You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS EKS(Kubernetes)中独立部署ThingsBoard微服务

Deploying ThingsBoard as Independent Microservices on AWS EKS

Got it, deploying ThingsBoard as separate microservices on AWS EKS is totally feasible—let’s walk through this step by step, with practical, EKS-specific details I’ve picked up from doing this myself.

1. Prerequisites First

Make sure you have these tools and permissions ready:

  • AWS CLI (configured with an account that has permissions to create EKS clusters, RDS/ElastiCache instances, and ALBs)
  • eksctl (to simplify EKS cluster setup)
  • kubectl (Kubernetes command-line tool)
  • Helm 3 (optional but helpful for deploying dependencies like PostgreSQL, Redis, or Kafka)

2. Spin Up Your EKS Cluster

First, create a basic EKS cluster with worker nodes sized appropriately for ThingsBoard (I recommend m5.xlarge or similar for most workloads):

eksctl create cluster \
  --name tb-eks-cluster \
  --region us-east-1 \
  --nodegroup-name tb-worker-nodes \
  --node-type m5.xlarge \
  --nodes 3 \
  --nodes-min 2 \
  --nodes-max 5

Wait for the cluster to provision (this takes ~15 minutes), then verify your connection:

kubectl get nodes

You should see all nodes in Ready state.

3. Deploy Dependent Services

ThingsBoard needs three core dependencies: a PostgreSQL database, Redis cache, and a message queue (Kafka for production). You can use AWS managed services or deploy them directly in EKS—here’s how to do both:

  • PostgreSQL: Create an RDS PostgreSQL instance (version 12+), configure the security group to allow inbound traffic from your EKS node group, and note the endpoint, username, and password.
  • Redis: Set up an ElastiCache Redis cluster, again updating security groups to allow EKS node access.
  • Kafka: Deploy an AWS MSK cluster, or use Amazon MQ if you prefer a managed message queue alternative.

Option B: Deploy in EKS (For Testing/Development)

Use Helm to deploy these services quickly:

# Add Bitnami repo (they maintain solid Helm charts)
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo update

# Deploy PostgreSQL
helm install tb-postgres bitnami/postgresql \
  --namespace thingsboard \
  --create-namespace \
  --set auth.username=thingsboard \
  --set auth.password=tb-secure-pass \
  --set auth.database=thingsboard

# Deploy Redis
helm install tb-redis bitnami/redis \
  --namespace thingsboard \
  --set auth.password=tb-redis-secure-pass

# Deploy Kafka (for message queue)
helm install tb-kafka bitnami/kafka \
  --namespace thingsboard \
  --set replicas=3

4. Deploy ThingsBoard Microservices

ThingsBoard splits into four key microservices: tb-core, tb-rule-engine, tb-transport, and tb-web-ui. We’ll create Kubernetes Deployments and Services for each.

First, create a namespace to keep ThingsBoard resources organized:

kubectl create namespace thingsboard

Deploy tb-core (Core Business Logic)

Create a file tb-core-deployment.yaml with this content:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: tb-core
  namespace: thingsboard
spec:
  replicas: 2
  selector:
    matchLabels:
      app: tb-core
  template:
    metadata:
      labels:
        app: tb-core
    spec:
      containers:
      - name: tb-core
        image: thingsboard/tb-core:3.4.4 # Use the latest stable version
        env:
        # Database config
        - name: SPRING_DATASOURCE_URL
          value: "jdbc:postgresql://tb-postgres.thingsboard.svc.cluster.local:5432/thingsboard" # Replace with RDS endpoint if using managed DB
        - name: SPRING_DATASOURCE_USERNAME
          value: "thingsboard"
        - name: SPRING_DATASOURCE_PASSWORD
          value: "tb-secure-pass"
        # Redis config
        - name: SPRING_REDIS_HOST
          value: "tb-redis-master.thingsboard.svc.cluster.local" # Replace with ElastiCache endpoint if using managed Redis
        - name: SPRING_REDIS_PASSWORD
          value: "tb-redis-secure-pass"
        # Kafka config
        - name: TB_QUEUE_TYPE
          value: "kafka"
        - name: TB_KAFKA_BOOTSTRAP_SERVERS
          value: "tb-kafka.thingsboard.svc.cluster.local:9092" # Replace with MSK endpoint if using managed Kafka
        ports:
        - containerPort: 9090
        resources:
          requests:
            cpu: "1"
            memory: "2Gi"
          limits:
            cpu: "2"
            memory: "4Gi"
---
apiVersion: v1
kind: Service
metadata:
  name: tb-core
  namespace: thingsboard
spec:
  selector:
    app: tb-core
  ports:
  - port: 9090
    targetPort: 9090

Apply it with:

kubectl apply -f tb-core-deployment.yaml

Deploy tb-rule-engine (Rule Processing)

Create tb-rule-engine-deployment.yaml:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: tb-rule-engine
  namespace: thingsboard
spec:
  replicas: 2
  selector:
    matchLabels:
      app: tb-rule-engine
  template:
    metadata:
      labels:
        app: tb-rule-engine
    spec:
      containers:
      - name: tb-rule-engine
        image: thingsboard/tb-rule-engine:3.4.4
        env:
        - name: SPRING_DATASOURCE_URL
          value: "jdbc:postgresql://tb-postgres.thingsboard.svc.cluster.local:5432/thingsboard"
        - name: SPRING_DATASOURCE_USERNAME
          value: "thingsboard"
        - name: SPRING_DATASOURCE_PASSWORD
          value: "tb-secure-pass"
        - name: SPRING_REDIS_HOST
          value: "tb-redis-master.thingsboard.svc.cluster.local"
        - name: SPRING_REDIS_PASSWORD
          value: "tb-redis-secure-pass"
        - name: TB_QUEUE_TYPE
          value: "kafka"
        - name: TB_KAFKA_BOOTSTRAP_SERVERS
          value: "tb-kafka.thingsboard.svc.cluster.local:9092"
        resources:
          requests:
            cpu: "1"
            memory: "2Gi"
          limits:
            cpu: "2"
            memory: "4Gi"
---
apiVersion: v1
kind: Service
metadata:
  name: tb-rule-engine
  namespace: thingsboard
spec:
  selector:
    app: tb-rule-engine
  ports:
  - port: 9091
    targetPort: 9091

