For bare metal or VMs over SSH, use Remote control plane. This guide uses kind: KubernetesControlPlane on a Kubernetes cluster.
Deploy Control Plane on a Kubernetes with potctl
Use kind: KubernetesControlPlane to install the operator in a namespace, apply a ControlPlane custom resource, wait until the stack is ready, and register the CLI user against the Controller API.
| Layer | kind | Purpose |
|---|---|---|
| CLI deploy YAML | KubernetesControlPlane | What you author for deploy -f |
| Cluster custom resource | ControlPlane | What the operator reconciles |
The CLI translates most of spec into the operator CR. Fields such as spec.config, spec.ca, and spec.iofogUser are CLI-only. See Kubernetes deploy guide and ControlPlane CRD.
Full KubernetesControlPlane fields: Kubernetes schema. Production TLS: Kubernetes TLS (CLI) and Kubernetes TLS (operator).
Deploy a control plane on Kubernetes
Set auth.mode: embedded in your control plane YAML. See Embedded OIDC.
When NATS is enabled, use at least 2 NATS replicas to initialize the JetStream cluster.
You must configure an external database when replicas.controller is greater than 1. See Database installation.
Prerequisites
kubectlaccess viaspec.config(kubeconfig path)- CLI namespace (
-n) equals the Kubernetes namespace where the operator and CR live - If both
metadata.namespaceand-nare set, they must match
Create controlplane.yaml:
---
apiVersion: datasance.com/v3
kind: KubernetesControlPlane
metadata:
name: minimal-k8s-cp
namespace: iofog
spec:
config: ~/.kube/config
iofogUser:
name: Admin
surname: User
auth:
mode: embedded
bootstrap:
username: admin
password: ChangeMe12!
replicas:
controller: 1
nats: 2
controller:
publicUrl: https://controller.example.com
logLevel: info
https: true
secretName: controller-tls
images:
operator: ghcr.io/datasance/operator:3.9.0
controller: ghcr.io/datasance/controller:v3.9.0
router: ghcr.io/datasance/router:3.9.0
nats: ghcr.io/datasance/nats:2.15.0
services:
controller:
type: LoadBalancer
router:
type: LoadBalancer
nats:
enabled: true
jetStream:
storageSize: 10Gi
Set spec.config to your kubeconfig path. Use a dedicated namespace in production.
Deploy:
potctl deploy -f controlplane.yaml -n iofog
Check cluster objects:
kubectl get all -n iofog
Verify the deployment
potctl describe controlplane
potctl get controllers
For ingress patterns (B1/B2), vault, and service overrides, see Kubernetes schema and Operator TLS guide.
Go to Set up Edgelet nodes to provision Edgelet v1.1.0 on edge hosts.