Skip to main content

Mesh Nodes

A Mesh Node is the small service you run inside your own environment. It holds a hardware-protected identity, enforces your signed policy locally, serves certificates to your workloads (ACME, EST, Kubernetes CSR and more), and rotates certificates on web servers, keystores and secret stores without downtime. It only ever connects outbound to Sectigo Edge, so you never open an inbound firewall port.

This section covers everything an operator needs to put a node into production and keep it healthy:

If you want to…Read
Understand what a node does and how it talks to the consoleMesh Node overview
Check operating system, hardware key, network and sizing prerequisitesRequirements
Install on a Linux server (systemd, TPM 2.0)Install on Linux
Install on Windows (Windows service, Platform Crypto Provider)Install on Windows
Run redundant nodes in a clusterKubernetes / Helm
Create the one-time enrollment package and bring a node onlineEnrollment
Look up a config.json key, its type and its limitsConfiguration reference
Use the edgepki-node and sectigo-edge command-line toolsCLI reference
Turn on the read-only on-host status pageLocal operations UI
Upgrade in place or roll backUpgrades
Remove a node from a hostUninstall
First time?

Follow the pages in order: Requirements → Install (Linux, Windows or Kubernetes) → Enrollment. Once the node shows as healthy under ConsoleMesh nodes, connect your first integration.

In this section​