Configuration
These objects are created before the microservice that names them. Deploy each file with potctl deploy -f. There is no apply.
The short map is Registries and catalog, Models and knowledge, and Config, secrets, and volumes. This section is how each object is declared, updated, and consumed. Field tables sit on the fields page beside each guide.
Objects
| Object | Kind | Consumed by |
|---|---|---|
| Registry | Registry | Catalog items, models, knowledge, and image pulls. Built-in aliases: remote is id 1, local is id 2. |
| Catalog item | CatalogItem | Microservice images.catalogId or catalog name. Multi-arch image set. |
| Model | Model | Attach to Edgelet nodes, then spec.models on the microservice. |
| Knowledge | Knowledge | Attach, then spec.knowledge. |
| Runtime class | RuntimeClass | Attach, then container.runtime on the microservice. |
| Config map | ConfigMap | valueFromConfigMap, or a volume mount. |
| Secret | Secret | valueFromSecret, or a volume mount. |
| Certificate authority | CertificateAuthority | Signs leaf certificates. Router and NATS site CAs on control plane deploy are a different path. See Securing the cluster. |
| Certificate | Certificate | Leaf cert signed by a CA, or ca.type: self-signed on the leaf. |
| Volume | Volume | Stages a directory from the operator machine onto nodes. Microservice type: volume. The CLI stores the record in namespace config. It is not a Controller API object. |
| Volume mount | VolumeMount | Attaches a Secret or ConfigMap onto nodes. Microservice type: volumeMount. |
| Offline image | OfflineImage | Pulls on the operator machine, copies to remote nodes, and upserts a catalog item on registry id 2. Re-running deploy repeats the transfer. It is not a long-lived Controller object. |
A Controller kind: Registry registers a pull endpoint with the Controller API. The Edgelet host registry uses edgelet.iofog.org/v1. That manifest is on Manifests.
A Volume lists Edgelet nodes in its own spec. Attach applies to the volume mount, the model, the knowledge object, and the runtime class.
Deploy order
When one file holds several documents, potctl sorts them by kind. Write the file in an order a person can read. The CLI still uses its own kind order.
Secret, CertificateAuthority, Certificate, ConfigMap
Agent or LocalAgent
Volume, OfflineImage, VolumeMount
Registry, Model, Knowledge, RuntimeClass, CatalogItem
Application, Microservice
- Put the Secret and the ConfigMap before the volume mount, and before microservice env that names them.
- Put the CertificateAuthority before the Certificate.
- Enroll Edgelet nodes before a Volume, an OfflineImage, or
attach. - Put the Registry before a Model, Knowledge, or standalone CatalogItem. OfflineImage registers the catalog row on registry id 2 itself.
- Put the catalog item or the offline image before the microservice that uses that image.
Order of operations checklist
- Registry and catalog item, or an offline image, before the microservice image.
- Attach the model, the knowledge object, the runtime class, and the volume mount before the microservice that binds them.
- Secret and ConfigMap before the volume mount that names them.
Skipping attach is a common cause of lastError on describe microservice. See Microservices.
Console
| Console | Objects |
|---|---|
| Catalog and templates | Registries, catalog microservices, AI Model Catalog, AI Knowledge Catalog |
| Configuration | Config maps, secrets, certificates, volume mounts, runtime classes |
Offline images and Volumes are CLI flows. The console chapter has no screen for those two kinds. After an offline image deploy, the catalog row appears under Catalog Microservices.
Application and microservice templates are workload objects. See Application templates and Microservice templates.