Skip to content
Get Started for Free

IoT

AWS IoT provides cloud services to manage IoT devices and integrate them with other AWS services.

LocalStack supports IoT Core, IoT Data, IoT Analytics. Common operations for creating and updating things, groups, policies, certificates and other entities are implemented with full CloudFormation support. The supported APIs are available on our API Coverage section.

LocalStack ships a Message Queuing Telemetry Transport (MQTT) broker powered by Eclipse Mosquitto which supports both pure MQTT and MQTT-over-WSS (WebSockets Secure) protocols.

This guide is for users that are new to IoT and assumes a basic knowledge of the AWS CLI and LocalStack lstk aws command.

Start LocalStack using your preferred method.

To retrieve the MQTT endpoint, use the DescribeEndpoint operation.

Terminal window
lstk aws iot describe-endpoint
Output
{
"endpointAddress": "000000000000.iot.eu-central-1.localhost.localstack.cloud:4510"
}

This endpoint can then be used with any MQTT client to publish and subscribe to topics. In this example, we will use the Hive MQTT CLI.

Run the following command to subscribe to an MQTT topic.

Terminal window
mqtt subscribe \
--host 000000000000.iot.eu-central-1.localhost.localstack.cloud \
--port 4510 \
--topic climate

In a separate terminal session, publish a message to this topic.

Terminal window
mqtt publish \
--host 000000000000.iot.eu-central-1.localhost.localstack.cloud \
--port 4510 \
--topic climate \
-m "temperature=30°C;humidity=60%"

This message will be pushed to all subscribers of this topic, including the one in the first terminal session.

LocalStack IoT maintains its own root certificate authority which is regenerated at every run. The root CA certificate can be retrieved from http://localhost.localstack.cloud:4566/_aws/iot/LocalStackIoTRootCA.pem.

When connecting to the endpoints, you will need to provide this root CA certificate for authentication. This is illustrated below with Python AWS IoT SDK,

import awscrt
import boto3
from awsiot import mqtt_connection_builder
region = 'eu-central-1'
iot_client = boto3.client('iot', region=region)
endpoint = aws_client.iot.describe_endpoint()["endpointAddress"]
endpoint, port = endpoint.split(':')
event_loop_group = io.EventLoopGroup(1)
host_resolver = io.DefaultHostResolver(event_loop_group)
client_bootstrap = io.ClientBootstrap(event_loop_group, host_resolver)
credentials_provider = awscrt.auth.AwsCredentialsProvider.new_static(
access_key_id='...',
secret_access_key='...',
)
client_id = 'example-client'
# Path to root CA certificate downloaded from `/_aws/iot/LocalStackIoTRootCA.pem`
ca_filepath = '...'
mqtt_over_wss = mqtt_connection_builder.websockets_with_default_aws_signing(
region=region,
credentials_provider=credentials_provider,
client_bootstrap=client_bootstrap,
client_id=client_id,
endpoint=endpoint,
port=port,
ca_filepath=ca_filepath,
)
mqtt_over_wss.connect().result()
mqtt_over_wss.subscribe(...)

If you are using pure MQTT, you also need to set the client-side X509 certificates and Application Layer Protocol Negotiation (ALPN) for a successful mutual TLS (mTLS) authentication. This is not required for MQTT-over-WSS since it does not use mTLS.

AWS IoT SDKs automatically set the ALPN when the endpoint port is 443. However, because LocalStack does not use this port, this must be done manually. For details on how ALPN works with AWS, see this page.

The client certificate and key can be retrieved using CreateKeysAndCertificate operation. The certificate is signed by the LocalStack root CA.

result = iot_client.create_keys_and_certificate(setAsActive=True)
# Path to file with saved content `result["certificatePem"]`
cert_file = '...'
# Path to file with saved content `result["keyPair"]["PrivateKey"]`
priv_key_file = '...'
tls_ctx_options = awscrt.io.TlsContextOptions.create_client_with_mtls_from_path(
cert_file, priv_key_file
)
tls_ctx_options.alpn_list = ["x-amzn-mqtt-ca"]
mqtt = mqtt_connection_builder._builder(
tls_ctx_options,
cert_filepath=cert_file,
pri_key_filepath=priv_key_file,
client_bootstrap=client_bootstrap,
client_id=client_id,
endpoint=endpoint,
port=port,
ca_filepath=ca_filepath,
)
mqtt.connect().result()
mqtt.subscribe(...)

