How to set up Agent Controller on Windows Server
Aembit provides many different deployment options you can use to deploy Aembit Edge Components in your environment. Each of these options provide similar features and functionality. The steps for each of these options, however, are specific to the deployment option you select.
This page describes the process to deploy Agent Controller to a Windows Server virtual machine (VM).
To install Agent Controller on Windows Server, Aembit provides a Windows installer file (.msi).
See Installation details for more information about what it does.
Aembit supports three primary configurations when you install Agent Controller on Windows Server:
-
A single Windows Server.
-
A single Windows Server with Kerberos attestation enabled. See Kerberos Trust Provider.
-
Multiple Windows Servers in a high availability (HA) configuration using an Active Directory Group Managed Service Account (gMSA). Using a gMSA reduces the operational difficulty in managing secrets across multiple Agent Controller hosts.
Supported versions
Section titled “Supported versions”Use the following table to make sure that Aembit supports the operating system and platform you’re deploying to your VM:
| Operating system | Edge Component versions |
|---|---|
| Windows Server 2019 | Agent Controller v1.21.2101+ |
| Windows Server 2022 | Agent Controller v1.21.2101+ |
Prerequisites
Section titled “Prerequisites”Before you install Agent Controller on Windows Server, you must have the following:
-
Network and system access to download and install software on the Windows Server host.
-
If installing with Kerberos attestation enabled:
- Your Agent Controller Windows Server host joined to an Active Directory (AD) domain.
Install Agent Controller on Windows Server
Section titled “Install Agent Controller on Windows Server”To install an Aembit Agent Controller on Windows Server:
-
Download the latest release version of the Agent Controller installer from the Agent Controller releases page, making sure to replace the instances of
<version>with the latest version in the following command. Note that downloading directly via a browser may result in unexpected behavior.Terminal window Invoke-WebRequest `-Uri https://releases.aembit.io/agent_controller/<version>/windows/amd64/aembit_agent_controller_windows_amd64_<version>.msi `-Outfile aembit_agent_controller.msiNext, follow the installation steps in the appropriate tab:
-
Install Agent Controller using the following command. Make sure to replace
<TenantId>with your Aembit Tenant ID and<AgentControllerId>with the ID of the Agent Controller you are configuring.Terminal window msiexec /i aembit_agent_controller.msi /l*v installer.log `AEMBIT_TENANT_ID=<TenantId> `AEMBIT_AGENT_CONTROLLER_ID=<AgentControllerId>
-
Decide which hostname Agent Proxies use to reach this Agent Controller.
Each Agent Proxy requests a Kerberos ticket for the Agent Controller’s Service Principal Name (SPN)
HTTP/<hostname>. The Agent Controller service runs as the host’s computer account by default, and when the host joins the domain, Windows registers SPN entries on that computer account that cover the host’s own name. If Agent Proxies reach the Agent Controller by a different name, such as a DNS alias, register that SPN on the Agent Controller’s computer account from a domain-joined host with AD administrator privileges:Terminal window setspn -S HTTP/<alias> <Agent Controller computer name>To list every SPN registered on the Agent Controller’s computer account, run
setspn -L <Agent Controller computer name>. -
Install the Agent Controller, using the following command. Make sure to replace
<TenantId>with your Aembit Tenant ID and<AgentControllerId>with the ID of the Agent Controller you are configuring.Terminal window msiexec /i aembit_agent_controller.msi /l*v installer.log `AEMBIT_AGENT_CONTROLLER_ID=<AgentControllerId> `AEMBIT_TENANT_ID=<TenantId> `AEMBIT_KERBEROS_ATTESTATION_ENABLED=true -
Make sure to add the Kerberos Trust Provider in your Aembit Tenant.
-
When installing the Agent Proxy, set the host part of
AEMBIT_AGENT_CONTROLLERto the hostname in the SPN, for exampleAEMBIT_AGENT_CONTROLLER=http://<hostname>:5000. An IP address doesn’t work, because no SPN matches it.