Apply it:

kubectl apply -f tb-rule-engine-deployment.yaml

Deploy tb-transport (Device Connectivity)

This handles MQTT, HTTP, and CoAP connections. Create tb-transport-deployment.yaml:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: tb-transport
  namespace: thingsboard
spec:
  replicas: 2
  selector:
    matchLabels:
      app: tb-transport
  template:
    metadata:
      labels:
        app: tb-transport
    spec:
      containers:
      - name: tb-transport
        image: thingsboard/tb-transport:3.4.4
        env:
        - name: TB_CORE_HOST
          value: "tb-core.thingsboard.svc.cluster.local"
        - name: TB_CORE_PORT
          value: "9090"
        - name: TB_QUEUE_TYPE
          value: "kafka"
        - name: TB_KAFKA_BOOTSTRAP_SERVERS
          value: "tb-kafka.thingsboard.svc.cluster.local:9092"
        ports:
        - containerPort: 1883 # MQTT
        - containerPort: 8080 # HTTP
        - containerPort: 5683 # CoAP
        resources:
          requests:
            cpu: "1"
            memory: "2Gi"
          limits:
            cpu: "2"
            memory: "4Gi"
---
apiVersion: v1
kind: Service
metadata:
  name: tb-transport
  namespace: thingsboard
spec:
  selector:
    app: tb-transport
  type: NodePort # Or LoadBalancer if you need direct device access
  ports:
  - port: 1883
    targetPort: 1883
    nodePort: 30083
  - port: 8080
    targetPort: 8080
    nodePort: 30080
  - port: 5683
    targetPort: 5683
    nodePort: 30683

Apply it:

kubectl apply -f tb-transport-deployment.yaml

Deploy tb-web-ui (User Interface)

Create tb-web-ui-deployment.yaml:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: tb-web-ui
  namespace: thingsboard
spec:
  replicas: 2
  selector:
    matchLabels:
      app: tb-web-ui
  template:
    metadata:
      labels:
        app: tb-web-ui
    spec:
      containers:
      - name: tb-web-ui
        image: thingsboard/tb-web-ui:3.4.4
        env:
        - name: TB_API_URL
          value: "http://tb-core.thingsboard.svc.cluster.local:9090/api"
        ports:
        - containerPort: 8080
        resources:
          requests:
            cpu: "0.5"
            memory: "1Gi"
          limits:
            cpu: "1"
            memory: "2Gi"
---
apiVersion: v1
kind: Service
metadata:
  name: tb-web-ui
  namespace: thingsboard
spec:
  selector:
    app: tb-web-ui
  ports:
  - port: 8080
    targetPort: 8080

Apply it:

kubectl apply -f tb-web-ui-deployment.yaml

5. Expose the Web UI with AWS ALB Ingress

To access the Web UI from the internet, set up an ALB Ingress. First, make sure the AWS Load Balancer Controller is installed in your EKS cluster (follow AWS docs if you haven’t done this already). Then create tb-ingress.yaml:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: tb-web-ui-ingress
  namespace: thingsboard
  annotations:
    alb.ingress.kubernetes.io/scheme: internet-facing
    alb.ingress.kubernetes.io/target-type: ip
    alb.ingress.kubernetes.io/certificate-arn: "arn:aws:acm:us-east-1:YOUR_ACCOUNT_ID:certificate/YOUR_CERT_ID" # Optional: add SSL cert from ACM
spec:
  ingressClassName: alb
  rules:
  - http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: tb-web-ui
            port:
              number: 8080

Apply it:

kubectl apply -f tb-ingress.yaml

Wait a few minutes for the ALB to provision, then get the ingress URL:

kubectl get ingress -n thingsboard

6. Initialize the ThingsBoard Database

First, check that all tb-core pods are running:

kubectl get pods -n thingsboard

Then exec into one of the tb-core pods to run the database initialization script:

kubectl exec -it <tb-core-pod-name> -n thingsboard -- /usr/share/thingsboard/bin/install/install.sh --loadDemo

This will set up the database schema and load demo data (remove --loadDemo if you don’t want demo data).

7. Verify the Deployment

  • Access the Web UI using the ALB URL from step 5. Default credentials:
    • Tenant user: tenant@thingsboard.org / tenant
    • Administrator: sysadmin@thingsboard.org / sysadmin
  • Test device connectivity by sending an MQTT message to the tb-transport NodePort or LoadBalancer endpoint.

Production Best Practices

  • Managed Databases: Replace in-cluster PostgreSQL/Redis with AWS RDS/ElastiCache for higher availability and managed backups.
  • Auto-Scaling: Set up Horizontal Pod Autoscalers (HPA) for each microservice to handle varying workloads.
  • Monitoring: Use Prometheus and Grafana to monitor ThingsBoard metrics, plus AWS CloudWatch for EKS cluster logs.
  • Security: Enable SSL/TLS for all endpoints, use IAM roles for service accounts (IRSA) to grant pod permissions, and restrict network access with Security Groups and Network Policies.

内容的提问来源于stack exchange,提问作者Vishwanath.M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:12:28