Skip to main content
Version: v3.9.0

LocalControlPlane fields

Reference for kind: LocalControlPlane. Deploy flow is on Local.

Deploy
apiVersion: datasance.com/v3 # required, string
kind: LocalControlPlane # required, string
metadata:
name: local-cp # required, string
namespace: my-ecn # no, string
spec:
endpoint: https://127.0.0.1:51121 # no, string. Must match controller.publicUrl when both are set
ca: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # no, string. Base64 PEM
iofogUser: # required, object
email: [email protected] # required, string
password: "ChangeMe!12345" # no, string
routerSiteCA: # no, object
tlsCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # string
tlsKey: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ # string
routerLocalCA:
tlsCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # string
tlsKey: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ # string
natsSiteCA:
tlsCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # string
tlsKey: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ # string
natsLocalCA:
tlsCert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # string
tlsKey: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ # string
airgap: false # no, bool
systemAgent: # required, object
config:
arch: amd64 # required, string. amd64, arm64, arm, riscv64, or auto where supported
host: 127.0.0.1 # no, string
deploymentType: native # no, string
containerEngine: edgelet # no, string, default edgelet
routerConfig:
routerMode: interior # no, string
messagingPort: 5671 # no, int
edgeRouterPort: 45671 # no, int
interRouterPort: 55671 # no, int
natsConfig:
natsMode: server # no, string
natsServerPort: 4222 # no, int
natsLeafPort: 7422 # no, int
natsClusterPort: 6222 # no, int
natsMqttPort: 8883 # no, int
natsHttpPort: 8222 # no, int
package: {} # no, object
scripts: {} # no, object
controller:
publicUrl: https://127.0.0.1:51121 # recommended, string
trustProxy: false # no, bool
consoleUrl: https://127.0.0.1:8008 # no, string
consolePort: 8008 # no, int, default 8008
logLevel: info # no, string
package:
image: ghcr.io/datasance/controller:3.9.0 # no, string
registry: registry.example.com # no, string
username: pull-user # no, string
password: pull-token # no, string
email: [email protected] # no, string
auth: # required, object. Keep the fields for one mode
mode: embedded # required, embedded or external
insecureAllowHttp: false # no, bool
insecureAllowBootstrapLog: false # no, bool
bootstrap:
username: bootstrap-user # required if embedded, string
password: "ChangeMe!12345" # required if embedded, string
issuerUrl: https://idp.example.com # required if external, string. Remove when mode is embedded
client:
id: cli # required if external, string
secret: client-secret # required if external, string
rateLimit:
enabled: false # no, bool
maxRequestsPerWindow: 100 # no, int
windowMs: 60000 # no, int
sessionStore:
type: memory # no, string
ttlMs: 3600000 # no, int
secret: session-secret # no, string
tokenTtl:
accessTokenTtlSeconds: 3600 # no, int
refreshTokenTtlSeconds: 86400 # no, int
oidcTtl:
interactionTtlSeconds: 600 # no, int
grantTtlSeconds: 600 # no, int
sessionTtlSeconds: 3600 # no, int
idTokenTtlSeconds: 3600 # no, int
database: # no, object. Omit provider for SQLite
provider: postgres # no, string. postgres or mysql
host: db.example.com # required when provider is set, string
port: 5432 # required when provider is set, int
user: pot # required when provider is set, string
password: db-password # required when provider is set, string
databaseName: pot # required when provider is set, string
ssl: false # no, bool
ca: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # no, string. Base64 PEM
systemMicroservices:
router:
amd64: ghcr.io/datasance/router:3.9.0
arm64: ghcr.io/datasance/router:3.9.0
arm: ghcr.io/datasance/router:3.9.0
riscv64: ghcr.io/datasance/router:3.9.0
nats:
amd64: ghcr.io/datasance/nats:2.15.0
arm64: ghcr.io/datasance/nats:2.15.0
arm: ghcr.io/datasance/nats:2.15.0
riscv64: ghcr.io/datasance/nats:2.15.0
nats:
enabled: true # no, bool
events:
auditEnabled: false # no, bool
retentionDays: 30 # no, int
cleanupInterval: 3600 # no, int. Seconds
captureIpAddress: false # no, bool
vault: # no, object. Keep the provider block that matches provider
enabled: false # no, bool
provider: hashicorp # no, string
basePath: secret/data/ecn # no, string. Literal on Edgelet
hashicorp:
address: https://vault.example.com # string
token: vault-token # string
mount: secret # string
aws:
region: us-east-1 # string
accessKeyId: <access-key-id> # string
accessKey: <secret-access-key> # string
azure:
url: https://example.vault.azure.net # string
tenantId: <tenant-id> # string
clientId: <client-id> # string
clientSecret: <client-secret> # string
google:
projectId: <project-id> # string
credentials: "<service-account-json>" # string
tls: # no, object. cert and key are set together
ca: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # string
cert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t # string
key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ # string

metadata.namespace, when set, must match -n.

CLI-only fields​

These are not copied into the Edgelet manifest.

