Install Nucleus
Progress checklist
You install Nucleus
Greengrass Nucleus — the edge runtime on the core device. Installs components, talks to AWS, and hosts the local client-device stack. with manual provisioning
on the NUC
Intel NUC6CAY — compact x86 PC used as the Greengrass core in this lab (spare unit on hand; any quiet Ubuntu 24.04 x86 host works). — every cloud resource already exists
from Identities, and the host OS is ready from
Prepare the core.
Official path:
Install with manual resource provisioning
(--init-config + config.yaml, not interactive prompts).
What moves where:
walkthrough.env/greengrass/v2/certs/--init-configNucleus 2.18.xget-core-device- Workstation only ships certs + config over SSH.
- NUC runs the install; no AWS CLI on it.
- Nucleus ↔ IoT Core over mTLS.
- Verify HEALTHY with
get-core-device.
Steps on this page:
- 1
Copy core certsworkstation
- 2
Host packagesNUC
- 3
Place certificatesNUC
- 4
Download installerNUC
- 5
Endpoints + config.yamlNUC
- 6
Install (manual provision)NUC
- 7
Verify HEALTHYNUC + workstation
1. Copy core certificates to the NUC
Section titled “1. Copy core certificates to the NUC”From the workstation (repo root, after Identities):
set -a && source config/walkthrough.env && set +assh "${NUC_USER}@${NUC_HOST}" 'mkdir -p ~/gg-edge-core-certs'scp "$CORE_CERTS_DIR/device.pem.crt" \ "$CORE_CERTS_DIR/private.pem.key" \ "$CORE_CERTS_DIR/AmazonRootCA1.pem" \ "${NUC_USER}@${NUC_HOST}:~/gg-edge-core-certs/"device.pem.crt 100%private.pem.key 100%AmazonRootCA1.pem 100%2. Host packages (on the NUC)
Section titled “2. Host packages (on the NUC)”SSH in, then install Java for Nucleus (AWS requires 8+; this lab uses OpenJDK
21) and Ubuntu’s Python 3.12 for closed-loop components (awsiotsdk).
Same default interpreter as the workstation — no deadsnakes PPA.
SSH to the NUC
Section titled “SSH to the NUC”ssh "${NUC_USER}@${NUC_HOST}"… login on the NUC …Install OpenJDK and Python
Section titled “Install OpenJDK and Python”sudo apt-get updatesudo apt-get install -y openjdk-21-jdk-headless python3 python3-pip curl unzipjava -versionpython3 --versionopenjdk version "21.0.12.1" 2026-08-18OpenJDK Runtime Environment (build 21.0.12.1+1-1-24.04.4-Ubuntu)OpenJDK 64-Bit Server VM (build 21.0.12.1+1-1-24.04.4-Ubuntu, mixed mode, sharing)Python 3.12.3Install AWS IoT Device SDK for Python (IPC)
Section titled “Install AWS IoT Device SDK for Python (IPC)”Loop components import awsiot.greengrasscoreipc. Install system-wide so
ggc_user can import it (Ubuntu 24.04 needs --break-system-packages for
PEP 668):
sudo python3 -m pip install --break-system-packages awsiotsdkpython3 -c "import awsiot.greengrasscoreipc; print('ok')"… Successfully installed awsiotsdk-…okSee
Linux device setup
and
interprocess communication
in the AWS docs. The installer can create ggc_user / ggc_group when you pass
--component-default-user.
3. Place certificates (on the NUC)
Section titled “3. Place certificates (on the NUC)”sudo mkdir -p /greengrass/v2/certssudo chmod 755 /greengrasssudo cp ~/gg-edge-core-certs/device.pem.crt \ ~/gg-edge-core-certs/private.pem.key \ ~/gg-edge-core-certs/AmazonRootCA1.pem \ /greengrass/v2/certs/sudo chmod 644 /greengrass/v2/certs/device.pem.crt /greengrass/v2/certs/AmazonRootCA1.pemsudo chmod 600 /greengrass/v2/certs/private.pem.key(no output)4. Download the installer (on the NUC)
Section titled “4. Download the installer (on the NUC)”curl -s https://d2s8p88vqu9w66.cloudfront.net/releases/greengrass-nucleus-latest.zip \ -o /tmp/greengrass-nucleus-latest.ziprm -rf /tmp/GreengrassInstallerunzip -o /tmp/greengrass-nucleus-latest.zip -d /tmp/GreengrassInstallerjava -jar /tmp/GreengrassInstaller/lib/Greengrass.jar --versionArchive: /tmp/greengrass-nucleus-latest.zip …AWS Greengrass v2.18.3Record that version — you need it in config.yaml next.