LocalStack publishes the lifecycle events to the standard endpoints.

  • $aws/events/presence/connected/clientId: when a client connects
  • $aws/events/presence/disconnected/clientId: when a client disconnects
  • $aws/events/subscriptions/subscribed/clientId: when a client subscribes to a topic
  • $aws/events/subscriptions/unsubscribed/clientId: when a client unsubscribes from a topic

Currently the principalIdentifier and sessionIdentifier fields in event payload contain dummy values.

LocalStack can publish the registry events, if you enable it.

Terminal window
lstk aws iot update-event-configurations \
--event-configurations '{"THING":{"Enabled": true}}'

You can then subscribe or use topic rules on the follow topics:

  • $aws/events/thing/<thingName>/created: when a new thing is created
  • $aws/events/thing/<thingName>/updated: when a thing is updated
  • $aws/events/thing/<thingName>/deleted: when a thing is deleted

It is possible to use actions with SQL queries for IoT Topic Rules.

For example, you can use the CreateTopicRule operation to define a topic rule with a SQL query SELECT * FROM 'my/topic' where attr=123 which will execute a trigger whenever a message with attribute attr=123 is received on the MQTT topic my/topic.

The following actions are supported:

Node.js aws-iot-device-sdk Connection Issues

Section titled “Node.js aws-iot-device-sdk Connection Issues”

When using the aws-iot-device-sdk library, you may encounter SSL certificate errors because Node.js rejects self-signed certificates by default.

Solution: Set the environment variable to disable certificate validation:

Terminal window
export NODE_TLS_REJECT_UNAUTHORIZED=0

For Lambda functions, you also need to explicitly set the region parameter in the device configuration:

const device = new iot.device({
protocol: 'wss',
host: endpoint,
region: process.env.AWS_REGION, // Required for LocalStack
// ... other options
});

And configure the Lambda environment:

Terminal window
lstk aws lambda update-function-configuration \
--function-name your-function-name \
--environment "Variables={NODE_TLS_REJECT_UNAUTHORIZED=0}"

109 of 272 operations implemented

Available from the Base plan. Licensing details

Find an API

Search the full operation list, then sort the table to compare current support.

