EdgeGuard
EdgeGuard periodically fingerprints host hardware and compares it to a baseline. When the fingerprint changes, Edgelet reports a warning, deprovisions the node from the Controller, and clears the stored baseline. Use it on untrusted or physically accessible edge hardware when you need tamper detection.
v3.9 replaces legacy HAL scan fields with edgeGuardFrequency. Do not use deviceScanFrequency, bluetoothEnabled, or abstractedHardwareEnabled in new YAML.
Enable from the orchestrator
Set edgeGuardFrequency in AgentConfig (seconds between attestation runs). 0 disables EdgeGuard.
---
apiVersion: datasance.com/v3
kind: AgentConfig
metadata:
name: zebra-1
spec:
edgeGuardFrequency: 3600
Apply:
potctl deploy -f agent-config.yaml
You can also set edgeGuardFrequency under spec.config on initial Agent deploy. After provision, the Controller can push the same key when you update AgentConfig.
EdgeGuard runs only on provisioned nodes (valid agent credentials in Edgelet SQLite). If the node is unprovisioned, the runtime forces edgeGuardFrequency to 0.
What operators see
| Signal | Meaning |
|---|---|
describe agent / Console node status | Warning such as HW signature changed when a mismatch occurred |
| Controller record | Node deprovisioned; microservices on that node stop |
| Local Edgelet | Baseline signature row removed after mismatch |
EdgeGuard compares a stable hash claim, not the full JWT string, so periodic refreshes with unchanged hardware do not deprovision the node.
Response runbook
- Investigate physical or VM changes (NIC swap, disk change, USB devices that affect the fingerprint, VM identity drift).
- If hardware change is expected and the node should rejoin the ECN:
- Fix or replace hardware as needed.
- Run
edgelet provisionon the host with a valid provisioning key from the Controller, or redeployAgentif the host was wiped. - Confirm
describe agentshows an empty warning and the node is provisioned again.
- If you only need to change the interval (and the node is still provisioned), deploy
AgentConfigwith a newedgeGuardFrequency. Setting0stops attestation and deletes the baseline on the device. - Lab and VMs: use a reasonable interval in production (for example 3600 seconds). Very short intervals are for testing only.
Break-glass on the device: see Edgelet configuration and the Edgelet repo operator notes for EdgeGuard persistence and validation steps.
See also
- Edgelet nodes in Learn - YAML field and v3.9 removals
- Configuration updates - AgentConfig workflow
- Edgelet configuration reference -
edgeGuardFrequencyand Controller push - Attach and detach - move a node between ECNs after reprovision