Configuration reference
A Mesh Node reads one JSON file, config.json, passed with -config. The console generates the core of this file inside the enrollment package; you add integration settings to it afterwards.
| Platform | Location |
|---|---|
| Linux | /etc/edgepki/config.json (owner root:edgepki, mode 0640) |
| Windows | C:\ProgramData\Sectigo\Edge\config.json |
| Kubernetes | Generated by the Helm chart into a ConfigMap and mounted at /etc/edgepki/config.json — set values with Helm, not by editing the file |
Rules that apply to every key
- Unknown keys are rejected. A misspelled key stops the node with
decode config: json: unknown field "<name>". - Validation runs before anything else. The node will not start (and
-validate-configfails) if any rule below is broken. Production meansinsecure_developmentisfalse. - Booleans default to
false, numbers to0, strings to empty when a key is omitted. A number with a minimum must therefore be set explicitly whenever its feature is enabled. - Paths: where a rule says absolute, a relative path is an error.
state_directory, the policy and registration trust files, the ACME credential file and the OTLP files are converted to absolute paths relative to the working directory. - Adapter references must match
local/<name>: 9–128 characters in total,<name>made of lowercase letters, digits,.,-and_, not starting or ending with.or-, and never containing... - Profile and exporter identifiers must be 2–128 characters of letters, digits,
.,-and_, not starting or ending with.or-, and never containing... - SHA-256 pins are exactly 64 lowercase hexadecimal characters.
After editing, validate offline and then restart the service:
- Linux
- Windows
sudo -u edgepki /usr/local/bin/edgepki-node -validate-config -config /etc/edgepki/config.json
Sectigo Edge bootstrap configuration and trust files validated.
sudo systemctl restart edgepki-node
& 'C:\Program Files\Sectigo\Edge\edgepki-node.exe' -validate-config -config C:\ProgramData\Sectigo\Edge\config.json
Sectigo Edge bootstrap configuration and trust files validated.
Restart-Service SectigoEdgeMeshNode
Example (Linux, as generated by the console)
Sample values; your package contains your own tenant, node name, API URL and keys.
{
"tenant_id": "acme-corp",
"node_name": "mesh-node-01",
"edge_url": "https://api.sharppki.com",
"listen_address": "127.0.0.1:9443",
"local_api_url": "https://127.0.0.1:9443",
"state_directory": "/var/lib/edgepki",
"enrollment_token_file": "/var/lib/edgepki/enrollment-token",
"tls_certificate_file": "/etc/edgepki/local-api.crt",
"tls_private_key_file": "/etc/edgepki/local-api.key",
"workload_trust_bundle_file": "/etc/edgepki/workload-ca.pem",
"workload_trust_domain": "acme-corp.sharppki.local",
"policy_trust_bundle_file": "/etc/edgepki/policy-trust.json",
"policy_bundle_max_ttl_seconds": 300,
"audit_checkpoint_key_id": "audit-production-2026-01",
"audit_checkpoint_public_key_base64": "<43-character base64url Ed25519 public key>",
"registration_trust_bundle_file": "/etc/edgepki/registration-trust.json",
"registration_grant_max_ttl_seconds": 600,
"acme_external_account_required": true,
"acme_external_account_credentials_file": "/etc/edgepki/acme-eab.json",
"spire_enabled": false,
"node_key_provider": "tpm2",
"tls_client_certificate_file": "/etc/edgepki/edge-client.crt",
"tls_client_private_key_file": "/etc/edgepki/edge-client.key",
"poll_interval_seconds": 10,
"allowed_spiffe_prefixes": ["spiffe://acme-corp.sharppki.local/"],
"trust_event_subscriber_spiffe_prefixes": ["spiffe://acme-corp.sharppki.local/"],
"allowed_dns_suffixes": [],
"max_validity_seconds": 86400,
"cloud_fallback_enabled": true,
"require_pqc_transport": false
}
The Windows package uses C:\ProgramData\Sectigo\Edge\… for every path (written with doubled backslashes inside JSON strings) and sets node_key_provider to windows_cng with windows_cng_provider and windows_cng_key_name.
