Skip to content

Troubleshooting

SymptomLikely causeWhat to check

Discovery
Greengrass discovery API — HTTPS call with the client certificate that returns associated core connectivity (host, port, CA) for local MQTT.
returns empty GGGroups

No association or IP detector not reporting

list-client-devices-associated-with-core-device; component list includes IPDetector
aws.greengrass.clientdevices.IPDetector — publishes the core's LAN address so discovery returns a reachable host for Moquette.
; wait 1–2 minutes

Discovery HTTP 403

Client policy
AWS IoT policy — JSON permissions attached to a certificate (core connect/publish; client greengrass:Discover and related actions).
missing greengrass:Discover

Attach artifacts/policies/client-device-policy.json

MQTT
MQTT — publish/subscribe messaging. This lab uses local MQTT to Moquette on the core, bridged to and from IoT Core.
connect to core fails

Auth
aws.greengrass.clientdevices.Auth — Greengrass component that decides which client device certificates may connect to the local MQTT broker.
selection rule / policy

Auth selectionRule Thing name; Moquette
aws.greengrass.clientdevices.mqtt.Moquette — local MQTT broker on the core. Not Mosquitto; client devices connect here over mTLS.
RUNNING; port from discovery

Sensor publishes, RGB never changes

Loop component
Greengrass component — a versioned unit of software on the core (AWS public components or custom recipes such as GgEdgeLoop / ZoneAnomaly).
or bridge

com.example.GgEdgeLoop logs; bridge
aws.greengrass.clientdevices.mqtt.Bridge — maps topics between LocalMqtt (Moquette), Pubsub (components), and IotCore.
LocalMqtt↔Pubsub mappings

Console MQTT quiet, RGB worksBridge to IoT Core only

Local loop is fine; check SensorLocalToIotCore mapping and core IoT policy

Nucleus
Greengrass Nucleus — the edge runtime on the core device. Installs components, talks to AWS, and hosts the local client-device stack.
not HEALTHY

Cert / role alias / network

greengrass.service logs under /greengrass/v2/logs/

greengrass-cli not found

Dev tools not installed

Deploy aws.greengrass.Cli ( —deploy-dev-tools only works with —provision true)

Cloud deployment FAILED: artifact download / access deniedToken-exchange role cannot read the artifact bucket

gg-artifacts-s3 inline policy on the token-exchange role; recipe URI has the real bucket, not ARTIFACT_BUCKET

Cloud deployment FAILED right after the local loop workedLocal deployment still owns com.example.GgEdgeLoop

greengrass-cli deployment create —remove com.example.GgEdgeLoop on the NUC, then redeploy

No objects in the data bucket / no DynamoDB itemsRule role not yet assumable, or wrong policy resource

aws iot get-topic-rule; role trust has your account ID; wait a minute after create-role. Add a rule errorAction to CloudWatch Logs if it stays silent

DynamoDB has telemetry but never actuatorBridge not forwarding component publishes to IoT Core

Deployment has ActuatorPubsubToIotCore; Bridge log under /greengrass/v2/logs/

Alarm never leaves INSUFFICIENT_DATAMetric name mismatch

get-metric-statistics on ChipTempC-<thing> in GgEdge/Greenhouse; the CloudWatch rule exists

Alarm email arrives, RGB never turns blueLambda not subscribed / no permission, or command not bridged

aws logs tail /aws/lambda/$COMMAND_FUNCTION; SNS lambda subscription; deployment has CommandIotCoreToPubsub; GgEdgeLoop is 1.1.0

SageMaker job FailedToo few samples, role, or pip install

describe-training-job —query FailureReason; job log in /aws/sagemaker/TrainingJobs; wait for 120 post-boot samples per zone

ZoneAnomaly BROKEN on install

No python3-venv, or no onnxruntime wheel for the CPU

/greengrass/v2/logs/com.example.ZoneAnomaly.log; sudo apt-get install -y python3-venv. The pinned onnxruntime runs on the NUC6CAY (no AVX); on other CPUs check the wheel exists for your architecture

Terminal window
aws greengrassv2 get-core-device --core-device-thing-name "$CORE_THING_NAME"
{
"coreDeviceThingName": "gg-edge-wt-dev-core",
"status": "HEALTHY",
…
}
Terminal window
sudo journalctl -u greengrass -n 100 --no-pager
sudo /greengrass/v2/bin/greengrass-cli component list
sudo tail -n 100 /greengrass/v2/logs/greengrass.log
… greengrass.service / component list / greengrass.log …