{"_id":"aws-iot-provision","_rev":"60-46661e3746311216480c4531221af9f3","name":"aws-iot-provision","dist-tags":{"move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5":"0.1.0-move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5","add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42":"0.2.0-add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42","dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465":"0.2.0-dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465","dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7":"0.2.1-dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7","dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd":"0.2.1-dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd","dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114":"0.2.2-dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114","add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5":"0.3.0-add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5","dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824":"0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824","dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec":"0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec","refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668":"0.3.1-refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668","fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0":"0.3.1-fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0","fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4":"0.3.2-fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4","fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011":"0.3.3-fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011","dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb":"0.3.4-dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb","fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65":"0.3.4-fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65","dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595":"0.3.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595","dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609":"0.3.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609","unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561":"0.4.0-unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561","allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30":"0.4.1-allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30","define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df":"0.4.2-define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df","dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d":"0.4.3-dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d","doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2":"0.4.3-doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2","dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc":"0.4.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc","uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f":"0.4.4-uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f","dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432":"0.4.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432","dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d":"0.4.5-dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d","add-repo-yml-20781bed13ee981641d886b8ed625600026d7980":"0.4.5-add-repo-yml-20781bed13ee981641d886b8ed625600026d7980","dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116":"0.4.6-dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116","dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb":"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb","dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7":"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7","dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03":"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03","add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49":"0.5.0-add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49","add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e":"0.5.0-add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e","add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d":"0.5.0-add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d","latest":"0.5.0","dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e","dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a","dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4","dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714","dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b":"0.5.1-dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b","dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42","dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1","dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd","dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429"},"versions":{"0.1.0-move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5":{"name":"aws-iot-provision","version":"0.1.0-move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.1.0-move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"7665591a6f817f46fa2f73478db3c9c2a3a4d5de","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.1.0-move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5.tgz","fileCount":15,"integrity":"sha512-9WUQ6MtgLGfTum2eMqFiTQGZAZMn8rFvuJqvAvo3Ksf8vw2pjelJKaQ2TZkAWDWze4RO3kZqzf7m4J0jWXBWzQ==","signatures":[{"sig":"MEUCIBQe4PQoZcV/G7dyz+PGd3uzmkNsAxpNdur0Jg67y3uZAiEA5PhFXQroGUt6w5cYbU7n9tDtcs9Dv4ZgY+MK91j5y/M=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299071,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihRCvACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoFcA/+Nf25RcHKTyYHHSNkHmQ2MPLrw1C8cio4ruyzi91CDKfuGTme\r\nDptgK1QfZhZlBywCxsWSQi9otS5ONMRQazNszSfNDkwRDgW00LrePXxTeesr\r\npPV+5AczPipSp9vmciJfO7xz2i0GDnUTUB9X57qdiuj3YCyhNyfgjLJqgugf\r\nW68/u7ENT0KOLDMZrk5RgpiNIDbvdTdCNWUVB6GLGwa64saZKNDmXFk3H7dX\r\n+62Ud0mySZBlhAUNBfcA5T1NCZIEkE4P+d9dcVBEwFG0EipUfAL0oYvL2NuS\r\nCQPiEhHnoTJbSopY9/y1fUxGZFFZ1pFmE5WvdGukwjP8Wmgd3hiS9Mh0hpX9\r\nkVTlOCTnceuSLSGPUxyjZ2WGMfX6y14yANZJ2pDhARQio8EBL/SMfuALelcf\r\nm8nhqF6EDM41l6OV/rQ6X4vZ9rsXX6RykgDuiPY60Lwf6DSq8HekiZczW6kE\r\nVX8gcv0kFEjDAF3BgcLqZiC+BrTdaY+0f6VSZGZXCTksb6ciJTu9BctzwkK/\r\n9NBu52iK/doYr8RFUWAGAxVZ1UtxQM2OzVqPSctQugal8pecoPI5KRTcKwST\r\nKsj+QG78B5Kjv4pHfQhVZum1cY9oPsG64BhVUY9ia94DzFKMVU9pkp6VWOCK\r\nzfXt6Q8kTo6cWa2Lp6AzYok/OZtq1QQueeo=\r\n=Rx/Q\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"38cf947c56ec79b3672515e42a3f0dcb8561a2e5","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T15:27:11.899Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.1.0-move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5_1652887727251_0.646992509007188","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.0-add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42":{"name":"aws-iot-provision","version":"0.2.0-add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.0-add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"e8cd0be89e8d934f8d843050b727186cd6d2bd70","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.0-add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42.tgz","fileCount":16,"integrity":"sha512-wTplFBGFCNuB1a343I9UQtBymw2j9oHfqVWv6DRTrgAC7stFdvjCi8399MzJxbZEktd7RSGjjA6QwlWyFWIBPg==","signatures":[{"sig":"MEUCIHIdv1BiUvbxnJC4m06oDPu8JKI2c4XzzNFpto3eZTFbAiEAtB1g9x6f+b29nYAnTgMLXReVErbK97Dwc2bddNiy9II=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299555,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihU2KACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmouww//XY5UBEk8/4naJnGpLP8vHUshTvwtv8rBlMGXIKm1qi8JwvmR\r\n4gVBTKGDMfyuxd96UASmj2tLMUGQfDMPpAAWFgsCaSkpBUs6DpoM2AQ9YjRe\r\nAhxXfJ8sGJqxowlTba8/Zg3NWzChIedT1x2aMijmbjzsQx9PtAZE6SOpXFtE\r\nhCcEz77m2BdzQVAld8NuKbGtD1wiv8SgZGi7M/nDS8f+Eus3ne6fOHVQW/gK\r\n2z5/F3NPq1fezgGnflgp3i/PtDeoW+mLWaF0zab8Expc1Kv1m8DGKfu4gfwa\r\nsyBlGVGc9rsxz29KmxIHvvhFd+KwMpgSRC/xp9DtTiQP7oWANmugbuFEpJvS\r\nQeNNXekVSDZWrOzZqfb8OxO4I7cYIiK0GaL4CtnYH+7UiAdAfB/y2LBgK5hk\r\nRZ2zYY/2btrqOsSGMlFntOO/f0jeQn76NhVB2XpnBkgAzU88jwHi/rJ6Mho/\r\nrwwCV+/PgrCpluwGe2e0gKEuITaaydA1VoNw3uwWiD7K4SBsSTzfGLWHSCeS\r\naGrB8OWX11r71rF3f9AWhQ5h6aQRBI08SMHTJTrlXExcmUmOE6Ahf7mHsGue\r\nl+brOFb8FGLf33DoiIiGDXHCRYqU7GE7aHOzP9CYuhN8cpQK0g26PoAUpXtr\r\n7OVawYua1a1AYOptRaHaA6eWeH1R6xCRCc0=\r\n=1VP6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_EMAIL | For balena account |\n| BALENA_PASSWORD | For balena account |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. Make sure the Method for the route is ANY