The installers require the file locations above for signed packages, and -Upgrade/--upgrade revalidates the installed file before replacing the binary. Change only the keys you need to.
Core and connection
| Key | Type | Required | Rules and effect |
|---|---|---|---|
tenant_id | string | Yes | At least 3 characters. Must match your workspace and the trust files. |
node_name | string | Yes | Non-empty. Must equal the name bound to the enrollment token. |
edge_url | string | Yes | Sectigo Edge API origin. Must start with https:// outside development. Signed packages require an HTTPS origin with no path. |
listen_address | string | Yes | host:port the local TLS API listens on, for example 127.0.0.1:9443. |
local_api_url | string | Yes | URL workloads use to reach this node (advertised in discovery and ACME URLs). Overridden by SECTIGO_EDGE_LOCAL_API_URL. |
state_directory | string | Yes | Directory for identity, key blobs, audit log and adapter state. |
poll_interval_seconds | integer | Yes | At least 1. How often the node polls Sectigo Edge. |
require_pqc_transport | boolean | No | When true, refuse any outbound connection that does not negotiate TLS 1.3 with X25519MLKEM768. Requires an HTTPS edge_url. |
cloud_fallback_enabled | boolean | No | Whether connectivity-only cloud fallback is configured. Shown as "cloud fallback configured" in the local UI. |
enrollment_token_file | string | No | Path to the one-time token. Read at start if present; deleted after enrollment. |
enrollment_token | string | No | Legacy inline token. Signed packages forbid it; leave it out. Environment variables take precedence. |
insecure_development | boolean | No | Development only. Relaxes HTTPS, TLS, trust-domain, ACME and key-provider requirements. Never set in production. |
Local API and workload trust
| Key | Type | Required | Rules and effect |
|---|---|---|---|
tls_certificate_file | string | Yes (production) | Server certificate for the local TLS 1.3 API. |
tls_private_key_file | string | Yes (production) | Key for the server certificate. |
workload_trust_bundle_file | string | Yes (production) | PEM bundle that issues workload (and operator) client certificates. Must contain at least one certificate. |
workload_trust_domain | string | Yes (production) | SPIFFE trust domain: lowercase, at most 255 characters, letters, digits, ., -, _. |
allowed_spiffe_prefixes | string array | Yes (production) | At least one. Each must start with spiffe://<workload_trust_domain>/, end with /, and contain no %, ? or #. Requesters outside these prefixes are refused. |
allowed_dns_suffixes | string array | No | DNS name suffixes workloads may request. |
max_validity_seconds | integer | Yes | At least 300. Upper bound on certificate lifetime enforced locally. |
trust_event_subscriber_spiffe_prefixes | string array | No | Identities allowed to read the signed trust-event feed (GET /v1/events). Each must be in the trust domain and end with /. Grant only dedicated observers. |
local_ui_enabled | boolean | No | Enables the read-only local operations UI at /ui/. |
local_ui_allowed_spiffe_prefixes | string array | When UI enabled | At least one operator prefix in production; same format rules as allowed_spiffe_prefixes. Use a dedicated operator path. |
Outbound connection to Sectigo Edge
| Key | Type | Required | Rules and effect |
|---|---|---|---|
tls_client_certificate_file | string | Signed packages | Organization-issued client certificate for outbound mTLS. If either client key is set, both are loaded. |
tls_client_private_key_file | string | Signed packages | Key for the client certificate. |
tls_root_ca_file | string | No | PEM root(s) used to verify the Sectigo Edge server instead of the system roots. Must contain at least one certificate. |
Policy and registration trust
| Key | Type | Required | Rules and effect |
|---|---|---|---|
policy_trust_bundle_file | string | Yes | Pinned policy-signing public keys (sectigo-edge.policy-trust.v1), bound to your tenant. |
policy_bundle_max_ttl_seconds | integer | Yes | 60–900. Maximum lifetime accepted for a signed policy bundle. |
registration_trust_bundle_file | string | Yes | Pinned service-registration grant keys (sectigo-edge.registration-trust.v1), bound to your tenant. |
registration_grant_max_ttl_seconds | integer | Yes | 60–600. Maximum lifetime accepted for a registration grant. |
Node key provider
| Key | Type | Required | Rules and effect |
|---|---|---|---|
node_key_provider | string | Yes (production) | tpm2 (Linux only), windows_cng (Windows only), pkcs11, or software. A missing or unavailable provider stops the node. |
allow_software_node_key | boolean | No | Explicit exception required to use software outside development. Signed packages reject it. |
windows_cng_provider | string | No | CNG provider name. Defaults to Microsoft Platform Crypto Provider. |
windows_cng_key_name | string | With windows_cng | Name of the existing, non-exportable ECDSA P-256 key to open. |
pkcs11_module_path | string | With pkcs11 | Vendor PKCS#11 library. |
pkcs11_token_label / pkcs11_token_serial | string | One of them | Token selector (mutually exclusive). |
pkcs11_key_label / pkcs11_key_id_hex | string | One of them | Key selector. The key must be ECDSA P-256. |
pkcs11_max_sessions | integer | No | Session pool size (Helm default 8). |
The PKCS#11 PIN is never a configuration key: set SHARPPKI_PKCS11_PIN in the service's secret environment.
