Prepare remote hosts
An Edge Compute Network (ECN) has a Controller and one or more Edgelet nodes. Production setups usually run each component on a different host.
potctl connects over SSH to install the remote control plane and fleet Edgelet nodes. Complete the steps below on every remote host you plan to use.
Add an SSH public key
potctl uses the private key you reference in deploy YAML (ssh.keyFile). Install the matching public key on the remote user account:
ssh-copy-id -i ~/.ssh/id_rsa.pub <username>@<controller-or-edgelet-hostname>
Do this for:
- The Controller host when you deploy a remote
ControlPlane(not when the Controller runs only on Kubernetes). - Every Edgelet node host you list under
kind: Agent.
Keep the private key path. You will use the same key in ssh.keyFile.
Add the SSH user to the sudo group
potctl runs bootstrap scripts with sudo on remote Linux hosts:
usermod -aG sudo $USER
Log out and back in so group membership applies.
Allow passwordless sudo
potctl cannot answer sudo password prompts over SSH. On each host, ensure sudoers allows NOPASSWD for your deploy user. With visudo, confirm a line like:
%sudo ALL=(ALL) NOPASSWD:ALL
The embedded check_prereqs.sh layer verifies passwordless sudo before install proceeds.
Airgap and container engines
| Deploy path | Host preparation |
|---|---|
| Native Edgelet (default) | Sudo and SSH only. Edge hosts do not need outbound registry access when you use airgap: true and package.version. |
Container Edgelet (deploymentType: container) | Install docker or podman on the host before deploy, or supply a custom scripts.deps layer. Required for airgap container flows. |
The machine that runs potctl needs registry access to pull images or stage Edgelet binaries. Edge hosts receive artifacts over SSH.
Deploy the control plane: Remote control plane or Kubernetes - prepare a cluster.
After the Controller is running, enroll fleet nodes at Setup Edgelet nodes.