This version of the documentation is no longer actively maintained. The site that you are currently viewing is an archived snapshot.

For up-to-date documentation, see the latest version.

Binding running services to an IoT core

This sample shows how to bind a running service to an IoT core using GCP PubSub as the event source. With minor modifications, it can be used to bind a running service to anything that sends events via GCP PubSub.

Note: All commands are given relative to the root of this repository.

Deployment Steps

Environment Variables

To make the following commands easier, we are going to set the various variables here and use them later.

Variables you must Change

export IOTCORE_PROJECT="s9-demo"

Variables you may Change

export IOTCORE_REGISTRY="iot-demo"
export IOTCORE_DEVICE="iot-demo-client"
export IOTCORE_REGION="us-central1"
export IOTCORE_TOPIC_DATA="iot-demo-pubsub-topic"
export IOTCORE_TOPIC_DEVICE="iot-demo-device-pubsub-topic"



  1. Have a running Kubernetes cluster with kubectl pointing at it.


  1. Create a Google Cloud Project.

  2. Have gcloud installed and pointing at that project.

  3. Enable the Cloud Pub/Sub API on that project.

    gcloud services enable
  4. Create the two GCP PubSub topics.

    gcloud pubsub topics create $IOTCORE_TOPIC_DATA
    gcloud pubsub topics create $IOTCORE_TOPIC_DEVICE
  5. Setup Knative Eventing.

GCP PubSub Source

  1. Create a GCP Service Account.

    1. Determine the Service Account to use, or create a new one.

    2. Give that Service Account the ‘Pub/Sub Editor’ role on your GCP project.

    3. Download a new JSON private key for that Service Account.

    4. Create two secrets with the downloaded key (one for the Source, one for the Receive Adapter):

      kubectl --namespace knative-sources create secret generic gcppubsub-source-key --from-file=key.json=PATH_TO_KEY_FILE.json
      kubectl --namespace default create secret generic google-cloud-key --from-file=key.json=PATH_TO_KEY_FILE.json
  2. Deploy the GcpPubSubSource controller as part of eventing-source’s controller.

    kubectl apply --filename



  1. Install the default Broker.

    kubectl create -f - <<EOF
    kind: Broker
     name: default

GCP PubSub Source

  1. Deploy gcp-pubsub-source.yaml.

        docs/eventing/samples/iot-core/gcp-pubsub-source.yaml |
    kubectl apply --filename -


Even though the Source isn’t completely ready yet, we can setup the Trigger for all events coming out of it.

  1. Deploy trigger.yaml.

    kubectl apply --filename docs/eventing/samples/iot-core/trigger.yaml
    • This uses a very simple Knative Service to see that events are flowing. Feel free to replace it.

IoT Core

We now have everything setup on the Knative side. We will now setup the IoT Core.

  1. Create a device registry:

    gcloud iot registries create $IOTCORE_REGISTRY \
        --project=$IOTCORE_PROJECT \
        --region=$IOTCORE_REGION \
        --event-notification-config=topic=$IOTCORE_TOPIC_DATA \
  2. Create the certificates.

    openssl req -x509 -nodes -newkey rsa:2048 \
        -keyout device.key.pem \
        -out device.crt.pem \
        -days 365 \
        -subj "/CN=unused"
    curl > ./root-ca.pem
  3. Register a device using the generated certificates.

    gcloud iot devices create $IOTCORE_DEVICE \
      --project=$IOTCORE_PROJECT \
      --region=$IOTCORE_REGION \
      --registry=$IOTCORE_REGISTRY \
      --public-key path=./device.crt.pem,type=rsa-x509-pem


We now have everything installed and ready to go. We will generate events and see them in the subscriber.

  1. Run the following program to generate events:

    go run \
        -project $IOTCORE_PROJECT \
        -region $IOTCORE_REGION \
        -registry $IOTCORE_REGISTRY \
        -device $IOTCORE_DEVICE \
        -ca "$PWD/root-ca.pem" \
        -key "$PWD/device.key.pem" \
        -src "iot-core demo" \
        -events 10
  2. Inspect the logs of the subscriber:

    kubectl logs --selector -c user-container

    You should see something along the similar to:



To cleanup the knative resources:

  1. Remove the GcpPubSubSource:

        docs/eventing/samples/iot-core/gcp-pubsub-source.yaml |
    kubectl delete --filename -
  2. Remove the Trigger:

    kubectl delete --filename docs/eventing/samples/iot-core/trigger.yaml
  3. Remove the GcpPubSubSource controller:

    kubectl delete --filename