Skip to main content

Configuration reference

A Mesh Node reads one JSON file, config.json, passed with -config. The console generates the core of this file inside the enrollment package; you add integration settings to it afterwards.

PlatformLocation
Linux/etc/edgepki/config.json (owner root:edgepki, mode 0640)
WindowsC:\ProgramData\Sectigo\Edge\config.json
KubernetesGenerated by the Helm chart into a ConfigMap and mounted at /etc/edgepki/config.json — set values with Helm, not by editing the file

Rules that apply to every key​

  • Unknown keys are rejected. A misspelled key stops the node with decode config: json: unknown field "<name>".
  • Validation runs before anything else. The node will not start (and -validate-config fails) if any rule below is broken. Production means insecure_development is false.
  • Booleans default to false, numbers to 0, strings to empty when a key is omitted. A number with a minimum must therefore be set explicitly whenever its feature is enabled.
  • Paths: where a rule says absolute, a relative path is an error. state_directory, the policy and registration trust files, the ACME credential file and the OTLP files are converted to absolute paths relative to the working directory.
  • Adapter references must match local/<name>: 9–128 characters in total, <name> made of lowercase letters, digits, ., - and _, not starting or ending with . or -, and never containing ...
  • Profile and exporter identifiers must be 2–128 characters of letters, digits, ., - and _, not starting or ending with . or -, and never containing ...
  • SHA-256 pins are exactly 64 lowercase hexadecimal characters.

After editing, validate offline and then restart the service:

mesh-node-01 (bash)
sudo -u edgepki /usr/local/bin/edgepki-node -validate-config -config /etc/edgepki/config.json
Sectigo Edge bootstrap configuration and trust files validated.
sudo systemctl restart edgepki-node

Example (Linux, as generated by the console)​

Sample values; your package contains your own tenant, node name, API URL and keys.

{
"tenant_id": "acme-corp",
"node_name": "mesh-node-01",
"edge_url": "https://api.sharppki.com",
"listen_address": "127.0.0.1:9443",
"local_api_url": "https://127.0.0.1:9443",
"state_directory": "/var/lib/edgepki",
"enrollment_token_file": "/var/lib/edgepki/enrollment-token",
"tls_certificate_file": "/etc/edgepki/local-api.crt",
"tls_private_key_file": "/etc/edgepki/local-api.key",
"workload_trust_bundle_file": "/etc/edgepki/workload-ca.pem",
"workload_trust_domain": "acme-corp.sharppki.local",
"policy_trust_bundle_file": "/etc/edgepki/policy-trust.json",
"policy_bundle_max_ttl_seconds": 300,
"audit_checkpoint_key_id": "audit-production-2026-01",
"audit_checkpoint_public_key_base64": "<43-character base64url Ed25519 public key>",
"registration_trust_bundle_file": "/etc/edgepki/registration-trust.json",
"registration_grant_max_ttl_seconds": 600,
"acme_external_account_required": true,
"acme_external_account_credentials_file": "/etc/edgepki/acme-eab.json",
"spire_enabled": false,
"node_key_provider": "tpm2",
"tls_client_certificate_file": "/etc/edgepki/edge-client.crt",
"tls_client_private_key_file": "/etc/edgepki/edge-client.key",
"poll_interval_seconds": 10,
"allowed_spiffe_prefixes": ["spiffe://acme-corp.sharppki.local/"],
"trust_event_subscriber_spiffe_prefixes": ["spiffe://acme-corp.sharppki.local/"],
"allowed_dns_suffixes": [],
"max_validity_seconds": 86400,
"cloud_fallback_enabled": true,
"require_pqc_transport": false
}

The Windows package uses C:\ProgramData\Sectigo\Edge\… for every path (written with doubled backslashes inside JSON strings) and sets node_key_provider to windows_cng with windows_cng_provider and windows_cng_key_name.

warning

The installers require the file locations above for signed packages, and -Upgrade/--upgrade revalidates the installed file before replacing the binary. Change only the keys you need to.

Core and connection​

KeyTypeRequiredRules and effect
tenant_idstringYesAt least 3 characters. Must match your workspace and the trust files.
node_namestringYesNon-empty. Must equal the name bound to the enrollment token.
edge_urlstringYesSectigo Edge API origin. Must start with https:// outside development. Signed packages require an HTTPS origin with no path.
listen_addressstringYeshost:port the local TLS API listens on, for example 127.0.0.1:9443.
local_api_urlstringYesURL workloads use to reach this node (advertised in discovery and ACME URLs). Overridden by SECTIGO_EDGE_LOCAL_API_URL.
state_directorystringYesDirectory for identity, key blobs, audit log and adapter state.
poll_interval_secondsintegerYesAt least 1. How often the node polls Sectigo Edge.
require_pqc_transportbooleanNoWhen true, refuse any outbound connection that does not negotiate TLS 1.3 with X25519MLKEM768. Requires an HTTPS edge_url.
cloud_fallback_enabledbooleanNoWhether connectivity-only cloud fallback is configured. Shown as "cloud fallback configured" in the local UI.
enrollment_token_filestringNoPath to the one-time token. Read at start if present; deleted after enrollment.
enrollment_tokenstringNoLegacy inline token. Signed packages forbid it; leave it out. Environment variables take precedence.
insecure_developmentbooleanNoDevelopment only. Relaxes HTTPS, TLS, trust-domain, ACME and key-provider requirements. Never set in production.

