> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloud.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Private Cloud Connector

> The Private Cloud Connector feature of Connect AI is software you install in an on-premises network. The connector acts as a bridge between your on-premises data (not in the cloud) and Connect AI.

The Private Cloud Connector is an on-premises connector, which you can run as a Docker container or deploy to Kubernetes via Helm. The connector acts as a secure reverse tunnel between the data behind your company's firewall, private network, or Virtual Private Cloud (VPC) and the Connect AI cloud-based services. It allows Connect AI to access your data without exposing your data directly to the internet.

<Frame>
  <img src="https://mintcdn.com/cdata/FAluS_11BOyREE-4/en/images/private_cloud_connector_architecture.svg?fit=max&auto=format&n=FAluS_11BOyREE-4&q=85&s=9e3522d8a6011228772640bb48f34fa9" alt="Private Cloud Connector Architecture" width="960" height="340" data-path="en/images/private_cloud_connector_architecture.svg" />
</Frame>

You then register each connector in the Connect AI user interface, within the individual connection setup. You can have connectors in multiple locations. You must register a connector in Connect AI for each location.

The Private Cloud Connector provides high availability by supporting multiple connector instances—either multiple Docker containers, or replicas in a Kubernetes deployment—pointing to the same location and account Id. If one instance goes down, requests are automatically routed to the remaining connector instances.

The following diagram shows how Private Cloud Connector supports multiple locations and multiple data sources.

<Frame>
  <img src="https://mintcdn.com/cdata/FAluS_11BOyREE-4/en/images/private_cloud_connector_architecture_advanced.svg?fit=max&auto=format&n=FAluS_11BOyREE-4&q=85&s=3b262978e479a06870cf2e482760c9f1" alt="Private Cloud Connector Architecture Advanced" width="1000" height="680" data-path="en/images/private_cloud_connector_architecture_advanced.svg" />
</Frame>

The following is a list of some of the connectors that Connect AI supports with the Private Cloud Connector:

* [API](/en/Data-Sources/APIConnector)
* [Confluence](/en/Data-Sources/Confluence)
* [Databricks](/en/Data-Sources/Databricks)
* [GitHub](/en/Data-Sources/GitHub)
* [Jira](/en/Data-Sources/JIRA)
* [MySQL](/en/Data-Sources/MySQL)
* [PostgreSQL](/en/Data-Sources/PostgreSQL)
* [QuickBooks](/en/Data-Sources/QuickBooks)
* [SAP Business One](/en/Data-Sources/SAPBusinessOne)
* [SAP Gateway](/en/Data-Sources/SAPGateway)
* [Snowflake](/en/Data-Sources/Snowflake)
* [Splunk](/en/Data-Sources/Splunk)
* [SQL Server](/en/Data-Sources/SQL)

Contact [CData Support](https://www.cdata.com/support/submit.aspx) if you need a different connector with the Private Cloud Connector.

Setting up the Private Cloud Connector involves three main steps:

<Steps>
  <Step>
    [Register the Private Cloud Connector in Connect AI](#register-the-private-cloud-connector-in-connect-ai).
  </Step>

  <Step>
    Install and run the connector in each location where your on-premises data is located. You can either [deploy the Private Cloud Connector with Docker](#deploy-the-private-cloud-connector-with-docker) or [deploy the Private Cloud Connector on Kubernetes](#deploy-the-private-cloud-connector-on-kubernetes).
  </Step>

  <Step>
    [Finish the Private Cloud Connector setup](#finish-private-cloud-connector-setup) in Connect AI to test the connector and complete the connection.
  </Step>
</Steps>

## Register the Private Cloud Connector in Connect AI

To register the Private Cloud Connector in Connect AI:

<Steps>
  <Step>
    Go to **Sources** and click **Add Connection** for a new connection, or edit an existing connection.
  </Step>

  <Step>
    Click the **Private Cloud Connector** tab in the **Add/Edit Connection** page.
  </Step>

  <Step>
    In **Connectors**, click **Add**. The **Add Connector** dialog appears.

    <Frame>
      <img src="https://mintcdn.com/cdata/FAluS_11BOyREE-4/en/images/private_cloud_connector_add_connector.png?fit=max&auto=format&n=FAluS_11BOyREE-4&q=85&s=334c8696467767e5941b1b77637b8951" alt="Add Connector" width="600" height="317" data-path="en/images/private_cloud_connector_add_connector.png" />
    </Frame>
  </Step>

  <Step>
    Enter a descriptive location name to identify where the connector is installed, and click **Confirm**.

