Prerequisites
Progress checklist
Before cloud steps, skim Concepts and Why Greengrass? if the hub vs direct-IoT choice is still fuzzy.
Tools and access
Section titled “Tools and access”Finish Tooling first. Confirm access here before cloud steps.
| Requirement | Detail |
|---|---|
AWS CLI | latest — |
| jq | 1.6+ — cert JSON |
| Python | 3.12 — Ubuntu 24.04 default on workstation (ESP-IDF) and NUC (components); see Tooling |
| ESP-IDF | ≥ 5.1 (verified 5.3.2) — ESP32-S3 |
| Profile | Named profile with IoT / IAM / Greengrass permissions (example:
|
| Region | ap-southeast-2 |
| Mutation gate |
|
| NUC6CAY Intel NUC6CAY — compact x86 PC used as the Greengrass core in this lab (spare unit on hand; any quiet Ubuntu 24.04 x86 host works). | Hardware on hand — Ubuntu Server via the Ubuntu Server walkthrough ; lab names in Prepare the core |
| ESP32-S3 Espressif ESP32-S3 — Wi‑Fi microcontroller used here as the Greengrass client device (not a second core). | USB flash; Wi‑Fi to the NUC’s LAN |
Confirm profile
Section titled “Confirm profile”export AWS_PROFILE=labexport AWS_REGION=ap-southeast-2aws sts get-caller-identityaws greengrassv2 help >/dev/null && echo greengrassv2_ok{ "UserId": "AROAEXAMPLE:you", "Account": "123456789012", "Arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_…/you"}greengrassv2_okMutation gate
Section titled “Mutation gate”Agents authoring this repo refuse mutating AWS CLI unless
GG_EDGE_ALLOW_AWS=1 is set. You run the walkthrough commands in your own
shell; the gate is for agent sessions. Read-only describe / list / get /
sts stay allowed without it.
Opt in for agent mutations
Section titled “Opt in for agent mutations”export GG_EDGE_ALLOW_AWS=1(no output)Bill of materials
Section titled “Bill of materials”| Part | Role |
|---|---|
| Intel NUC6CAY (spare unit on the shelf) | Greengrass core |
| ESP32-S3 DevKit (e.g. DevKitC-1) | Greengrass client |
| Momentary button (or onboard BOOT) | Sensor input — GPIO 0 on DevKitC-1 |
| Onboard RGB (DevKitC-1) | Actuator — green = on (GPIO 48 default; 38 on DevKitC-1 v1.1) |
| USB cable | Flash / serial |
Naming config
Section titled “Naming config”Copy env example
Section titled “Copy env example”cp config/walkthrough.env.example config/walkthrough.env(no output)Edit config/walkthrough.env (gitignored). Then load it before every CLI page:
Load env and capture account ID
Section titled “Load env and capture account ID”set -a && source config/walkthrough.env && set +aexport AWS_ACCOUNT_IDAWS_ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text)echo "$AWS_ACCOUNT_ID"123456789012| Variable | Example purpose |
|---|---|
| CLI target |
CORE_THING_NAME | NUC core Thing |
CORE_THING_GROUP | Thing group |
CLIENT_THING_NAME | Primary ESP32-S3 client Thing ( |
CLIENT_THING_PREFIX | Auth selectionRule prefix ( |
| Optional zone clients ( |
| X.509 |
| Optional — certs for extra zones ( |
ARTIFACT_BUCKET | Not set in the file. Pages derive it as
|
| DynamoDB table, SNS topic, and Lambda names for the Wire into AWS pages |
ALERT_EMAIL | Your address for the CloudWatch alarm email (confirm the SNS mail) |
GG_ROOT | Nucleus root ( |
| SSH target (fill on Prepare the core) |
Cost warning
Section titled “Cost warning”Things and certs are cheap, and a running Nucleus with
Moquette
aws.greengrass.clientdevices.mqtt.Moquette — local MQTT broker on the core. Not Mosquitto; client devices connect here over mTLS. mostly costs electricity. The AWS
integration pages add usage-billed services: IoT Core messages and rule
actions (two zones at 10 s send about 17,000 telemetry messages a day, each
matched by three rules), S3 requests and storage, DynamoDB on-demand writes, a CloudWatch
custom metric and alarm per zone, CloudWatch Logs ingestion, and a few minutes
of a SageMaker ml.m5.large training job. Check current prices on
the AWS Pricing Calculator for your Region.
Teardown removes every resource when you finish.