Loading operations…

Verified on Kubernetes
Loading operations…
Complete static API list All 272 operations and their current support status
OperationStatus
AcceptCertificateTransferNot implemented
AddThingToBillingGroupImplemented
AddThingToThingGroupImplemented
AssociateSbomWithPackageVersionNot implemented
AssociateTargetsWithJobNot implemented
AttachPolicyImplemented
AttachPrincipalPolicyImplemented
AttachSecurityProfileNot implemented
AttachThingPrincipalImplemented
CancelAuditMitigationActionsTaskNot implemented
CancelAuditTaskNot implemented
CancelCertificateTransferNot implemented
CancelDetectMitigationActionsTaskNot implemented
CancelJobImplemented
CancelJobExecutionImplemented
ClearDefaultAuthorizerNot implemented
ConfirmTopicRuleDestinationNot implemented
CreateAuditSuppressionNot implemented
CreateAuthorizerNot implemented
CreateBillingGroupImplemented
CreateCertificateFromCsrImplemented
CreateCertificateProviderNot implemented
CreateCommandNot implemented
CreateCustomMetricNot implemented
CreateDimensionNot implemented
CreateDomainConfigurationImplemented
CreateDynamicThingGroupImplemented
CreateFleetMetricNot implemented
CreateJobImplemented
CreateJobTemplateImplemented
CreateKeysAndCertificateImplemented
CreateMitigationActionNot implemented
CreateOTAUpdateNot implemented
CreatePackageNot implemented
CreatePackageVersionNot implemented
CreatePolicyImplemented
CreatePolicyVersionImplemented
CreateProvisioningClaimNot implemented
CreateProvisioningTemplateNot implemented
CreateProvisioningTemplateVersionNot implemented
CreateRoleAliasImplemented
CreateScheduledAuditNot implemented
CreateSecurityProfileNot implemented
CreateStreamNot implemented
CreateThingImplemented
CreateThingGroupImplemented
CreateThingTypeImplemented
CreateTopicRuleImplemented
CreateTopicRuleDestinationImplemented
DeleteAccountAuditConfigurationNot implemented
DeleteAuditSuppressionNot implemented
DeleteAuthorizerNot implemented
DeleteBillingGroupImplemented
DeleteCACertificateImplemented
DeleteCertificateImplemented
DeleteCertificateProviderNot implemented
DeleteCommandNot implemented
DeleteCommandExecutionNot implemented
DeleteCustomMetricNot implemented
DeleteDimensionNot implemented
DeleteDomainConfigurationImplemented
DeleteDynamicThingGroupImplemented
DeleteFleetMetricNot implemented
DeleteJobImplemented
DeleteJobExecutionImplemented
DeleteJobTemplateImplemented
DeleteMitigationActionNot implemented
DeleteOTAUpdateNot implemented
DeletePackageNot implemented
DeletePackageVersionNot implemented
DeletePolicyImplemented
DeletePolicyVersionImplemented
DeleteProvisioningTemplateNot implemented
DeleteProvisioningTemplateVersionNot implemented
DeleteRegistrationCodeNot implemented
DeleteRoleAliasImplemented
DeleteScheduledAuditNot implemented
DeleteSecurityProfileNot implemented
DeleteStreamNot implemented
DeleteThingImplemented
DeleteThingGroupImplemented
DeleteThingTypeImplemented
DeleteTopicRuleImplemented
DeleteTopicRuleDestinationImplemented
DeleteV2LoggingLevelNot implemented
DeprecateThingTypeImplemented
DescribeAccountAuditConfigurationNot implemented
DescribeAuditFindingNot implemented
DescribeAuditMitigationActionsTaskNot implemented
DescribeAuditSuppressionNot implemented
DescribeAuditTaskNot implemented
DescribeAuthorizerNot implemented
DescribeBillingGroupImplemented
DescribeCACertificateImplemented
DescribeCertificateImplemented
DescribeCertificateProviderNot implemented
DescribeCustomMetricNot implemented
DescribeDefaultAuthorizerNot implemented
DescribeDetectMitigationActionsTaskNot implemented
DescribeDimensionNot implemented
DescribeDomainConfigurationImplemented
DescribeEncryptionConfigurationNot implemented
DescribeEndpointImplemented
DescribeEventConfigurationsNot implemented
DescribeFleetMetricNot implemented
DescribeIndexNot implemented
DescribeJobImplemented
DescribeJobExecutionImplemented
DescribeJobTemplateImplemented
DescribeManagedJobTemplateNot implemented
DescribeMitigationActionNot implemented
DescribeProvisioningTemplateNot implemented
DescribeProvisioningTemplateVersionNot implemented
DescribeRoleAliasImplemented
DescribeScheduledAuditNot implemented
DescribeSecurityProfileNot implemented
DescribeStreamNot implemented
DescribeThingImplemented
DescribeThingGroupImplemented
DescribeThingRegistrationTaskNot implemented
DescribeThingTypeImplemented
DetachPolicyImplemented
DetachPrincipalPolicyImplemented
DetachSecurityProfileNot implemented
DetachThingPrincipalImplemented
DisableTopicRuleImplemented
DisassociateSbomFromPackageVersionNot implemented
EnableTopicRuleImplemented
GetBehaviorModelTrainingSummariesNot implemented
GetBucketsAggregationNot implemented
GetCardinalityNot implemented
GetCommandNot implemented
GetCommandExecutionNot implemented
GetEffectivePoliciesNot implemented