and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T19:46:54.955Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.0-add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42_1652903306711_0.9325549491846041","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.0":{"name":"aws-iot-provision","version":"0.2.0","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.0","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"d170356dfd7cef4b3232cedecb1171a33b108be6","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.0.tgz","fileCount":16,"integrity":"sha512-4AIFvKLf6nL8kFWxEwqpAE6u2qeqHWOJVWZ4uGdC7oYBIuyrT5qJS9lbzpMztWVShFyJ8iy7pCRR3zcSHwLs7A==","signatures":[{"sig":"MEUCIQDrn1KngU5MNITOBGRVz1cZVBFYlXNFJcuajiHNSVbUSQIgE+de+6w7yE9PQWu277/U1bDGYr62D8J9zKNDMULECx4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299499,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihU7GACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqZcQ/+M4S7wzZ3zxdlHWqVf3TTl0s/QnmrP0EXg/6fx40gnweBO4qM\r\ndv0TmBfN1mGKcK/9CYt0CZ3YvSEy4EAqGYYcjIESdUqJphalND4l/wDyUSO3\r\nyjuOXTWo0XeIiR/kG8Iej6G9+AfMZS678NkXj6Bl338AA51hgmdKTbtyR6iP\r\ngxU0rotHKedaTM8KfsrJbG8AnZILktBNqlN6RxPPb1ijSxc3QUn6Pmcbd3VO\r\nUwjnPXPzbUQTFuj2Shb+SeHD06b1GwZdlLaFjMZq4WHlNXxrBf+Xc644fej1\r\nMNbFlWf0dToeyi10FiPOQJiwXglG+SdR+V5e/FrGwtRfOqRu22HMnuOuV++D\r\n9musPKxFe0MjMFXa4QgXvWDy3/3w61Aa6E04vEypM2iF23DKUjMhWg2v8eBx\r\nkeI1Hpz7pYTcEDwtN5bcmdrE4MMRg3HFqxxAkM65b3ZGKwg3xEpDhQJj+2GI\r\n1zETngY0exeSxd1qt0fQSxyJ2Iw+9EgT4w4GCsuHOZ2FlplYUxrYdQQsoji0\r\ngvRLKDlwotg9Wn5TNTPeC+CIs9VpOLNb023EGj4GMKxjscp4id28VVMCnr+3\r\nZ14Cy1+zB0BH9hGjFFeNKpQBqTsI3J5gvLfJcxmZW1eW1YAWsFQ+F8Z+Ky3P\r\n6G1AYhagsTWPQZT+22MmWJX4tePdQzP8E58=\r\n=bWT+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"a999f931aab288a03475e4b651755912a3eb5a4c","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T19:51:38.856Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.0_1652903622134_0.6854857906035736","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.0-dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465":{"name":"aws-iot-provision","version":"0.2.0-dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.0-dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"a49df392997216d982dc459621c178cfb0b859f6","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.0-dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465.tgz","fileCount":16,"integrity":"sha512-NuiGd8dH66e8WMTdhnxEB+SO3TnRdMzKYu1VV2MUASEAcaOVyCKsSfN2TQ5r+mBSOq077HiV0SyyGBDoLiLbBg==","signatures":[{"sig":"MEYCIQDZ4SP8riC8KFIHnD4ZPYIn8k1fD6V5k4AzFLgjGI5bfAIhAJDi+okh6DXsndL8IAhL3D7vznhIQbnAIRCZ+gcA+owj","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299650,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihU/GACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpOqhAAgqptqCUZVOJkRvfCuWXUzY625gOlFjhj0S8FpCNLRHD9GfVj\r\nzU14bE95S2B+iwupEaxtoN48TsqA42E+7rdXpKKOjDLBVNTWp2caIvcpn0+I\r\ncWtZ/dfJS6cSEb2j1BBPYaPvlC6h0TLYRvIp1QxQJHmPks8Sm53pMTxC0i6U\r\nX2FtUkaaU3gk/lnBkWSMzojXF3TPvnD9Cxqai3Mt9pa9h8aRn5nzNu7Y0bf/\r\nh8xp+XQNuk6OwH+8tJU4O/5CY1uoKJsGP7afUYeIAuHFgllR5j5xmFJcrWIA\r\nwgD6Dmzzbl+5tIvNnFetFKwEXK0d562hwZxLqXl1cB7Rt89lY7KdzUu/6MlX\r\nBScyLkphSJ15sZimZerEcaUWO719oG2ClIYIUBGb3W87nhe/wo8OketxEEiH\r\nbp/iFDy9y4AxDR0Jmk78g+ZkI3ExelkSaNvbI4Yg7n2CCOEGFVTtNyzxBYpH\r\nnjr5hSN9VCwxzMQc8HPZvCTY85zrafJsd0QnQ1pOKhoyt0hw5PAD/ZC0rceU\r\nRbr3u68zJEO3vXMiZ33+0CbtvtkeePlhwFyfRBai7RURqB2xGhvo+EmVaXrK\r\n3T1DspPnsuiohVZHLFaVC3flLDK3wjcr79MP/nzQpgD/RIT3SFJCgwUP+M9S\r\n/PKVYEMwGbxbruIxGeXAVrv6P3gCzCgmnPU=\r\n=YS1s\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_EMAIL | For balena account |\n| BALENA_PASSWORD | For balena account |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. Make sure the Method for the route is ANY and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"4e87b386b5bc6edda3cf0f4ccff5094017bd1465","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T19:54:06.144Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.0-dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465_1652903878422_0.4291568389852567","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.1-dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7":{"name":"aws-iot-provision","version":"0.2.1-dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.1-dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"332799338de519a6d28b102035fa0cbc855aa524","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.1-dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7.tgz","fileCount":16,"integrity":"sha512-iEoA6yzobPXtyIUPznlBnRtioSOlT4cMuAmXyZv7qODVk9bwwJNczgzbIF5JF+tW3Sn/FJgt6mIqlBZ15AaGLw==","signatures":[{"sig":"MEQCIBgKat7mg97NrOytkoNOM+Bt2udCeZuPBYWElWb/SPVdAiBepGkFfjx6xQ/Xl9bw56MiJDsQAbQ6mBGCQAbAPsKo2Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299666,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihVAuACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqTOQ/+MN8UCL7VnjVO+Sflf+XtnGYYA5OKYSo/UcLTKjo2XGYETV41\r\nHIDi4XzcwgArT9POzAoI6KFRdVB1cO5pNNWnbm8uF/auqnKs/Rh4bwqDfZ2E\r\n83tBnOfYXswmfn0xXDVENG8ZOO33KahR0QoCeRb0hkxUrZGLdLlqc9P7Vfy0\r\n7pZMbDsvGYJscAd3oRZmt7qtjjSgJbNABkOAzye8Rncquu8bc/3vFbyqPnna\r\npeb2vtaqjUfNLR+qLCFX7pQ9xwXOqPGVovP3Ta4AK1M5VcKN/ys6GgS4d91O\r\nL085B5oV+gskufhIIf3VRxjZU2h/zVPitRUSTmoerVwNSj45GvildpGqSZhq\r\na3pQh01pBrgA+zStYAVTVDVauSAERd0H5Y7Vm/QK3vv2kvf38k8pxw0o0cT+\r\nXf4mtfVfZIZMZSjDKF4x9KuMwb11E+RotAAbjqLrY935qHK3jtTjtpCWb06I\r\nOPsUcYLnvieiF9xw4BkUBkLdQOUKCP1yus4qqm6HnPBF1JkjpZAnFn9AOX7q\r\nlCowfEusLUbSOrxpbAHg0zA0MToxVv+9Y3jAnNoguNXW5CZnVZi/flUosTEm\r\n1zGbGyYsuLamGwsOEVfioIQVg4kgvR/KvrsdJvyblF/Ub7dFbz35bChHZ92N\r\nQN2ByITMgPx2oNH6ruiol0rzb4FaatwtQh0=\r\n=0R4T\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_EMAIL | For balena account |\n| BALENA_PASSWORD | For balena account |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. Make sure the Method for the route is ANY and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"6083eab67d8c3141e01a972094cecd67957348a7","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T19:57:45.474Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.1-dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7_1652903982458_0.5896284617581855","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.1":{"name":"aws-iot-provision","version":"0.2.1","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.1","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"962f16035c740cbd1d33ee76f7f91145005e148d","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.1.tgz","fileCount":16,"integrity":"sha512-X+TBj9liQM1VgL5T4y/Q/0A2SH9HxY+9yVP0zhYFWnaGh280hHj2xhNRsWvq2aPuB0m7DXaQ+xngxcDWR3l7Yw==","signatures":[{"sig":"MEQCIDfQgBxwdkDUpC7juDWWRuRGhIqJSU+4cn8X54eU1CLlAiBd8scPsdET3JjfRr8AiEAOd96LInVVgq1ZsfKNoFBmXA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299587,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihVZKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpL3g//WoAra1rBFoAKMEIAmU0c4sbR5Dme56xuXjhkR1mvua6hCZoY\r\nfBPUuVX2RyqMxeThd12z+iqiCWQEpLIoXmH+w2CSzpuDx7qe4aYTuXU4RAku\r\n1lJgMbqofdTun18C8AnOkLesrtIkGU4J3cgtdKpMohWbJ5WD591vmNpJs42I\r\nR3ikxKjrRNKaUBsKZ5uJjSASDGm9MV5lUFL2w0WL7lNyYU3G3CIxBIL7IAxY\r\nxwlo42sMzhQMVopoCOuH9Rt2MEkuEObWlDi8k5xNrSW5hEr2d8y/0YpGIkNI\r\n9cxJaBOuvuRktdh0ZCtK86VhhhyWXqjKGNnt01/M7PSk68XgDrZIAdJrP59h\r\nRECeavIG4CK+Q5GYSGEJ4ON8GsoxaZ0c0R66B6ik/5LHaQUTe+uuO4fwMj+5\r\nnyHVhdfVB/aOsGEHzObc+OB5yTD7xkXQ/Cf6pLr7hVL3FyZtNKTwJPTepmsZ\r\nsyL+V1Ml23UNOjMlohovc1mrNWY2Xxfl06EfaOq8ZM0mu44cQgKuwoeBExko\r\nAF/C1X6vanqMwPYJqhzPk6vO+gvyIApzvVLyYnya8bnOT8SB/y3jAtpKs22Q\r\nIH83HtOQaULXBMpW19W/K7LVnxh1mUCyo0sFH8oFYOP+/hmxEHfG0D4csFjT\r\nxkJ6oFBMgYTnV1UdE/0vin2+IcNC0xGnFh4=\r\n=lDTm\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"06e66a903f29a7eaac228bb94d27b68b2f8fd6cc","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T20:24:12.791Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.1_1652905546470_0.1021859458897405","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.1-dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd":{"name":"aws-iot-provision","version":"0.2.1-dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.1-dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"efcc30a2b6292ed19a6f3c06a8f124df28a6279a","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.1-dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd.tgz","fileCount":16,"integrity":"sha512-VQgicl6vh5GzDry+7OMGtKpzR7U4nAevoNNFaI3PxJTSmEeUVN0KQyFWAUIMChlNkL7nBgIGBaszN10RrA8Adg==","signatures":[{"sig":"MEYCIQDuOrxiARDRypwCenWyc+2Nfntahp9x13pTcBhV6/i1uQIhAJ6bNdYcJTC1k4b9bkrhETjAfmUQUgJDFhlqt6PtdOk1","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299728,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihVatACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpvsg/7B27tJpa+l3yrutoA7F7tQjkD+B78LsyC0uY4y/JXAj+2zPbE\r\nmPZb/MLTRIcHRh0J6ZaxgTSEjQMIztkMQNGr9agxViONPg/1XWYHxoaIynL9\r\nBJG6GYhnyFXQ/ECHmz1JHHxzha1nDds19ZPdbwIDTQGbSTgtyG6rD0VwA5at\r\nZadZX7OR6qpRd1gq7cjwHENOpKq8gEh3fFLdG9akKCcigwBLfxz5fAeKxItL\r\n6Vo4P0TGIbaiht+gejZcf8oJV8mSOqQZg3QoazDEEiv3Jgmn4F+OigUiyZEm\r\nw2TO9IInjB8MN8LIiuCtYYh+yVN6ePnu9rf1XJd5DndMn6hoj+ntu6nzY63n\r\nOfUfyL30opPnEqxvM8vmj7u7ruPUgUWPtx5UOn/EXE47F3z2gvZ33ipOYmA1\r\nNAhWU5jm8LjQ9scFbQS58zm+jmlQDaMj7J3p8PDrPjEMSWHZo9/u78QyhnHz\r\nMiaeWrBtNSuXbONh/ZWGsc9vP7EGuDeEeBUvfpux/MUdaXoZXk9mhyP6wQUh\r\nuL8jZeS2mVcPaMxT44Lr7P4oTryREswG64QcekIAaUzLVL9LiDXI3r8JGr/G\r\nR4gu6qJK11WH2ZkPDh8CB4ELriUs0yFRnd5DcQhMQsyhDrcZLW0faSobMeLV\r\nbLtyp/J4bUr1aVBPSTWgZt+icxKloZBl1DE=\r\n=GX71\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_EMAIL | For balena account |\n| BALENA_PASSWORD | For balena account |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. Make sure the Method for the route is ANY