Skip to main content
Version: v3.9.0

EdgeGuard module

Edge Guard is the daemon hardware attestation loop. It fingerprints the host, signs a baseline JWT, stores it in SQLite, and on fingerprint drift triggers controller warning + agent deprovision.

Code: internal/edgeguard/

Operator guide: EdgeGuard (configuration, fingerprint sources, mismatch behavior)

Purpose​

  • Periodic hardware fingerprint collection (platform-specific)
  • Sign stable hash claim into Edge Guard JWT
  • Compare new fingerprint hash to stored baseline (not full JWT string)
  • POST warning + deprovision on real hardware change
  • Disable cleanly when edgeGuardFrequency=0

Dependencies​

Depends onReason
authGenerateEdgeGuardJWT, EdgeGuardHashFromJWT()
storeagent_edgeguard_signature singleton row
configedgeGuardFrequency, iofogUuid, private key
fieldagentDeprovision + status POST on mismatch
statusreporterWarning message on supervisor status
Used byReason
supervisorStarted last in module sequence

Lifecycle​

Start​

(*Manager).Start():

  1. If unprovisioned or no private key → force frequency to 0, delete stored signature if disabled
  2. If frequency ≤ 0 → no-op (disabled)
  3. Load signature cache from DB
  4. Run initial checkHardwareSignature()
  5. Start attestationWorker ticker at edgeGuardFrequency seconds

Stop​

Cancel attestation context; stop ticker.

Config update​

InstanceConfigUpdated() reschedules attestation interval; cancels prior worker goroutine to avoid leaks.

Attestation flow​

Comparison uses auth.EdgeGuardHashFromJWT() on the stored JWT vs newly computed hash. Avoids false deprovision when only iat/exp/jti rotate.

Configuration​

KeyEffect
edgeGuardFrequencyInterval seconds; 0 disables
iofogUuidMust be set (provisioned) for attestation to run

Unprovisioned agents force frequency to 0 at Field Agent and Edge Guard start.

Data and persistence​

TableContent
agent_edgeguard_signatureLatest attestation JWT (id=1)

On disable, signature row is deleted.

External APIs​

No direct HTTP. Side effects:

  • Field Agent deprovision path
  • Controller status POST with warning
  • Clears supervisor warning after successful re-provision (Field Agent)

Observability​

  • Log module name: "Edge Guard Manager"
  • Not in modulesStatus[] fixed array; warning via SupervisorStatus.warningMessage

Failure modes​

SymptomTypical cause
Unexpected deprovisionHardware change; VM migration; fingerprint source drift
Attestation skippedFrequency 0 or unprovisioned
Start errorDB signature load failure on enabled config

Platform fingerprint collection: fingerprint_linux.go, fingerprint_darwin.go, etc.

Code map​

FileRole
manager.goStart/stop, attestation worker, deprovision trigger
fingerprint_*.goPlatform fingerprint collectors
fingerprint_types.go, fingerprint_diff.goCanonical payload + diff

Related: Auth, Field agent, Store, EdgeGuard.

Group 3See anything wrong with the document? Help us improve it!