Uninstall
Removing a Mesh Node has two parts: retiring it from the work it does for your workspace, and removing the software and (optionally) its data from the host.
The state directory holds the node's identity, its TPM-wrapped or provider key references, the signed audit log, ACME accounts and rotation generations. Once deleted, the node cannot be recovered — a reinstall enrolls as a new node. Back up the state directory first if you may need its audit history (Backup and recovery).
1. Retire the node from your workspace
- Keep quorum. Under ConsoleMesh nodes, make sure the remaining healthy nodes still satisfy the approval quorum without this one.
- Move integrations. In ConsoleIntegrations, open each integration this node is assigned to, clear the node under Target Mesh Nodes (assign a replacement if needed) and select Save desired state. The node receives a withdrawal for each integration and stops serving it immediately.
- Let rotations finish. Wait until no rotation for this node is pending under ConsoleRotation.
- Move ACME clients. ACME accounts live only on this node. Point clients at another node's directory and create new accounts there with new external-account credentials (ACME).
2. Remove the software
- Linux
- Windows
- Kubernetes
There is no separate uninstall script for Linux. Reverse what the installer created:
sudo systemctl disable --now edgepki-node
Removed "/etc/systemd/system/multi-user.target.wants/edgepki-node.service".
sudo rm /etc/systemd/system/edgepki-node.service /usr/local/bin/edgepki-node
sudo systemctl daemon-reload
To also remove all configuration, customer-held material and node state permanently:
sudo rm -rf /etc/edgepki /var/lib/edgepki
sudo userdel edgepki
Use uninstall-node-windows.ps1 from the release, in an elevated session. It stops and deletes the SectigoEdgeMeshNode service and removes C:\Program Files\Sectigo\Edge. Data in C:\ProgramData\Sectigo\Edge is kept unless you add -RemoveData. -WhatIf shows what would be removed.
.\uninstall-node-windows.ps1
Service removed. Data was preserved unless -RemoveData was specified.
To remove the node identity, keys, certificates and audit data as well:
.\uninstall-node-windows.ps1 -RemoveData
Service removed. Data was preserved unless -RemoveData was specified.
If the node used a Platform Crypto Provider key that you provisioned for it, delete that key with your usual key-management tooling once you no longer need the node identity.
helm uninstall mesh --namespace edgepki
release "mesh" uninstalled
Helm does not delete the StatefulSet's persistent volume claims or the Secrets you created. Delete them to remove node state and credentials permanently:
kubectl -n edgepki delete pvc -l app.kubernetes.io/instance=mesh
kubectl -n edgepki delete secret edgepki-node-credentials edgepki-workload-trust \
edgepki-policy-trust edgepki-registration-trust edgepki-acme-eab
If the PVCs do not carry the release labels in your cluster, delete them by name (state-mesh-edgepki-node-0, -1, -2, …).
3. After removal
- The node stops polling and reporting, and its status under ConsoleMesh nodes changes accordingly. The console currently has no action to delete an enrolled node record.
- Revoke certificates that were issued for workloads on this host if they are no longer needed (Revocation).
- Delete leftover copies of the bootstrap package, the release directory and the
node-materialdirectory from any machine used during installation.