    Your location appears in the **Connectors** list, along with a key and a **Pending** status. Click the eye icon to view the key.

    <Frame>
      <img src="https://mintcdn.com/cdata/FAluS_11BOyREE-4/en/images/private_cloud_connector_list.png?fit=max&auto=format&n=FAluS_11BOyREE-4&q=85&s=68154e7f8516801b08ba71b588a1e99e" alt="Connectors List" width="1147" height="287" data-path="en/images/private_cloud_connector_list.png" />
    </Frame>

    You must copy the following values for the connector (click the copy icons):

    * **Account Id**–this is the ACCOUNT\_ID environment variable for the connector.
    * **Location Id**–this is the GATEWAY\_LOCATION\_ID environment variable for the connector.
    * **Key**–this is the GATEWAY\_API\_KEY environment variable for the connector.
  </Step>
</Steps>

## Deploy the Private Cloud Connector with Docker

The Private Cloud Connector is a lightweight service that runs inside your network and acts as a secure reverse tunnel between Connect AI and your local data sources. The connector registers itself with Connect AI on startup. It then listens for incoming connections, via Azure Relay technology, without ever exposing them to the public internet.

The connector is protocol-agnostic: it forwards raw bytes without any knowledge of the database protocol (such as MySQL, PostgreSQL, or SQL Server), making it compatible with any TCP-based data source.

### Prerequisites

To run the Private Cloud Connector as a Docker container, you must have the following:

* Docker installed on the host machine.
* Network access to `cloud.cdata.com`.
* The connector created in Connect AI.
* Host IP forwarding (`net.ipv4.ip_forward=1`) enabled. Docker requires this for container outbound connectivity; note that OS patching and security-hardening baselines (CIS/STIG) may reset it to 0.
* Egress TLS inspection must be bypassed for `*.servicebus.windows.net`, `*.azurecr.io`, and `*.cdata.com`. SSL inspection on these endpoints will prevent the connector relay tunnel from establishing.

### Environment Variables

The following environment variables are required to run the connector:

| Variable | Description |
| :- | :- |
| GATEWAY\_LOCATION\_ID | The unique identifier for this connector instance. Copy the value under the user-defined **Location Name** in the Connectors list in Connect AI. |
| GATEWAY\_API\_KEY | The secret API key used to authenticate this connector with Connect AI. Copy the value under **Key** in the Connectors list in Connect AI. |
| ACCOUNT\_ID | Your CData Connect AI account identifier. This is specific to your organization. Copy **Account Id** in the Connectors list in Connect AI. |

### Run the Connector in Docker

Run the connector as follows:

```bash wrap theme={null}
docker run \
    --name my-onprem-gateway \
    -e GATEWAY_LOCATION_ID=<gateway_location_id> \
    -e GATEWAY_API_KEY=<gateway_api_key> \
    -e ACCOUNT_ID=<account_id> \
    connectaipublic.azurecr.io/connectgateway:latest
```

<Note>`docker run` will pull the Docker image from the registry if it is not already present on the host.</Note>

#### View Docker Logs

```bash wrap theme={null}
docker logs -f my-onprem-gateway
```

#### Stop the Connector

```bash wrap theme={null}
docker stop my-onprem-gateway
docker rm my-onprem-gateway
```

### Docker Compose

Copy the following and save as `docker-compose.yml`:

```yaml theme={null}
version: "3.8"

services:
  onprem-gateway:
    image: connectaipublic.azurecr.io/connectgateway:latest
    container_name: my-onprem-gateway
    restart: unless-stopped
    environment:
      GATEWAY_LOCATION_ID: <gateway_location_id>
      GATEWAY_API_KEY: <gateway_api_key>
      ACCOUNT_ID: <account_id>
```

#### Start the Private Cloud Connector

```bash wrap theme={null}
docker compose up
```

<Note>`docker compose up` will pull the Docker image from the registry if it is not already present on the host.</Note>

#### View Logs

```bash wrap theme={null}
docker compose logs -f
```

#### Stop the Private Cloud Connector

```bash wrap theme={null}
docker compose down
```

## Deploy the Private Cloud Connector on Kubernetes

The Private Cloud Connector Kubernetes Helm chart is available in a [GitHub repository](https://github.com/CDataSoftware/connect-gateway-helm/).

