🏭 Final Stage

Scaling and Security

Industry deployment ke liye architecture hardening, scale planning aur secure design

πŸ“‹ Topics Covered in Final Stage

1Full IoT architecture overview
2Scaling strategy for 1000+ devices
3SSL and secure MQTT communication
4Industry deployment strategy and operations model

πŸ—οΈ Step 1: Complete IoT Architecture

/* ╔══════════════════════════════════════════════════════════════════════════════╗ β•‘ FULL STACK IoT ARCHITECTURE β•‘ ╠══════════════════════════════════════════════════════════════════════════════╣ β•‘ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ EDGE / FIELD LAYER β”‚ β•‘ β•‘ β”‚ β”‚ β•‘ β•‘ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β•‘ β•‘ β”‚ β”‚ ESP32 β”‚ β”‚ ESP32 β”‚ β”‚ ESP32 β”‚ β”‚ ESP32 β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ WiFi β”‚ β”‚ 4G LTE β”‚ β”‚ WiFi β”‚ β”‚ Ethernetβ”‚ β”‚ β•‘ β•‘ β”‚ β”‚ Home β”‚ β”‚ Remote β”‚ β”‚ Factory β”‚ β”‚ Industrial β”‚ β”‚ β•‘ β•‘ β”‚ β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”˜ β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β”‚ β”‚ β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ NETWORK LAYER β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ WiFi Router ──┬──► Internet ──┬──► LTE Gateway β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ CLOUD LAYER β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β•‘ β•‘ β”‚ β”‚ LOAD BALANCER β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ (TLS Termination + DDoS Protection) β”‚ β”‚ β•‘ β•‘ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β•‘ β•‘ β”‚ β”‚ MQTT Broker β”‚ β”‚ REST API β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ Cluster β”‚ β”‚ (Node.js) β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ (Mosquitto) β”‚ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β•‘ β•‘ β”‚ β”‚ DATA PIPELINE β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ Message β”‚ β”‚ Time β”‚ β”‚ Analytics β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ Queue │──│series DB│──│ Engine β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β•‘ β•‘ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β•‘ β•‘ β”‚ β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ PRESENTATION LAYER β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ Web β”‚ β”‚ Android β”‚ β”‚ Admin β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ Dashboardβ”‚ β”‚ App β”‚ β”‚ Portal β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β•‘ β•‘ β”‚ β”‚ β”‚ β”‚ β•‘ β•‘ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β•‘ β•‘ β”‚ β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β• */

πŸ” Step 2: MQTT Security Implementation

# mosquitto-secure.conf - Production Mosquitto Configuration # =========================================== # Basic Settings # =========================================== pid_file /var/run/mosquitto.pid persistence true persistence_location /var/lib/mosquitto/ log_dest file /var/log/mosquitto/mosquitto.log log_dest stdout # =========================================== # Listeners (Multiple Ports) # =========================================== # Standard MQTT with TLS (Port 8883) listener 8883 protocol mqtt cafile /etc/mosquitto/certs/ca.crt certfile /etc/mosquitto/certs/server.crt keyfile /etc/mosquitto/certs/server.key require_certificate true tls_version tlsv1.2 # WebSocket for Web Clients (Port 9001) listener 9001 protocol websockets allow_anonymous false # =========================================== # Authentication # =========================================== # Disable anonymous access allow_anonymous false # Password file (create with: mosquitto_passwd -c /path/to/passwd username) password_file /etc/mosquitto/passwd # ACL file for topic authorization acl_file /etc/mosquitto/acl # =========================================== # Connection Limits # =========================================== max_connections 10000 max_keepalive 120 # Message size limits message_size_limit 65536 # =========================================== # Persistence # =========================================== autosave_interval 1800 autosave_on_changes false

