Networking
Datasance PoT builds the router and NATS fabrics from declarative config. You set router and NATS roles on an Edgelet node (Agent, LocalAgent, or AgentConfig). Controller platform reconcile then creates the system application, the router and nats microservices, certificate authorities, TLS material, configs, and upstream links.
You do not install fabric CAs, write router JSON or NATS config, or copy JWT bundles by hand.
| Fabric | Node fields | System microservice | User-facing layer |
|---|---|---|---|
| Service interconnection (AMQP router) | routerConfig, upstreamRouters | system-<agentName>/router | Services add TCP bridges |
| Messaging (NATS) | natsConfig, upstreamNatsServers | system-<agentName>/nats | Applications natsAccess, NATS account rules, NATS user rules |
Field tables are on AgentConfig fields. Deploy order is on Edgelet nodes.
Declare, then the platform builds
- potctl
deploysends the configuration. It resolvesupstreamRoutersandupstreamNatsServersfrom Edgelet node names to UUIDs. - Create returns the node UUID. Provisioning continues in the background.
- The Controller flags the node. Edgelet applies the
system-<agentName>workloads.
System applications such as system-<agentName> are created by the platform. Operators inspect them. They do not deploy them as user applications. See Applications.
potctl get system-microservices -n my-ecn
potctl describe system-microservice system-plant-a/router -n my-ecn
potctl describe system-microservice system-plant-a/nats -n my-ecn
potctl reconcile agent plant-a -n my-ecn
Stuck platform reconcile is covered in Reconcile.
Defaults on a typical edge node
| Setting | Default | Meaning |
|---|---|---|
routerConfig.routerMode | edge | Workload node. It dials interior routers. |
natsConfig.natsMode | leaf | Local NATS. It dials hub servers on port 7422. |
upstreamRouters | omit | default-router plus every system-node router |
upstreamNatsServers | omit | default-nats-hub plus every system-node NATS server |
apiVersion: datasance.com/v3
kind: Agent
metadata:
name: plant-a
namespace: my-ecn
spec:
host: 203.0.113.10
ssh:
user: ubuntu
keyFile: ~/.ssh/id_rsa
package:
version: "1.1.0"
config:
host: 203.0.113.10
arch: amd64
routerConfig:
routerMode: edge
messagingPort: 5671
natsConfig:
natsMode: leaf
natsServerPort: 4222
natsLeafPort: 7422
jsStorageSize: 10g
jsMemoryStoreSize: 1g
Omitting the upstream lists attaches this node to default-router and default-nats-hub, plus fabrics on system Edgelet nodes.
An interior router and a NATS server on a later node need explicit ports. See Router fabric and NATS fabric.
Control plane kind
| Remote or local control plane | Kubernetes control plane | |
|---|---|---|
| First node in an empty cluster | Becomes the system Edgelet node. The Controller forces routerMode: interior and natsMode: server. | You cannot create a system Edgelet node through the node API. The platform router and NATS are the hub. |
| Hub | The first system node is default-router and the NATS hub. See Remote networking and Local networking. | Operator Deployment router and StatefulSet nats, then registered with the Controller. See Kubernetes networking. |
| Later nodes | Roles you set. Omitted roles are edge and leaf. | Usually edge and leaf. Extra server nodes join hub cluster routes. |
System nodes on control plane hosts are controllers[].systemAgent or spec.systemAgent, not user kind: Agent. See Edgelet nodes.
Fabric CAs and catalog certificates
Certificates (kind: CertificateAuthority and kind: Certificate) are catalog resources for workload TLS.
Router and NATS use separate CAs created during platform reconcile: router-site-ca, default-router-local-ca, nats-site-ca, and default-nats-local-ca. The Controller issues and mounts those certificates. You do not name them in node YAML.
What you declare
| You set | The platform does |
|---|---|
routerMode, natsMode, and host | Installs router and NATS CAs and issues per-node certificates |
| Node config, or a Service | Writes router config and NATS server.conf or leaf config |
upstreamRouters and upstreamNatsServers, or the defaults | Wires upstream links |
Application natsAccess and NATS rules | Places account JWTs on NATS nodes |
kind: Service | Opens Service TCP bridges in the router config |
Fabric pages
| Page | Contents |
|---|---|
| Router fabric | routerMode, TLS, listeners, connectors, Service bridges |
| NATS fabric | natsMode, JetStream, server and leaf, resolver bundles |