and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"c80da8bcb6bdcad2785a57da444eeaea318533cd","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T20:25:17.848Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.1-dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd_1652905645456_0.5822620378707895","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.2-dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114":{"name":"aws-iot-provision","version":"0.2.2-dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.2-dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"b660719f75451d400a4ecb588c002d3c43cfc4cd","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.2-dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114.tgz","fileCount":16,"integrity":"sha512-p/BP4WKpZeSGQ17bmL5VcIP5+8MCEMaJequdMrlsGPrv71yT+8TuXQA45XL4j2WhumFj3vwgzURUQ6V54UGX5Q==","signatures":[{"sig":"MEYCIQCApno3yvUuzApMccaOGFme7Hl4h83kGd5BS96l1pKurgIhANRdhewX2rGFD6121Ss+STpJxyAT7P22hh0bI2YabuLU","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299755,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihVhJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrjQBAAl2sFVklRwl9gRa8JrEl7Z6p3UHxzI7v+ae+9xvO60mX1QLJh\r\nQg28fWjg1EozUW9jpW4O/aYcyCFiCzM9tJa9cDzNIkOA4r75PBnkVGJJj8TK\r\ng+vgqfQWnB2ag4XZ+rH6F9v1ati82XDADqJ/rBWWn6uOsLY813HmpUEAWUNX\r\njHD25cwES4hPrW1/M8bFDaQFUG0Pt8JlCIpMTPWIUEqJTysBGTv4F+QFTwcW\r\nE8MCIoxpdhxn7rh+eCm3+EDqcb08vkAHv0uTMoRjpesFVSw51sjObRB+68vV\r\n4uMcQHjcZTvfviubbUwk+9egkLq77urdQg+s+0rz8qPSiO9EEuFv3IhRvZ/n\r\nnxbns/D9IhAps5FtaGMH3Lbv9ZfE1LN8yopuegL27bDoiPLM31H/0QMF0rEy\r\n2Dp7U/xdH/jBIFv6o6Cx5XZvYDVnJgJsG5oOnV4qBa12Gzjtp5DTwCdVZVOQ\r\nARcRBGsxMJJWBC9qHXl7t93TPmo/7GaHvQVOev2VEIwv7JeTypnfRbiYTUPX\r\n2aSksp8fTKCBNAyHd56RcT1BKmxGxaQZLc1kKy9JLXCGWvr/gWIP4KOJr30g\r\nHoy9anOfYV5l/OaWXNRDSFkTMHMeglY7BgWRPnQYa2e2JXZWVF6lf4EE+aTF\r\nnnvphPHw0a+x2vfZaqO3O3WFAd7B7F+p5bY=\r\n=2+8E\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_EMAIL | For balena account |\n| BALENA_PASSWORD | For balena account |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. Make sure the Method for the route is ANY and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"4e248631bbbe37e433c5d290a1a0edee0a833114","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T20:32:27.984Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.2-dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114_1652906057269_0.5186924583472856","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.2.2":{"name":"aws-iot-provision","version":"0.2.2","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.2.2","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"42d09c2d143aaa833281851169b6469b1238e836","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.2.2.tgz","fileCount":16,"integrity":"sha512-uDEvARbtc2FBAFuTYTYNELdQcADP+ES+9tACH14hAwxfbniWUcbFSL8ty8n/7qN9tJKlCf7bGKgGkHidQSAnzw==","signatures":[{"sig":"MEUCIGfuMSkxjEIIwP3fbFaJFB54ezu1EIpLU9NtsVNJLoWmAiEAtMOAZxjUSNLtyTciEqZpnjNBPuoIawqVzlxDq44AXg8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299675,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJihVpRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqeIg/9EgMPUEPbIwWwv5iNeFg3MTaKuBA/iRzolwaDF9bDCSZVjm5Q\r\nhdg3MvgvwclKPIchsd8W20xjp++4GNMd/UwYqE3yO71p0zVYqN0ZvsUtouck\r\nJV8bGbTRMfjdMoHxXFD/4t1yIKXFB6kwT6oDZq4APwxiI9yveDfUCAawYl+7\r\n6HukBvhCZQWWezQSb7k1TYAMd9ksGb9d9a5OhoqGUPPZLx1WzSoyPfmAQI1t\r\npPEGb62pg/vDEbfjVStw94ls2KYGAQzPJFot4LX0S1YakRStO91cD5L4z2FY\r\nKPQcfg6JtxDypG7KvMlu2dpjQrxb3OWnwaH7sLCZuF7Uv5CiOoOCRtqPp0Rj\r\nACoTsq0sZuSs1QoXNflr3j4L5uRHhSvQm3sZes0jQzPnc7UfZEXOKh9Qgu/J\r\n52nS4Tl52RrACaSShro1qrmPbdboUMr+U6wfcKw6THP48h4Tlqdpd960H44J\r\ndVrnkATr/dGA8p/AyEAJJmMkDE8RkabK6v6PEBMGJU3eMHWFVyG3u/E7mfDZ\r\nd3vdFdc3cnrVQMJZapqnBJKBCZScWP+TKNyzIVmzjz222kBBJLGzHbe/iFQC\r\nIeACO5yiAgpPUkGdRSLGhsd9mbuDOWxYAs5fug2LbDe9hQJB13RWM3F48YPf\r\nKmNGCc3rN1M20CX1vXZCd+7ziWUY+//Fncs=\r\n=F+3+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"8265d02c0001d46d025d26fe6be081043e29e83f","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-18T20:41:11.579Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.2.2_1652906577440_0.518867806423144","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.0-add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5":{"name":"aws-iot-provision","version":"0.3.0-add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.0-add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"944396951a3f00fc0853721901fb99bc3a92fc4a","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.0-add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5.tgz","fileCount":16,"integrity":"sha512-UsAp/FQvBcnL9DiLhO7HuCojjeSEkaj46IG891Rc0kRu6GL49U71cN7b2k257mrI8m+IJHTRRQ11Zz4YQYhLqQ==","signatures":[{"sig":"MEYCIQC784Pj+tCSJvHy2loa42tiaa2fOqPm8vEH7TgwIPLESgIhAOARkij6hE2B69mC1JTMiaQcW80afBJ6f3/PEc0vKj/x","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299791,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiiQtkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoVxA/+LhIWx9E1mAq6wEjTO73XauEuPyV2feZG4T/uP6D9yIjmYeoo\r\nk0Zo0YsW+bEwxc/VStQd8z0Is2+isRQeuBqJ7f4w04IL1RV0WWM7Z8Fgheia\r\nvNP2sSG2NTDyFOyOPAqcJl8NewFwAus9F/40nZXcvbL78RJSav/83ovapjc0\r\n+rnvcqrsIacRxoAQrqJ3dfJjkJXCFBlBkWCV10xrC1EwVJWqF0LSED07CLMM\r\nBgGSflQ+4Vr1Qujw6tG3Gvb+h+Wy7cNFY8jpXlziNg6UudbDvjNMLbRHnDVR\r\n6HKG9Kv/Bg6dYNqhfqxbX5wisVHg38Aa52nEL9JIveJlfD3lfeuy24WZVshU\r\nt5Y94Ni3/DC33Jpjf8uHqtXbI09zP9gS2y55KBTh8G1GFJqV56x1ogeEJtjN\r\nikij1qa92eOWk+m15zzGVSxn8zEjS+unLhNSg/s4+MkCCBqL35uNtz6VHt25\r\ng+OrKj6UOdTMYG2DhNTIyIgoEyIiS0GpnlWMwWWTYI6WIsY0SxtNP5lKHXQ9\r\nb22B9jGe3U2KJEVtuU7OWXFDviKZRfB1yPzTRfrGhFUBnZsHSyBV4hWFZKBN\r\naPe0LyD8qqFYXItpc2udp9s3r+1Tfz+cmEP+xQYM0mYG04EaYjlDRdURhP7Z\r\npJmkndo1vRUsysUimcu5sFTiESqse423Xuo=\r\n=lt5e\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-21T15:53:21.296Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.0-add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5_1653148515824_0.6396728475831837","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.0":{"name":"aws-iot-provision","version":"0.3.0","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.0","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"1a30f904087407aad32f07091634520ed6450935","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.0.tgz","fileCount":16,"integrity":"sha512-KqAfCey1WloLEeHplitmnZ1nguHDtAC7mwg/DG+crKQaeUSY3f3J+CuINeGWVeBjtG9MIVgGPhrsbXwxcD86Aw==","signatures":[{"sig":"MEUCIG4lLQx3FN58hezM4+WBJVtP1c6JdN+wqLMum6+XR25bAiEAw5Pul+IGVPi9G50h23qVFKZuUHetok2Wkus4zZj/wDE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299727,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiiQx2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqzthAAn36kZkzLYryMPOfpUkLfZiTVQo1fH3UBc1xhq+JlgxobUAOD\r\ne8D0bp26ybZSVx87evi4KuorUAcg7eOswFBnucQZGGjqAvnYAopg8JNY2tOP\r\nHwDc34OJmoGRcXovvVZwWNEk/etjX29kV808ne+XytZfco3sSUz2HeeRBt9Y\r\nt/aBX9YXUcLJ6aBvzwZ1BOYZi21c/aqTwOOIRZSw/Z4W69lIIHcdIdiCW8+N\r\n5v7cIR95Q+i2fUdNG6xUpxa9JJkyFFBlmnuzcYM49GqHEsCFiK1wxN2z1dN1\r\nDCqg+LheNjfcroDmhmKkYIN/T1sL30e20YImnIeT6NJYOpSZ0BT1PIK5goKc\r\nOkbtBdoVZhuHgbfKIptP9iordELAEBVEBrZG78b4ZP4lWPFuZtvjTIverzQj\r\nx28FD8F5N/ZoLRqsN0ReE86LTpzHAm0hN8MjDR4yKaIoyi5Wv53k5BqZRh0m\r\n05jSoQ9bbfbGvi/G8KyxwMf7ElPcR6NnmYhyibbML9A8VXVfBO4Gso81KVEO\r\n2TD4Xh1HVSeebyT3sOPyWY9TVtF6GscGlyChy/Imr3mT4NhCYE5Y/WbWTo6/\r\nP7ofd/SBNGSP+xmyTId5x2OJDWjhWuYVjYxSCmPHe7DztW4pqaneR0bGwjP8\r\nMJ02FJR0GYt6SvbqnyMg9cO8wPl++0HyQwc=\r\n=NpwQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"c62f370eeb7028576baa038b50d7189519dd0a15","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-21T15:58:18.578Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.0_1653148790058_0.9375412562636138","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824":{"name":"aws-iot-provision","version":"0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"a419219eec2d0e01f692f103f27abf47183c21c7","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824.tgz","fileCount":16,"integrity":"sha512-63UQvTsf3CGZ0HyFPMlTO8gNe0G2LBq0Fq/UTwERZGWayfNxEp0Pj05Ik2dl+R3C+zYa89O9DqX/JZE50q/NIQ==","signatures":[{"sig":"MEUCIAvc5G6ZTeeNwMbBF0PWt76R3X+UUIbc6aUfK1262qYwAiEAvtFK7eERkiGdmCBcMzKSWUEtQxrcG6DffuxJove00HQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299905,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJii4s1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmppiA//fVOhW2ivBKRPIPxS3XIWRPiKEMjs/h/qoc/ahNnZF5bN1/jB\r\ntd21UPD8t11SfzXytOWGCuj+zF7DbGN6OC7cpZk4yTQEAX9JpMfLcXyTCcYG\r\ndrycY2dxSOkTOWxhweyw4fKVPGx1DlM46j3Fq3I5sPPCMunt9yhM6lHHJyj1\r\nSurLgq8FAVpzwlHR51vOp64W9nTM0ndUwl5CvV1tsVbhEZyjPoRdgfDwv04H\r\n6ZDrTppv75qpnBL76gYND3TwBmRbkFuhohRrw5WQL6HJsW1Ti0ddi8hd38xo\r\n5ByYcwnC0kCPw3xBw9V9xIR3fcztAIBrTnpr8p+PHJlEe/giVQ2ihzB6MJ8A\r\n5wsi5DE+cXUxarPlptsW4VFLReGCHfnoRkB5bxdIql4g59DzTz+BpjAhF8eH\r\nlthK723Qy4euqxoo3kqYVMhHg5TBsnXMkJusCjB16anFjEHX3B6CquwdCpng\r\nlQfOKMFlRN+iHqxsRgL+KU/AzRwRgq5muCdlKxy8aQekL4MvyO+7619CR+1O\r\nZP8eUdEXwR6l/AauxGlL8/4u0SDuQ4nPTu6H5rQClfs5hcNYt9JLk72IkBGB\r\nIsMGk2OwCnKS/94ErE/bELb+0opjZTc2OvliXxdBD329sCggb03QI8LXu4QE\r\nHit0XclUbbrBFakUhDu0ITgBIqEG5Rc73S8=\r\n=yH9L\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"ecacb6b3398c36a9b4038e45758c0e927c7d3824","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-23T13:23:05.429Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.17.1","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824_1653312308854_0.429074791375772","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec":{"name":"aws-iot-provision","version":"0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"04a0f96b3fd8080b7a49bc3cedfef14c83710762","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec.tgz","fileCount":16,"integrity":"sha512-MKYKYakOI6Fi9YnlOr4DjOr7F4rgvQYt2LvuXhtKtM4zwbpTEX6cghjveZap5RD49Mk+kNq4XCPhNYogMLFmGw==","signatures":[{"sig":"MEQCIHl5uyKhmCGfUpdzcxKC3Z6NK9oA9mcq4t/wEAT1hlrbAiAspmWzViFOCSOJY6F/vgznwlIkv0qKdZsZKqisUl7okA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":299905,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJilMddACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoTShAAhEZaX2UptJ9O5fhI7p0Cv3fu/Y+TCIItIUjZfkyC28u/bdvG\r\nkYgRZBWCHYttd/BAd4LVhIrV7bojVGnS6Hra7Xx0A+JSnw1W6xYfeF3dy5QC\r\neWEyACWqVITj22S8WBdg3mEec5T4m/F91x/GwZE9aGTniz5/xx2RN1gfBM/S\r\nSSG4ocdxvvIehSLyrcTaLEwT1LgydXxVqccrObbhdMRPI5Ly0NLj+QKvD8fy\r\n215hesWLfP9OiBmmu8UVrS8x19eEs0kCS+MaUtY8e81FAxl9gxJ/2SGX3CmH\r\n/7uOIfxRqn5k3QeK9JWjlF65IpVVxLCzhjwI+KcpK7iW5ghOLYdWB5Mj0fic\r\nmsQjQZDTzzbh8uZLJdGeKBPNZwXy78sj+3wmE21Ew1OOJv3qzWlEL92lUZFq\r\nnSPsLEgA6Yud78CcK0xVqFytO9OgZ36gouRY7iMj55+oq3b8lcR8rHA7192c\r\nko094IdxM7B741hm92n1/scbGgThCcsWqDmvZoMqVWQYey31nq9q3sP88/+o\r\nAvcAUp8PAynyYT665/oFQerO8YPaofIx2phgjfV10LWPePfBlicZMy60Z29J\r\n+/Cg2imY1Dtv0GfuvkTH4XxAtd7PkbK/DGjhNCtoKH22lvhtR1zv6Qa0PCJY\r\nxuiLVqgI6SjPUlnsYARRTBra0XFszHGbDoU=\r\n=5foE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS IoT Core setup\nThese instructions assume you are somewhat familiar with AWS. See the AWS IoT Core [Getting Started](https://docs.aws.amazon.com/iot/latest/developerguide/iot-gs.html) guide for background.