ACL Configuration File

# /etc/mosquitto/acl - Access Control List # =========================================== # Pattern-based ACLs # =========================================== # Devices can only publish to their own topics pattern publish "device/%u/+" # Devices can subscribe to commands addressed to them pattern subscribe "device/%u/command" # Dashboard can publish commands to any device user dashboard topic write "home/relay/+/command" topic read "home/relay/#" # Android app user user mobile_app topic write "home/relay/+/command" topic read "home/relay/#" # Admin user - full access user admin topic readwrite "#" # Analytics service - read only user analytics topic read "home/+/+" topic read "lte/+/+"

SSL/TLS Certificate Setup

# =========================================== # Generate Self-Signed Certificates (for testing) # =========================================== # 1. Generate CA key openssl genrsa -out ca.key 2048 # 2. Generate CA certificate openssl req -new -x509 -days 365 -key ca.key -out ca.crt \ -subj "/C=IN/ST=DL/L=Delhi/O=YaranaIoT/CN=Yarana Root CA" # 3. Generate server key openssl genrsa -out server.key 2048 # 4. Generate server CSR openssl req -new -key server.key -out server.csr \ -subj "/C=IN/ST=DL/O=YaranaIoT/CN=broker.yaranaiot.com" # 5. Sign server certificate with CA openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \ -CAcreateserial -out server.crt -days 365 # 6. Copy certificates to mosquitto sudo cp ca.crt server.crt server.key /etc/mosquitto/certs/ sudo chmod 644 /etc/mosquitto/certs/*.crt sudo chmod 600 /etc/mosquitto/certs/*.key

πŸ“ˆ Step 3: Scaling Strategy for 1000+ Devices

/* ╔══════════════════════════════════════════════════════════════════════════════╗ β•‘ SCALING ARCHITECTURE β•‘ ╠══════════════════════════════════════════════════════════════════════════════╣ β•‘ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ Load Balancer β”‚ β•‘ β•‘ β”‚ (AWS ALB/NLB) β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ β”‚ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ Broker 1 β”‚ β”‚ Broker 2 β”‚ β”‚ Broker 3 β”‚ β•‘ β•‘ β”‚ (Cluster) │◄────►│ (Cluster) │◄────►│ (Cluster) β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β”‚ β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ Redis Cluster β”‚ β•‘ β•‘ β”‚ (Session DB) β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β•‘ β•‘ β”‚ β”‚ β”‚ β•‘ β•‘ β”Œβ”€β”€β”€β”€β”΄β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β” β•‘ β•‘ β”‚ TimescaleDBβ”‚ β”‚ Analytics β”‚ β”‚ Alerting β”‚ β•‘ β•‘ β”‚ (Hot Data)β”‚ β”‚ Engine β”‚ β”‚ Service β”‚ β•‘ β•‘ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β•‘ β•‘ β•‘ β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β• */ // =========================================== // Mosquitto Cluster Configuration (Bridge Mode) // =========================================== # mosquitto-bridge.conf - On each broker node connection broker-cluster address broker2.local:1883 clientid bridge-broker1 try_private true start_type automatic topic # in 0 topic # out 0 topic # both 0 # Authentication remote_username bridge_user remote_password secure_bridge_password // =========================================== // Redis Session Store for Distributed State // =========================================== # Install Redis Cluster # 3 master nodes + 3 replica nodes recommended # Redis configuration for MQTT session persistence bind 0.0.0.0 port 6379 cluster-enabled yes cluster-config-file nodes.conf cluster-node-timeout 5000 appendonly yes
⚠️

Device Scaling Limits:
β€’ Single Mosquitto: ~10,000 concurrent connections
β€’ Clustered (3 nodes): ~25,000 concurrent connections
β€’ For 1000+ devices: MQTT over TLS with proper connection handling
β€’ Consider MQTT-SN for battery-powered sensor networks