Local API and workload trust​

KeyTypeRequiredRules and effect
tls_certificate_filestringYes (production)Server certificate for the local TLS 1.3 API.
tls_private_key_filestringYes (production)Key for the server certificate.
workload_trust_bundle_filestringYes (production)PEM bundle that issues workload (and operator) client certificates. Must contain at least one certificate.
workload_trust_domainstringYes (production)SPIFFE trust domain: lowercase, at most 255 characters, letters, digits, ., -, _.
allowed_spiffe_prefixesstring arrayYes (production)At least one. Each must start with spiffe://<workload_trust_domain>/, end with /, and contain no %, ? or #. Requesters outside these prefixes are refused.
allowed_dns_suffixesstring arrayNoDNS name suffixes workloads may request.
max_validity_secondsintegerYesAt least 300. Upper bound on certificate lifetime enforced locally.
trust_event_subscriber_spiffe_prefixesstring arrayNoIdentities allowed to read the signed trust-event feed (GET /v1/events). Each must be in the trust domain and end with /. Grant only dedicated observers.
local_ui_enabledbooleanNoEnables the read-only local operations UI at /ui/.
local_ui_allowed_spiffe_prefixesstring arrayWhen UI enabledAt least one operator prefix in production; same format rules as allowed_spiffe_prefixes. Use a dedicated operator path.

Outbound connection to Sectigo Edge​

KeyTypeRequiredRules and effect
tls_client_certificate_filestringSigned packagesOrganization-issued client certificate for outbound mTLS. If either client key is set, both are loaded.
tls_client_private_key_filestringSigned packagesKey for the client certificate.
tls_root_ca_filestringNoPEM root(s) used to verify the Sectigo Edge server instead of the system roots. Must contain at least one certificate.

Policy and registration trust​

KeyTypeRequiredRules and effect
policy_trust_bundle_filestringYesPinned policy-signing public keys (sectigo-edge.policy-trust.v1), bound to your tenant.
policy_bundle_max_ttl_secondsintegerYes60–900. Maximum lifetime accepted for a signed policy bundle.
registration_trust_bundle_filestringYesPinned service-registration grant keys (sectigo-edge.registration-trust.v1), bound to your tenant.
registration_grant_max_ttl_secondsintegerYes60–600. Maximum lifetime accepted for a registration grant.

Node key provider​

KeyTypeRequiredRules and effect
node_key_providerstringYes (production)tpm2 (Linux only), windows_cng (Windows only), pkcs11, or software. A missing or unavailable provider stops the node.
allow_software_node_keybooleanNoExplicit exception required to use software outside development. Signed packages reject it.
windows_cng_providerstringNoCNG provider name. Defaults to Microsoft Platform Crypto Provider.
windows_cng_key_namestringWith windows_cngName of the existing, non-exportable ECDSA P-256 key to open.
pkcs11_module_pathstringWith pkcs11Vendor PKCS#11 library.
pkcs11_token_label / pkcs11_token_serialstringOne of themToken selector (mutually exclusive).
pkcs11_key_label / pkcs11_key_id_hexstringOne of themKey selector. The key must be ECDSA P-256.
pkcs11_max_sessionsintegerNoSession pool size (Helm default 8).

The PKCS#11 PIN is never a configuration key: set SHARPPKI_PKCS11_PIN in the service's secret environment.

ACME​

KeyTypeRequiredRules and effect
acme_external_account_requiredbooleanYes (production)Must be true outside development.
acme_external_account_credentials_filestringYes (production)Credential store for External Account Binding. Start with {"version":1,"credentials":[]}. See ACME.

