Skip to main content
Version: v3.9.0

Control plane

The Datasance PoT control plane is the Controller, the Router, optional NATS, and a system Edgelet node on each Controller host. You declare it in potctl YAML. The kind is the only switch. metadata.controlPlaneType is retired.

User YAML apiVersion follows the build flavor. Examples on these pages use <FlavorYaml> so the group and image registry match the site you are reading. The manifest Edgelet stores is always apiVersion: edgelet.iofog.org/v1 and kind: ControlPlane. That apiVersion stays fixed.

Which kind​

KindUse it when
KubernetesControlPlaneController, Router, and NATS run on Kubernetes. potctl installs the operator and applies a ControlPlane custom resource.
ControlPlaneController hosts are remote machines. Edgelet runs on each host.
LocalControlPlaneOne machine, for a local trial. potctl translates this file into an Edgelet ControlPlane.
ControllerYou are adding one controller host to a remote control plane that is already deployed.

On Kubernetes the operator custom resource name is fixed: pot.

GuideFields
KubernetesKubernetesControlPlane fields, ControlPlane CRD
Remote, Multi-controller HA, Controller add-onRemote ControlPlane fields
LocalLocalControlPlane fields

Install steps stay in Get started. Use these pages for the manifest and for what potctl does with it.

TargetInstall
Kubernetes with potctlKubernetes CLI
Kubernetes with HelmHelm
Remote hostsRemote control plane
This machineQuick start (local)
Sign-inEmbedded OIDC, External OIDC

Greenfield files use auth.mode: embedded or auth.mode: external. When NATS is on, bind NATS account rules and NATS user rules. After the control plane is ready, add fleet nodes with kind: Agent. See Edgelet nodes.

Component pairing (v3.9.0)​

Keep the CLI, the operator, the Controller, and the Router on v3.9.0. Edgelet on Controller hosts is v1.1.0. The NATS image tag for this train is 2.15.0.

Container tags in the manifest omit the v prefix on Controller, operator, and Router images. The Edgelet image tag is 1.1.0. The CLI binary tag keeps the v.

ComponentReleaseImage tagWhere to set it
potctlv3.9.0Workstation binary
Operatorv3.9.03.9.0spec.images.operator (Kubernetes)
Controllerv3.9.03.9.0spec.images.controller or spec.controller.package.image
Routerv3.9.03.9.0spec.images.router or spec.systemMicroservices.router
NATS2.15.0spec.images.nats or spec.systemMicroservices.nats
Edgelet (system node)v1.1.01.1.0spec.systemAgent package image or version

Registry host comes from the build flavor ({{REGISTRY}} inside examples). Router and NATS on local and remote control planes take four architecture keys: amd64, arm64, riscv64, and arm.

Who owns TLS​

Start at Securing the cluster. Each deploy path has its own page.

LayerKubernetesLocalRemote
Controller HTTPSThe operator sets pod TLS and Ingress. See also operator TLS.potctl writes spec.tls to Edgelet spec.tls.base64.Same as local. A host may override with controllers[].tls.
Router and NATS CAsThe operator creates or reuses namespace Secrets, then imports the CAs into the Controller API.YAML blocks are validated. potctl does not upload them on local deploy today.potctl uploads routerSiteCA, routerLocalCA, natsSiteCA, and natsLocalCA once per deploy.
CLI trust of the Controller APIspec.ca goes into the namespace trust store.Same.Same.
connect --caConnect-time override for API TLS.Same.Same.

Vault settings​

spec.vault tells the Controller how to reach a secret store. The field tables live with each kind:

On Kubernetes the operator expands $namespace inside basePath. On Edgelet, basePath is stored as written. Supported providers: hashicorp, openbao, vault, aws, aws-secrets-manager, azure, azure-key-vault, google, google-secret-manager.

Day-2​

The console does not install a control plane. Deploy with potctl, then open Overview. Cluster controllers shows each controller as Active, Standby, or Stale. That block does not open a detail panel.

The command that sends a file is deploy. Open the generated page for each verb. The blocks below show the usual form, not every flag.

Connect​

Use connect when the control plane is already running and this workstation only needs namespace state. Use an empty namespace. See Connect and disconnect.

potctl connect -f controlplane.yaml
potctl describe controlplane

A remote add-on host needs the full control plane file in that namespace, from an earlier deploy -f or from connect -f with the same file. A URL-only connect is not enough for kind: Controller.

Describe​

potctl describe controlplane
potctl describe controller CONTROLLER_NAME

Upgrade the platform train​

v3.8.0 to v3.9.0 stays on the same Controller database. It is an in-train upgrade. Read What's New and Upgrading to v3.9.0 before you change tags.

Componentv3.9.0 pin
potctlv3.9.0
Controllerimage 3.9.0
Operator (Kubernetes)image 3.9.0
Routerimage 3.9.0
NATSimage 2.15.0
System Edgelet on Controller hostsv1.1.0 (image 1.1.0)
  1. Upgrade potctl on the workstation to v3.9.0.
  2. Set the image tags and Edgelet pin in the control plane file. Use the table in Default image pins.
  3. Run deploy -f on the updated file. On Kubernetes you can upgrade the operator with Helm on the same train, then deploy the updated KubernetesControlPlane file. See Kubernetes and Remote.
  4. Upgrade fleet Edgelet nodes to v1.1.0 with upgrade. The node steps are in Upgrade and rollback Edgelet. Controller hosts pick up the system Edgelet pin in step 3.
  5. Check What's New for YAML changes that affect workloads and config.
potctl deploy -f controlplane.yaml
deploy

Air-gapped sites stage images first. See Airgap deployment and Offline images.

To drop local CLI state and leave the running control plane in place:

potctl disconnect
disconnect
Group 3See anything wrong with the document? Help us improve it!