The agent on Windows
Windows is where the agent does the most — VSS, application-consistent Hyper-V and SQL Server, a Dokany-backed cloud drive, and a tray application for the user. This page is everything specific to it.
Requirements #
- Windows 10 or 11, or Windows Server 2016 or later; x64 or ARM64 builds. The agent is self-contained (.NET bundled) and installs the Visual C++ runtime it needs.
- Outbound HTTPS (443) to
console.caryvane.com. Nothing inbound. A proxy that inspects TLS must trust the chain or exempt the host. - Local administrator rights for the install; the service then runs as SYSTEM.
- For Hyper-V incremental backup: Server 2016 or later. For SQL Server: the SQL Server VSS Writer service running.
The two installers #
CaryvaneAgentSetup-<ver>-x64.exe is an Inno Setup wrapper for double-click installs; it runs the MSI inside it. CaryvaneAgent-<ver>-x64.msi is for Intune, SCCM, RMM and scripts. Both are Authenticode-signed, as is every binary they install, so Defender and SmartScreen stay quiet. Use the arm64 builds on Snapdragon devices.
# MSI, silent, enrolled (the console writes this line for you under Agents → Enroll Agent)
msiexec /i "https://console.caryvane.com/downloads/agent/CaryvaneAgent-x64.msi" /quiet AURAWOLF_SERVER=https://console.caryvane.com AURAWOLF_TOKEN=<token>
# Setup EXE, silent, enrolled
CaryvaneAgentSetup-x64.exe /SP- /VERYSILENT /NORESTART /server="https://console.caryvane.com" /token="<token>"
# Uninstall (forgets the enrolment; keeps logs)
msiexec /x "CaryvaneAgent-x64.msi" /quiet
Intune: deploy the MSI as a line-of-business app with the two properties in the command-line arguments; one deployment token per device is the safe default (tokens are single-use), or create a multi-use token through the API for a batch.
What lands where #
| Item | Location |
|---|---|
| Service and tray binaries | C:\Program Files\Caryvane\Caryvane Agent\ |
| Service | CaryvaneAgent, Automatic, runs as SYSTEM |
| Tray application | Caryvane.Agent.Tray.exe, started at logon (HKCU Run) and relaunched by the service if it dies |
| Enrolment, database, manifests, cache | C:\ProgramData\Aurawolf\ — token.json, local_store.db, manifests\, cache\, hyperv-chains\ |
| Logs | C:\ProgramData\Aurawolf\logs\agent.log (daily rolling); shipped to the console at INFO and above |
| Server URL and deployment token from an MSI install | HKLM\SOFTWARE\Centurion Computers\Aurawolf Agent |
| Cloud-drive driver | Dokany, installed by the MSI; appears in Add or Remove Programs as Dokan Library |
The Aurawolf names are the product's original name, kept deliberately so upgrades never orphan an enrolment.
The tray application #
Runs in the user's session: shows enrolled/online state, the upload queue for cloud drives, offers Enroll Agent… when the machine is not enrolled, opens the console, and registers the Version history… Explorer context-menu verb on cloud drives. It talks to the service over a local named pipe; it holds no credentials.
Self-update #
When a release is published the agent downloads the MSI on its next check-in, verifies its signature, stops, upgrades and restarts — a minute of downtime, during which a running job is interrupted and reported honestly; the next run continues. Upgrades keep everything in ProgramData. The console's version column shows who has and has not moved; a machine stuck on an old version is offline or cannot reach the console.
Uninstall #
Add or Remove Programs, or msiexec /x. A true uninstall stops the service, removes the program, and forgets the machine: enrolment token, local database, status file and drive cache are deleted so a reinstall enrols afresh; logs are kept. An upgrade never does this.
Windows-only features #
- Use VSS for open files on Files jobs.
- Hyper-V, SQL Server and Active Directory App-consistent jobs.
- EFS-encrypted files are skipped with a warning (SYSTEM cannot read another user's EFS files); decrypt or exclude them.