Local MQTT stack
This deployment follows the AWS pattern for
connecting client devices:
Client device auth
aws.greengrass.clientdevices.Auth — Greengrass component that decides which client device certificates may connect to the local MQTT broker.,
Moquette
aws.greengrass.clientdevices.mqtt.Moquette — local MQTT broker on the core. Not Mosquitto; client devices connect here over mTLS.,
MQTT bridge
aws.greengrass.clientdevices.mqtt.Bridge — maps topics between LocalMqtt (Moquette), Pubsub (components), and IotCore., and
IP detector
aws.greengrass.clientdevices.IPDetector — publishes the core's LAN address so discovery returns a reachable host for Moquette..
Steps on this page:
- 1
Prepare deployment doc
sed template → JSON - 2
Create deployment
create-deployment - 3
Verify RUNNING
list-installed-components
SUCCEEDED on the core = all four RUNNING.1. Prepare the deployment document
Section titled “1. Prepare the deployment document”Render the deployment JSON
Section titled “Render the deployment JSON”Substitute the Thing group ARN and client Auth prefix into the repo template:
CORE_THING_GROUP_ARN=$(aws iot describe-thing-group \ --thing-group-name "$CORE_THING_GROUP" \ --query thingGroupArn --output text)echo "$CORE_THING_GROUP_ARN"sed -e "s|TARGET_THING_GROUP_ARN|${CORE_THING_GROUP_ARN}|g" \ -e "s|CLIENT_THING_PREFIX|${CLIENT_THING_PREFIX}|g" \ artifacts/deployments/client-device-support.json \ > /tmp/client-device-support.jsonarn:aws:iot:ap-southeast-2:123456789012:thinggroup/gg-edge-wt-dev-coresOptional — list public component versions
Section titled “Optional — list public component versions”Pin newer versions in /tmp/client-device-support.json if you choose:
aws greengrassv2 list-components --scope PUBLIC \ --query "components[?contains(componentName, 'clientdevices') || componentName=='aws.greengrass.Nucleus'].[componentName,latestVersion.componentVersion]" \ --output table----------------------------------------------------------| ListComponents |+----------------------------------------------+---------+| aws.greengrass.Nucleus | 2.18.3 || aws.greengrass.clientdevices.Auth | 2.5.7 || aws.greengrass.clientdevices.mqtt.Moquette | 2.3.7 || aws.greengrass.clientdevices.mqtt.Bridge | 2.3.4 || aws.greengrass.clientdevices.IPDetector | 2.2.5 |+----------------------------------------------+---------+Repo pins in artifacts/deployments/client-device-support.json match this evidence
pass (Nucleus 2.18.3 — same as the installed core).
Auth selectionRule is thingName: <CLIENT_THING_PREFIX>* so numbered clients
(…-esp32-1, …-esp32-2, …-esp32-3, …) match. One board is enough for this
deployment to succeed.
The MQTT bridge maps the two closed-loop topics across
Pubsub
Greengrass interprocess pub/sub — in-process messaging between components on the core (the closed-loop component uses it for sensor/actuator topics)., LocalMqtt, and
IoT Core
AWS IoT Core — cloud MQTT and device identity service. Client devices use it for discovery; the MQTT bridge forwards zone topics here, where IoT rules route them to other AWS services.:
- sensor: LocalMqtt → Pubsub (to the component).
- actuator: Pubsub → LocalMqtt (to the client).
- Both topics also mirror LocalMqtt → IoT Core (one-way).
2. Create the deployment
Section titled “2. Create the deployment”aws greengrassv2 create-deployment \ --cli-input-json file:///tmp/client-device-support.json{ "deploymentId": "01234567-89ab-cdef-0123-456789abcdef"}3. Wait and verify
Section titled “3. Wait and verify”Check effective deployments
Section titled “Check effective deployments”aws greengrassv2 list-effective-deployments \ --core-device-thing-name "$CORE_THING_NAME" \ --output table… coreDeviceExecutionStatus | SUCCEEDED …… deploymentName | gg-edge-client-device-support …(coreDeviceExecutionStatus is SUCCEEDED, not COMPLETED.)
List installed components (workstation)
Section titled “List installed components (workstation)”Manual Nucleus install does not include
greengrass-cli
Greengrass CLI — local tool under /greengrass/v2/bin/greengrass-cli for listing components and creating local deployments on the core. until you deploy it.
Use the cloud API:
aws greengrassv2 list-installed-components \ --core-device-thing-name "$CORE_THING_NAME" \ --output table… Auth 2.5.7 RUNNING …… IPDetector 2.2.5 RUNNING …… Bridge 2.3.4 RUNNING …… Moquette 2.3.7 RUNNING …Next: Associate zones.