Skip to main content
Version: v3.9.0

Configuration

Operator reference for /etc/edgelet/config.yaml (paths on darwin/windows: Installation). This file configures the field agent (Controller client, engine, limits, logging, GPS, Edge Guard). It is not the same as deploy manifests (ControlPlane, Microservice, ...). See Manifests.

Related: Edgelet API (GET/PATCH /v1/system/config), CLI edgelet config, Engine lifecycle, Workload continuity, EdgeGuard, Local control plane (controllerUrl vs local ControlPlane).


File layout​

currentProfile: production # active profile name
profiles:
production: # flat string key/value map
controllerUrl: "https://controller.example.com/api/v3/"
containerEngine: edgelet
# ...
development:
devMode: "on"
# ...
ConceptBehavior
ProfilesNamed property sets; only currentProfile is active at runtime.
Property typesStored as strings in YAML; parsed to numbers/bools on load.
Booleans in YAMLOften "on" / "off" (e.g. watchdogEnabled, devMode, secureMode). CLI/API use JSON booleans where applicable.
First installSample from packaging or edgelet init-config (does not overwrite existing file).

How settings are changed​

ChannelWhen to use
Edit YAML + reloadBulk or GitOps-style changes; edgelet system reload or POST /v1/system/reload (SIGHUP-style). Invalid changes are rejected and do not corrupt on-disk YAML.
edgelet config ...Same keys as PATCH /v1/system/config; persists to active profile and triggers in-process reload when successful.
edgelet config switch <profile>Sets currentProfile only (POST /v1/system/config/switch).
edgelet config cert ...Installs Controller CA PEM (path written to controllerCert).
Controller fleet configAfter provision, when getChanges includes config: Controller pushes a snapshot; Edgelet applies diff-only keys (see below).

Credentials (iofogUuid, agent private key) live in SQLite, not in editable config. Proxy / SSH tunnel settings come from Controller on config / tunnel changes. Not from config.yaml.


Controller sync (provisioned agent)​

Edgelet talks to {controllerUrl} (Controller-compatible /api/v3/agent/...).

PhaseEdgelet behavior
InitializationEdgelet posts local config to Controller (PATCH /api/v3/agent/config). It does not pull Controller config until initialization clears via the normal getChanges handshake.
Steady stateOn config change flag: GET /api/v3/agent/config, map Controller JSON keys to local short codes, apply only changed values (FilterChangedConfigKeys), persist YAML, reload modules.
GPS coordinatesLocal updates can also PATCH /api/v3/agent/config/gps with latitude/longitude (derived from gpsCoordinates when posting full config).

Pull (Controller → Edgelet). Keys Edgelet understands when present on GET config:

diskLimit, diskDirectory, memoryLimit, cpuLimit, controllerUrl, controllerCert, containerEngineUrl, containerEngine, networkInterface, logLimit, logDirectory, logFileCount, logLevel, statusFrequency, changeFrequency, watchdogEnabled, edgeGuardFrequency, gpsMode, gpsDevice, gpsScanFrequency, arch, secureMode, pruningFrequency, availableDiskThreshold, upgradeScanFrequency, devMode, timeZone.

Push (Edgelet → Controller). Subset sent on PATCH /api/v3/agent/config (postFogConfig):

networkInterface, containerEngineUrl, diskLimit, diskDirectory, memoryLimit, cpuLimit, logLimit, logDirectory, logFileCount, statusFrequency, changeFrequency, watchdogEnabled, edgeGuardFrequency, gpsDevice, gpsScanFrequency, gpsMode, latitude, longitude, logLevel, availableDiskThreshold, pruningFrequency, upgradeScanFrequency.

Not uploaded on that PATCH (remain local unless Operator changes them on Controller UI/API and Edgelet pulls them): e.g. controllerUrl, controllerCert, containerEngine, arch, secureMode, devMode, timeZone.

Conflict rule: After provision, Controller pull can overwrite local values for any mapped pull key. Set controllerUrl locally before provision, or manage those fields on Controller if the fleet owns them.