-
Create a Group Managed Service Account (gMSA) in AD and allow every Agent Controller host to retrieve its password. Every Agent Controller in the cluster runs as this gMSA.
-
Register the SPN
HTTP/<Load Balancer hostname>on the gMSA:Terminal window setspn -S HTTP/<Load Balancer hostname> <gMSA name>You don’t need an SPN for each individual Agent Controller host.
-
Install Agent Controller on each host, using the following command. Run the
.msiinstaller to enable Trust Provider-based Agent Controller registration, making sure to replace<AgentControllerId>and<TenantId>with the values from your Aembit Tenant.To install Agent Controller on Windows Server using a gMSA, you must also set the
SERVICE_LOGON_ACCOUNTenvironment variable using Down-Level Logon Name formatSERVICE_LOGON_ACCOUNT=<NetBIOS domain name>\\<sAMAccountName of gMSA>. Use the same gMSA on every host.Terminal window msiexec /i aembit_agent_controller.msi /l*v installer.log `AEMBIT_AGENT_CONTROLLER_ID=<AgentControllerId> `AEMBIT_TENANT_ID=<TenantId> `AEMBIT_KERBEROS_ATTESTATION_ENABLED=true `SERVICE_LOGON_ACCOUNT=<NetBIOS domain name>\<sAMAccountName of gMSA>$ -
When installing the Agent Proxy, set the host part of
AEMBIT_AGENT_CONTROLLERto the load balancer hostname in the SPN, for exampleAEMBIT_AGENT_CONTROLLER=http://<Load Balancer hostname>:5000. -
Make sure to add the Kerberos Trust Provider in your Aembit Tenant and select every Agent Controller in the cluster in its Agent Controller field.
Agent Controller environment variables
Section titled “Agent Controller environment variables”For a list of all available environment variables for configuring the Agent Controller installer, see Agent Controller environment variables reference.
(Optional) Verify the service account
Section titled “(Optional) Verify the service account”By default, the Agent Controller service runs as the LocalService
account.
To verify that the Agent Controller service is running as the expected service account, use the following PowerShell command:
(Get-WmiObject Win32_Service -Filter "Name='AembitAgentController'").StartNameIf you don’t see the Aembit Agent Controller service running or if it’s running as a different user, uninstall Agent Controller and retry these instructions.
Uninstall Agent Controller
Section titled “Uninstall Agent Controller”To uninstall Agent Controller from your Windows Server, use Windows built-in Add/Remove Programs feature like you’d normally uninstall any other program or app from Windows.
Limitations
Section titled “Limitations”Agent Controller on Windows has the following limitations:
-
The Kerberos Trust Provider can’t register the Agent Controller -
The Agent Controller attests Agent Proxies for the Kerberos Trust Provider and can’t attest itself the same way. Register a domain-joined Agent Controller on premises with a Device Code. When the host runs in AWS, Azure, or Kubernetes, register it with an AWS Role, AWS Metadata Service, Azure Metadata Service, or Kubernetes Service Account Trust Provider instead.
-
Changing the service logon account after installation isn’t supported -
If you need to change to a different Windows service account, you must uninstall and reinstall the Agent Controller on your Windows Server host.
-
Changing the TLS strategy may not work as expected -
Because of the way Aembit stores and preserves parameters, changing from a TLS configuration using customer certificates to a configuration using Aembit-managed certificates may not work as expected. To remediate:
- Uninstall the Agent Controller.
- Delete the
C:\ProgramData\Aembit\AgentControllerdirectory and its contents. - Reinstall the Agent Controller.
Installation details
Section titled “Installation details”| Attribute | Value |
|---|---|
| Service name | AembitAgentController |
| Binary location | C:\Program Files\Aembit\AgentController\aembit_agent_controller.exe |
| Log files | C:\ProgramData\Aembit\AgentController\Logs |