Skip to main content
Version: v3.9.0

Securing a local control plane

LocalControlPlane runs the Controller on the same machine as potctl, through Edgelet. This page covers CLI trust and listener TLS. Field tables are LocalControlPlane fields.

What local deploy applies​

MechanismPurposeOn local deploy
spec.caCLI trust for Controller API HTTPSStored in the namespace trust directory
spec.tlsController listener certificateWritten to Edgelet spec.tls.base64
routerSiteCA, routerLocalCA, natsSiteCA, natsLocalCABring-your-own messaging CAsValidated. Not uploaded
Edgelet spec.tls.pathHost directory for certificate filesNot set. potctl uses the base64 block only

Production bring-your-own messaging CAs use a remote control plane, or a manual Controller API import, until local deploy gains that upload.

CLI trust: spec.ca​

Same store as Kubernetes and remote. spec.ca is a base64 PEM on one line. After deploy it is ca.pem under ~/.iofog/v3/trust/<namespace>/. potctl uses it when it calls the Controller API over HTTPS.

base64 -i controller-ca.pem | tr -d '\n'

connect --ca overrides trust for that connect only.

Listener TLS: spec.tls​

FieldRequiredNotes
caNoIntermediate or root
certYes, with keyServer certificate, base64 PEM
keyYes, with certPrivate key, base64 PEM

If you set cert or key, set both.

potctl maps this block to Edgelet spec.tls.base64. It does not set spec.tls.path. Listener fields on the Edgelet manifest: spec.tls.

Set spec.controller.publicUrl, and spec.controller.consoleUrl when the console hostname differs, to https:// URLs that match the certificate SANs.

local-listener-tls.yaml
apiVersion: datasance.com/v3
kind: LocalControlPlane
metadata:
name: local
spec:
ca: <base64-pem>
tls:
cert: <base64-pem>
key: <base64-pem>
ca: <base64-pem>
controller:
publicUrl: https://127.0.0.1:51121

Messaging CA blocks​

Each block has tlsCert and tlsKey, both base64 PEM.

YAML blockSecret name on a remote deploy
routerSiteCArouter-site-ca
routerLocalCAdefault-router-local-ca
natsSiteCAnats-site-ca
natsLocalCAdefault-nats-local-ca

On a remote deploy, potctl uploads these blocks once. See Securing a remote control plane. On a local deploy the blocks are validated and not uploaded. You can keep them in a file you will deploy remotely later. They do not create Controller secrets or CA catalog entries on the local Controller.

Edgelet rejects legacy inline site and local CA fields in its own manifest. Import messaging CAs with the Controller API after deploy, or use a remote control plane.

Database TLS​

When spec.database.provider is set, ssl and ca (base64 PEM) are the Controller connection to that database. They are separate from spec.tls and from the messaging CA blocks. See LocalControlPlane fields.

Provision​

After the system Edgelet node is provisioned, a caCert in the provision key response is applied with edgelet config cert. The node then trusts the messaging CAs published in the Controller catalog for Router port 5671 and NATS ports 4222 and 8883.

Checks​

  • Set spec.ca when the Controller API uses a private CA.
  • Set spec.tls when you want to test an HTTPS listener.
  • Do not expect routerSiteCA and the other three blocks to upload on local deploy.
  • Keep bootstrap and database passwords out of Git.

Troubleshooting​

SymptomLikely cause
CLI TLS error to the APIspec.ca is missing or wrong
The API accepts HTTPS and messaging failsMessaging CAs are not in the Controller catalog
Validation error on tlscert and key are not both set, or the base64 is invalid
routerSiteCA is in the file and nothing changesExpected on local deploy. The block is validated and not uploaded
Group 3See anything wrong with the document? Help us improve it!