Skip to main content
Version: v3.9.0

Securing the cluster

Datasance PoT trust for the control plane depends on the deploy path. This page names who owns each TLS layer, then links the page for that path.

Who owns TLS​

LayerKubernetesLocalRemote
Controller HTTPSOperator: pod TLS and/or Ingresspotctl writes spec.tls to Edgelet spec.tls.base64Same as local. A host may override with controllers[].tls
Router and NATS CAsOperator creates or reuses namespace Secrets, then imports the CAs into the ControllerYAML blocks are validated. They are not uploadedpotctl uploads routerSiteCA, routerLocalCA, natsSiteCA, and natsLocalCA once after the API is up
CLI trust of the Controller APIspec.ca in ~/.iofog/v3/trust/<namespace>/SameSame
connect --caConnect-time overrideSameSame

~/.iofog/v3 is the CLI config directory for both flavors.

Listener TLS is spec.tls or controllers[].tls. Legacy controllers[].https is retired. Edgelet listener fields (spec.tls.path and spec.tls.base64) are documented at spec.tls.

Local bring-your-own messaging CAs are validated and not uploaded. Production bring-your-own CAs use a remote control plane, or a manual Controller API import, until local deploy gains that upload.

A remote upload runs once, after the Controller API is up. A Controller add-on deploy does not upload those CAs again.

Control plane TLS​

Deploy pathTLSFields
Kubernetes (KubernetesControlPlane)CLI YAML, operatorKubernetesControlPlane fields, ControlPlane CRD
Remote (ControlPlane)RemoteRemote ControlPlane fields
Local (LocalControlPlane)LocalLocalControlPlane fields

Access, certificates, and sign-in​

Access control is who may call the Controller API.

Workload certificates are separate from Router and NATS site CAs:

Message bus authorization:

Certificates manager is the x509 lifecycle for microservices.

Sign-in:

Edgelet node JWT​

After provision, the Controller stores the Edgelet node's public key. The node signs a short-lived JWT. Agent routes under /api/v3/agent/* use that token. User routes use an OIDC bearer token. See Access control.

Group 3See anything wrong with the document? Help us improve it!