Parameter reference​

Columns:

ColMeaning
YAML keyName in profiles.<name>
CLI / APIedgelet config long flag; GET/PATCH /v1/system/config JSON field (API may use suffixed names)
Ctrl pullApplied from Controller GET config when value differs
Ctrl pushSent on agent PATCH config during init / post
DefaultBuilt-in when omitted (see loader)

Controller connectivity​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
controllerUrl--controller-url / controllerUrlYesNohttp://localhost:54421/api/v3/Base URL for /api/v3/agent/.... Must match TLS/trust. Not auto-set by ControlPlane deploy (Local control plane).
controllerCert--controller-cert / controllerCertYesNo/etc/edgelet/cert.crtPath to PEM CA for Controller HTTPS. Install via edgelet config cert or provision flow. Empty allowed for some lab setups.
controllerRequestTimeoutSeconds-NoNo30HTTP timeout for Controller API requests (5-300). YAML / manual edit only.
controllerPingTimeoutSeconds-NoNo60Ping worker timeout (5-300). YAML / manual edit only.

Container runtime​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
containerEngine--container-engine / containerEngineYesNoedgelet (linux), platform-specific on desktopedgelet, docker, or podman. Cold change requires service restart (pendingRestart). See Engine lifecycle.
containerEngineUrl--container-engine-url / containerEngineUrlYesYesunix:///run/edgelet/containerd.sockEngine socket/URL (tcp:// or unix://). Fixed when containerEngine=edgelet. Required for podman when engine is podman.

Resource limits (agent stack)​

Host memoryLimit and cpuLimit raise alarms. They do not set cgroup limits. The engine enforces a microservice memoryLimit. See cgroups.

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
diskLimit--disk-limit-gib / diskLimitGiBYesYes10Max disk use for agent data (GiB). 0.5 - platform max.
diskDirectory--disk-directory / diskDirectoryYesYes/var/lib/edgelet/SQLite, volumes, models, bundles. See Persistence.
memoryLimit--memory-limit-mib / memoryLimitMiBYesYes4096Memory alarm threshold (MiB). 128 - 1048576.
cpuLimit--cpu-limit-percent / cpuLimitPercentYesYes80CPU alarm for Edgelet stack: 5-400 (100 ≈ one logical CPU).
availableDiskThreshold--available-disk-threshold / availableDiskThresholdYesYes20Free-disk threshold (GiB) for status/alerts.

Logging​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
logDirectory--log-directory / logDirectoryYesYes/var/log/edgelet/Agent log files. Legacy alias logDiskDirectory accepted on load.
logLimit--log-limit-gib / logLimitGiBYesYes10Max log disk (GiB). Legacy alias logDiskLimit.
logFileCount--log-file-count / logFileCountYesYes10Rotated files (1-100).
logLevel--log-level / logLevelYesYesINFODEBUG, INFO, WARN, ERROR, FATAL, OFF.
logReconcileCycleEveryNTicks-NoNo60Log reconcile.cycle at INFO every N monitor ticks when idle. YAML only.

Polling and maintenance​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
statusFrequency--status-frequency-seconds / statusFrequencySecondsYesYes10Interval (seconds) for status POST to Controller. Must be ≥ 1.
changeFrequency--change-frequency-seconds / changeFrequencySecondsYesYes20Interval for getChanges poll. Must be ≥ 1.
upgradeScanFrequency--upgrade-scan-frequency / upgradeScanFrequencyYesYes24OTA / version scan interval (hours).
pruningFrequency--pruning-frequency / pruningFrequencyYesYes0Hours between image + unused local model prune cycles (0 = off). Does not delete persistent VOLUME data (Volumes).
watchdogEnabled--watchdog-enabled / watchdogEnabledYesYesoffOrphan container cleanup; local model watchdog. See Workload continuity.

Network and identity​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
networkInterface--network-interface / networkInterfaceYesYesdynamicHost interface for status/IP, or dynamic / concrete name. Validated against Controller URL when patched via API.
arch--arch / archYesNoautoFog type: auto, amd64, arm64, arm, riscv64. Maps to Controller arch id for image selection.
namespace-NoNodefaultLocal default namespace label context. YAML only (not in Controller config sync).
timeZone--timezone / timezoneYesNoEurope/Istanbul (loader default if empty in file)Agent timezone string.

Security and modes​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
secureMode--secure-mode / secureModeYesNooffHardened TLS/verification behavior when on.
devMode--dev-mode / devModeYesNooffDeveloper diagnostics.
edgeGuardFrequency--edge-guard-frequency / edgeGuardFrequencyYesYes0Hardware attestation interval (seconds); 0 disables. Requires provisioned agent: forced to 0 if unprovisioned when set via CLI. EdgeGuard.

