Software Secure Workload
Activity Configure

High Availability Best Practices for Secure Connector client

A single VM running Secure Connector client is a single point of failure.

The recommended best practice is to create 2 dedicated VMs in different failure zones and install Secure Connector client software on both of them. The registration token is a OTP and must be generated twice and put at the required path on each installation (at /etc/tetration/cert/registration.token).

At the Secure Workload server, we only allow one active tunnel, but the clients will all keep trying to connect and become the active tunnel. So multiple installations of Secure Connector clients will act as a single hot and multiple cold standby clients - the currently active tunnel client VM can be discovered from the UI as we report its hostname and IP on the Secure Connector UI page.