Architecture
This page is the map of the finished lab. Read it before Deploy from the cloud; the pages after that only build the pieces shown here.
RGB: green = button loop · blue = cloud command · red = edge model.
Zones never talk to AWS. They use mTLS MQTT to
Moquette
aws.greengrass.clientdevices.mqtt.Moquette — local MQTT broker on the core. Not Mosquitto; client devices connect here over mTLS.. The
MQTT bridge
aws.greengrass.clientdevices.mqtt.Bridge — maps topics between LocalMqtt (Moquette), Pubsub (components), and IotCore. is the only process that
crosses LocalMqtt ↔ Pubsub ↔ IoT Core.
Overall architecture
Section titled “Overall architecture”ESP32 → Greengrass core → IoT Core → rules → S3 · DynamoDB · CloudWatch, then the control and ML return paths.
Topic-level interconnection
Section titled “Topic-level interconnection”Every bridge mapping, rule artifact, and component pub/sub.
1 · On the core (every MQTT hop)
- pub
gg-edge/sensorBOOT press/release - pub
gg-edge/telemetry/<thing>every 10 s - sub
gg-edge/actuator/<thing>RGB green · blue · red
Bridge routes from greenhouse-cloud.json (reset /mqttTopicMapping then merge):
| Mapping | Topic | Source → target | Consumer |
|---|---|---|---|
SensorLocalToPubsub | gg-edge/sensor | LocalMqtt → Pubsub | GgEdgeLoop (button) |
SensorLocalToIotCore | gg-edge/sensor | LocalMqtt → IotCore | console optional |
TelemetryLocalToPubsub | gg-edge/telemetry/+ | LocalMqtt → Pubsub | ZoneAnomaly |
TelemetryLocalToIotCore | gg-edge/telemetry/+ | LocalMqtt → IotCore | rules S3 · DDB · CW |
ActuatorPubsubToLocal | gg-edge/actuator/+ | Pubsub → LocalMqtt | RGB on zone |
ActuatorPubsubToIotCore | gg-edge/actuator/+ | Pubsub → IotCore | rule actuator_ddb |
CommandIotCoreToPubsub | gg-edge/cloud/command/+ | IotCore → Pubsub | Lambda / manual |
AckPubsubToIotCore | gg-edge/cloud/ack/+ | Pubsub → IotCore | rule ack_ddb |
InferencePubsubToIotCore | gg-edge/inference/+ | Pubsub → IotCore | rule inference_ddb |
2 · Data up (IoT rules)
gg-edge/telemetry/+telemetry-to-s3S3 PutObjecttelemetry/thing=…/dt=…/ts.jsongg-edge/telemetry/+telemetry-to-dynamodbDDB PutItemkind=telemetrygg-edge/telemetry/+telemetry-to-cloudwatchPutMetricDataChipTempC-<thing>gg-edge/actuator/+actuator-to-dynamodbDDB PutItemkind=actuatorgg-edge/cloud/ack/+ack-to-dynamodbDDB PutItemkind=cloud-ackgg-edge/inference/+inference-to-dynamodbDDB PutItemkind=inference3 · Control down (blue RGB)
metric
ChipTempC-<thing>→ alarm ALARM/OKSNS topic (email + Lambda)
Lambda publishes
gg-edge/cloud/command/<thing>blueBridge
CommandIotCoreToPubsub→ GgEdgeLoop →actuator/<thing>GgEdgeLoop ack →
gg-edge/cloud/ack/<thing>→ rule → DynamoDB
4 · Edge inference (red RGB)
inference/+~20 s · two-sidedkind=actuator records source.Software handover (local → cloud)
Section titled “Software handover (local → cloud)”Act 1 installed with greengrass-cli
Greengrass CLI — local tool under /greengrass/v2/bin/greengrass-cli for listing components and creating local deployments on the core..
Act 2 moves that same stack to a Thing-group deployment from S3 and turns on
LogManager.
greengrass-cli local installUpload artifact to S3
Register component version (1.1.0)
Thing-group deployment replaces the root set
- The button loop keeps working — only the install source moves from local disk to S3.
- A Thing-group deploy replaces the whole root set, so the stack ships complete (client-device components, Cli, LogManager, GgEdgeLoop).
- LogManager uploads component logs to CloudWatch every 60 s.
Component subscriptions
Section titled “Component subscriptions”| Component | Subscribes | Publishes |
|---|---|---|
|
|
|
| gg-edge/telemetry/+ |
|
Control down — ordered hops
Section titled “Control down — ordered hops”The cloud command (blue RGB) path, in order:
- 1
CloudWatch alarmChipTempC metric breaches → ALARM
- 2
SNS topicfans out to email + Lambda
- 3
Lambdapublishes the command (blue)
gg-edge/cloud/command/<thing> - 4
IoT Core → BridgeCommandIotCoreToPubsub → Pubsub
- 5
GgEdgeLoopdrives the actuator
gg-edge/actuator/<thing> - 6
ESP32-S3 zoneRGB turns blue
- 7
DynamoDBack rule records the command
gg-edge/cloud/ack/<thing>
gg-edge/cloud/command/<thing> — same bridge mapping and GgEdgeLoop handling.Who owns the RGB
Section titled “Who owns the RGB”| Color | Publisher | Topic path | Page |
|---|---|---|---|
| green |
| sensor → Pubsub → actuator → LocalMqtt | Prove the LAN loop |
| blue |
| IoT Core → command → Pubsub → actuator | Cloud commands |
| red | ZoneAnomaly | telemetry → Pubsub → actuator | Edge inference |
Last message wins on the wire. DynamoDB kind=actuator records source so you
can see which layer acted last.
Next: Deploy from the cloud.