\n\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png), and the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\nYou also must define an AWS IAM Role with permissions to run the Lambda function as described by the AWS_ROLE_ARN entry in the table below. See an [example screenshot](doc/iam-provision-role.png).\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-05-30T13:29:14.104Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec_1653917532862_0.6379010611251588","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.1-refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668":{"name":"aws-iot-provision","version":"0.3.1-refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.1-refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"9f9888924027dbcda329a30416d481b8f91212e3","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.1-refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668.tgz","fileCount":17,"integrity":"sha512-xmhaYDNzFqsvAe5PdhjV8JrelspDPm5WN3GzRd5yECFEzQMmrYH6cYomoEhukZJ0oyqF5vK7/7oOEqduVkOwPA==","signatures":[{"sig":"MEUCIG+P5PZF5fJcYE1LFPTy5n23bWuY2XIfJ3PsdAOWQZH9AiEAjsl8dOq08Hsm+Nfte5QYJS8mB+eH3bwQ7t/UpVDnvLE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":372819,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJil+JRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrF5g//RoxjcpT2GZ/eJZA2lfr+19b4tdaoWI9INi4x6xBKRdvSo/A4\r\nh/VBtR2IY2JYUlK6gVkLarhr9EURJX/p0Ifum072SjuFPhTVLHMBq2jEXa90\r\njlTEGPnlco64ab3Vce6Ri1u3t+7Y/tkNPR+UZ+v3ZBvF3VcdBakVXuaPxmqF\r\nzgxxQeVEcnY+2t8LWFcBz/rFMM+w2iYOwkGJdiUEOy2OdKsDKl/XSHTELl5E\r\nqyzCgpJUH0ypB605XghnygLMfXYEL3rPR/XYJbwnSWKMrQm9+UAgGGt73HVS\r\nHyq1Z+LKwsDMctEEcJRrBF1KqbXGjiUAl3S1Vyu05GmAeDkFkP8tFDry60yh\r\ngnBAJGKIsJ/LR38pwkcCzTki+yYMjOF0ZmX3skkuCVaDtK+x8vRDU2Q+l4NH\r\nBSL3BgUwt3kiSGIRRQT9tzjrWDNOGLpsz42JLKpt5vPqLK/a2mpvEtUIxsyS\r\n19MXCE07gImvlOoFtcmPxhe032k1ElpOmx+77cfbadPY/aVXsOaGK+FUH0QP\r\noFc9aeVGaQ1m80Crv3rZ/xXwTkgVygc7iJqxa3HrPfnlZVcoR/ax/SnoXd2x\r\n0SAMztuCQqzEhbTA1G3OIRY7eSKh2rBLkV8CNmg8kX/5ZKctFIxoboFSZNlb\r\n9xm7UKq+S+t1U+q2CJMr+dVgm2nnuejlyVE=\r\n=sjHh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See these pages:\n\n* [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html)\n* [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html)\n\n#### IoT Core\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the *Create resources* documentation page above for background\n\nSee the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png). Your AWS account ID is available from the IAM dashboard. Also see the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\n#### Lambda role\nYou also must define an AWS IAM Role with permissions to execute the Lambda function as shown in the AWS_ROLE_ARN entry in the table below. When creating the rule, use the \"Lambda\" use case, which allows a Lambda function to to assume the role. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"59295383b7aad4c8eee41215b235ac119f1fa668","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-01T22:02:12.524Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.1-refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668_1654121040795_0.12395854830829744","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.1":{"name":"aws-iot-provision","version":"0.3.1","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.1","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"ca7bc0cca4b7f9c369d9e77ff86b1603abe45d3d","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.1.tgz","fileCount":17,"integrity":"sha512-mULWHV+WvqwNmiwMvW5JtDh7dIIUhIE11bS0cROCw3j4GMwtqDKXK0AoAkkwrkIzljgAWUgkD0jEqG1gwDtyVQ==","signatures":[{"sig":"MEUCIAdMCRIC3Rz7L5rGh2rwVknXYu7qxyJDhBAiPFE2hsHTAiEAn7crW98oyNl+2y6JfYhV42mOApDe83hFrRq20R/XQ7k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":372751,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJil+3NACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmofug//QStmUmV4477XsNZV9eCgcQ2H95HLRu2q+DXRdrjhN08E/k/X\r\nXMpDrwNy9//Yiv3UoCAX43KaveSDj4FiXTAWRYkqdA0lKim58WCoULeYoLIB\r\n7DQwOzXJDpq1q6KvYWbXVIRPRwbtI6wqUScqp26Gw4hq/4seJS5xBjX6XdO+\r\nvzJckp0jElGc3v6e4+FvLC+QxlC9dhsakoSk7XoIrQQjNBaNhEEV9Gbm1zU4\r\nQHWOXhRKXOyBPg+VvhiMoi9iNLFDH/E+f8NdhB0U/xmCh0HCAw5mITuQRwzl\r\nCe+m3koIPISYIrGFDpPg9yleYPqDfzoq1b05/1HPGoA4t3wN9gHiZjMQDl6k\r\nwYIC3E0BKY+A1rfKofXsCTiUa3lfjbMeoi4GnuL8qNE42U+xN4O1EavFmfbC\r\n4eyJo8OgK2oQ3jO1O5JlG6qFhFKv/LqyqfuUwaUdnwGxlY5LxLald4aHLxGD\r\ny3HP6cwoAvRsnUjChYYUQAluMJ728MNRh/PInlJfUQ4yigNFYHinguysaM/j\r\nfT0DL/Z0rtarHzuptGN8p4r2SLomTXUBN4gTrkrHR+0ycEYie9S92t32IiPV\r\ngEv3WjNHiRzgq2WJMiPD8h1a92eqz6wbt7RyPrQQ7nOpleVWLj2Eb6nIJhWu\r\nQxjNZpVacKi23gPTj4zFiFf2iGYWQr+to2Q=\r\n=dtR/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"eb509b8c3897408e3ee40eb98f52cfaf910fa5e4","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-01T22:51:11.619Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.1_1654123981504_0.08679546571555852","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.1-fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0":{"name":"aws-iot-provision","version":"0.3.1-fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.1-fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"653371e2439a5072e285d27de0ab6a876e5ecfa0","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.1-fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0.tgz","fileCount":17,"integrity":"sha512-rx2fVkOmL+Wf+kGGKuPz3DfwC2Jed+9/mMl2MCGZT2qNks0k+ofP0xQIVyPJ+uwjtNud4DPKJV2HZfhKiEw1IA==","signatures":[{"sig":"MEUCIDG6qe4zXfoNQ4X4NTtCEvMh9UauixkvxTo+q2MOehzjAiEAv/x4dKgJQ+Rw2INFDyQhbCkyMlNv1DJhirkvCNGZ9xA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":372803,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJil+7hACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqI8A//fT+xM0v7UriHHqHE3xghIIuMXYRsmvKC8zQV63d8PFIpb1PD\r\nRsUK9EEumLpAqD8rptdpIKQHkRiGipE5nrhtaDMEzlLFcpyTQBqH0F/88rLG\r\nLdZBPFiJA8D8fu756MCHfQfKtVb67pnmVO1WWJ84HkqdPW73bu6Vm0iRtAZd\r\nS6Y7qaIMxqAn8Rh4yOvawY/o4GqY9yTjZ0UFrvRxoaa5h/JaTIAi+3yWBpDQ\r\nXM+8YzHSJMbc6s5ARTKnIhIC57mZYzrkSvhxEW2Tjj0lqeRI2kTERwqJluQ7\r\nTtFDoP1+UpcCVDDnQDUemdmoAJGynf11mFM+siRAxOu61exavUylvnXuoMXT\r\nHwsec6cEsKhdN2EoiHJll96FDvNxjq7TdlYayBujSfTaA2ehCYN5s0TRvg/x\r\nxEldvfmAwpmRiKum5x6Z9c+9lq778V4V05NPhjmoYKXm6pd0Z+zFAiBk46Ic\r\n1ba5tHlCguE7G5vu9CKbzf3f5xwk9ZkVi0XOsucinacsZ8e1vJlGP2a+iiFA\r\nKBAotzHur1pl2WB0Q5w5GoRF0Y9BW7tgKvhP4T7EMs23LJ2LVTsqfZVpw7+W\r\nVAsmkfLwEl9EtnNDVam70LK/4Jq/AclSBlcAGVMdkdIXkPLWWI6Qgjhnb5vR\r\nesw1+kCwMfqtkTZ7eIyd3ga8dyZJxQOikx4=\r\n=5Jh1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See these pages: [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html) and [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html).\n\n#### IoT Core\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the *Create resources* documentation page above for background\n\nSee the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png). Your AWS account ID is available from the IAM dashboard. Also see the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\n#### Lambda role\nYou also must define an AWS IAM Role with permissions to execute the Lambda function as shown in the AWS_ROLE_ARN entry in the table below. When creating the rule, use the \"Lambda\" use case, which allows a Lambda function to assume the role. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"c25048c65295950f6c38689a89a8003dc516d6e0","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-01T22:54:43.155Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.1-fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0_1654124256726_0.564247907331541","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.2-fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4":{"name":"aws-iot-provision","version":"0.3.2-fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.2-fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"298e122956447be7c7cf0af2f0b521d49558e7a1","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.2-fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4.tgz","fileCount":17,"integrity":"sha512-dLSzQvFG6twqYpPpw1R977XmaKbNxh+il0YoTr7JJ3xDOZKhoOx6pmkAcWvdHASXm2H5nPbEb+Bmz4RfZJ8FVA==","signatures":[{"sig":"MEYCIQCbuOcuP+HMk5fkGvtlwX3mKqmG+dZ2e6PM3oN1dE5DAQIhAJWNmHxQCmMDmihe7tMYKNrSqZRec3lpVyIe5W3Tsydr","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":372873,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJimAq3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoCVw/9GkZyY6bqZTpvT2e/eYq8pERy50MFmpwJtBi9I8pzPkWkuXH8\r\nUSM2iGhnH+tOpjNbDixzRSYQFyDA9ooJnEMn0EGF8Y7ZxKfKdTKpl1vPdl5Z\r\nhjlWGE9UA5PYR+jzBHvcobbBQIXvGW2Bak0ww5DCNY8BE2BRmKCChBFq8xBH\r\nJBv/Wm4gKGzF9L/SaJxvZ+zIruJ64qPuLn442omOk+aZJlurcvgzEAEYqeie\r\n9+r5EtxWUqLZoRJyHcDK4fYVLMEFg9Jvk7aO+F72L50LAyqUYQ95lSX88Fb/\r\nEhYhGUJV/jUH3VZlziUeLrPQnAa/mIxAy6ksiS8I+/32KK12j8C24WSs4JM8\r\ntGjW87Tx20oR4kHxrHPAgF2Ntk1sYGpSUj1tnZF5h21gwwWLIx+CUX4Nyc11\r\nxcw/3RSvXMuUmaL8QJYoKgQIm/CM90dLZkGz8C8izv7U+bUogG/FPqc+vCV8\r\n6kG8A9S0NrSjv9X2Zk3SwClz6l4W1oSWYJwqHW3xcx0CTxprbVZ7xK+Ty4OA\r\nuBna1gY7wvRGMduJw/d4TLMeTHQRimeLW+GJLomps2HdWVPsAR0ECybM5XfP\r\nPoJ2xwlNh/KNwm33nr0OrrX5PtIsI+t3tA1PFSoIy9JrzA73QA1XHWbuedix\r\n6ol1oL1heRfQGE7OwFDY6K9vz5JJ6Wnl2TA=\r\n=Gpya\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See these pages: [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html) and [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html).\n\n#### IoT Core\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches this policy to the public key certificate created for a device. See the *Create resources* documentation page above for background\n\nSee the statements in the example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png). Your AWS account ID is available from the IAM dashboard. Also see the IoT Core policy [documentation](https://docs.aws.amazon.com/iot/latest/developerguide/iot-policies.html) for background.\n\n#### Lambda role\nYou also must define an AWS IAM Role with permissions to execute the Lambda function as shown in the AWS_ROLE_ARN entry in the table below. When creating the rule, use the \"Lambda\" use case, which allows a Lambda function to assume the role. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"750fb9a9a4c627a45ca5e2dd701b137d7e1951a4","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-02T00:53:40.847Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.2-fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4_1654131383192_0.8529232631947992","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.2":{"name":"aws-iot-provision","version":"0.3.2","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.2","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"c1ecdf26b46244bfe51873ae2938becfbec57d2f","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.2.tgz","fileCount":17,"integrity":"sha512-D/1aym4hZUnFpwzTq64yHWEY7H1vtz2sBmNt2B0Ne7NAvvPCGYVJjytviqX0NTPNGJ0Ihwyvx+Lo5ANdSDlV8Q==","signatures":[{"sig":"MEYCIQCfXIv++Ytkvbo0gmQw9pUfFblhS34RD0j80MHbCC/YRQIhAMvahDqzQN14REFZnW8/qvMdZGZZiaoeW1Ks8w06FYxR","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":372818,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJimAt1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqizg//Q7Z2xlw6+KXdQgQfiF2EZJFRdYNsIOwFpaSFmpi17Zc3o/h5\r\npAKqZHFFWFtc1FDJDSCgBmbrk2yiZ+7OOAegUwpQxl2asYQdcPB4+tsZRmC/\r\nLheMErq7yCvS9shdFDR+GOUNrTtcYI0oqL4jtHct7k++0i3UaL6wM5n91bnv\r\nbCNBe2ypneGk3yl/v6j7ulUU0+Svf9/hq2XxPKnlBfmwJimT7Se31KeQHaPu\r\n41vQXtE8DMkQsGqlMjwSGJYIQ4Dx/CNLntJIIMcwA+A/3yLkCgQG4kSNatY4\r\nU9ddFYZ2cZfJSEJjw/MQ/AG0i6JtY3rp4+n7S/TIyTzcJENO/gUgNAl68RJp\r\n5Y3kVD+3K8Ac0QS+K2iqczlu83ozGzXiCvwHpBz1bWm4L1j8AVQFw1Kt2sDl\r\n83KJ2fCiw0P25XXQpenfFaKPLaVVYtIMTqi5j4q8oRxPXcsgppxKBHpZzHi/\r\nIPyBg3rkch6DxU41m3uvZVqfSj7ALVg0JIPnZOqutHgFLCVVRgHyIGeGTk0z\r\ndoThS44xWPwqbbgxofGNNBe+VhzKpziFYYB3Ih1c4SOqDoCksy1VfbXoKtrY\r\nfFwYj/P+0zR/AnG5QKxUM9lWxdloSsUcPtGjBUplZDoSPrKOPDY3/uiqn4Xi\r\nU+4vyhzW4AYY4OtL+yRgK6UAht49XaHOx6s=\r\n=vywS\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"54f433410a2d4f0b3977dcd9b83e1bf3c176a0d8","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-02T00:57:24.473Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.2_1654131573633_0.003780452896120279","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.3-fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011":{"name":"aws-iot-provision","version":"0.3.3-fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.3-fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"fdcb7c46d659dba727a99be45a526eb1aa3981ea","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.3-fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011.tgz","fileCount":17,"integrity":"sha512-eZtxbf5ogdjpO9qA/8Mu1cDcvfDgHud5ujydRSYmJ3vYij8YuqbMBjIKVvXpvUOKx53wqlBt2MxhSoAjYKYeAg==","signatures":[{"sig":"MEYCIQDFAckKaqZJW7uAMaSYcNljuAwF6le7bKrfLDmXUqihYAIhAJ7VO5C3eJpQ1BkHyyKglKLg3TcvzJaM011jWTr/iaAC","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":373000,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJimKbJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqSgg/7BkD5RKGRusncaGjnJkNT9DmcztV4rGzL+zQqm8dU36f4xPWL\r\ndUcIU+vk7MuyryhdJg57yu5IYkQsxNe2WHzRlkoBV41mjlDwnRefcZaKx3e6\r\nkTrd7HuxJQMLCDHe/IHWVzhsPBPtmd84rgBjWPNYweMbLIcZ+SSudyofXC95\r\nMA33PBlg7cpB0E6zo7RNtwVFKFcDUY/tbYwbeclwRmmRqMZsKmrIjHQwhiRK\r\nM0lBqqJykxgvDL5fBcGF/a3MfMaUHMDaF/AynW3r9XgKcqKMejj/bl1zdQJI\r\n1cxkMQwwUdPVdZOylMgJq2Nme3czUCkcejjqdq7dKZSp8rQAwM0IQoQrtcK0\r\nRkkGxCgIecdFcvu4A3vSl4WbmG6VGGq6+f3sHTwzcANC9l37UIM6/T+Lv/XT\r\nb4qKH8NSHaw+GCdPeSpZDYylexrK3Ymkhv0MleIoR+HtwfeKwkDbEyJY9UhP\r\n6al4wfURHsqC3qRr6QFMYClND/TI69DCxJdOsMt6k7EgE/LclZyDmK8bJptb\r\nc+x1fI6bUMZD84tE1ZlM5nPKYUF9c5t6s6/H3Vsyzq0zXCjkd7kTUhpBZfTU\r\n7nANqmDCLl2T8dkxthWYiv/UFCuVlvHC6kwLISBMNRhhi/Rmbhqv3pLcrkE5\r\nn4ENPZdEzA241u56XN7rgiBowVqFXVLVNWE=\r\n=E8b0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html) for steps to follow. Also see an example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png). Your AWS account ID is available from the IAM dashboard.\n\n#### Lambda role\nYou also must define an AWS IAM Role with permissions to execute the Lambda function as shown in the AWS_ROLE_ARN entry in the table below. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html), and specifically the section, *Creating an execution role in the IAM console*. When creating the role, use the \"Lambda\" use case, which allows a Lambda function to assume the role. Also see example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"90390092c0274d47b361aaa83b255fb25f71a011","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-02T12:00:08.977Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.3-fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011_1654171337355_0.41646171135234256","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.3":{"name":"aws-iot-provision","version":"0.3.3","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.3","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"25e90ea38ee26efd4c21d97d6ec9c6850c7c5769","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.3.tgz","fileCount":17,"integrity":"sha512-YX9Ey9in/1z6S6iD0rRsqEf70Cc88TP1QvL9K1UDBxIAJaDrjxX6jZrzDQN7Rdkh1PwkB2JQYlRFS5uz62cAKQ==","signatures":[{"sig":"MEUCIQDAn7rMZfbTzhVR3adrtSLI/uz8uuTGEVm8aC2LF9LDHgIgY4Kd6OFSMRVGim3Eeprvti/0/laYityM/0LEWmJhZIg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":372944,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJimKixACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoFXw//SrteYjhu1nx8Cibn/V60luLEyWXI1siEQ73O3UbVlnTHHxx0\r\nfw2W3b0lqIvaZy275V5Yb0KGWJG24l4Eh836aHzB50JdG+Cviw9SsDzBMHQU\r\n5etRq1PWjqZY28lcv/6RuWP5s9XOxD6uQZjHiYwUdjFhDCAzOU0wCWuXYPnf\r\n9zK6Q4AOeHDhYFltmlBZn36pH8f2fzs5vtwYqciL3SbIJwI0k0XBYuSEcUeN\r\nxmujWF5ISFJl1fw+mEx7DY8d2ieHn9K3EcYu3ELiuxIyLKqmGCpXb/sSL6mW\r\ngE6wAFjuoLTQAzPRv1OmpjmuP7l9+SROnT6kJibXS+KlxCRgrzP3Lqb0QYE/\r\nmfNzcvSSKkmwSC0dR/0QCnpMBY3BpoNtYU3I5I+q/iMciWtSoWjxCWmwFNsT\r\nOU467zQvr80lNI4/rmmKqqsHe9QMRkYBo7OxhtvDCuFCX1JEozuAsmAUiYS3\r\njFJN3GXEqJ/vm9RQRHJLPdcJKmHMPV7l4Q8h2CMoq7csqE811Yvypq0ZNQGe\r\nGpN5nFkVJRrOEUbonE/TzwiW3+PVIWKKYaIDjD7m68et/Kl/S/qTO01bZ16Y\r\ndhYxJDmnA66fsN617PgapciZwWcYIr7P2v7FrUQwAzfMvxgVMvIXWd8LcRpr\r\ngtieFnUEB8eLpsvPXyiHutOnrKjXcFcLEcg=\r\n=W9cT\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"14db5ccbe3bbf64ed92ace12399a7c58ee1b8c27","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-02T12:08:35.974Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.3_1654171825698_0.6805404610950008","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.4-dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb":{"name":"aws-iot-provision","version":"0.3.4-dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.4-dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"ce5aa99d2c73ae8d34b4f455cadc1794d7309af1","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.4-dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb.tgz","fileCount":17,"integrity":"sha512-9Stg4VAD7y1YKKiMOmKSRURgcfhmkQn58Udye/3qdPJmj888GhDP0hEgNFypCJwqTm7XwSaE7PnFUtjwfHoqiQ==","signatures":[{"sig":"MEUCIQCfit6b0KIYuKzcjEslP703QJ13CFl9QcFcG0dHg3NCXQIgfBjCD8Ju/VvFOg1CwffOe1ByTRVRMtHdNzPrG7IpIyc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":373122,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJingQiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrVcA/8C9/DH1LM8rP8aFCXgXXrtzr7dv55IfOFQix9YEja+EWOcbQE\r\nktn+T8iYhHt7QeSiBHLO0awQV5ugLioReHeeo+EMTDVoGGmrV/+0IzRCaYV5\r\nu/LNEpUTdObmNjqU3bW9wvZkGUpp8/oFGB5ISXb24KQ5E3egs7Hz5LUn5EH4\r\nOqPBIHgUTuyOCpK2LwNJSdNAieqXofP7ElGfnWc0aKvbwyCgFE4vMJU8AqKp\r\nVCmT3yg7D/XUOn8NA+I4LCA5wvIXsuiujp04GLlhQkgRIuMO5bSE4kYYbBOZ\r\nU5bC3IQiLsSJA4KHYdpLrXE095K7OGTkQuZCvnP8pd6mb2L9/0oaQjQZVPfi\r\nF/AevcvaI3FFAmUDf9TR/o2O49En1c0lgBYaGn3u5V2g+wX/wS7G5JKGOkL9\r\n3ODDHXZ0b6wk37CJyUTIvWT4yRRAP/RTZzWDIerg310Zfzk4ZNHsQLu8J5vi\r\n/Vpm5cEMrxcibesoOoaC0ms5iLJiXr4FTiJ2WGdCwnAyQOjJ1nr01gwwpj+b\r\n+Y4zOqSc7D3eAvYmr2umG7/oPbwQZUPKcu0nTJX1QZ1/oDa8GMCTR40n9R9A\r\n7MUJ6gFA9Mbh6xRxZlDQEHP3KiTiyRXWPKK2bSxIewf2MmkfCVLbKdRRgXTG\r\ny0NvczB6BgXMYSlmTrkqRVFXB3G4OlzBw/0=\r\n=OHrJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html) for steps to follow. Also see an example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png). Your AWS account ID is available from the IAM dashboard.