Remote and Kubernetes are the two control plane deployment models. This guide deploys a remote control plane on a single Linux host over SSH. For Kubernetes, start at Kubernetes - Prepare a cluster.
Deploy Control Plane on Remote Hosts
Use kind: ControlPlane (not RemoteControlPlane) to run the control plane on one or more SSH-accessible hosts via Edgelet. Global settings (auth, database, images, TLS) are declared once; each host is listed under spec.controllers[].
See the remote deploy guide for multi-host orchestration and multi-controller HA when you add hosts.
Procedures below use YAML that potctl applies. Field reference: Remote ControlPlane schema.
Set auth.mode: embedded in your control plane YAML. See Embedded OIDC for bootstrap credentials and console URLs.
Enable Controller HTTPS with spec.tls (cert, key, optional ca) or controllers[].tls per host. For bring-your-own Router and NATS CAs, set the four global CA blocks; the CLI uploads them after the Controller API is up. See Securing remote control plane.
Prerequisites
- Passwordless sudo on remote hosts
- SSH key access:
ssh.user,ssh.keyFile, optionalssh.port(default 22) spec.controllers[].systemAgenton every controller (may be{}for defaults)spec.endpointorspec.controller.publicUrlfor API wait and Edgelet configuration
Details: Prepare remote hosts.
Deploy a control plane on a remote host
Create controlplane.yaml (single-host example):
---
apiVersion: datasance.com/v3
kind: ControlPlane
metadata:
name: edge-prod
spec:
endpoint: http://203.0.113.10:51121
iofogUser:
password: "ReplaceMe-password!"
controller:
publicUrl: http://203.0.113.10:51121
consoleUrl: http://203.0.113.10:80
logLevel: info
package:
image: ghcr.io/datasance/controller:v3.9.0
auth:
mode: embedded
bootstrap:
username: admin
password: RemoteTest12!
systemMicroservices:
router:
amd64: ghcr.io/datasance/router:3.9.0
arm64: ghcr.io/datasance/router:3.9.0
arm: ghcr.io/datasance/router:3.9.0
riscv64: ghcr.io/datasance/router:3.9.0
nats:
amd64: ghcr.io/datasance/nats:2.15.0
arm64: ghcr.io/datasance/nats:2.15.0
arm: ghcr.io/datasance/nats:2.15.0
riscv64: ghcr.io/datasance/nats:2.15.0
nats:
enabled: true
events:
auditEnabled: true
retentionDays: 14
controllers:
- name: ctrl-1
host: 203.0.113.10
ssh:
user: ubuntu
keyFile: ~/.ssh/prod.pem
port: 22
systemAgent:
config:
arch: amd64
host: 203.0.113.10
Edit host, ssh, URLs, and architecture keys for your environment.
Deploy:
potctl deploy -f controlplane.yaml -n prod
Verify the deployment
potctl get controllers
potctl describe controller ctrl-1
potctl describe controlplane
You need a full remote ControlPlane record in namespace config (includes auth and controller). Use initial deploy -f or connect -f with the same YAML. See Controller add-on.
With the control plane running, go to Set up Edgelet nodes to provision Edgelet v1.1.0 on your edge hosts.