Client devices
Greengrass client device — an IoT Thing (here the ESP32-S3) that discovers a core and uses local MQTT. It does not run Nucleus. need Nucleus 2.2.0+;
this evidence pass used 2.18.3.
5. Endpoints and config.yaml
Section titled “5. Endpoints and config.yaml”Look up credentials endpoint
Section titled “Look up credentials endpoint”On the workstation (has AWS CLI); keep your data endpoint from
walkthrough.env:
aws iot describe-endpoint --endpoint-type iot:CredentialProvider \ --query endpointAddress --output textexample123abc.credentials.iot.ap-southeast-2.amazonaws.comWrite config.yaml on the NUC
Section titled “Write config.yaml on the NUC”Create /tmp/GreengrassInstaller/config.yaml (use your real endpoints and thing
name — placeholders below):
cat >/tmp/GreengrassInstaller/config.yaml <<'EOF'---system: certificateFilePath: "/greengrass/v2/certs/device.pem.crt" privateKeyPath: "/greengrass/v2/certs/private.pem.key" rootCaPath: "/greengrass/v2/certs/AmazonRootCA1.pem" rootpath: "/greengrass/v2" thingName: "gg-edge-wt-dev-core"services: aws.greengrass.Nucleus: componentType: "NUCLEUS" version: "2.18.3" configuration: awsRegion: "ap-southeast-2" iotRoleAlias: "gg-edge-wt-dev-token-alias" iotDataEndpoint: "example123abc-ats.iot.ap-southeast-2.amazonaws.com" iotCredEndpoint: "example123abc.credentials.iot.ap-southeast-2.amazonaws.com"EOF(no output)Replace version with the java -jar … --version value, and both endpoints with
your account’s values from walkthrough.env / the CredentialProvider lookup.
The role alias is the token exchange
IoT role alias + IAM role — lets Nucleus exchange its device certificate for temporary AWS credentials on the core.
alias from the cloud page.
6. Install with manual provisioning
Section titled “6. Install with manual provisioning”sudo -E java -Droot="/greengrass/v2" -Dlog.store=FILE \ -jar /tmp/GreengrassInstaller/lib/Greengrass.jar \ --init-config /tmp/GreengrassInstaller/config.yaml \ --component-default-user ggc_user:ggc_group \ --setup-system-service trueCreating user ggc_userggc_user createdCreating group ggc_groupggc_group createdAdded ggc_user to ggc_groupSuccessfully set up Nucleus as a system service7. Verify
Section titled “7. Verify”Check systemd and effective config (NUC)
Section titled “Check systemd and effective config (NUC)”sudo systemctl status greengrass.service --no-pagersudo grep -E 'thingName|version:' /greengrass/v2/config/effectiveConfig.yaml | head -10● greengrass.service - Greengrass Core Active: active (running) …… thingName: "gg-edge-wt-dev-core" version: "2.18.3"Confirm IoT Core connect in logs (NUC)
Section titled “Confirm IoT Core connect in logs (NUC)”sudo grep 'Successfully connected to AWS IoT Core' /greengrass/v2/logs/greengrass.log | tail -1… Successfully connected to AWS IoT Core. {clientId=gg-edge-wt-dev-core, …}List HEALTHY cores (workstation)
Section titled “List HEALTHY cores (workstation)”aws greengrassv2 list-core-devices --status HEALTHY{ "coreDevices": [ { "coreDeviceThingName": "gg-edge-wt-dev-core", "status": "HEALTHY", "platform": "linux", "architecture": "amd64", … } ]}Get this core device (workstation)
Section titled “Get this core device (workstation)”aws greengrassv2 get-core-device --core-device-thing-name "$CORE_THING_NAME"{ "coreDeviceThingName": "gg-edge-wt-dev-core", "coreVersion": "2.18.3", "status": "HEALTHY", "platform": "linux", "architecture": "amd64", …}Next: Local MQTT stack.