### Prerequisites

To deploy the Private Cloud Connector on Kubernetes, you must have the following:

* Kubernetes 1.25 or later
* Helm 3.10 or later
* Metrics Server installed on your cluster (required for memory-based autoscaling)
* Network egress from the cluster to `cloud.cdata.com`
* Egress TLS inspection must be bypassed for `*.servicebus.windows.net`, `*.azurecr.io`, and `*.cdata.com`. SSL inspection on these endpoints will prevent the connector relay tunnel from establishing.
* Your **Account Id**, **Location Id**, and **Key** from Connect AI. See [Register the Private Cloud Connector in Connect AI](#register-the-private-cloud-connector-in-connect-ai) for the location of these values.

### Quick Start

Add the Helm repository:

```bash wrap theme={null}
helm repo add cdata https://cdatasoftware.github.io/connect-gateway-helm
helm repo update
```

Install the chart:

```bash wrap theme={null}
helm install connect-gateway cdata/connect-gateway \
  --set gateway.locationId=<location-id> \
  --set gateway.accountId=<account-id> \
  --set gateway.apiKey=<api-key> \
  -n connect-gateway --create-namespace
```

You can also install directly from a [GitHub release](https://github.com/CDataSoftware/connect-gateway-helm/releases). This is useful for air-gapped environments or when you do not want to add a Helm repo. Replace the version in the URL below with the latest release.

```bash wrap theme={null}
helm install connect-gateway \
  https://github.com/CDataSoftware/connect-gateway-helm/releases/download/v1.0.0/connect-gateway-1.0.0.tgz \
  --set gateway.locationId=<location-id> \
  --set gateway.accountId=<account-id> \
  --set gateway.apiKey=<api-key> \
  -n connect-gateway --create-namespace
```

<Note>For production, create a Kubernetes Secret containing your gateway credentials and pass `--set existingSecret=<secret-name>` instead of `--set gateway.apiKey=…`. Passing the API key with `--set` writes it to shell history and to the Helm release's stored values. See the Helm chart [Readme file](https://github.com/CDataSoftware/connect-gateway-helm/blob/main/charts/connect-gateway/README.md) for secret-management patterns.</Note>

### Verify the Private Cloud Connector is Running

Check that the connector pods are ready and view their logs:

```bash wrap theme={null}
kubectl get pods -n connect-gateway
kubectl logs -n connect-gateway -l app.kubernetes.io/name=connect-gateway -f
```

### Upgrade the Private Cloud Connector

```bash wrap theme={null}
helm repo update
helm upgrade connect-gateway cdata/connect-gateway -n connect-gateway
```

### Uninstall the Private Cloud Connector

```bash wrap theme={null}
helm uninstall connect-gateway -n connect-gateway
```

Refer to the Helm chart [Readme file](https://github.com/CDataSoftware/connect-gateway-helm/blob/main/charts/connect-gateway/README.md) for the full list of installation options, configuration values, and secret-management patterns.

## Finish Private Cloud Connector Setup

Return to Connect AI and finish the Private Cloud Connector setup.

<Steps>
  <Step>
    After you complete the steps to [deploy the Private Cloud Connector with Docker](#deploy-the-private-cloud-connector-with-docker) or [deploy the Private Cloud Connector on Kubernetes](#deploy-the-private-cloud-connector-on-kubernetes), you can test the connectors you added to **Connectors**. Click the **Private Cloud Connector** tab of the **Add/Edit Connection** page. Click **Test Connectors**. The **Status** turns to **Success** if all connector setup is complete.
    <Note>You still must click **Save & Test** to test the entire connection.</Note>
  </Step>

  <Step>
    Return to the **Basic Settings** tab of your connection. Under **Connection Type**, select **Private Cloud Connector**.
  </Step>

  <Step>
    Select the **Private Cloud Connector** location to use from the drop-down list.

    <Frame>
      <img src="https://mintcdn.com/cdata/FAluS_11BOyREE-4/en/images/private_cloud_connector_basic_settings.png?fit=max&auto=format&n=FAluS_11BOyREE-4&q=85&s=95809297d1131b88f15bd33265d9bc0e" alt="Basic Settings" width="751" height="249" data-path="en/images/private_cloud_connector_basic_settings.png" />
    </Frame>
  </Step>

  <Step>
    Enter the **Authentication** instructions for the connector according to the connector's **Documentation** pane.
  </Step>

  <Step>
    Click **Save & Test** to authenticate your connector.
  </Step>
</Steps>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.