Skip to main content

Uninstall

Removing a Mesh Node has two parts: retiring it from the work it does for your workspace, and removing the software and (optionally) its data from the host.

Deleting node data is irreversible

The state directory holds the node's identity, its TPM-wrapped or provider key references, the signed audit log, ACME accounts and rotation generations. Once deleted, the node cannot be recovered — a reinstall enrolls as a new node. Back up the state directory first if you may need its audit history (Backup and recovery).

1. Retire the node from your workspace​

  1. Keep quorum. Under ConsoleMesh nodes, make sure the remaining healthy nodes still satisfy the approval quorum without this one.
  2. Move integrations. In ConsoleIntegrations, open each integration this node is assigned to, clear the node under Target Mesh Nodes (assign a replacement if needed) and select Save desired state. The node receives a withdrawal for each integration and stops serving it immediately.
  3. Let rotations finish. Wait until no rotation for this node is pending under ConsoleRotation.
  4. Move ACME clients. ACME accounts live only on this node. Point clients at another node's directory and create new accounts there with new external-account credentials (ACME).

2. Remove the software​

There is no separate uninstall script for Linux. Reverse what the installer created:

mesh-node-01 (bash)
sudo systemctl disable --now edgepki-node
Removed "/etc/systemd/system/multi-user.target.wants/edgepki-node.service".
sudo rm /etc/systemd/system/edgepki-node.service /usr/local/bin/edgepki-node
sudo systemctl daemon-reload

To also remove all configuration, customer-held material and node state permanently:

mesh-node-01 (bash)
sudo rm -rf /etc/edgepki /var/lib/edgepki
sudo userdel edgepki

3. After removal​

  • The node stops polling and reporting, and its status under ConsoleMesh nodes changes accordingly. The console currently has no action to delete an enrolled node record.
  • Revoke certificates that were issued for workloads on this host if they are no longer needed (Revocation).
  • Delete leftover copies of the bootstrap package, the release directory and the node-material directory from any machine used during installation.