Audit witness and OTLP export​

KeyTypeRequiredRules and effect
audit_checkpoint_key_idstringPairIdentifier of the pinned audit checkpoint key. Must be set together with the public key.
audit_checkpoint_public_key_base64stringPairRaw 32-byte Ed25519 public key, base64url without padding.
otlp_audit_enabledbooleanNoEnables signed audit export over OTLP. Every other otlp_audit_* key must be absent when this is false.
otlp_audit_exporter_idstringWith OTLPIdentifier (for example primary-siem).
otlp_audit_endpointstringWith OTLPExact https://…/v1/logs URL, at most 2048 characters, no credentials, query or fragment.
otlp_audit_trust_bundle_filestringWith OTLPAbsolute path to the collector CA.
otlp_audit_client_certificate_filestringWith OTLPAbsolute path to the client certificate.
otlp_audit_client_private_key_filestringWith OTLPAbsolute path to the client key.
otlp_audit_batch_sizeintegerWith OTLP1–64.
otlp_audit_request_timeout_secondsintegerWith OTLP2–60.
otlp_audit_poll_interval_secondsintegerWith OTLP1–300.

Dependency discovery​

KeyTypeRequiredRules and effect
dependency_discovery_enabledbooleanNoAccepts SDK dependency observations at POST /v1/dependencies/observe. All other dependency keys must be absent when false.
dependency_probesarrayNoUp to 256 explicit active TLS probes (fields below).
dependency_probe_interval_secondsintegerWith probes30–3600. Must be absent (or 0) when there are no probes.
dependency_observation_ttl_secondsintegerWith probesAt least twice the interval, at most 86400.
dependency_probe_timeout_secondsintegerWith probes2–60.

Each entry in dependency_probes:

FieldRules
idUnique identifier (same rules as profile identifiers).
source_endpoint_id, target_endpoint_id3–256 characters, no whitespace; must differ.
addressExact host:port; host is an IP address or lowercase DNS name; port 1–65535.
server_nameLowercase DNS name verified in the server certificate.
channeltls, mtls, grpc, mqtt, database, mcp or a2a.
expected_alpnnone, h2, http/1.1, mqtt, mcp or a2a.
trust_bundle_fileOptional absolute path.
client_certificate_file, client_private_key_fileOptional absolute paths, set together; required when channel is mtls.

SPIRE​

KeyTypeRequiredRules and effect
spire_enabledbooleanNoDirect SPIRE Server Entry API reconciliation. Not allowed on Windows.
spire_server_api_socketstringWith SPIREAbsolute path to the SPIRE Server API Unix socket.
spire_parent_idstringWith SPIREValid SPIFFE ID used as the entries' parent.

See SPIFFE / SPIRE.

Kubernetes CSR signer​

KeyTypeRequiredRules and effect
kubernetes_csr_enabledbooleanNoEnables the custom signer.
kubernetes_adapter_referencestringYeslocal/… reference matching the console.
kubernetes_api_server_urlstringYesMust start with https://.
kubernetes_ca_file, kubernetes_token_filestringYesAbsolute paths.
kubernetes_signer_namestringYesdomain/name; the domain may not be kubernetes.io or end in .kubernetes.io.
kubernetes_managed_labelstringYesOne key=value label selector.
kubernetes_cluster_idstringYesDNS label. spiffe://<trust domain>/kubernetes/<cluster id>/ must be covered by allowed_spiffe_prefixes.
kubernetes_allowed_namespacesstring arrayYesAt least one DNS-label namespace.
kubernetes_allowed_usagesstring arrayYesAny of digital signature, key encipherment, server auth, client auth.
kubernetes_max_requests_per_pollintegerYes1–100.
kubernetes_request_timeout_secondsintegerYes2–30.
kubernetes_lease_namespace, kubernetes_lease_namestringYesDNS labels of the pre-created coordination Lease.
kubernetes_lease_duration_secondsintegerYes15–120.

All "Yes" entries apply only when kubernetes_csr_enabled is true. See Kubernetes CSR.

EST​

KeyTypeRequiredRules and effect
est_enabledbooleanNoEnables the RFC 7030 listener.
est_adapter_referencestringWith ESTlocal/… reference matching the console.
est_ca_certificate_bundle_filestringWith ESTAbsolute path to the public root and intermediates returned by /cacerts.

See EST.

Microsoft ADCS (Windows only)​

KeyTypeRequiredRules and effect
microsoft_adcs_enabledbooleanNoWindows nodes only.
microsoft_adcs_adapter_referencestringYeslocal/… reference matching the console.
microsoft_adcs_ca_configurationstringYesExactly server\CA name (one backslash; in JSON write \\).
microsoft_adcs_templatestringYesCertificate template name.
microsoft_adcs_profile_idstringYesProfile that must match the console.
microsoft_adcs_ca_chain_filestringYesAbsolute path to the public ADCS CA chain.
microsoft_adcs_online_responder_urlstringYesOnline Responder URL, at most 2048 characters.
microsoft_adcs_request_timeout_secondsintegerYes2–120.
microsoft_adcs_recovery_spiffe_idsstring arrayYesAt least one exact SPIFFE ID in workload_trust_domain allowed to run adcs-recover.

See Microsoft ADCS.

