Skip to content

Local MQTT stack

This deployment follows the AWS pattern for connecting client devices: Client device auth
aws.greengrass.clientdevices.Auth — Greengrass component that decides which client device certificates may connect to the local MQTT broker.
, Moquette
aws.greengrass.clientdevices.mqtt.Moquette — local MQTT broker on the core. Not Mosquitto; client devices connect here over mTLS.
, MQTT bridge
aws.greengrass.clientdevices.mqtt.Bridge — maps topics between LocalMqtt (Moquette), Pubsub (components), and IotCore.
, and IP detector
aws.greengrass.clientdevices.IPDetector — publishes the core's LAN address so discovery returns a reachable host for Moquette.
.

Steps on this page:

  1. 1Prepare deployment docsed template → JSON
  2. 2Create deploymentcreate-deployment
  3. 3Verify RUNNINGlist-installed-components
One Thing-group deployment installs Auth, Moquette, Bridge, and IPDetector.SUCCEEDED on the core = all four RUNNING.

Substitute the Thing group ARN and client Auth prefix into the repo template:

Terminal window
CORE_THING_GROUP_ARN=$(aws iot describe-thing-group \
--thing-group-name "$CORE_THING_GROUP" \
--query thingGroupArn --output text)
echo "$CORE_THING_GROUP_ARN"
sed -e "s|TARGET_THING_GROUP_ARN|${CORE_THING_GROUP_ARN}|g" \
-e "s|CLIENT_THING_PREFIX|${CLIENT_THING_PREFIX}|g" \
artifacts/deployments/client-device-support.json \
> /tmp/client-device-support.json
arn:aws:iot:ap-southeast-2:123456789012:thinggroup/gg-edge-wt-dev-cores

Optional — list public component versions

Section titled “Optional — list public component versions”

Pin newer versions in /tmp/client-device-support.json if you choose:

Terminal window
aws greengrassv2 list-components --scope PUBLIC \
--query "components[?contains(componentName, 'clientdevices') || componentName=='aws.greengrass.Nucleus'].[componentName,latestVersion.componentVersion]" \
--output table
----------------------------------------------------------
| ListComponents |
+----------------------------------------------+---------+
| aws.greengrass.Nucleus | 2.18.3 |
| aws.greengrass.clientdevices.Auth | 2.5.7 |
| aws.greengrass.clientdevices.mqtt.Moquette | 2.3.7 |
| aws.greengrass.clientdevices.mqtt.Bridge | 2.3.4 |
| aws.greengrass.clientdevices.IPDetector | 2.2.5 |
+----------------------------------------------+---------+

Repo pins in artifacts/deployments/client-device-support.json match this evidence pass (Nucleus 2.18.3 — same as the installed core).

Auth selectionRule is thingName: <CLIENT_THING_PREFIX>* so numbered clients (…-esp32-1, …-esp32-2, …-esp32-3, …) match. One board is enough for this deployment to succeed.

The MQTT bridge maps the two closed-loop topics across Pubsub
Greengrass interprocess pub/sub — in-process messaging between components on the core (the closed-loop component uses it for sensor/actuator topics).
, LocalMqtt, and IoT Core
AWS IoT Core — cloud MQTT and device identity service. Client devices use it for discovery; the MQTT bridge forwards zone topics here, where IoT rules route them to other AWS services.
:

Pubsublocal components
gg-edge/sensor←gg-edge/actuator→
LocalMqttMoquette brokerMQTT bridge
gg-edge/sensor→gg-edge/actuator→
IoT Corecloud mirror
  • sensor: LocalMqtt → Pubsub (to the component).
  • actuator: Pubsub → LocalMqtt (to the client).
  • Both topics also mirror LocalMqtt → IoT Core (one-way).
Terminal window
aws greengrassv2 create-deployment \
--cli-input-json file:///tmp/client-device-support.json
{
"deploymentId": "01234567-89ab-cdef-0123-456789abcdef"
}
Terminal window
aws greengrassv2 list-effective-deployments \
--core-device-thing-name "$CORE_THING_NAME" \
--output table
… coreDeviceExecutionStatus | SUCCEEDED …
… deploymentName | gg-edge-client-device-support …

(coreDeviceExecutionStatus is SUCCEEDED, not COMPLETED.)

Manual Nucleus install does not include greengrass-cli
Greengrass CLI — local tool under /greengrass/v2/bin/greengrass-cli for listing components and creating local deployments on the core.
until you deploy it. Use the cloud API:

Terminal window
aws greengrassv2 list-installed-components \
--core-device-thing-name "$CORE_THING_NAME" \
--output table
… Auth 2.5.7 RUNNING …
… IPDetector 2.2.5 RUNNING …
… Bridge 2.3.4 RUNNING …
… Moquette 2.3.7 RUNNING …

Next: Associate zones.