ACME
| Key | Type | Required | Rules and effect |
|---|---|---|---|
acme_external_account_required | boolean | Yes (production) | Must be true outside development. |
acme_external_account_credentials_file | string | Yes (production) | Credential store for External Account Binding. Start with {"version":1,"credentials":[]}. See ACME. |
Audit witness and OTLP export
| Key | Type | Required | Rules and effect |
|---|---|---|---|
audit_checkpoint_key_id | string | Pair | Identifier of the pinned audit checkpoint key. Must be set together with the public key. |
audit_checkpoint_public_key_base64 | string | Pair | Raw 32-byte Ed25519 public key, base64url without padding. |
otlp_audit_enabled | boolean | No | Enables signed audit export over OTLP. Every other otlp_audit_* key must be absent when this is false. |
otlp_audit_exporter_id | string | With OTLP | Identifier (for example primary-siem). |
otlp_audit_endpoint | string | With OTLP | Exact https://…/v1/logs URL, at most 2048 characters, no credentials, query or fragment. |
otlp_audit_trust_bundle_file | string | With OTLP | Absolute path to the collector CA. |
otlp_audit_client_certificate_file | string | With OTLP | Absolute path to the client certificate. |
otlp_audit_client_private_key_file | string | With OTLP | Absolute path to the client key. |
otlp_audit_batch_size | integer | With OTLP | 1–64. |
otlp_audit_request_timeout_seconds | integer | With OTLP | 2–60. |
otlp_audit_poll_interval_seconds | integer | With OTLP | 1–300. |
Dependency discovery
| Key | Type | Required | Rules and effect |
|---|---|---|---|
dependency_discovery_enabled | boolean | No | Accepts SDK dependency observations at POST /v1/dependencies/observe. All other dependency keys must be absent when false. |
dependency_probes | array | No | Up to 256 explicit active TLS probes (fields below). |
dependency_probe_interval_seconds | integer | With probes | 30–3600. Must be absent (or 0) when there are no probes. |
dependency_observation_ttl_seconds | integer | With probes | At least twice the interval, at most 86400. |
dependency_probe_timeout_seconds | integer | With probes | 2–60. |
Each entry in dependency_probes:
| Field | Rules |
|---|---|
id | Unique identifier (same rules as profile identifiers). |
source_endpoint_id, target_endpoint_id | 3–256 characters, no whitespace; must differ. |
address | Exact host:port; host is an IP address or lowercase DNS name; port 1–65535. |
server_name | Lowercase DNS name verified in the server certificate. |
channel | tls, mtls, grpc, mqtt, database, mcp or a2a. |
expected_alpn | none, h2, http/1.1, mqtt, mcp or a2a. |
trust_bundle_file | Optional absolute path. |
client_certificate_file, client_private_key_file | Optional absolute paths, set together; required when channel is mtls. |
SPIRE
| Key | Type | Required | Rules and effect |
|---|---|---|---|
spire_enabled | boolean | No | Direct SPIRE Server Entry API reconciliation. Not allowed on Windows. |
spire_server_api_socket | string | With SPIRE | Absolute path to the SPIRE Server API Unix socket. |
spire_parent_id | string | With SPIRE | Valid SPIFFE ID used as the entries' parent. |
See SPIFFE / SPIRE.