NGINX (Linux only)​

KeyTypeRequiredRules and effect
nginx_enabledbooleanNoLinux nodes only.
nginx_adapter_referencestringYeslocal/… reference matching the console.
nginx_profile_idstringYesProfile identifier matching the console.
nginx_binary_pathstringYesAbsolute path to the NGINX executable.
nginx_binary_sha256stringYesSHA-256 pin of that executable.
nginx_configuration_filestringYesAbsolute path to the root configuration.
nginx_managed_directorystringYesAbsolute path where generations are stored.
nginx_bootstrap_certificate_file, nginx_bootstrap_private_key_filestringYesAbsolute paths to the currently served key pair (imported as generation one).
nginx_reload_timeout_secondsintegerYes2–60.
nginx_rollback_window_secondsintegerYes60–86400.

Apache HTTP Server (Linux only)​

Same shape as NGINX with the apache_ prefix: apache_enabled, apache_adapter_reference, apache_profile_id, apache_binary_path, apache_binary_sha256, apache_configuration_file, apache_managed_directory, apache_bootstrap_certificate_file, apache_bootstrap_private_key_file, apache_reload_timeout_seconds (2–60) and apache_rollback_window_seconds (60–86400). All paths absolute. See Apache HTTP Server.

Java PKCS#12​

KeyTypeRequiredRules and effect
java_keystore_enabledbooleanNoWindows and Linux.
java_keystore_adapter_referencestringYeslocal/… reference.
java_keystore_profile_idstringYesProfile identifier.
java_keystore_keytool_path, java_keystore_keytool_sha256stringYesAbsolute path and SHA-256 pin of JDK keytool.
java_keystore_aliasstringYes1–128 characters: letters, digits, ., -, _.
java_keystore_password_filestringYesAbsolute path to the keystore password file.
java_keystore_active_filestringYesAbsolute path of the keystore your application reads.
java_keystore_managed_directorystringYesAbsolute path for generations.
java_keystore_bootstrap_certificate_file, java_keystore_bootstrap_private_key_filestringYesAbsolute paths to the current chain and key.
java_keystore_reload_binary_path, java_keystore_reload_binary_sha256stringYesAbsolute path and pin of the reload executable.
java_keystore_reload_argumentsstring arrayNoUp to 32 fixed arguments, each at most 512 characters, no NUL or line breaks. {keystore} is replaced with the active keystore path.
java_keystore_reload_timeout_secondsintegerYes2–60.
java_keystore_rollback_window_secondsintegerYes60–86400.

HashiCorp Vault KV v2​

KeyTypeRequiredRules and effect
hashicorp_vault_enabledbooleanNoEnables the Vault adapter.
hashicorp_vault_adapter_referencestringYeslocal/… reference.
hashicorp_vault_profile_idstringYesProfile identifier.
hashicorp_vault_addressstringYesExact HTTPS origin (no path, query, fragment or credentials). Loopback HTTP is allowed only in development.
hashicorp_vault_namespacestringNoVault Enterprise namespace.
hashicorp_vault_token_filestringYesAbsolute path to the token file.
hashicorp_vault_ca_certificate_filestringNoAbsolute path to the Vault server CA.
hashicorp_vault_client_certificate_file, hashicorp_vault_client_private_key_filestringNoAbsolute paths, set together, for Vault TLS authentication.
hashicorp_vault_kv_mountstringYesSingle path segment.
hashicorp_vault_kv_base_pathstringYesRelative path; segments of letters, digits, -, _, .; no empty, . or .. segments; no leading or trailing /; at most 512 characters.
hashicorp_vault_managed_directorystringYesAbsolute path for local state.
hashicorp_vault_bootstrap_certificate_file, hashicorp_vault_bootstrap_private_key_filestringYesAbsolute paths to the first generation's chain and key.
hashicorp_vault_request_timeout_secondsintegerYes2–60.
hashicorp_vault_rollback_window_secondsintegerYes60–86400.
hashicorp_vault_reload_binary_pathstringNoAbsolute path to an optional reload executable.
hashicorp_vault_reload_binary_sha256stringWith reloadSHA-256 pin.
hashicorp_vault_reload_argumentsstring arrayNoUp to 32 fixed arguments (512 characters each). {certificate} is substituted.
hashicorp_vault_reload_timeout_secondsintegerWith reload2–60.

Environment variables​

VariableEffect
SECTIGO_EDGE_ENROLLMENT_TOKENOne-time enrollment token (takes precedence over enrollment_token_file). The legacy names SHARPPKI_ENROLLMENT_TOKEN and EDGEPKI_ENROLLMENT_TOKEN are also read. Used by the Helm chart.
SECTIGO_EDGE_LOCAL_API_URLOverrides local_api_url. The Helm chart sets it per pod.
SHARPPKI_PKCS11_PINPIN for the PKCS#11 token.