: 30

Re-running the installer with --force rewrites the file and keeps one thing from the old one: the upgrade block. Everything else, including the keys listed under What an older file may still carry, is dropped.

Every key is optional. A string that is absent or blank falls back to its default, and so does a heartbeat_seconds or request_timeout_seconds of zero or less. A boolean is taken as written rather than read as unset, which is what makes upgrade.enabled: false a real veto instead of a line that reads as missing.

Every field​

KeyDefaultWhat it does
connect_urlwss://connect.fleet.wazuh.comThe gateway this host dials. The session URL is this plus /connect.
enroll_urlderivedUnset, it is connect_url as https plus /enroll. Certificate renewal follows it, at /renew on the same base.
data_dir/var/lib/fleet-connectorHolds key.pem, cert.pem, ca.pem, connector_id and staged updates.
upgrade.enabledtruefalse logs and ignores every update directive.
upgrade.plugins_enabledtruefalse refuses plugin installs while still updating the core.
upgrade.download_hostdl.fleet.wazuh.comWhere core artifacts are fetched from. Any other host is refused, including on a redirect hop.
upgrade.download_hosts_allowemptyExtra hosts, additive: the Fleet site stays allowed whatever this says.
heartbeat_seconds30How often the host reports.
request_timeout_seconds30Parsed for compatibility. The connector relays no queries, so it has no effect today.

Fleet marks a host Disconnected when no heartbeat has arrived in 90 seconds, so a heartbeat_seconds above that reads as an outage between beats.

Changing data_dir also means changing the unit

The unit runs ProtectSystem=strict with ReadWritePaths=/var/lib/fleet-connector, the only writable path the service has. Pointing data_dir elsewhere without changing the unit gives a connector that cannot write its own identity. That directory is named in four places on purpose: the installer, the binary's compiled default, the unit, and the path unit that watches upgrade/requests/ for a staged update.

What an older file may still carry​

A connector installed before this release wrote five more keys, and every one of them is about Wazuh: indexer, wazuh_api, deployment, dashboard_config and active_response. A file that still has them loads. The connector reads none of them, and it says so once, at start, in one log line that names the keys it found:

connector.yaml: deployment, indexer, wazuh_api are ignored since this release: no login is read from this file. You may remove them; the file is never rewritten.

You may delete those keys or leave them. The connector never edits the file, so the line repeats on every start until you do. A login left under indexer or wazuh_api is never read and never reaches a service on the host. A service gets its login from its own console, or starts with the one the installer finds on the host. Active Response is configured from Mobius, not from Fleet, and installing with --active-response or --no-active-response is refused. What Fleet can do is the full list of what the connector will and will not do.

What the connector reports about its host​

Every heartbeat, 30 seconds apart by default, carries two things and nothing else. Node is the hostname, OS, architecture, the distribution's PRETTY_NAME from /etc/os-release, the kernel release and when this process started, read once at start so the console can tell a restart loop from a long-running host. Services is the status of each Fleet service running on the host (Connected services).

It reports nothing about your Wazuh deployment: it does not probe the indexer or the Wazuh server API, count agents or read cluster membership. Nothing about the machine beyond the node facts leaves it: no CPU, no disk, no process list.

Applying a change​

The file is read once, at start, so a change takes effect on a restart.

sudo vi /etc/fleet-connector/connector.yaml
sudo systemctl restart fleet-connector
journalctl -u fleet-connector -n 50

The startup line confirms what was loaded: fleet-connector <version> starting; gateway=…, preceded by the one line about ignored keys when the file has any. See Connector logs for the other lines it writes.

A YAML error is fatal: the process exits with config: parse config /etc/fleet-connector/connector.yaml: …, systemd restarts it five seconds later, and it exits again. The host reads Disconnected 90 seconds after the last good heartbeat, and the journal is the only place that says why.

Re-running the installer keeps an existing file unless you pass --force, which rewrites it, keeping the upgrade block and discarding every other hand edit. The installer takes no typed Wazuh credentials. Updates to the binary are separate, in Connector lifecycle, with upgrade.enabled as the host owner's veto.