\n\n#### Lambda role\nYou also must define an AWS IAM Role with permissions to execute the Lambda function as shown in the AWS_ROLE_ARN entry in the table below. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html), and specifically the section, *Creating an execution role in the IAM console*. When creating the role, use the \"Lambda\" use case, which allows a Lambda function to assume the role. Also see example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"a57c9d254a6f4b9729609bbf5f04bb9814a191bb","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-06T13:39:10.438Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.4-dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb_1654522914419_0.8196655227020024","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.4-fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65":{"name":"aws-iot-provision","version":"0.3.4-fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.4-fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"da49e692085a015d4a4538c2a216db2390713322","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.4-fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65.tgz","fileCount":18,"integrity":"sha512-0V6EB/RYhfmL6QohdX7aITCnqzlyXo+LYjv4fQikxlZaTa7Keml4EAoZfGlu1w42bMN9hxvpr8dasFAnhaWJ+Q==","signatures":[{"sig":"MEUCIFIt/NTIsG5glP/7xUYDoLI41EpvU8cj8tlfZ7cndcN8AiEAysAzSmoxOcEV9GGRWwdQLTmAieU+/+zji31GzCSgsUU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":456800,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJin9tFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqaPg//fxcYP0nOTFaDoP2ecNEs9ab8tfilqo0VPb0YEBjVau0NLzDf\r\nnkBJugWLFP0OXpIVVXafDexJgVwLNwW7k5wpThr6/8TjbUBRpgYAyn8GLpF7\r\nPt6omdl+WUCggUnlMB+Qbr4yjeatYObyvIxAs2QJbQwWIDMa/I/aqWdxgou7\r\nW2XhYfxgZ+giJikEZINIAS+3IFXCyJg35B0et45bl+H6yOgilsZfLz5uNV/b\r\nOwwIZ+AXJXliIC1gGW89+mAwHAAlpt1zbGqsO2pqu9C06QcvjJBtYHIpghEV\r\ntJYCjxyhQ16JAXkQLN6T6ZBFRZ27gOlTo1JxRQNPVLfMWBEAUE/T5rN6IvYQ\r\ngSyDQVwRGpz8tiTz+7hp3uGVDgP+tX9TAfp4CcdKlMLQtEHfw1uKtrUQuIgt\r\n+1MPngauyA+sM5xpIZM5vd6f8YBP6xi4MT1HZLvMDEQhl1VnAL4BolXJywOo\r\nhTaU4RzN3Qn4WQOseQEgxXrQAuUtOBn2x1m9N7Pp4KLe8qTsFTDggMXBjQaN\r\nMNAmYSqFX8Z6I5Yrd7DSg6Y8a7PqG3/xMVRcr+mxjPR8/CYHWd6P4K+nS1vp\r\nkFoXjQNYtiOC88+ooIvQh3m0h681J0ktP9q6e2+PDZXwDJ4UGtumVMVip9pV\r\nYbGNhCR3ELMoS0rtbMhxA4c8AS7VkFf8Lnc=\r\n=zb6e\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IoT policy that allows your device to connect to IoT Core and publish MQTT messages. Later you will use the policy name for the AWS_IOT_POLICY variable in the table below. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. Also see an example [doc/policy.json](doc/policy.json) and a [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below.  Also see example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nNext we will verify that our AWS configuration works locally before deploying it. We will use NodeJS based development tools. First clone the [aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS IoT Core policy with permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of fleet service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to AWS and visit the Lambda console for your function. Next create an API Gateway trigger from the link in the *Function overview* section on that page. See the screenshot below for the settings.\n\n![Lambda trigger](doc/lambda-create-trigger.png)\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-07T23:10:26.658Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.4-fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65_1654643525122_0.7584601941627174","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.4":{"name":"aws-iot-provision","version":"0.3.4","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.4","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"4c7abee17fb94a63e3e3fb8df9954663a70051d8","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.4.tgz","fileCount":18,"integrity":"sha512-/21ErSol24RLSMx1b4nBCY00TrjvAWSslnztml1Q8diC+fll5kb1FoZAarjWOXdbKGomPpKTfgb0MZB9GbcwAA==","signatures":[{"sig":"MEUCIQCCFIpp54wdUOtzCR5WsRKrIjAC+HSDLPnuoSJzunHxEQIgQaIb1ulN76Gn/+M5EFg3vOXgKK+Y8dKJaOHnBSBbnKM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":456744,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJin9wbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqYoA//Wa2LbtgBypVEMMMOhMm5mXk82B2pY9XWqBJ/zsztELh6TtXl\r\n3AOy1CU+7YRk0KPXY5ZtH6KICwO45Z7rB4DQbNSv9U6xgW+yifqYzWZcra4N\r\nFIZZEAFBDht39TUVCOlFztE1BB68TGhiw6k3tTGp/ARfP4JzzeHW60e2gUcE\r\nO6uxVkOLqCZIUA+/U1S3y7ok6QJ2uvNr7ufWVNJxn0WSjy1E50R0qpECfAso\r\nzXeH4e1T3PqBl6Cpfwmljvz1vWIHiyM2dQxtpl/+Ki+oBXRaTbYyhcXH2rgr\r\nLAZF14gd3U1Wj33hX91nNDQ7r7iPf6TbVf/SOO2w2swdq7Jjo/u2nj2CiNYE\r\nyIUCiVg6/1yBwrLIhzSBXTAh1TKQ4eYouzacvqxiSF+NfQo+7uOnmxnav60v\r\nh03BavHmPx/GQnPGvudB8Pg+QS4M3hYwPJr/zbaRNOdVNaelh1MK6CL1KyOe\r\n5m6fddTiLWieuuYeML0Hs89VPjgDDgQQepDj91r0sqk9yBj/VoeObaLlMEt+\r\n3TGnDBISIIfW3Ycd6L2Gfh6yWFSVRFlNsm+BAsxTzUmcgACvCzMJMnBACaVB\r\nbjCWR8CqSlwbvbQlwCcUPMt2PTcuxxFAO/d9SGDH6wWYHCT7TfuZBvtMOoR9\r\nrsuKaPPSGItAWCYL5+wnBZGCIkVn7YitJII=\r\n=NUGU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"2c6a9e057adc01c667cbb6cc5f4dc3f9633ca6fc","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-07T23:13:49.628Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.4_1654643738907_0.9565628704472304","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595":{"name":"aws-iot-provision","version":"0.3.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"f5783b99cc425b2034379bc9da32ddbc354a34ed","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595.tgz","fileCount":17,"integrity":"sha512-yZCVnRNIFheJAR29bQPQxK/Vu/Pyg1iDCUVBFCxmbJLmr98P3jrJiM4BdsDpVUzWX3TZjYLMSCqW26YdABkZ0w==","signatures":[{"sig":"MEQCIHM+bygj9qQ4Q7oUh70KrkFxff/X19WQX0gEcFXGzBX8AiBu86X59D6T0O8I/i5f5ovALRVZqBhOsPsCo0kXFVAWmQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":373122,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJin90IACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrNhxAAg3V9xMX8upt5tCw9oN3BJX0NW7a+o5YVisd2A30rxURfZbPB\r\nT0y46zN9H29JL6fIGgWR2C/Sr3tqA7atDVawYE+xPFqKQj6d51wnYk7b1T9R\r\n7y3+iCZWsiywgTlWr/LL0sc4T1qWLUZKXigh8XdbwVkAmCc5rgfRZhcDxUbc\r\n/HTrBZHEm/wNwDgP+zo/PuiP8qpuWbdDSg3BZsjPn4Ck1KvHZhNwmTk28O7k\r\nM+nuW9d2uyCI5PKGDokoqXLIWmq03lF2F+Sxe1S+qyZymEIDRHSiNXec0z1i\r\nr/mW42JmYHgbFp7SpQgyWEnJGa4uQvVvysEXIb2bUZbTiIu52+6BFl9HJn7V\r\npLjM7w+8fspQVgnu6p4ohVeywjDoZBddgiGJb/pzN58HZvhjsEFKrYATBy+b\r\nTq2AlpeLgIai4sxoqJlHZe4iUXdRNPE+sLq67dOfn41BhxtzQSXjNA8D3hp9\r\nN3FFo7e0gVEflu+I8omJRUPbnhg0FkQbDqWMTs53YZIlByNAqkns22uzWtHB\r\n/4MSnXY7ofBma7snICwUCFVAszV4UTzjBrvDYNwaju+9h+a6BFUxnh04VQs8\r\n/Nn/+b87COialeZi7L5Y50SxEGUgbvEfC+oEzWbmsnmkvE7OVLy8S3nnQc4L\r\nc282Zoaw3TgdUYfHVdslmmakLO1fMRUgLLc=\r\n=NpWB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IoT policy that describes the permissible messaging operations between IoT Core and a balena device, and provide its name as the AWS_IOT_POLICY variable in the table below. Provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html) for steps to follow. Also see an example `doc/policy.json` and a [screenshot](doc/iot-messaging-policy.png). Your AWS account ID is available from the IAM dashboard.\n\n#### Lambda role\nYou also must define an AWS IAM Role with permissions to execute the Lambda function as shown in the AWS_ROLE_ARN entry in the table below. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html), and specifically the section, *Creating an execution role in the IAM console*. When creating the role, use the \"Lambda\" use case, which allows a Lambda function to assume the role. Also see example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nFirst clone the [balena-io-examples/aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User with permissions policies to deploy the Lambda function |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS policy with permissions for messaging with IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: `account -> Preferences -> Access tokens` |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to the AWS console and visit the Lambda console for your Lambda function. Next add an API Gateway trigger from the link on that page. The API type is HTTP, and Security is open (though you could add this later). The result should be a Lambda and API Gateway like below.\n\n![Alt text](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console. Execution of the script requires a POST/DELETE parameter.