infinimesh

Apache-2.0 · device registry · MQTT · digital twin

Connect anything.
Change everything.

An open IoT platform for a fleet you can name, authorize, and shadow. One tenant graph. REST, gRPC, and Connect on the same API. No vendor lock-in.

What it is

Smart devices should use a resource when it is needed, and stay quiet when it is not. infinimesh is the backbone for that fleet: register a device, decide who can see it, and keep a live shadow of what it last reported.

The project is open source, Apache-2.0, with no private fork of the platform. The same tree runs on one machine with Docker Compose, or in a cluster with the Kubernetes operator.

  • RegistryNamespaces, accounts, and devices, with access down to a single device.
  • ShadowDesired and reported state for every device, over MQTT.
  • AuthTokens on port 1883. Client certificates on port 8883.
  • APIsREST, gRPC, and Connect from one service.

Two pillars

Asset management

See the fleet as a graph that matches the organization: groups, projects, and the devices inside them. Permissions follow that graph, so a team sees its own assets and nothing past them. Gateways, edge boxes, and devices that dial in directly sit in the same registry.

Device security

Provision a certificate when the device is built, and present it when the device connects. The broker on port 8883 requires a client certificate and checks it against the device record. Tokens cover the simpler path on plaintext MQTT. Transport is TLS 1.2 and 1.3.

In the platform

Device management

Namespaces and devices, with permissions that stop at the device you name.

Device shadow

Desired and reported state, both ways, for each device in the fleet.

MQTT bridge

MQTT 3 and 5 into the shadow. Plain on 1883, TLS on 8883.

Console and CLI

A web console for accounts and devices. The inf command for the same API.

Connectors

Addons sink the fleet into Elasticsearch, Snowflake, SAP HANA, timeseries, or object storage. They are not part of the platform process.

Your infrastructure

Docker Compose on one host. Kubernetes through the platform operator and the cluster recipes.

Where it fits

Electric grids

Long-lived assets on a low-voltage or high-voltage network: meters, transformers, switchgear. One registry for the fleet, a shadow for the last state, and permissions that follow the operating company.

Renewables

Wind, solar, biomass, and combined heat and power produce a steady stream of telemetry. The shadow holds the latest point. Addons carry history into a timeseries store or a warehouse when the business needs the archive.

Automotive and mobile

Vehicles, robots, and drones that connect over changing networks. Certificates identify the unit. The shadow keeps the last good report when the link drops and resumes.

Industry

Lines and sites that are far apart, on LTE, site networks, or a gateway at the edge. Devices report into MQTT. Operators read the twin and send desired state back without a custom broker per plant.

Install

One machine, with Docker and Docker Compose. Go 1.24 or newer if you want the CLI.

git clone https://github.com/infinimesh/core.git
cd core
cp .env.example .env
docker compose up -d
go install github.com/infinimesh/inf-cli@main

Local default domain is infinimesh.local. On a public name, Traefik or Caddy with Let's Encrypt is in the public TLS guide. A cluster install starts from the platform operator and a recipe in k8s.

Repositories