GetIndexingConfigurationImplemented
GetJobDocumentImplemented
GetLoggingOptionsNot implemented
GetOTAUpdateNot implemented
GetPackageNot implemented
GetPackageConfigurationNot implemented
GetPackageVersionNot implemented
GetPercentilesNot implemented
GetPolicyImplemented
GetPolicyVersionImplemented
GetRegistrationCodeImplemented
GetStatisticsNot implemented
GetThingConnectivityDataNot implemented
GetTopicRuleImplemented
GetTopicRuleDestinationNot implemented
GetV2LoggingOptionsNot implemented
ListActiveViolationsNot implemented
ListAttachedPoliciesImplemented
ListAuditFindingsNot implemented
ListAuditMitigationActionsExecutionsNot implemented
ListAuditMitigationActionsTasksNot implemented
ListAuditSuppressionsNot implemented
ListAuditTasksNot implemented
ListAuthorizersNot implemented
ListBillingGroupsImplemented
ListCACertificatesNot implemented
ListCertificateProvidersNot implemented
ListCertificatesImplemented
ListCertificatesByCAImplemented
ListCommandExecutionsNot implemented
ListCommandsNot implemented
ListCustomMetricsNot implemented
ListDetectMitigationActionsExecutionsNot implemented
ListDetectMitigationActionsTasksNot implemented
ListDimensionsNot implemented
ListDomainConfigurationsImplemented
ListFleetMetricsNot implemented
ListIndicesNot implemented
ListJobExecutionsForJobImplemented
ListJobExecutionsForThingImplemented
ListJobTemplatesImplemented
ListJobsImplemented
ListManagedJobTemplatesNot implemented
ListMetricValuesNot implemented
ListMitigationActionsNot implemented
ListOTAUpdatesNot implemented
ListOutgoingCertificatesNot implemented
ListPackageVersionsNot implemented
ListPackagesNot implemented
ListPoliciesImplemented
ListPolicyPrincipalsImplemented
ListPolicyVersionsImplemented
ListPrincipalPoliciesImplemented
ListPrincipalThingsImplemented
ListPrincipalThingsV2Not implemented
ListProvisioningTemplateVersionsNot implemented
ListProvisioningTemplatesNot implemented
ListRelatedResourcesForAuditFindingNot implemented
ListRoleAliasesImplemented
ListSbomValidationResultsNot implemented
ListScheduledAuditsNot implemented
ListSecurityProfilesNot implemented
ListSecurityProfilesForTargetNot implemented
ListStreamsNot implemented
ListTagsForResourceImplemented
ListTargetsForPolicyImplemented
ListTargetsForSecurityProfileNot implemented
ListThingGroupsImplemented
ListThingGroupsForThingImplemented
ListThingPrincipalsImplemented
ListThingPrincipalsV2Implemented
ListThingRegistrationTaskReportsNot implemented
ListThingRegistrationTasksNot implemented
ListThingTypesImplemented
ListThingsImplemented
ListThingsInBillingGroupImplemented
ListThingsInThingGroupImplemented
ListTopicRuleDestinationsNot implemented
ListTopicRulesImplemented
ListV2LoggingLevelsNot implemented
ListViolationEventsNot implemented
PutVerificationStateOnViolationNot implemented
RegisterCACertificateImplemented
RegisterCertificateImplemented
RegisterCertificateWithoutCAImplemented
RegisterThingNot implemented
RejectCertificateTransferNot implemented
RemoveThingFromBillingGroupImplemented
RemoveThingFromThingGroupImplemented
ReplaceTopicRuleImplemented
SearchIndexImplemented
SetDefaultAuthorizerNot implemented
SetDefaultPolicyVersionImplemented
SetLoggingOptionsNot implemented
SetV2LoggingLevelNot implemented
SetV2LoggingOptionsNot implemented
StartAuditMitigationActionsTaskNot implemented
StartDetectMitigationActionsTaskNot implemented
StartOnDemandAuditTaskNot implemented
StartThingRegistrationTaskNot implemented
StopThingRegistrationTaskNot implemented
TagResourceImplemented
TestAuthorizationNot implemented
TestInvokeAuthorizerNot implemented
TransferCertificateNot implemented
UntagResourceImplemented
UpdateAccountAuditConfigurationNot implemented
UpdateAuditSuppressionNot implemented
UpdateAuthorizerNot implemented
UpdateBillingGroupImplemented
UpdateCACertificateImplemented
UpdateCertificateImplemented
UpdateCertificateProviderNot implemented
UpdateCommandNot implemented
UpdateCustomMetricNot implemented
UpdateDimensionNot implemented
UpdateDomainConfigurationImplemented
UpdateDynamicThingGroupImplemented
UpdateEncryptionConfigurationNot implemented
UpdateEventConfigurationsImplemented
UpdateFleetMetricNot implemented
UpdateIndexingConfigurationImplemented
UpdateJobNot implemented
UpdateMitigationActionNot implemented
UpdatePackageNot implemented
UpdatePackageConfigurationNot implemented
UpdatePackageVersionNot implemented
UpdateProvisioningTemplateNot implemented
UpdateRoleAliasImplemented
UpdateScheduledAuditNot implemented
UpdateSecurityProfileNot implemented
UpdateStreamNot implemented
UpdateThingImplemented
UpdateThingGroupImplemented
UpdateThingGroupsForThingImplemented
UpdateThingTypeNot implemented
UpdateTopicRuleDestinationNot implemented
ValidateSecurityProfileBehaviorsNot implemented
Was this page helpful?