Eval Kit Quick Start Guide

Time to Admin UI: typically 15 to 20 minutes after you click Create stack. First-Time Setup runs automatically (headless) - you do not walk the wizard yourself.

Have your own VPC and Active Directory® already? Use the standard Quick Start Guide (Single-AZ or Dual-AZ) instead.


What the Eval Kit is

The Eval Kit is a self-contained, single-AZ Marketplace launch that stands up everything you need to try Roadrunner SMB™ without bringing your own network or directory.

Piece What you get
Single-AZ VPC Private + public subnets, NAT, and supporting networking in one Availability Zone
Windows Server® AD / DC A deploy-time domain controller for corp.acme.com (NetBIOS ACME)
Single-AZ Roadrunner SMB Nested appliance stack (default 2 nodes) on Amazon EFS®, behind an internet-facing NLB

Headless First-Time Setup joins the appliance to that domain and finishes product setup before you log in. The stack self-uninstalls after EvalLifetimeDays (default 30, maximum 30), removing every billable resource it created.


Step 1 - Subscribe and launch

  1. Open Roadrunner SMB in AWS Marketplace and Subscribe.

  2. Choose the Eval Kit delivery option → Continue to Configuration → pick your RegionContinue to Launch.

  3. Choose Launch CloudFormation®Launch.

  4. On the Create stack page you typically see:

    Parameter What to enter
    AdminAccessCidr Your public IP as x.x.x.x/32 (or leave 0.0.0.0/0 for open Admin UI access during evaluation)
    InstanceType c6i.2xlarge (default) unless you need a smaller or larger size
    EvalLifetimeDays 30 (default) - days until automatic self-uninstall
  5. Acknowledge the capability checkboxes, then Create stack.

  6. Wait for the parent stack RoadrunnerSMB-Eval to reach CREATE_COMPLETE.

Parent stack name is typically RoadrunnerSMB-Eval. Nested stacks under it create the VPC/DC and the Roadrunner SMB appliance - use the parent for day-one Outputs (next steps).


Step 2 - Find the Admin URL (CloudFormation Outputs)

  1. Open the AWS CloudFormation console in the same Region as your stack.

  2. Select the parent stack: RoadrunnerSMB-Eval (not a nested ...-EvalStack-... or ...-InnerStack-... name).

  3. Open the Outputs tab.

  4. Use these outputs:

    Output Use it for
    AdminUIUrl Admin console URL (https://...) - open this in your browser
    EvalAdminLogin Suggested domain admin login (for example ACME\eval-admin)
    EvalCredentialsConsoleUrl One-click link into Secrets Manager for passwords
    EvalCredentialsSecretArn Secret ARN for CLI / automation
    NlbDnsName SMB hostname (\\<NlbDnsName>\<sharename>) after you create a share
    EvalLifetimeDays / EvalTeardownAt When automatic self-uninstall is scheduled

Confirm the Admin URL starts with https://. HTTP is not supported. Accept the browser warning for the self-signed certificate.


Step 3 - Get passwords from Secrets Manager

Passwords are never printed in CloudFormation Outputs. Retrieve them from AWS® Secrets Manager.

Open the secret

  1. On the RoadrunnerSMB-Eval Outputs tab, click EvalCredentialsConsoleUrl
    (or open Secrets Manager and search for eval-dc-passwords).
  2. Choose Retrieve secret value. The secret is JSON.

JSON fields you need

Field Account Used for
EvalAdminPassword Domain user eval-admin (Domain Admin) Day-to-day Admin UI login and SMB as a privileged AD user
EvalUserPassword Domain user eval-user (regular user) Non-admin SMB / ACL tests - not for Admin UI day-to-day
ApplianceOwnerPassword Local rrsmb-admin (Appliance Owner) Break-glass Admin UI when AD is unreachable - cannot access SMB shares
DSRMPassword Windows® Directory Services Restore Mode DC recovery only - not used for Roadrunner Admin UI or SMB

After headless First-Time Setup finishes, ApplianceOwnerPassword is written into the same secret as the AD passwords. If that field is missing, wait a minute and retrieve the secret again, or confirm the stack has reached CREATE_COMPLETE.


Step 4 - Log in as eval-admin

  1. Open AdminUIUrl from the parent stack Outputs.

  2. Username - use one of these (all accepted):

    • eval-admin (simple)
    • ACME\eval-admin (NetBIOS - matches EvalAdminLogin)
    • eval-admin@corp.acme.com (UPN)
  3. Password - paste EvalAdminPassword from Secrets Manager (copy/paste exactly; do not type it by hand if you can avoid it).

  4. Sign in. You should see the Dashboard.

Do not combine formats. ACME\eval-admin@corp.acme.com is rejected. With a DOMAIN\ prefix, use the short account name, not the UPN.

Other accounts (same secret)

Login Password field Notes
eval-admin EvalAdminPassword Domain Admin - primary Eval Kit operator account
eval-user EvalUserPassword Regular AD user for share permission tests
rrsmb-admin ApplianceOwnerPassword Local Appliance Owner (break-glass Admin UI only)

Full identity model: Identity and permissions.


Step 5 - Create a share and mount (same as standard Quick Start)

From here the product workflow matches the standard guide:

  1. SharesCreate Share → name the share → set permissions → Create (wait 15-60 seconds).
  2. On a Windows client that can reach the NLB, mount:
\\<NlbDnsName>\<sharename>

Use NlbDnsName from the RoadrunnerSMB-Eval Outputs tab. Sign in with an AD account that has share access (for example eval-admin or eval-user and the matching password from the secret).

Detailed steps: Quick Start - Create your first share · Quick Start - Mount from Windows


What's next


Common Eval Kit issues

Symptom Likely cause Fix
Admin UI won't load Stack still converging, or AdminAccessCidr excludes your IP Wait for parent CREATE_COMPLETE; confirm your public IP is allowed; use parent Outputs AdminUIUrl
Can't find passwords Looking at Outputs instead of Secrets Manager Use EvalCredentialsConsoleUrlRetrieve secret value
Login failed for eval-admin Wrong password field, or mixed username format Paste EvalAdminPassword; use one username format only
ApplianceOwnerPassword missing Headless FTS still finishing Wait until CREATE_COMPLETE, retrieve the secret again
Can't mount share No share yet, or NLB not healthy Create a share in Admin UI; wait ~2 minutes; check Cluster
Reinstall in same Region fails with CloudFormation name-conflict on a log group Straggler Eval Kit log groups left after uninstall Delete /rrsmb/eval/<region>/cfn-lambda and /rrsmb/eval/<region>/lambda if present, then relaunch. See Release Notes - Errata

More help: Support & Troubleshooting.

Get it on AWS Marketplace

Subscribe and launch into your VPC — most teams reach a first SMB share in about 30 minutes.

AWS Marketplace · Home · Product · Pricing · Partners · Documentation · Windows File Server · Samba on EFS · FSx for Windows · Resources · Blog · About · Quick Start · Release Notes · Support

© 2026 Roadrunner SMB, LLC

Roadrunner SMB is an independent software project and is not affiliated with, endorsed by, or sponsored by Amazon Web Services, Inc.
Amazon Web Services, AWS, and Amazon EFS are trademarks of Amazon.com, Inc. or its affiliates.
Microsoft, Windows, and Active Directory are trademarks of the Microsoft Corporation in the United States and/or other countries.
Citrix and SoftNAS are registered trademarks of their respective owners.
Roadrunner SMB and Elastic SMB are trademarks of Roadrunner SMB, LLC. All rights reserved.