Connector configuration
The connector keeps one configuration file on the host it runs on. The installer writes it, and after that it is yours to edit: where the gateway is, where the connector keeps its identity, how often it reports, and the switches that decide what this host accepts from Fleet. Nothing in it is about the Wazuh deployment, because the connector reads nothing from Wazuh. The one Wazuh login Fleet handles on a host is the one the installer finds, and it is kept in a file of its own, described in The Wazuh login the installer finds. None of this file reaches Fleet, and Fleet cannot change it. Install the connector writes the file, and The connector is the shape around it.
Where the file is
/etc/fleet-connector/connector.yaml, mode 0600, owned by root, and named
explicitly by the systemd unit. The daemon reads it once, at start, and never
writes to it. A missing file is not an error: the defaults are the shipped
gateway and the shipped data directory. A file it cannot parse is an error, and
a fatal one.
Hosts installed before the rename keep their configuration at
/etc/mobius/connector.yaml. It is still read, but only while
/etc/fleet-connector/connector.yaml does not exist, and the log says so. The
installer copies it across rather than moving it, so the original stays where
a pre-move unit still points, and it leaves the old file alone on a host that
also runs a mobius-connector binary or unit, where that file is the other
product's. A --config pointing anywhere else never falls back.
What the installer writes
A host installed with --connect. Nothing else is written; the rest of the
table below is yours to add, and the file is the same on every host whatever
Wazuh runs beside it.
# Wazuh Fleet connector configuration.
# Written by `fleet-connector provision`. The connector reads nothing from
# Wazuh, so this file names no Wazuh address and no login.
connect_url: "wss://connect.fleet.wazuh.com" # only when --connect was given
data_dir: "/var/lib/fleet-connector" # identity, gateway CA, staged updates
heartbeat_seconds: 30
request_timeout_seconds: 30
Re-running the installer with --force rewrites the file and keeps one thing
from the old one: the upgrade block. Everything else, including the keys
listed under What an older file may still
carry, is dropped.
Every key is optional. A string that is absent or blank falls back to its
default, and so does a heartbeat_seconds or request_timeout_seconds of zero
or less. A boolean is taken as written rather than read as unset, which is what
makes upgrade.enabled: false a real veto instead of a line that reads as
missing.
Every field
| Key | Default | What it does |
|---|---|---|
connect_url | wss://connect.fleet.wazuh.com | The gateway this host dials. The session URL is this plus /connect. |
enroll_url | derived | Unset, it is connect_url as https plus /enroll. Certificate renewal follows it, at /renew on the same base. |
data_dir | /var/lib/fleet-connector | Holds key.pem, cert.pem, ca.pem, connector_id and staged updates. |
upgrade.enabled | true | false logs and ignores every update directive. |
upgrade.plugins_enabled | true | false refuses plugin installs while still updating the core. |
upgrade.download_host | dl.fleet.wazuh.com | Where core artifacts are fetched from. Any other host is refused, including on a redirect hop. |
upgrade.download_hosts_allow | empty | Extra hosts, additive: the Fleet site stays allowed whatever this says. |
heartbeat_seconds | 30 | How often the host reports. |
request_timeout_seconds | 30 | Parsed for compatibility. The connector relays no queries, so it has no effect today. |
Fleet marks a host Disconnected when no heartbeat has arrived in 90
seconds, so a heartbeat_seconds above that reads as an outage between beats.
data_dir also means changing the unitThe unit runs ProtectSystem=strict with
ReadWritePaths=/var/lib/fleet-connector, the only writable path the service
has. Pointing data_dir elsewhere without changing the unit gives a connector
that cannot write its own identity. That directory is named in four places on
purpose: the installer, the binary's compiled default, the unit, and the path
unit that watches upgrade/requests/ for a staged update.
What an older file may still carry
A connector installed before this release wrote five more keys, and every one
of them is about Wazuh: indexer, wazuh_api, deployment, dashboard_config
and active_response. A file that still has them loads. The connector reads
none of them, and it says so once, at start, in one log line that names the
keys it found:
connector.yaml: deployment, indexer, wazuh_api are ignored since this release: no login is read from this file. You may remove them; the file is never rewritten.
You may delete those keys or leave them. The connector never edits the file, so
the line repeats on every start until you do. A login left under indexer or
wazuh_api is never read and never reaches a service on the host. A service gets
its login from its own console, or starts with the one the installer finds on
the host. Active Response is configured from
Mobius, not from Fleet, and installing with --active-response or
--no-active-response is refused. What Fleet can
do is the full list of what the connector will
and will not do.
What the connector reports about its host
Every heartbeat, 30 seconds apart by default, carries two things and nothing
else. Node is the hostname, OS, architecture, the distribution's
PRETTY_NAME from /etc/os-release, the kernel release and when this process
started, read once at start so the console can tell a restart loop from a
long-running host. Services is the status of each Fleet service running on
the host (Connected services).
It reports nothing about your Wazuh deployment: it does not probe the indexer or the Wazuh server API, count agents or read cluster membership. Nothing about the machine beyond the node facts leaves it: no CPU, no disk, no process list.
Applying a change
The file is read once, at start, so a change takes effect on a restart.
sudo vi /etc/fleet-connector/connector.yaml
sudo systemctl restart fleet-connector
journalctl -u fleet-connector -n 50
The startup line confirms what was loaded: fleet-connector <version> starting; gateway=…, preceded by the one line about ignored keys when the file has any.
See Connector logs for the other lines it writes.
A YAML error is fatal: the process exits with config: parse config /etc/fleet-connector/connector.yaml: …, systemd restarts it five seconds later,
and it exits again. The host reads Disconnected 90 seconds after the last
good heartbeat, and the journal is the only place that says why.
Re-running the installer keeps an existing file unless you pass --force, which
rewrites it, keeping the upgrade block and discarding every other hand
edit. The installer takes no typed Wazuh credentials. Updates to the binary are
separate, in Connector lifecycle, with
upgrade.enabled as the host owner's veto.