Kubernetes CSR signer
| Key | Type | Required | Rules and effect |
|---|---|---|---|
kubernetes_csr_enabled | boolean | No | Enables the custom signer. |
kubernetes_adapter_reference | string | Yes | local/… reference matching the console. |
kubernetes_api_server_url | string | Yes | Must start with https://. |
kubernetes_ca_file, kubernetes_token_file | string | Yes | Absolute paths. |
kubernetes_signer_name | string | Yes | domain/name; the domain may not be kubernetes.io or end in .kubernetes.io. |
kubernetes_managed_label | string | Yes | One key=value label selector. |
kubernetes_cluster_id | string | Yes | DNS label. spiffe://<trust domain>/kubernetes/<cluster id>/ must be covered by allowed_spiffe_prefixes. |
kubernetes_allowed_namespaces | string array | Yes | At least one DNS-label namespace. |
kubernetes_allowed_usages | string array | Yes | Any of digital signature, key encipherment, server auth, client auth. |
kubernetes_max_requests_per_poll | integer | Yes | 1–100. |
kubernetes_request_timeout_seconds | integer | Yes | 2–30. |
kubernetes_lease_namespace, kubernetes_lease_name | string | Yes | DNS labels of the pre-created coordination Lease. |
kubernetes_lease_duration_seconds | integer | Yes | 15–120. |
All "Yes" entries apply only when kubernetes_csr_enabled is true. See Kubernetes CSR.
EST
| Key | Type | Required | Rules and effect |
|---|---|---|---|
est_enabled | boolean | No | Enables the RFC 7030 listener. |
est_adapter_reference | string | With EST | local/… reference matching the console. |
est_ca_certificate_bundle_file | string | With EST | Absolute path to the public root and intermediates returned by /cacerts. |
See EST.
Microsoft ADCS (Windows only)
| Key | Type | Required | Rules and effect |
|---|---|---|---|
microsoft_adcs_enabled | boolean | No | Windows nodes only. |
microsoft_adcs_adapter_reference | string | Yes | local/… reference matching the console. |
microsoft_adcs_ca_configuration | string | Yes | Exactly server\CA name (one backslash; in JSON write \\). |
microsoft_adcs_template | string | Yes | Certificate template name. |
microsoft_adcs_profile_id | string | Yes | Profile that must match the console. |
microsoft_adcs_ca_chain_file | string | Yes | Absolute path to the public ADCS CA chain. |
microsoft_adcs_online_responder_url | string | Yes | Online Responder URL, at most 2048 characters. |
microsoft_adcs_request_timeout_seconds | integer | Yes | 2–120. |
microsoft_adcs_recovery_spiffe_ids | string array | Yes | At least one exact SPIFFE ID in workload_trust_domain allowed to run adcs-recover. |
See Microsoft ADCS.
NGINX (Linux only)
| Key | Type | Required | Rules and effect |
|---|---|---|---|
nginx_enabled | boolean | No | Linux nodes only. |
nginx_adapter_reference | string | Yes | local/… reference matching the console. |
nginx_profile_id | string | Yes | Profile identifier matching the console. |
nginx_binary_path | string | Yes | Absolute path to the NGINX executable. |
nginx_binary_sha256 | string | Yes | SHA-256 pin of that executable. |
nginx_configuration_file | string | Yes | Absolute path to the root configuration. |
nginx_managed_directory | string | Yes | Absolute path where generations are stored. |
nginx_bootstrap_certificate_file, nginx_bootstrap_private_key_file | string | Yes | Absolute paths to the currently served key pair (imported as generation one). |
nginx_reload_timeout_seconds | integer | Yes | 2–60. |
nginx_rollback_window_seconds | integer | Yes | 60–86400. |
Apache HTTP Server (Linux only)
Same shape as NGINX with the apache_ prefix: apache_enabled, apache_adapter_reference, apache_profile_id, apache_binary_path, apache_binary_sha256, apache_configuration_file, apache_managed_directory, apache_bootstrap_certificate_file, apache_bootstrap_private_key_file, apache_reload_timeout_seconds (2–60) and apache_rollback_window_seconds (60–86400). All paths absolute. See Apache HTTP Server.
