Datasance PoT v3.9.0 uses embedded OIDC by default. You do not need an external IdP for a new lab deploy. Set auth.mode: embedded and bootstrap credentials in your Control Plane YAML before you deploy.
Upgrading from v3.8.0? See Upgrading to v3.9.0. Greenfield from v3.7.x or older starts at Migrating to v3.8.0.
Download and install potctl from the download page before continuing.
Try the Quick Start Guide before this guide. It covers the same potctl workflows on a single machine.
Introduction
An Edge Compute Network (ECN) has two main parts: a Control Plane (Controller, Router, optional NATS) and Edgelet nodes at the edge.
potctl deploys and manages both from YAML manifests. This guide walks through a distributed ECN on remote hosts or a Kubernetes cluster.
For architecture context, see Architecture.
Deployment path
Follow these steps in order:
- Embedded OIDC - Set
auth.mode: embeddedand bootstrap credentials in your Control Plane YAML. For a corporate IdP, see External OIDC. - Prepare your network - Open firewall ports for Controller, Router, NATS, and EdgeOps Console.
- Prepare remote hosts - SSH keys and passwordless sudo for potctl.
- Deploy the Control Plane - Choose remote or Kubernetes (potctl or Helm).
- Setup Edgelet nodes - Install Edgelet v1.1.0 on edge hosts (platform train v3.9.0).
Deployment options
Remote Control Plane
Deploy the Controller on one or more Linux hosts over SSH. Prepare the Controller host and each Edgelet node host. See Remote Control Plane.
Kubernetes Control Plane
Deploy the Controller, Operator, Router, and NATS on a Kubernetes cluster. You only need remote hosts for Edgelet nodes. Start at Kubernetes - Prepare A Cluster.
TLS and trust by deploy path
| Layer | Kubernetes | Local quick start | Remote SSH |
|---|---|---|---|
| Controller HTTPS | Operator pod TLS or Ingress | CLI spec.tls on Edgelet | spec.tls or controllers[].tls |
| Router / NATS CAs | Operator Secrets | YAML validated; BYO upload on remote only today | CLI uploads global CA blocks after API is up |
| CLI API trust | spec.ca in namespace trust store | Same | Same |
Start at Securing the cluster, then open the guide for your path (Kubernetes, remote, or local).
Air-gapped networks
For hosts that cannot reach the internet or container registries, see Airgap Deployment. That page covers Edgelet image bundles, multi-arch offline transfer, and Offline images in Learn for microservice images.
Start with Embedded OIDC Authentication, then Prepare your network.