FieldTypeRequiredDescription
endpointstringNoStored CLI endpoint. Must match controller.publicUrl when both are set.
cabase64 PEMNoCLI trust for the Controller API
iofogUserobjectYes (email)CLI user. Embedded auth bootstrap runs after deploy.
routerSiteCAsite certificateNoValidated. Not uploaded on local deploy today.
routerLocalCAsite certificateNoSame
natsSiteCAsite certificateNoSame
natsLocalCAsite certificateNoSame
airgapboolNoOffline image and binary staging

iofogUser.password, when set, follows the same complexity rules as bootstrap passwords. See Securing a local control plane.

spec.systemAgent (required)​

FieldRequiredDescription
config.archYesHost architecture for Edgelet and system microservice images. amd64, arm64, arm, riscv64, or auto where supported.
config.*NoOther Edgelet node settings (router and NATS environment, deploymentType, and similar)
packageNoEdgelet package and WASM shims for the install
scriptsNoCustom install script layers

Invalid arch values are rejected. WASM and Podman combinations follow Edgelet node validation.

spec.controller​

FieldTypeNotes
publicUrlstringRecommended. CONTROLLER_PUBLIC_URL on Edgelet.
trustProxybool
consoleUrlstringConsole URL. Edgelet does not copy this from publicUrl on its own.
consolePortintDefault 8008
logLevelstring
package.imagestringController image when you are not using the CLI default (controller:3.9.0). See Default image pins.
package.registrystringRegistry hostname for a private pull
package.usernamestringRequired with registry and password
package.passwordstring
package.emailstringOptional

When any of registry, username, or password is set, all three are required.

Translated to Edgelet spec.controller.image and an optional registry id.

spec.auth (required)​

FieldTypeRequiredNotes
modeembedded or externalYes
insecureAllowHttpboolNoTrials. AUTH_INSECURE_ALLOW_HTTP on the Controller.
insecureAllowBootstrapLogboolNoTrials
bootstrap.usernamestringYes if embedded
bootstrap.passwordstringYes if embeddedRequired in YAML at deploy. At least 12 characters, one uppercase letter, one special character.
issuerUrlstringYes if external
client.idstringYes if external
client.secretstringYes if external
rateLimit.*objectNo
sessionStore.*objectNo
tokenTtl.*objectNo
oidcTtl.*objectNo

Translated to Edgelet spec.auth, then to Controller container environment. See Edgelet control plane.

ModeCLI after deploy
embeddedBootstrap login. Creates iofogUser if it is missing.
externalSkips embedded user bootstrap. The Controller uses your identity provider.

Keycloak-shaped auth.url and realm fields are retired.

BlockFields
rateLimitenabled, maxRequestsPerWindow, windowMs
sessionStoretype, ttlMs, secret
tokenTtlaccessTokenTtlSeconds, refreshTokenTtlSeconds
oidcTtlinteractionTtlSeconds, grantTtlSeconds, sessionTtlSeconds, idTokenTtlSeconds

spec.database​

Optional external database. When provider is postgres or mysql, user, host, port, password, and databaseName are required.

FieldNotes
sslDatabase TLS
caBase64 PEM. Becomes DB_SSL_CA.

Omit provider for the SQLite default on a single local Controller.

spec.systemMicroservices​

Per-architecture images for the Router and NATS system microservices. Keys are amd64, arm64, arm, and riscv64.

systemMicroservices
systemMicroservices:
router:
amd64: ghcr.io/datasance/router:3.9.0
arm64: ghcr.io/datasance/router:3.9.0
arm: ghcr.io/datasance/router:3.9.0
riscv64: ghcr.io/datasance/router:3.9.0
nats:
amd64: ghcr.io/datasance/nats:2.15.0
arm64: ghcr.io/datasance/nats:2.15.0
arm: ghcr.io/datasance/nats:2.15.0
riscv64: ghcr.io/datasance/nats:2.15.0

Maps to Edgelet spec.systemMicroservices and Controller environment ROUTER_IMAGE_* / NATS_IMAGE_*.

spec.nats​

FieldNotes
enabledDeploy the NATS system microservice when true

Local YAML has no JetStream PVC fields. JetStream behavior lives on the system microservice image and its config. Kubernetes storage fields are on KubernetesControlPlane fields.

spec.events​

auditEnabled, retentionDays, cleanupInterval, captureIpAddress.

spec.vault​

Optional Controller vault integration. Translated to Edgelet spec.vault. basePath is stored literally. Edgelet does not expand $namespace. Put the real path in the file.

FieldDescription
enabledEnable vault integration
providerhashicorp, openbao, vault, aws, aws-secrets-manager, azure, azure-key-vault, google, or google-secret-manager
basePathBase path inside the vault. Literal on Edgelet.
hashicorp.address, hashicorp.token, hashicorp.mountHashiCorp, OpenBao, or Vault
aws.region, aws.accessKeyId, aws.accessKeyAWS Secrets Manager
azure.url, azure.tenantId, azure.clientId, azure.clientSecretAzure Key Vault
google.projectId, google.credentialsGoogle Secret Manager

On Kubernetes, $namespace in basePath is expanded. See KubernetesControlPlane fields.

spec.tls​

Optional Controller listener TLS. See Securing a local control plane. Translated only to Edgelet spec.tls.base64.

Deploy flow​

potctl installs Edgelet, deploys the translated ControlPlane, waits for the Controller API, creates the embedded user when that mode is on, then installs and provisions the system Edgelet node.

The user apiVersion is the flavor group. The manifest Edgelet stores is apiVersion: edgelet.iofog.org/v1, kind: ControlPlane.

Worked YAML is on Local.

Group 3See anything wrong with the document? Help us improve it!