Discovery Greengrass discovery API — HTTPS call with the client certificate that returns associated core connectivity (host, port, CA) for local MQTT. returns empty
GGGroups
No association or IP detector not reporting
list-client-devices-associated-with-core-device; component
list includes IPDetector aws.greengrass.clientdevices.IPDetector — publishes the core's LAN address so discovery returns a reachable host for Moquette.; wait
1–2 minutes
Discovery HTTP 403
Client policy AWS IoT policy — JSON permissions attached to a certificate (core connect/publish; client greengrass:Discover and related actions). missing
greengrass:Discover
MQTT MQTT — publish/subscribe messaging. This lab uses local MQTT to Moquette on the core, bridged to and from IoT Core. connect to core fails
Auth aws.greengrass.clientdevices.Auth — Greengrass component that decides which client device certificates may connect to the local MQTT broker. selection rule / policy
Auth selectionRule Thing name;
Moquette aws.greengrass.clientdevices.mqtt.Moquette — local MQTT broker on the core. Not Mosquitto; client devices connect here over mTLS. RUNNING; port from
discovery
Sensor publishes, RGB never changes
Loop component Greengrass component — a versioned unit of software on the core (AWS public components or custom recipes such as GgEdgeLoop / ZoneAnomaly). or bridge
com.example.GgEdgeLoop logs;
bridge aws.greengrass.clientdevices.mqtt.Bridge — maps topics between LocalMqtt (Moquette), Pubsub (components), and IotCore. LocalMqtt↔Pubsub mappings
Console MQTT quiet, RGB works
Bridge to IoT Core only
Local loop is fine; check SensorLocalToIotCore mapping and
core IoT policy
Nucleus Greengrass Nucleus — the edge runtime on the core device. Installs components, talks to AWS, and hosts the local client-device stack. not HEALTHY
Cert / role alias / network
greengrass.service logs under
/greengrass/v2/logs/
greengrass-cli not found
Dev tools not installed
Deploy aws.greengrass.Cli (
—deploy-dev-tools only works with
—provision true)
Token-exchange role cannot read the artifact bucket
gg-artifacts-s3 inline policy on the token-exchange role;
recipe URI has the real bucket, not
ARTIFACT_BUCKET
Cloud deployment FAILED right after the local loop worked
Local deployment still owns com.example.GgEdgeLoop
greengrass-cli deployment create —remove com.example.GgEdgeLoop
on the NUC, then redeploy
No objects in the data bucket / no DynamoDB items
Rule role not yet assumable, or wrong policy resource
aws iot get-topic-rule; role trust has your account ID;
wait a minute after create-role. Add a rule
errorAction to CloudWatch Logs if it stays silent
DynamoDB has telemetry but never actuator
Bridge not forwarding component publishes to IoT Core
Deployment has ActuatorPubsubToIotCore; Bridge log under
/greengrass/v2/logs/
Alarm never leaves INSUFFICIENT_DATA
Metric name mismatch
get-metric-statistics on
ChipTempC-<thing> in GgEdge/Greenhouse;
the CloudWatch rule exists
Alarm email arrives, RGB never turns blue
Lambda not subscribed / no permission, or command not bridged
aws logs tail /aws/lambda/$COMMAND_FUNCTION; SNS
lambda subscription; deployment has
CommandIotCoreToPubsub; GgEdgeLoop is 1.1.0
SageMaker job Failed
Too few samples, role, or pip install
describe-training-job —query FailureReason; job log in
/aws/sagemaker/TrainingJobs; wait for 120 post-boot samples
per zone
ZoneAnomaly BROKEN on install
No python3-venv, or no onnxruntime wheel for
the CPU
/greengrass/v2/logs/com.example.ZoneAnomaly.log;
sudo apt-get install -y python3-venv. The pinned
onnxruntime runs on the NUC6CAY (no AVX); on other CPUs
check the wheel exists for your architecture