Java PKCS#12
| Key | Type | Required | Rules and effect |
|---|---|---|---|
java_keystore_enabled | boolean | No | Windows and Linux. |
java_keystore_adapter_reference | string | Yes | local/… reference. |
java_keystore_profile_id | string | Yes | Profile identifier. |
java_keystore_keytool_path, java_keystore_keytool_sha256 | string | Yes | Absolute path and SHA-256 pin of JDK keytool. |
java_keystore_alias | string | Yes | 1–128 characters: letters, digits, ., -, _. |
java_keystore_password_file | string | Yes | Absolute path to the keystore password file. |
java_keystore_active_file | string | Yes | Absolute path of the keystore your application reads. |
java_keystore_managed_directory | string | Yes | Absolute path for generations. |
java_keystore_bootstrap_certificate_file, java_keystore_bootstrap_private_key_file | string | Yes | Absolute paths to the current chain and key. |
java_keystore_reload_binary_path, java_keystore_reload_binary_sha256 | string | Yes | Absolute path and pin of the reload executable. |
java_keystore_reload_arguments | string array | No | Up to 32 fixed arguments, each at most 512 characters, no NUL or line breaks. {keystore} is replaced with the active keystore path. |
java_keystore_reload_timeout_seconds | integer | Yes | 2–60. |
java_keystore_rollback_window_seconds | integer | Yes | 60–86400. |
HashiCorp Vault KV v2
| Key | Type | Required | Rules and effect |
|---|---|---|---|
hashicorp_vault_enabled | boolean | No | Enables the Vault adapter. |
hashicorp_vault_adapter_reference | string | Yes | local/… reference. |
hashicorp_vault_profile_id | string | Yes | Profile identifier. |
hashicorp_vault_address | string | Yes | Exact HTTPS origin (no path, query, fragment or credentials). Loopback HTTP is allowed only in development. |
hashicorp_vault_namespace | string | No | Vault Enterprise namespace. |
hashicorp_vault_token_file | string | Yes | Absolute path to the token file. |
hashicorp_vault_ca_certificate_file | string | No | Absolute path to the Vault server CA. |
hashicorp_vault_client_certificate_file, hashicorp_vault_client_private_key_file | string | No | Absolute paths, set together, for Vault TLS authentication. |
hashicorp_vault_kv_mount | string | Yes | Single path segment. |
hashicorp_vault_kv_base_path | string | Yes | Relative path; segments of letters, digits, -, _, .; no empty, . or .. segments; no leading or trailing /; at most 512 characters. |
hashicorp_vault_managed_directory | string | Yes | Absolute path for local state. |
hashicorp_vault_bootstrap_certificate_file, hashicorp_vault_bootstrap_private_key_file | string | Yes | Absolute paths to the first generation's chain and key. |
hashicorp_vault_request_timeout_seconds | integer | Yes | 2–60. |
hashicorp_vault_rollback_window_seconds | integer | Yes | 60–86400. |
hashicorp_vault_reload_binary_path | string | No | Absolute path to an optional reload executable. |
hashicorp_vault_reload_binary_sha256 | string | With reload | SHA-256 pin. |
hashicorp_vault_reload_arguments | string array | No | Up to 32 fixed arguments (512 characters each). {certificate} is substituted. |
hashicorp_vault_reload_timeout_seconds | integer | With reload | 2–60. |
Environment variables
| Variable | Effect |
|---|---|
SECTIGO_EDGE_ENROLLMENT_TOKEN | One-time enrollment token (takes precedence over enrollment_token_file). The legacy names SHARPPKI_ENROLLMENT_TOKEN and EDGEPKI_ENROLLMENT_TOKEN are also read. Used by the Helm chart. |
SECTIGO_EDGE_LOCAL_API_URL | Overrides local_api_url. The Helm chart sets it per pod. |
SHARPPKI_PKCS11_PIN | PIN for the PKCS#11 token. |