Skip to content

Associate zones

Client devices
Greengrass client device — an IoT Thing (here the ESP32-S3) that discovers a core and uses local MQTT. It does not run Nucleus.
can use discovery
Greengrass discovery API — HTTPS call with the client certificate that returns associated core connectivity (host, port, CA) for local MQTT.
only for cores you associate via BatchAssociateClientDeviceWithCoreDevice.

ESP32-S3client Thing + cert
→
IoT Coreassociate · discovery :8443
←
NUC coreMoquette :8883
③ LAN mTLS to the host:port from discovery
  • Associate the client Thing with the core (cloud API).
  • Discover: client cert → :8443 returns the core's HostAddress + 8883.
  • Connect: client then talks local MQTT to Moquette on the LAN.
Terminal window
aws greengrassv2 batch-associate-client-device-with-core-device \
--core-device-thing-name "$CORE_THING_NAME" \
--entries thingName="$CLIENT_THING_NAME"
{
"associatedClientDevices": [
{
"thingName": "gg-edge-wt-dev-esp32-1"
}
],
"errorEntries": []
}
Terminal window
aws greengrassv2 list-client-devices-associated-with-core-device \
--core-device-thing-name "$CORE_THING_NAME"
{
"associatedClientDevices": [
{
"thingName": "gg-edge-wt-dev-esp32-1",
"associationTimestamp": "2026-10-04T10:00:00.000000+00:00"
}
]
}

Only if you created $CLIENT_THING_NAME_2 (and optionally _3) on Identities:

Terminal window
aws greengrassv2 batch-associate-client-device-with-core-device \
--core-device-thing-name "$CORE_THING_NAME" \
--entries thingName="$CLIENT_THING_NAME_2"
# Third zone:
# aws greengrassv2 batch-associate-client-device-with-core-device \
# --core-device-thing-name "$CORE_THING_NAME" \
# --entries thingName="$CLIENT_THING_NAME_3"
{
"associatedClientDevices": [
{
"thingName": "gg-edge-wt-dev-esp32-2"
}
],
"errorEntries": []
}

Use the client certificate (not the core cert):

Terminal window
GG_DATA_ENDPOINT="greengrass-ats.iot.${AWS_REGION}.amazonaws.com"
curl --cert "$CLIENT_CERTS_DIR/device.pem.crt" \
--key "$CLIENT_CERTS_DIR/private.pem.key" \
--cacert "$CLIENT_CERTS_DIR/AmazonRootCA1.pem" \
"https://${GG_DATA_ENDPOINT}:8443/greengrass/discover/thing/${CLIENT_THING_NAME}" \
| jq .
{
"GGGroups": [
{
"GGGroupId": "…",
"Cores": [
{
"thingName": "gg-edge-wt-dev-core",
"Connectivity": [
{
"HostAddress": "192.168.1.50",
"PortNumber": 8883
}
]
}
]
}
]
}

You should see connectivity info for $CORE_THING_NAME (host / port for Moquette
aws.greengrass.clientdevices.mqtt.Moquette — local MQTT broker on the core. Not Mosquitto; client devices connect here over mTLS.
, typically 8883). If the list is empty, wait for IP detector
aws.greengrass.clientdevices.IPDetector — publishes the core's LAN address so discovery returns a reachable host for Moquette.
and re-check association.

Extra zones (optional): same curl, swap in $CLIENT_CERTS_DIR_2 / $CLIENT_THING_NAME_2 (and _3 if used).

Next: Loop component.