Skip to main content
Version: v3.9.0
Authentication first

Datasance PoT v3.9.0 uses embedded OIDC by default. You do not need an external IdP for a new lab deploy. Set auth.mode: embedded and bootstrap credentials in your Control Plane YAML before you deploy.

Upgrading from v3.8.0? See Upgrading to v3.9.0. Greenfield from v3.7.x or older starts at Migrating to v3.8.0.

New to potctl?

Download and install potctl from the download page before continuing.

Deployed a local ECN first?

Try the Quick Start Guide before this guide. It covers the same potctl workflows on a single machine.

Introduction

An Edge Compute Network (ECN) has two main parts: a Control Plane (Controller, Router, optional NATS) and Edgelet nodes at the edge.

potctl deploys and manages both from YAML manifests. This guide walks through a distributed ECN on remote hosts or a Kubernetes cluster.

For architecture context, see Architecture.

Deployment path​

Follow these steps in order:

  1. Embedded OIDC - Set auth.mode: embedded and bootstrap credentials in your Control Plane YAML. For a corporate IdP, see External OIDC.
  2. Prepare your network - Open firewall ports for Controller, Router, NATS, and EdgeOps Console.
  3. Prepare remote hosts - SSH keys and passwordless sudo for potctl.
  4. Deploy the Control Plane - Choose remote or Kubernetes (potctl or Helm).
  5. Setup Edgelet nodes - Install Edgelet v1.1.0 on edge hosts (platform train v3.9.0).

Deployment options​

Remote Control Plane​

Deploy the Controller on one or more Linux hosts over SSH. Prepare the Controller host and each Edgelet node host. See Remote Control Plane.

Kubernetes Control Plane​

Deploy the Controller, Operator, Router, and NATS on a Kubernetes cluster. You only need remote hosts for Edgelet nodes. Start at Kubernetes - Prepare A Cluster.

TLS and trust by deploy path​

LayerKubernetesLocal quick startRemote SSH
Controller HTTPSOperator pod TLS or IngressCLI spec.tls on Edgeletspec.tls or controllers[].tls
Router / NATS CAsOperator SecretsYAML validated; BYO upload on remote only todayCLI uploads global CA blocks after API is up
CLI API trustspec.ca in namespace trust storeSameSame

Start at Securing the cluster, then open the guide for your path (Kubernetes, remote, or local).

Air-gapped networks​

For hosts that cannot reach the internet or container registries, see Airgap Deployment. That page covers Edgelet image bundles, multi-arch offline transfer, and Offline images in Learn for microservice images.

Where to go from here?
Group 3See anything wrong with the document? Help us improve it!