- CLI instead of Helm: Kubernetes with potctl (
KubernetesControlPlaneYAML). - Linux hosts over SSH: Remote control plane.
Deploy the control plane on Kubernetes with Helm
This guide installs Datasance PoT on Kubernetes using the iofog-operator Helm chart. The chart deploys the operator Deployment and a ControlPlane custom resource with apiVersion: datasance.com/v3. The operator reconciles Controller, Router, NATS, Services, Secrets, and optional Ingress objects.
The legacy repo Datasance/helm (chart pot, https://datasance.github.io/helm) is deprecated. Use the Helm repository index linked below.
| Reference | Where to read |
|---|---|
Every controlplane.spec.* field | ControlPlane CRD |
| Controller, Router, NATS TLS on cluster | Securing Kubernetes cluster (operator) |
| CLI trust when the API uses HTTPS | Kubernetes TLS (CLI YAML) (spec.ca / connect --ca) |
| Auth bootstrap | Embedded OIDC |
Published chart defaults (values, tarball): Helm repository index.
Prerequisites
- Helm 3
- Kubernetes 1.22+
- kubectl
- Pull access to ghcr.io/datasance (operator, controller, router, nats)
- For NATS JetStream with PVCs: a suitable StorageClass
Charts are stamped per mirror at package time (crdGroup, imageRegistry, image tags). Do not override crdGroup or imageRegistry unless you run a custom build.
Add the Helm repository
helm repo add iofog-operator https://datasance.github.io/iofog-operator
helm repo update
Download defaults for editing:
helm show values iofog-operator/iofog-operator --version 3.9.0 > my-values.yaml
Or use the files on the index page: https://datasance.github.io/iofog-operator/values.yaml and values-3.9.0.yaml.
Quick install
Embedded OIDC is the default. Set a bootstrap password (≥12 characters, one uppercase, one special). Prefer a Secret in production (passwordSecretRef in values).
helm install pot iofog-operator/iofog-operator \
--namespace iofog-system --create-namespace \
--version 3.9.0 \
--set controlplane.spec.auth.mode=embedded \
--set controlplane.spec.auth.bootstrap.username=admin \
--set controlplane.spec.auth.bootstrap.password='ReplaceMe1!'
See Embedded OIDC for console URLs and bootstrap behavior.
Install with a values file
controlplane:
spec:
replicas:
controller: 1
nats: 2
database:
provider: sqlite
user: ""
host: ""
port: 0
password: ""
databaseName: ""
ssl: false
auth:
mode: embedded
bootstrap:
username: admin
password: "ReplaceMe1!"
controller:
publicUrl: https://controller.example.com
consoleUrl: https://console.example.com
images:
controller: ghcr.io/datasance/controller:3.9.0
router: ghcr.io/datasance/router:3.9.0
nats: ghcr.io/datasance/nats:2.15.0
services:
controller:
type: LoadBalancer
router:
type: LoadBalancer
nats:
enabled: true
jetStream:
storageSize: 10Gi
memoryStoreSize: 1Gi
helm install pot iofog-operator/iofog-operator \
--namespace iofog-system --create-namespace \
--version 3.9.0 \
-f my-values.yaml
Database: chart default is SQLite (single Controller replica). For HA, set replicas.controller > 1 and configure Postgres under controlplane.spec.database. See Database installation.
NATS: when nats.enabled is true, use at least 2 NATS replicas for JetStream.
LoadBalancer and externalTrafficPolicy
Defaults use LoadBalancer for Controller and Router Services. When externalTrafficPolicy is omitted, the operator sets Local on LoadBalancer Services (and Cluster on NodePort).
- Local preserves client source IP on many cloud load balancers.
- Cluster can help when Services stay pending or your LB controller does not support Local well.
controlplane:
spec:
services:
controller:
type: LoadBalancer
externalTrafficPolicy: Cluster
router:
type: LoadBalancer
externalTrafficPolicy: Cluster
Use Ingress instead of LoadBalancer when you have an ingress controller. Field list: ControlPlane CRD - ingresses.
Production TLS
Configure controlplane.spec.controller.https, secretName, and/or ingresses in values. Patterns (LoadBalancer + pod TLS, Ingress B1/B2, Router/NATS Secrets, cert-manager) are documented in Securing Kubernetes cluster (operator), not duplicated here.
External database TLS uses controlplane.spec.database.ssl and controlplane.spec.database.ca on the CR (CRD - database).
External auth
helm upgrade pot iofog-operator/iofog-operator \
--namespace iofog-system \
--version 3.9.0 \
--set controlplane.spec.auth.mode=external \
--set controlplane.spec.auth.issuerUrl=https://auth.example.com/realms/myrealm \
--set controlplane.spec.auth.client.id=controller \
--set controlplane.spec.auth.client.secret='YOUR_SECRET'
See External OIDC and External OIDC providers.
Verify
kubectl get pods -n iofog-system
kubectl get svc -n iofog-system
kubectl get controlplanes.datasance.com -n iofog-system
Wait until the ControlPlane status is Ready and Controller, Router, and NATS workloads are available.
Upgrade
helm upgrade pot iofog-operator/iofog-operator \
--namespace iofog-system \
--version 3.9.0 \
-f my-values.yaml
Platform train v3.9.0 supports in-place upgrade from v3.8.0 on the same Controller database. See Upgrading to v3.9.0 and Operator.
v3.7.x and legacy datasance/pot require a greenfield move to v3.8+ (uninstall old operator and CRDs first). See Migrating to v3.8.0.
Uninstall
helm uninstall pot -n iofog-system
kubectl delete controlplanes.datasance.com --all -n iofog-system
CRDs remain unless you remove them cluster-wide (only when no ControlPlane instances exist):
kubectl delete crd controlplanes.datasance.com
Connect with potctl
After the stack is ready, connect potctl in the same namespace you used for Helm (iofog-system in the examples above):
potctl create namespace iofog-system
potctl connect --email [email protected] --kube ~/.kube/config --namespace iofog-system
Sign in with the embedded bootstrap user you configured in values. If the Controller API uses HTTPS with a private CA, use connect --ca as described in Kubernetes TLS (CLI YAML).
Chart-only configuration
These keys are in the chart, not on the ControlPlane CR alone:
| Area | Values keys |
|---|---|
| Operator pod | operator.image, operator.replicaCount, operator.resources, scheduling |
| CR install | crds.install |
| CR metadata | controlplane.create, controlplane.name, controlplane.namespace |
Full chart reference: iofog-operator chart README and values.schema.json.
Go to Set up Edgelet nodes to provision Edgelet v1.1.0 on edge hosts.