zrok
Install, configure, start, stop, and update a zrok remote-access share from the Edge Portal.
zrok creates a remote-access share for the local SIA Connect service. When the share is running, the Edge Portal displays a Current URL that you can open in a browser.
The Edge Portal installs and controls the zrok client for you. You only need to provide a zrok account token and, when applicable, the API endpoint for a self-hosted zrok service.
A zrok share provides remote access to the gateway service. Protect the account token and Current URL, and stop the share when remote access is no longer required.
Before you begin
Prepare the following:
- A zrok account token.
- Internet and DNS access from SIA Connect when using the hosted zrok service.
- The API endpoint when your organization uses a self-hosted zrok service.
For the hosted service, create an account and obtain the token by following Get an account token in the official zrok documentation.
Treat the account token like a password. It authenticates the gateway with the zrok service.
Open the zrok settings
- Sign in to the Edge Portal.
- Expand Tools in the sidebar.
- Select Remote Access.
- Find the Zrok card.
The card shows the installed client version, API endpoint, Current URL, status, and the actions available for the current state.
Understand the status
| Status | Meaning |
|---|---|
| Checking | The Edge Portal is retrieving the current zrok state. |
| Not installed | The zrok client is not installed on the gateway. |
| Stopped | The zrok client is installed, but no share is currently active. |
| Running | The zrok share is active and has returned a Current URL. |
| Error | zrok reported an error. The card displays the returned error details when available. |
Configure the zrok share
| Parameter | Required | Description |
|---|---|---|
| API endpoint | Only for self-hosted zrok | Enter the API address of your self-hosted zrok service. Leave this field empty when using the hosted zrok service. |
| Account token | Yes | The token used to authenticate the gateway and start the share. Use the visibility control to show or hide the entered value. |
The Edge Portal automatically configures the share target as localhost. There is no separate target field on the zrok card.
Install and start zrok
- If you use a self-hosted service, enter its API endpoint. Otherwise, leave the field empty.
- Enter the Account token.
- Select Install zrok.
- Keep the page open while the client is installed and configured.
- Wait for the card to show Running.
- Confirm that the card displays a valid Current URL.
A successful first installation displays zrok has been installed and configured successfully. If the client was already installed, the Edge Portal can instead display zrok was already installed and is now configured.
The Account token field is cleared after a successful operation.
Open the remote share
- Confirm that the status is Running.
- Select the link displayed under Current URL.
- Confirm that the shared SIA Connect service opens in the new browser tab.
A working Current URL confirms that the zrok share was created. Access can still depend on browser, account, or service restrictions outside the Edge Portal.
Stop the zrok share
- Select Stop zrok share.
- Select Stop zrok share to confirm.
Stopping the share disconnects the active remote-access connection. A successful stop displays Zrok share stopped successfully. The card then changes to Stopped.
Start a stopped share
- Review the saved API endpoint. Leave it empty for the hosted service.
- Enter the Account token again.
- Select Start zrok share.
- Wait for Zrok share started successfully.
- Confirm that the status changes to Running and a Current URL is displayed.
Update the zrok client
- Select Update zrok client.
- Review the update confirmation.
- Select Update client.
- Wait for the update operation to finish.
The Edge Portal displays zrok client updated successfully. when an update is installed. If no update is required, it displays zrok is already up to date.
The Remote Access page does not provide an action for uninstalling zrok.
Troubleshoot zrok
| Message or condition | What to do |
|---|---|
| Account token is required. | Enter the zrok account token before installing or starting the share. |
| Unable to read zrok configuration. | Confirm that the Edge Portal can communicate with the gateway, refresh the page, and try again. |
| zrok error: [message] | Use the displayed zrok message as the first troubleshooting step. Check the account token, API endpoint, internet connection, and DNS settings. |
| Failed to install zrok. | Check internet access and confirm that the gateway can reach the zrok service. Verify the account token and self-hosted API endpoint, then retry. |
| Failed to start zrok share. | Enter a current account token and confirm that the saved API endpoint is correct. Review any more specific message returned by the gateway. |
| Failed to stop zrok share. | Refresh the card to check whether the share is still running, then retry the stop action. |
| Failed to update zrok client. | Check internet and DNS access, then run the update again. Review the system logs if the error continues. |
| The status is Running, but the Current URL does not open | Confirm that the displayed address is a valid HTTP or HTTPS URL. Check internet access, browser restrictions, and the zrok service status. |
Use the Ping tool to test whether SIA Connect can reach an IP address or hostname. If the problem continues, review the system logs for the time when the zrok action failed.