59 lines
2.4 KiB
Markdown
59 lines
2.4 KiB
Markdown
# Mosquitto MQTT Broker on Kubernetes
|
|
|
|
This project deploys a **secure Mosquitto MQTT broker** inside Kubernetes with:
|
|
|
|
- **TLS Encryption** (auto-generated via cert-manager with a self-signed CA)
|
|
- **User Authentication** (username/password using Kubernetes Secrets)
|
|
- **Access Control List (ACL)** for fine-grained publish/subscribe permissions
|
|
- **Persistent Storage** using PVCs
|
|
- **TCP passthrough for MQTT over TLS and WebSocket Secure (WSS)** via Ingress-NGINX
|
|
|
|
---
|
|
|
|
## 📂 Project Structure
|
|
```
|
|
|
|
├── ConfigMap-ingress-nginx.yaml # TCP passthrough ConfigMap for NGINX (ports 8883/9443)
|
|
├── ConfigMap.yaml # Mosquitto main configuration (mosquitto.conf)
|
|
├── README.md # This documentation
|
|
├── deployment.yaml # Mosquitto Kubernetes Deployment
|
|
├── mosquitto-acl-secret.yaml # ACL file as a Kubernetes Secret
|
|
├── mosquitto-internal-tls.yaml # TLS Certificate and CA with cert-manager
|
|
├── mosquitto-passwd-secret.yaml # Password file as a Kubernetes Secret
|
|
├── namespace.yaml # Namespace definition
|
|
├── pvc.yaml # Persistent Volume Claim for Mosquitto data
|
|
└── svc.yaml # Mosquitto Services (ClusterIP)
|
|
```
|
|
# 🔒 User Authentication
|
|
|
|
There are two users configured :
|
|
|
|
| Username | Permissions | Description |
|
|
|----------|-----------------------|---------------------------------|
|
|
| pubuser | publish + subscribe | Used by publishers |
|
|
| subuser | subscribe only | Used by all subscribers |
|
|
|
|
|
|
Passwords are securely stored in `mosquitto-passwd-secret.yaml`
|
|
|
|
## 📜 ACL Rules
|
|
ACL (Access Control List) enforces:
|
|
|
|
- **pubuser**: can publish and subscribe on all topics (`#`)
|
|
- **subuser**: can only subscribe to all topics (`#`)
|
|
|
|
ACL file is stored in `mosquitto-acl-secret.yaml`.
|
|
|
|
## 🔐 TLS Security
|
|
- Self-signed CA generated via cert-manager
|
|
- Broker certificates issued automatically
|
|
- Clients must trust the `ca.crt` (exported from Kubernetes)
|
|
|
|
## 📡 MQTT Ports
|
|
| Service | Port | Description |
|
|
|---------|------|-------------|
|
|
| MQTT over TLS | 8883 | Secure MQTT |
|
|
| WebSocket Secure (WSS) | 9443 | Secure WebSocket for MQTT |
|
|
|
|
TCP ports are passed directly to Mosquitto via NGINX Ingress TCP services.
|