Mesh Nodes
A Mesh Node is the small service you run inside your own environment. It holds a hardware-protected identity, enforces your signed policy locally, serves certificates to your workloads (ACME, EST, Kubernetes CSR and more), and rotates certificates on web servers, keystores and secret stores without downtime. It only ever connects outbound to Sectigo Edge, so you never open an inbound firewall port.
This section covers everything an operator needs to put a node into production and keep it healthy:
| If you want to… | Read |
|---|---|
| Understand what a node does and how it talks to the console | Mesh Node overview |
| Check operating system, hardware key, network and sizing prerequisites | Requirements |
| Install on a Linux server (systemd, TPM 2.0) | Install on Linux |
| Install on Windows (Windows service, Platform Crypto Provider) | Install on Windows |
| Run redundant nodes in a cluster | Kubernetes / Helm |
| Create the one-time enrollment package and bring a node online | Enrollment |
Look up a config.json key, its type and its limits | Configuration reference |
Use the edgepki-node and sectigo-edge command-line tools | CLI reference |
| Turn on the read-only on-host status page | Local operations UI |
| Upgrade in place or roll back | Upgrades |
| Remove a node from a host | Uninstall |
Follow the pages in order: Requirements → Install (Linux, Windows or Kubernetes) → Enrollment. Once the node shows as healthy under ConsoleMesh nodes, connect your first integration.
In this section
Mesh Node overview
What a Mesh Node does, how it communicates with the console, and how it delivers and rotates certificates for the workloads it serves.
Requirements
Supported operating systems and architectures, resource sizing, and the network access a Mesh Node needs.
Install on Linux
Installing the Mesh Node on supported Linux distributions, running it as a service, and confirming it is healthy.
Install on Windows
Installing the Mesh Node on Windows Server, running it as a Windows service, and confirming it is healthy using PowerShell.
Kubernetes / Helm
Deploying Mesh Nodes into a Kubernetes cluster with the Helm chart, including values, upgrades and namespace considerations.
Enrollment
Enrolling a newly installed Mesh Node into your workspace, how enrollment tokens work, and how to re-enroll a node.
Configuration reference
Every Mesh Node configuration setting, its default value and its effect.
CLI reference
The Sectigo Edge command-line interface: commands, flags, exit codes and examples.
Local operations UI
The local operations interface served by a Mesh Node for on-host status checks and troubleshooting.
Upgrades
Upgrading Mesh Nodes safely, including version compatibility, staged rollouts and rollback.
Uninstall
Removing a Mesh Node cleanly from a host and retiring it from your workspace.