Control plane
The Datasance PoT control plane is the Controller, the Router, optional NATS, and a system Edgelet node on each Controller host. You declare it in potctl YAML. The kind is the only switch. metadata.controlPlaneType is retired.
User YAML apiVersion follows the build flavor. Examples on these pages use <FlavorYaml> so the group and image registry match the site you are reading. The manifest Edgelet stores is always apiVersion: edgelet.iofog.org/v1 and kind: ControlPlane. That apiVersion stays fixed.
Which kind
| Kind | Use it when |
|---|---|
KubernetesControlPlane | Controller, Router, and NATS run on Kubernetes. potctl installs the operator and applies a ControlPlane custom resource. |
ControlPlane | Controller hosts are remote machines. Edgelet runs on each host. |
LocalControlPlane | One machine, for a local trial. potctl translates this file into an Edgelet ControlPlane. |
Controller | You are adding one controller host to a remote control plane that is already deployed. |
On Kubernetes the operator custom resource name is fixed: pot.
| Guide | Fields |
|---|---|
| Kubernetes | KubernetesControlPlane fields, ControlPlane CRD |
| Remote, Multi-controller HA, Controller add-on | Remote ControlPlane fields |
| Local | LocalControlPlane fields |
Install steps stay in Get started. Use these pages for the manifest and for what potctl does with it.
| Target | Install |
|---|---|
| Kubernetes with potctl | Kubernetes CLI |
| Kubernetes with Helm | Helm |
| Remote hosts | Remote control plane |
| This machine | Quick start (local) |
| Sign-in | Embedded OIDC, External OIDC |
Greenfield files use auth.mode: embedded or auth.mode: external. When NATS is on, bind NATS account rules and NATS user rules. After the control plane is ready, add fleet nodes with kind: Agent. See Edgelet nodes.
Component pairing (v3.9.0)
Keep the CLI, the operator, the Controller, and the Router on v3.9.0. Edgelet on Controller hosts is v1.1.0. The NATS image tag for this train is 2.15.0.
Container tags in the manifest omit the v prefix on Controller, operator, and Router images. The Edgelet image tag is 1.1.0. The CLI binary tag keeps the v.
| Component | Release | Image tag | Where to set it |
|---|---|---|---|
| potctl | v3.9.0 | Workstation binary | |
| Operator | v3.9.0 | 3.9.0 | spec.images.operator (Kubernetes) |
| Controller | v3.9.0 | 3.9.0 | spec.images.controller or spec.controller.package.image |
| Router | v3.9.0 | 3.9.0 | spec.images.router or spec.systemMicroservices.router |
| NATS | 2.15.0 | spec.images.nats or spec.systemMicroservices.nats | |
| Edgelet (system node) | v1.1.0 | 1.1.0 | spec.systemAgent package image or version |
Registry host comes from the build flavor ({{REGISTRY}} inside examples). Router and NATS on local and remote control planes take four architecture keys: amd64, arm64, riscv64, and arm.
Who owns TLS
Start at Securing the cluster. Each deploy path has its own page.
| Layer | Kubernetes | Local | Remote |
|---|---|---|---|
| Controller HTTPS | The operator sets pod TLS and Ingress. See also operator TLS. | potctl writes spec.tls to Edgelet spec.tls.base64. | Same as local. A host may override with controllers[].tls. |
| Router and NATS CAs | The operator creates or reuses namespace Secrets, then imports the CAs into the Controller API. | YAML blocks are validated. potctl does not upload them on local deploy today. | potctl uploads routerSiteCA, routerLocalCA, natsSiteCA, and natsLocalCA once per deploy. |
| CLI trust of the Controller API | spec.ca goes into the namespace trust store. | Same. | Same. |
connect --ca | Connect-time override for API TLS. | Same. | Same. |
Vault settings
spec.vault tells the Controller how to reach a secret store. The field tables live with each kind:
On Kubernetes the operator expands $namespace inside basePath. On Edgelet, basePath is stored as written. Supported providers: hashicorp, openbao, vault, aws, aws-secrets-manager, azure, azure-key-vault, google, google-secret-manager.
Day-2
The console does not install a control plane. Deploy with potctl, then open Overview. Cluster controllers shows each controller as Active, Standby, or Stale. That block does not open a detail panel.
The command that sends a file is deploy. Open the generated page for each verb. The blocks below show the usual form, not every flag.
Connect
Use connect when the control plane is already running and this workstation only needs namespace state. Use an empty namespace. See Connect and disconnect.
potctl connect -f controlplane.yaml
potctl describe controlplane
A remote add-on host needs the full control plane file in that namespace, from an earlier deploy -f or from connect -f with the same file. A URL-only connect is not enough for kind: Controller.
Describe
potctl describe controlplane
potctl describe controller CONTROLLER_NAME
Upgrade the platform train
v3.8.0 to v3.9.0 stays on the same Controller database. It is an in-train upgrade. Read What's New and Upgrading to v3.9.0 before you change tags.
| Component | v3.9.0 pin |
|---|---|
| potctl | v3.9.0 |
| Controller | image 3.9.0 |
| Operator (Kubernetes) | image 3.9.0 |
| Router | image 3.9.0 |
| NATS | image 2.15.0 |
| System Edgelet on Controller hosts | v1.1.0 (image 1.1.0) |
- Upgrade potctl on the workstation to v3.9.0.
- Set the image tags and Edgelet pin in the control plane file. Use the table in Default image pins.
- Run
deploy -fon the updated file. On Kubernetes you can upgrade the operator with Helm on the same train, then deploy the updatedKubernetesControlPlanefile. See Kubernetes and Remote. - Upgrade fleet Edgelet nodes to v1.1.0 with upgrade. The node steps are in Upgrade and rollback Edgelet. Controller hosts pick up the system Edgelet pin in step 3.
- Check What's New for YAML changes that affect workloads and config.
potctl deploy -f controlplane.yaml
Air-gapped sites stage images first. See Airgap deployment and Offline images.
To drop local CLI state and leave the running control plane in place:
potctl disconnect