πŸ› οΈ Step 4: Industry Deployment Operations

# =========================================== # Docker Compose for Production Deployment # =========================================== version: '3.8' services: # MQTT Broker Cluster mosquitto-1: image: eclipse-mosquitto:2.0 container_name: mosquitto-1 ports: - "1883:1883" - "8883:8883" - "9001:9001" volumes: - ./mosquitto/config:/mosquitto/config - ./mosquitto/data:/mosquitto/data - ./mosquitto/log:/mosquitto/log networks: - iot-network restart: unless-stopped # Node.js Backend API api: image: node:18-alpine container_name: iot-api working_dir: /app volumes: - ./api:/app environment: - NODE_ENV=production - MQTT_BROKER=mqtt://mosquitto-1:1883 - REDIS_HOST=redis - DB_HOST=timescale networks: - iot-network depends_on: - mosquitto-1 restart: unless-stopped # Redis Cache redis: image: redis:7-alpine container_name: iot-redis ports: - "6379:6379" volumes: - redis-data:/data networks: - iot-network restart: unless-stopped # Time-series Database timescale: image: timescale/timescaledb:latest-pg15 container_name: iot-timescale environment: - POSTGRES_PASSWORD=secure_password - POSTGRES_DB=iot_data volumes: - timescale-data:/var/lib/postgresql/data networks: - iot-network restart: unless-stopped # Nginx Reverse Proxy nginx: image: nginx:alpine container_name: iot-nginx ports: - "80:80" - "443:443" volumes: - ./nginx/nginx.conf:/etc/nginx/nginx.conf - ./nginx/ssl:/etc/nginx/ssl networks: - iot-network depends_on: - api restart: unless-stopped networks: iot-network: driver: bridge volumes: redis-data: timescale-data:

Nginx Configuration for MQTT WebSocket

# /etc/nginx/nginx.conf events { worker_connections 1024; } stream { # MQTT Proxy upstream mqtt_backend { server mosquitto-1:1883; } server { listen 1883; proxy_pass mqtt_backend; proxy_connect_timeout 10s; proxy_timeout 300s; } # MQTT over TLS upstream mqtts_backend { server mosquitto-1:8883; } server { listen 8883 ssl; proxy_pass mqtts_backend; ssl_certificate /etc/nginx/ssl/server.crt; ssl_certificate_key /etc/nginx/ssl/server.key; ssl_protocols TLSv1.2 TLSv1.3; } } http { # WebSocket MQTT Proxy upstream mqtt_ws_backend { server mosquitto-1:9001; } server { listen 443 ssl; server_name dashboard.example.com; ssl_certificate /etc/nginx/ssl/server.crt; ssl_certificate_key /etc/nginx/ssl/server.key; location /mqtt { proxy_pass http://mqtt_ws_backend; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_read_timeout 86400; } location / { root /var/www/html; index index.html; } } }

πŸ“Š Step 5: Monitoring and Alerting

// =========================================== // Key Metrics to Monitor // =========================================== // Broker Metrics "connection_count" // Current connected clients "message_count" // Messages per second "bytes_transferred" // Network bandwidth "queue_depth" // Pending messages "memory_usage" // RAM utilization // Device Metrics "device_online_count" // Active devices "device_offline_count" // Offline devices (alert!) "message_latency" // End-to-end delay "command_success_rate" // Command delivery % "last_seen_distribution" // Device freshness // =========================================== // Alert Rules (Prometheus/Grafana) // =========================================== # Alert: Too many offline devices groups: - name: device_alerts rules: - alert: DeviceOffline expr: device_offline_count > 10 for: 5m labels: severity: warning annotations: summary: "{{ $value }} devices offline" - alert: HighMessageLatency expr: message_latency > 5000 for: 2m labels: severity: critical annotations: summary: "High latency: {{ $value }}ms" - alert: BrokerConnectionLimit expr: connection_count > 9000 for: 1m labels: severity: critical annotations: summary: "Connection limit approaching"

βœ… Production Deployment Checklist

πŸŽ‰

Congratulations! Aapne MQTT Mastery Series complete kar liya hai! Ab aapke paas full-stack IoT system build karne ka complete knowledge hai - from broker setup se lekar production deployment tak.

πŸ’‘

Next Steps:
β€’ Apna project GitHub par share karo
β€’ Community se feedback lo
β€’ Next: Machine Learning integration, Voice control, Advanced analytics