Skip to main content
Version: v3.9.0
Other deploy paths

Deploy the control plane on Kubernetes with Helm

This guide installs Datasance PoT on Kubernetes using the iofog-operator Helm chart. The chart deploys the operator Deployment and a ControlPlane custom resource with apiVersion: datasance.com/v3. The operator reconciles Controller, Router, NATS, Services, Secrets, and optional Ingress objects.

The legacy repo Datasance/helm (chart pot, https://datasance.github.io/helm) is deprecated. Use the Helm repository index linked below.

ReferenceWhere to read
Every controlplane.spec.* fieldControlPlane CRD
Controller, Router, NATS TLS on clusterSecuring Kubernetes cluster (operator)
CLI trust when the API uses HTTPSKubernetes TLS (CLI YAML) (spec.ca / connect --ca)
Auth bootstrapEmbedded OIDC

Published chart defaults (values, tarball): Helm repository index.

Prerequisites​

  • Helm 3
  • Kubernetes 1.22+
  • kubectl
  • Pull access to ghcr.io/datasance (operator, controller, router, nats)
  • For NATS JetStream with PVCs: a suitable StorageClass

Charts are stamped per mirror at package time (crdGroup, imageRegistry, image tags). Do not override crdGroup or imageRegistry unless you run a custom build.

Add the Helm repository​

Add repo
helm repo add iofog-operator https://datasance.github.io/iofog-operator
helm repo update

Download defaults for editing:

helm show values iofog-operator/iofog-operator --version 3.9.0 > my-values.yaml

Or use the files on the index page: https://datasance.github.io/iofog-operator/values.yaml and values-3.9.0.yaml.

Quick install​

Embedded OIDC is the default. Set a bootstrap password (≥12 characters, one uppercase, one special). Prefer a Secret in production (passwordSecretRef in values).

Install release
helm install pot iofog-operator/iofog-operator \
--namespace iofog-system --create-namespace \
--version 3.9.0 \
--set controlplane.spec.auth.mode=embedded \
--set controlplane.spec.auth.bootstrap.username=admin \
--set controlplane.spec.auth.bootstrap.password='ReplaceMe1!'

See Embedded OIDC for console URLs and bootstrap behavior.

Install with a values file​

my-values.yaml (excerpt)
controlplane:
spec:
replicas:
controller: 1
nats: 2
database:
provider: sqlite
user: ""
host: ""
port: 0
password: ""
databaseName: ""
ssl: false
auth:
mode: embedded
bootstrap:
username: admin
password: "ReplaceMe1!"
controller:
publicUrl: https://controller.example.com
consoleUrl: https://console.example.com
images:
controller: ghcr.io/datasance/controller:3.9.0
router: ghcr.io/datasance/router:3.9.0
nats: ghcr.io/datasance/nats:2.15.0
services:
controller:
type: LoadBalancer
router:
type: LoadBalancer
nats:
enabled: true
jetStream:
storageSize: 10Gi
memoryStoreSize: 1Gi
helm install pot iofog-operator/iofog-operator \
--namespace iofog-system --create-namespace \
--version 3.9.0 \
-f my-values.yaml

Database: chart default is SQLite (single Controller replica). For HA, set replicas.controller > 1 and configure Postgres under controlplane.spec.database. See Database installation.

NATS: when nats.enabled is true, use at least 2 NATS replicas for JetStream.

LoadBalancer and externalTrafficPolicy​

Defaults use LoadBalancer for Controller and Router Services. When externalTrafficPolicy is omitted, the operator sets Local on LoadBalancer Services (and Cluster on NodePort).

  • Local preserves client source IP on many cloud load balancers.
  • Cluster can help when Services stay pending or your LB controller does not support Local well.
Override traffic policy
controlplane:
spec:
services:
controller:
type: LoadBalancer
externalTrafficPolicy: Cluster
router:
type: LoadBalancer
externalTrafficPolicy: Cluster

Use Ingress instead of LoadBalancer when you have an ingress controller. Field list: ControlPlane CRD - ingresses.

Production TLS​

Configure controlplane.spec.controller.https, secretName, and/or ingresses in values. Patterns (LoadBalancer + pod TLS, Ingress B1/B2, Router/NATS Secrets, cert-manager) are documented in Securing Kubernetes cluster (operator), not duplicated here.

External database TLS uses controlplane.spec.database.ssl and controlplane.spec.database.ca on the CR (CRD - database).

External auth​

Switch to external OIDC
helm upgrade pot iofog-operator/iofog-operator \
--namespace iofog-system \
--version 3.9.0 \
--set controlplane.spec.auth.mode=external \
--set controlplane.spec.auth.issuerUrl=https://auth.example.com/realms/myrealm \
--set controlplane.spec.auth.client.id=controller \
--set controlplane.spec.auth.client.secret='YOUR_SECRET'

See External OIDC and External OIDC providers.

Verify​

kubectl get pods -n iofog-system
kubectl get svc -n iofog-system
kubectl get controlplanes.datasance.com -n iofog-system

Wait until the ControlPlane status is Ready and Controller, Router, and NATS workloads are available.

Upgrade​

helm upgrade pot iofog-operator/iofog-operator \
--namespace iofog-system \
--version 3.9.0 \
-f my-values.yaml

Platform train v3.9.0 supports in-place upgrade from v3.8.0 on the same Controller database. See Upgrading to v3.9.0 and Operator.

v3.7.x and legacy datasance/pot require a greenfield move to v3.8+ (uninstall old operator and CRDs first). See Migrating to v3.8.0.

Uninstall​

helm uninstall pot -n iofog-system
kubectl delete controlplanes.datasance.com --all -n iofog-system

CRDs remain unless you remove them cluster-wide (only when no ControlPlane instances exist):

kubectl delete crd controlplanes.datasance.com

Connect with potctl​

After the stack is ready, connect potctl in the same namespace you used for Helm (iofog-system in the examples above):

potctl create namespace iofog-system
potctl connect --email [email protected] --kube ~/.kube/config --namespace iofog-system

Sign in with the embedded bootstrap user you configured in values. If the Controller API uses HTTPS with a private CA, use connect --ca as described in Kubernetes TLS (CLI YAML).

Chart-only configuration​

These keys are in the chart, not on the ControlPlane CR alone:

AreaValues keys
Operator podoperator.image, operator.replicaCount, operator.resources, scheduling
CR installcrds.install
CR metadatacontrolplane.create, controlplane.name, controlplane.namespace

Full chart reference: iofog-operator chart README and values.schema.json.

Next step

Go to Set up Edgelet nodes to provision Edgelet v1.1.0 on edge hosts.

Group 3See anything wrong with the document? Help us improve it!