Securing the cluster
Datasance PoT trust for the control plane depends on the deploy path. This page names who owns each TLS layer, then links the page for that path.
Who owns TLS
| Layer | Kubernetes | Local | Remote |
|---|---|---|---|
| Controller HTTPS | Operator: pod TLS and/or Ingress | potctl writes spec.tls to Edgelet spec.tls.base64 | Same as local. A host may override with controllers[].tls |
| Router and NATS CAs | Operator creates or reuses namespace Secrets, then imports the CAs into the Controller | YAML blocks are validated. They are not uploaded | potctl uploads routerSiteCA, routerLocalCA, natsSiteCA, and natsLocalCA once after the API is up |
| CLI trust of the Controller API | spec.ca in ~/.iofog/v3/trust/<namespace>/ | Same | Same |
connect --ca | Connect-time override | Same | Same |
~/.iofog/v3 is the CLI config directory for both flavors.
Listener TLS is spec.tls or controllers[].tls. Legacy controllers[].https is retired. Edgelet listener fields (spec.tls.path and spec.tls.base64) are documented at spec.tls.
Local bring-your-own messaging CAs are validated and not uploaded. Production bring-your-own CAs use a remote control plane, or a manual Controller API import, until local deploy gains that upload.
A remote upload runs once, after the Controller API is up. A Controller add-on deploy does not upload those CAs again.
Control plane TLS
| Deploy path | TLS | Fields |
|---|---|---|
Kubernetes (KubernetesControlPlane) | CLI YAML, operator | KubernetesControlPlane fields, ControlPlane CRD |
Remote (ControlPlane) | Remote | Remote ControlPlane fields |
Local (LocalControlPlane) | Local | LocalControlPlane fields |
Access, certificates, and sign-in
Access control is who may call the Controller API.
Workload certificates are separate from Router and NATS site CAs:
Message bus authorization:
Certificates manager is the x509 lifecycle for microservices.
Sign-in:
Edgelet node JWT
After provision, the Controller stores the Edgelet node's public key. The node signs a short-lived JWT. Agent routes under /api/v3/agent/* use that token. User routes use an OIDC bearer token. See Access control.