Skip to main content
Version: v3.9.0
Deploy on Linux hosts instead?

For bare metal or VMs over SSH, use Remote control plane. This guide uses kind: KubernetesControlPlane on a Kubernetes cluster.

Deploy Control Plane on a Kubernetes with potctl

Use kind: KubernetesControlPlane to install the operator in a namespace, apply a ControlPlane custom resource, wait until the stack is ready, and register the CLI user against the Controller API.

LayerkindPurpose
CLI deploy YAMLKubernetesControlPlaneWhat you author for deploy -f
Cluster custom resourceControlPlaneWhat the operator reconciles

The CLI translates most of spec into the operator CR. Fields such as spec.config, spec.ca, and spec.iofogUser are CLI-only. See Kubernetes deploy guide and ControlPlane CRD.

Field reference

Full KubernetesControlPlane fields: Kubernetes schema. Production TLS: Kubernetes TLS (CLI) and Kubernetes TLS (operator).

Deploy a control plane on Kubernetes​

Authentication

Set auth.mode: embedded in your control plane YAML. See Embedded OIDC.

NATS replicas

When NATS is enabled, use at least 2 NATS replicas to initialize the JetStream cluster.

External database for HA

You must configure an external database when replicas.controller is greater than 1. See Database installation.

Prerequisites​

  • kubectl access via spec.config (kubeconfig path)
  • CLI namespace (-n) equals the Kubernetes namespace where the operator and CR live
  • If both metadata.namespace and -n are set, they must match

Create controlplane.yaml:

controlplane.yaml
---
apiVersion: datasance.com/v3
kind: KubernetesControlPlane
metadata:
name: minimal-k8s-cp
namespace: iofog
spec:
config: ~/.kube/config
iofogUser:
name: Admin
surname: User
auth:
mode: embedded
bootstrap:
username: admin
password: ChangeMe12!
replicas:
controller: 1
nats: 2
controller:
publicUrl: https://controller.example.com
logLevel: info
https: true
secretName: controller-tls
images:
operator: ghcr.io/datasance/operator:3.9.0
controller: ghcr.io/datasance/controller:v3.9.0
router: ghcr.io/datasance/router:3.9.0
nats: ghcr.io/datasance/nats:2.15.0
services:
controller:
type: LoadBalancer
router:
type: LoadBalancer
nats:
enabled: true
jetStream:
storageSize: 10Gi

Set spec.config to your kubeconfig path. Use a dedicated namespace in production.

Deploy:

potctl deploy -f controlplane.yaml -n iofog

Check cluster objects:

kubectl get all -n iofog

Verify the deployment​

potctl describe controlplane
potctl get controllers

For ingress patterns (B1/B2), vault, and service overrides, see Kubernetes schema and Operator TLS guide.

Next step

Go to Set up Edgelet nodes to provision Edgelet v1.1.0 on edge hosts.

Group 3See anything wrong with the document? Help us improve it!