GPS​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
gpsMode--gps-mode / gpsModeYesYesautoauto, dynamic, manual, off.
gpsDevice--gps-device / gpsDeviceYesYes/dev/ttyUSB0Serial device for dynamic GPS.
gpsScanFrequency--gps-scan-frequency / gpsScanFrequencyYesYes60Scan interval (seconds).
gpsCoordinates--gps-coordinates / gpsCoordinatesNo*Yes†0,0lat,lon string. POST /v1/system/gps sets manual coordinates and persists here. †Push sends latitude/longitude fields, not the raw string.

*Controller config JSON may expose latitude/longitude separately on GET; Edgelet maps GPS-related pull keys listed above.

Shutdown and control-plane stop​

YAML keyCLI / APICtrl pullCtrl pushDefaultDescription
shutdownPolicy-NoNoleave-running for docker/podman; engine-specific default for edgeletleave-running or drain-all. Control stop vs workload containers. Workload continuity. YAML only.
shutdownGracePeriodSeconds-NoNo90Grace for stop/drain paths (5-600). YAML only.

Derived intervals (not in config.yaml)​

These are computed at load time. no YAML keys:

Internal settingTypical valueRole
Status report / monitor tick5sProcess manager baseline
Ping Controller30sConnectivity
Registry monitor60sRegistry health
Healthcheck interval30sEmbedded engine healthchecks
Reconcile full compare~60sSpec/env drift sweep (Process manager)

Do not confuse with statusFrequency / changeFrequency. Those are operator-tunable Controller poll intervals.


CLI and API quick reference​

# View effective config (daemon must be running)
edgelet system status -o json # includes runtime snapshot
# API equivalent: GET /v1/system/config (admin RBAC)

edgelet config --controller-url https://controller.example.com/api/v3/ --change-frequency-seconds 15
edgelet config switch production
edgelet config cert "$(base64 -w0 < ca.pem)" # platform-specific base64 flags
edgelet system reload

PATCH /v1/system/config body:

{ "set": { "logLevel": "DEBUG", "changeFrequencySeconds": 15 } }

Unsupported keys in set return 400 with no partial persist. containerEngine change may return "pendingRestart": true.

OpenAPI ConfigView in OpenAPI contract is a subset; GET /v1/system/config returns the full operator view (GPS, disk paths, frequencies, etc.).


Removed and forbidden keys​

KeyStatus
deviceScanFrequency / CLI sdRemoved: rejected by SetConfig and ignored on Controller pull filter.
Legacy dockerUrl, dockerPruningFrequency, isolatedDockerContainerRemoved: use containerEngineUrl, pruningFrequency, watchdogEnabled.

What is not agent config.yaml​

ItemWhere it lives
ControlPlane / Microservice / Registry / Model / Knowledge / RuntimeClassDeploy manifests: Manifests
Controller microservice desired stateController REST + SQLite cache after provision
Proxy / tunnelController getChanges + proxy worker (Proxy)
Edge Guard signature baselineSQLite + /etc/edgelet/agent-{uuid}.jwt
Local EdgeletAPI admin token/etc/edgelet/edgelet-api

Validation and reload​

  • Full config validated on load (ValidateConfig): limits, engine/url pairing, GPS format, shutdown policy, log level, etc.
  • Failed PATCH /v1/system/config or CLI update does not write invalid YAML.
  • Successful updates persist to the active profile and invoke the supervisor reload callback (Field Agent client refresh, engine URL reconnect, DNS, logging).
  • containerEngine family change: quiesce + edgelet.service restart required. See Engine lifecycle.

Sample minimal production profile​

See packaging sample edgelet-config.yaml.sample (install) and Deployment for paths. Example:

currentProfile: production
profiles:
production:
controllerUrl: "https://controller.example.com/api/v3/"
controllerCert: "/etc/edgelet/cert.crt"
containerEngine: edgelet
containerEngineUrl: unix:///run/edgelet/containerd.sock
diskDirectory: /var/lib/edgelet/
logDirectory: /var/log/edgelet/
logLevel: INFO
statusFrequency: "10"
changeFrequency: "20"
watchdogEnabled: "off"
shutdownPolicy: leave-running

After local ControlPlane deploy, set controllerUrl to the Controller API endpoint the agent should use, then provision (Local control plane).

Group 3See anything wrong with the document? Help us improve it!