how it works
From a token you mint to a gateway holding a certificate and a live stream to the control plane.
A cluster mints enrolment tokens. A token is single-use and time-bounded: an hour by default, five minutes at the shortest and a day at the longest. You choose the lifetime when you mint it, and a value outside those bounds is clamped rather than rejected, so a slightly wrong number does not cost you the mint.
The platform stores only a SHA-256 hash of the token. Nobody can read your token back out of the control plane, including us. Mint it when you are ready to boot the appliance, and revoke it if you do not use it.
On first boot the appliance generates a key pair and calls the control plane with the token and a certificate signing request. This is the one call it can make without already holding a certificate, and the control plane exempts exactly that call from its device authentication.
The claim is a single atomic update. Two gateways racing the same token means one succeeds and one is refused — there is no window where both proceed.
The control plane signs the request with the device authority and stores the gateway against that certificate identity. From here the gateway authenticates as itself and the token is spent.
The gateway holds one long-lived bidirectional connection to the control plane. Configuration arrives on it, acknowledgements and heartbeats go back on it.
A failed enrolment does not burn the token
The claim and the gateway record are written in one transaction. If anything after the claim fails, the whole thing rolls back and the token stays usable — rather than leaving you holding a spent token and no gateway.
The gateway heartbeats on the stream. The control plane advertises the interval when the stream opens, thirty seconds unless your configuration pins something else, and keeps a fast liveness view separate from the durable record so that a heartbeat does not become a database write every time.
Commands issued through the API are drained onto the stream on a ten-second poll. Configuration changes are pushed as they happen rather than polled.