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"e98cac905171a88da240c038cdafba0778a9f595","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-07T23:17:25.148Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595_1654643976179_0.7424281831838384","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.3.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609":{"name":"aws-iot-provision","version":"0.3.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.3.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"87a3d56737952900d4bd03c04de797acac1c8ded","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.3.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609.tgz","fileCount":18,"integrity":"sha512-AJhPpIO92DhENAZFE8hjAQ5nNaT0mWZCeCQqFjMFQnGOWCfloRmQlg68B5ASNjgyqt4dTw0C8y8ZVoITViSCmA==","signatures":[{"sig":"MEUCIQDYAYophdDlrgvnzPfSDhlBKgzusfhXL/lHmOME0p1Q1AIgdwBYaVLNVTj9Mnz+fBtvyHU0tvQ9qo+FGSZe5RbS8VQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":456922,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJipzzKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpdtA//UBd2IhjW0pBtli7rDa6YH4LTuTTdO8C3tSLocufN6UEEfCrt\r\nXItB5se+3He/D5CYQiPuKMv7pem3mjuCmdE35lI9UkFIcaufxAjfM0q2QGJz\r\n70kUsAJQ/QkbLhzjdUQin+bK6lDi5BVcanmtCePqYoWMMyx0oaWXoBkVJ2v0\r\n/kwSKGkCTbSZjSVg2wvu5oYXWOEbg1SgPhkH2XOG9YQkKB4zEstrdObIt5Xj\r\nu3evqKF2qlG5dL/vtaG1oCY82YRMIZT+0jmgPR6506lavv39NGGy/vLi5C3n\r\nkvwTjlxCVhOX9+wBoIn1R0HKE9QeaOE3aaOfjkuqEXGJ4YSD/YrVlcI8KlhX\r\nLq0uvgJkYTGPBHv/SAdz3q7r0IqQeiWOJng3q0ACdT1XXOnNoffd657iQ/0b\r\naz7mjO42VT9sDkio58GgnIZLHr28cx/reeCo58VqIAMQlS1vz8t/YfXUCrm5\r\nHyv0X4uD8PmpkcSDFJc9gN2SNSC8VvWmDfug79OqViqthAXIbRGk/4CCKiNV\r\nrxWC6ef/eADOHJ4UZxUi9PlY7Kmete1St2R1E4jlPfGz8dDD5oHaPlLXoQPa\r\n5lo+d5SRoffvTlaT52RhYgoZs0rRxpkGmErozx2vuyYmNnDTXyFFmrMA1RRb\r\n5pjqYXagVJUA4kgaRCoBfmwT+jB/Nc7uUyY=\r\n=kRgr\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The Lambda may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\n## Setup and Testing\n### AWS setup\nThese instructions assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IoT policy that allows your device to connect to IoT Core and publish MQTT messages. Later you will use the policy name for the AWS_IOT_POLICY variable in the table below. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. Also see an example [doc/policy.json](doc/policy.json) and a [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below.  Also see example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Development setup\nNext we will verify that our AWS configuration works locally before deploying it. We will use NodeJS based development tools. First clone the [aws-iot-provision](https://github.com/balena-io-examples/aws-iot-provision) repository. Then install the [node-lambda](https://www.npmjs.com/package/node-lambda) tool for local testing and deployment to AWS Lambda. It's simplest to install it globally:\n\n```\n   npm install -g node-lambda\n```\n\nYou will provide the environment variables below in files used by node-lambda. We include example files to help you get started.\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of AWS IoT Core policy with permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### HTTP API\nThe HTTP endpoint expects a request containing a JSON body with the attributes below. Use POST to add a device to the cloud registry, DELETE to remove.\n\n| Attribute | Value |\n|-----------|-------|\n| uuid | UUID of device  |\n| balena_service | (optional) Name of fleet service container on balena device that uses provisioned key and certificate, for example `cloud-relay`. If defined, creates service level variables; otherwise creates device level variables. Service level variables are more secure. |\n\n### Test locally\nTo test the Lambda function without deploying it, see `tools/test-local.sh`. The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/run.env`.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry, and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n## Deploy\nTo deploy to AWS Lambda, see `tools/deploy-func.sh`.The comments for that file include instructions on how to use it. You must provide environment variables from the table above in a file with contents like `tools/.env` to deploy the function to AWS Lambda. You also must provide the balena specific environment variables in a separate `tools/deploy.env` file, which are used when running the Lambda function.\n\nAfter deployment, login to AWS and visit the Lambda console for your function. Next create an API Gateway trigger from the link in the *Function overview* section on that page. See the screenshot below for the settings.\n\n![Lambda trigger](doc/lambda-create-trigger.png)\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, see `tools/test-remote.sh`. You must update the script to provide a balena device UUID and the URL for the API endpoint you created in the Lambda console.\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"8addb065b9e7c5a5d2f007a15cea06b5d5119609","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-13T13:32:26.968Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.3.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609_1655127242277_0.9508600650075778","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.0-unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561":{"name":"aws-iot-provision","version":"0.4.0-unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.0-unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"9ebf276a6024cd23bf9f3781c57d59e5afa3881b","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.0-unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561.tgz","fileCount":17,"integrity":"sha512-WQcq1D3qTSDVQiKi1Z6DanTskOjMWG5eWTyXdXXOywaWgm0erqhh4u74+goSrbpJBnXErP3ITB/7qW7VDDbdlg==","signatures":[{"sig":"MEYCIQD0arlQP67rGtyv1578DO5pmkiyoYA0UV+cCRiSNp7nnAIhAKMj23LbDPLxlDEKR5q44ABVObvt/M/mijsaX0Zl55I8","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":503681,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqIbvACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo51w//bJISDTn0PwIXAfl7IdHOUwTSALdrxw9TvKvWT2gsl1vT7nGo\r\nqBgT5I01/StUvQGiIYOyK874xjbmuDTveoCdDIa/7KK+uBVcCyZuUHGuTSeE\r\n6S6cVPhcv1ULYSIvJMfhJFDpPvF7LNz4M/G/ycq3KPGDRrTSOdaVmZesVGmA\r\nEVn25R2Mk2cKxXPut6sam+LGpJ3FoW7Yb3XzzNaTpnuWh+UFsD6ODzrVHngv\r\n2dcO0TYiYhBsN2hyTeasFSd8TKjVMNlHsBGCigpcf7CK1NWgcOXskn2EjjCJ\r\n2srXLsX9A9t0ZmMVAb11++2LketgbTLvDsPUUAdlYXJVzR+izaTL+FYLiPu4\r\nJu1AGrca1t9ZT7TeMKLB0FRZziWgNcNsA3meYOK5CcsgcYtFF5s22mE39duf\r\nMw+vAFBUTHJ2rXfxjgvvVvm/PZHQATsjVz7pT56H1n1Kozq51WYu/MBy26nE\r\nDGXnffldw5XSGOO8dRJHfAUJ9WoAB8QxbG9vtrpZ4fhd2fQR97ph5QBSXr08\r\nAwdC4EfNxJcPKwe0sSyuMDdsGTJJq0apv0lqODKFGDdbTeFJcDC9t1G2j18b\r\n2ymjs4Vb+ROjykp676mVk99FlhW7DIAE5r4hpBxqZgsnjTg4oR7jDKqQfiF7\r\n4GDmlv0OEAYlKa0pkBSWZyN7+ocK0k96y7k=\r\n=eBf2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Tools setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must identify your account, policies, and so on to execute, as shown in the table below. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n\n# edit tools.env to provide the values in the table below\n\n# prepare tools\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# UUID must be for a valid device\n# <method> is POST or DELETE\n\n./test-local.sh -u UUID <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. Corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# UUID must be for a valid device\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u UUID <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry and `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"b1ab58cc0140f47e6a898327ec793ed12ff86561","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-14T13:00:55.598Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.0-unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561_1655211759344_0.9233366781895755","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.0":{"name":"aws-iot-provision","version":"0.4.0","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.0","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"1d31dcc45eceea6d1964bfb095f0a66f2e1d479c","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.0.tgz","fileCount":17,"integrity":"sha512-X7m22EZXZgFfzZiv2rske1TrrvJnlGIoUuiYJ6t6beRcfhdNbUeTfM7Wcq7XvIJ+OcPMWhPqb4xtFpfzj9+p0Q==","signatures":[{"sig":"MEQCIDoh5zSuWXt775a3sqA9WId7MT76CypS5QUWU7Bc60GQAiAkG8pfbxrpaqAtZm4eUmjOFZGqivMZY3Jcyy/ELhFQBA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":503622,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqJOXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqdPhAAo6v6nfQFadxaC8EOa2ITqWYt6BPAc2EV+pyJo9n0yuBEjWgu\r\nbq5Rmpm/LCsNZ2KNNrOnIWduMLPVuBtI5nbvu7qCwgE5HQniif/Jcx4Gj6GP\r\n20YYgd2G263GmMslUR0RCho2YB8GfzlEUI+N+sejLdNQY9qgOm52mUyL9TvM\r\nLnrRDFv3kUm9OWQYqV/ILQ/JlPV4AH9ABvoADnVU6/tqIfi7UcKo3Y5AS06f\r\nECvR9qK89mn8zDTe4kMqPJbnfQNQS+PNmF7RMLRGD1ICgZfHgKQEJuDVpztV\r\nwP/aZkF7Pox+48ijZAaYETikHPOVIm9ShUDwobCrr6Am2PnymGvWpl9OQIIx\r\ni9jKsivlCiY4dLnlfuONq37PKnXHP1pS4aF2Q5r/gDT9tV3HEugX01K3fX9c\r\nJgo9I+A/aoEAfNMGevAvng3cw28aCNU67CgsO7XJQMne0rKAp8oNphPcRMqM\r\nCMY5c91q8fxTAGVIdRL6oO8a7Yj6nun44wvSK/Fj3GSydYavP3F7h5e1H7HM\r\nmJilUK6se1KLKUFXWad5js137Wgher0NcBacXR7D/62G4wzcmLsag0JBpBjn\r\nstFJydVM6slWpmg6SjzNVKorG4YtMCT+HLvbXp/Johr5FFkoODI1zp3vy2UZ\r\nQjAmpIrC7AYSxlx+qwn1ICoIJBm4yxWZLd8=\r\n=8q2l\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"52d97bd74aef04a9fd8e21bc816e3729edafb4f1","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-14T13:54:49.372Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.0_1655214999408_0.2535867917894725","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.1-allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30":{"name":"aws-iot-provision","version":"0.4.1-allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.1-allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"80fbd6f7bcb5021df419400a21c3b09a938ab8a2","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.1-allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30.tgz","fileCount":17,"integrity":"sha512-BWPCv737Wt0SH6UrQLCmQ6pKLCgkwdiQ6O4UtyeM1AYNNOnhL4RBGemT9GSEp+ZpI9UvIj/H2hkF8+ca5yoHYA==","signatures":[{"sig":"MEQCIAUrof/cHebe7Vn0RYK7nGkzEhQKn0YrsAtLat5oPZTyAiBBTXS7xMM7yztBJBDzPz81q0ZZ0o9GDFr5DX+26IuDng==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":504740,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqNxVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpstw/+M9f7RCouLeS3IMMBL8EcnawQFegKI0F+3tOwMhxhJhUMHkuV\r\nLp07eh41/Zb+6ttNKpKmDNsSKFSssciFvYtnBbXys24DUCHLRJWByXPG7uY4\r\nc2oj9PFEQj53A+KO2tvscEWWXxsw5vyvrXoAfJQGBN+fnGpID4P3F1zoY9k9\r\n93n2XEBfVMi6uQFOHQfhbaUKzRQBvwuO8gRVU+EkpV6SOJIiEw/8pVu3RgCn\r\nc8RlCS3b9Hhn1X8JXH8GG5gG8f8ldZ9wqCmHASojIjm7mOaNtqciSaRQ1gJE\r\nII5QMfwpIT7qWqZtJ5o2MbySp8LN2nDgE8n0OrOAVBs/bRjCJa29as8HkIeV\r\ndCwNLOSFuVtaphpAyWQ1PgOA3kDHiUJTmTo8KdxbgwN4Gqs9qhV/f3idsyPQ\r\n8p+DXmPGQKB4jzNqtoFkMYJOH514PBTlgGBoh3x0p4GgHsbiYEROW3TlsGUD\r\nZpOBvQXjl7JX7yQnkUU8AplqZR2v7AxBf1nvgZtBPfyx19njwmj3/LVsDXxs\r\nnLSmrRmzIO4YnFsloX+B34Di9X5S4lo0xUY/zx/nu6A1tz/VLZJ7gy8Bfksb\r\nPcZvcE/yY7CzCsUTLsqYb37MtEKjgQu5vuEwjc+AlkyZt9qOTFP9PlvpsxjF\r\nY1+faVwMwwmkQJHdkm3KgBYmxYfV99iImpI=\r\n=kgDH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n### Tools setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must identify your account, policies, and so on to execute, as shown in the table below. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n\n# edit tools.env to provide the values in the table below\n\n# prepare tools\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# UUID must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh [-u UUID] <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# UUID must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh [-u UUID] <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-14T19:05:04.827Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.1-allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30_1655233621430_0.3468696449246498","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.1":{"name":"aws-iot-provision","version":"0.4.1","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.1","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"ebf266be9bc013d2a09654bf7f172f446d883a90","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.1.tgz","fileCount":17,"integrity":"sha512-4xx5/JWwW5vrWGKMuvkPLafEnXpueDKSeEK9o/TO6WEqzO1yX34AWdBgP9pr8Sf9147XIdSr6XwMJsk8P2caLg==","signatures":[{"sig":"MEYCIQDkBqI0UONCFbKR21MBq0l3h6B33wPWqdCbB/4k9vWbqgIhANaeogw5Sz5AK2UVQaXAUGyVx2miy0K8P4xSum6OSm5b","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":504681,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqPglACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpgnA//cg3WU+8OdsVGX8x3rN1cfN1Gnue6tRsUi/PxfnlaSsEttbs0\r\n3qGJHCk6xRDkbtKLIiJGU6Ak2tQjS1OPlH8/WgK3Li4TkCSs5sFBAAZC1t3q\r\nt1ZRgHZiul0YTq9f0A0mLzFUjxwz0Me38AintOa3yaW0do3M31Bn2/kwhOKS\r\ni4Q4eNJ+/7p4yfqY6RHh0eNiRj/fGPd+UGN6wk/CTrTjmnGikDspA0NF2qWs\r\nhRGOwvlRG4+z3nmhx4arBmBERJmqM6MBKbXLCBsozdDaxILt40+O46BzoLp3\r\nU+61hmc7bZmJjTvFbd33yudw+oeLztFR4+HE24eReZGnBpFq7nX6OObQLFrh\r\npI8z66rPI5so9c3OXTPGfNYhCEjvaHchhrxtgK3y+FT9I9YgzDqXyEyuTNAf\r\nniWE+5GUU6ipcI5ezXnEwukArxSLKPjlwbRw+4w0fpeUp5vaTZj7w769GjhG\r\nBXw0kKZxOmupQ4SryXqeCjRo8eUzm5P06yRVxP0d6xgZv+DfS14gAeV1TjFT\r\n2AvMmohXSJZ3GQUP7oNsnr+Xt3NWaRhM3Oevd3Pq6bmBG+XMHf8aWM8Tipyt\r\nVEVl/1KprKLzyYF7yvdPUbWapE2Q8dBPlVagXkuCufD4CsDoE7GtDh6PlNce\r\nU8m1tl9gkp/NWVfcZqKEG2WyPsLm90MDu4c=\r\n=fQr7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"726ea6cb8e084a4c5e75c25c4f2f117af27f1b00","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-14T21:03:48.343Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.1_1655240741672_0.4987098409975921","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.2-define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df":{"name":"aws-iot-provision","version":"0.4.2-define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.2-define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"b979e19eb7549b0644879e16aa2617c99847a500","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.2-define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df.tgz","fileCount":18,"integrity":"sha512-CnwzqvvVqAkPA6qfdllmMlQeSw0jf5hdI6DDzqk+k5RVN+ekP113eeQR+s5/5Ud8Tbvc7P51K/XJc+I4C7Q5Ow==","signatures":[{"sig":"MEYCIQCS4Wlsy0MyHwagqOoaRywl9R4a4Kh7WGGgnb7qMC2PrwIhANH3itZLgRj6aPSvnA70GLC4kO68WtoEk4s2cgrdBZen","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":675993,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqcfiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmozMQ//SBmYI37esjN65YpRBpk3d/tX36+lVjLYSmqbICrnDHBgkB8R\r\n26sQ9TUZws8lhLlroIdgY/7r59zcxz6UTPYkyzS+waxperQ2i5jQGrZ/0iZG\r\nJ8qLBV2dva9iC8q1aIsUszxEMTe024cEcNhrvxW/mDBqODV3+YpcHSoDa9oU\r\nqjti5JBxOJ2aaUyxwBnxnps9ak2JjEMMsa5cZRkwYXioqDM7eCAV8s2YBx4D\r\n7rPS8hHDg6E9NBSEDaneXOuksWP6cJyQCcyIKNY4oLykIKF/kMPgD/lRcxl9\r\nzv/QdnDZFzryJMbe+TZki+U59PjpI8h1tGx/P3vwZWmKlcbVAUUxWFaJRCt2\r\n7U53rmOsQJoy11jXaoDkAR4rut3Wsxd+eoixUamozWpcfSLseBT+SOE/xtZ7\r\nGgxDrA0Wyc+8sqHBRiiCl8yhhrzLQeAY/xJnImII92AJL22DdoJ7jj1keaIz\r\nJ5spcXBgD5TouYcAemnlLq3j/wR4/+6xjuap7PkC3xl+qWrn0Z2jBpN+1ZSo\r\nWOFKU5Dw/iDWfi/a+qbLdXMaCTSlGflMmv/05M3WIiC2pD517pDy/aakXSdX\r\nBTlOSlEvCu2QDsRGH+bkuESg1eG4tmvjFkVBCCZXPqefDw4u/Dvv/Nn8Qqb0\r\nAH9EXn4ndodAv+VqYQMFfpr8uiy8QDq9pQk=\r\n=/pFi\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Tools setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"25d845e82907a0e7dd1e3abc96d9ece07b69e5df","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-15T11:49:06.436Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.2-define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df_1655293922397_0.8033372347138916","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.2":{"name":"aws-iot-provision","version":"0.4.2","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.2","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"532de45f78ac9e4e94625dfde5c4cd3148c8c2ab","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.2.tgz","fileCount":18,"integrity":"sha512-4Enh6bH21w6Sq2GeF6LprgO9Cu1Pe/HHegKn4pvFcBxvzLaKh/neUkhk5phZ9lyoxewytKCvnmpzG1kvSnrfrw==","signatures":[{"sig":"MEYCIQCyjm/4JCIUJ/4zKJANJoAW1UnjyipXGoKtAOOEs2fLjgIhAO2W+DdHlwMgtJE/ve+NJViUrKqK3aXGawG/WhViHXgO","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":675940,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiqckqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqrXRAAmPXMRbNJXhoLLQLviUpFGswY3uIQoQoAOEOFKhP067l4S7x5\r\nWnMTr0xwH9WD1SB8c+XxqcgXSNsS2Dv7EHHW3gHYzv2a/MEapya1Z65aB3Mo\r\npPnVmNWiaoPUG64dxGZN273/+4ABbdMEuM++iiGyB9TJAStUV3I88dE8gL2R\r\npYP30z5/2Bsj2VjUwHCZlMKpVSoWLQDEmWJ2jTlRwJBXt/gPAf+W0rDSKcU+\r\n3ArHhknhTx6vFvwvvSdtkgW6V0OEbsK4a+c75vBdogwH7RzvLdls63967Pfr\r\nX/KiBPFpKXmSRIVsyORRxsms25kEjKDqu1LymqR0OI6GNxNoLAI3F5a3XInT\r\nAw6e7zrJtAiJIho2043heH3JSdUE9zH2SUhq/p2pJnyfb5A3pdzoVB/mCqTY\r\n3pH1L0TRS6DIatz1IkX6mKcJ6ZNeLNPjegtLNDqAClul0X6w4N8V+06eLfA7\r\nfOYTUXrOju6duudWcm7xN3VRhZfiD8BkbRgzHiIB7cwuF+K+MqNhXc/QO8+u\r\nBBE4eT16o2DPYuOhEonRobQj0mObsj6c0fCt7FOnw5+WP0troXceVBZADdVB\r\n/vUmKaZKSgaZT1Wdpa65KTXogfhf/U2ApjBde8iXhvj12rU1gNPzg365YAbS\r\nwCfq4NSC6TQuG5uzdmwSjS134maRtbCccdY=\r\n=q15K\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"db6cea8676df55b019bc0ec1996a5e411aaf1ba0","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-15T11:55:53.398Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.2_1655294250413_0.3049994705369543","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.3-dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d":{"name":"aws-iot-provision","version":"0.4.3-dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.3-dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"38e07f2a579f837198d823efc6efcf344e46c729","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.3-dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d.tgz","fileCount":18,"integrity":"sha512-URmIPe++kR58HkVR3Iff+3JpLCRmgFz2Xs0msGL57z0I04BFs8xVW+VeatTnHjkdHZGfJvpHsN46dpZuoLWbhw==","signatures":[{"sig":"MEQCIE+vcEa62tIcod25SXZiJ2WU8bu3NyIy19aXyvfAATj2AiB7GuczYeLtZu1yf22gVAlgLlP4fP5SfLhyVv67I9Vu9Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676118,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJisHqNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpGcRAAjijWoXDgL9yI/UhbVom0kKacNn3dOdKA8qXwNJJnDkehxlAa\r\ncD6z6CinbCtZlGzvsjMw43URnWVUipvn2Bq4flLFFny2KE41wqZLZF62RxKF\r\nmQSN1xA6zQPmq+WpuarjsNUgwjEoDE77igwP9xsBy64iThwSVS9Xh99WD1K8\r\nsWlz5RcxHYfA5tmMElrddVpMR+ybnCHRTOhnUNDDO+Qxq+5ZhXP/5bGl5xj1\r\nHvtQdzYMGRo2zAy6FFt+wxrzSy8BFo+Vr8nNLau9zwhD9dEMplCi6lsbQdPg\r\npNBD4ycOJLvvQJA00HY17oDPBgHV3FDqweS22fUxJ68LvXE6zievnkpoyGR+\r\ny8ooNwxzNDFDmufUGBiejxnBdKZ2pNM55NLPQo49qdoUJq2lEO+HsMs8E1de\r\nqQDLvvBA60w4MEdJhFpd9fgRjiCbd7bMsD6R6X1QMd0sNZraJQzU5ugLq99J\r\njssKqBfeKfmpauYEJaxKfHHT3c6WfI8Hg10ZzmTEbk5xdgA9ZxHV/8Ed5BdB\r\n9t4+1kBCcLa6APrB9SP0yWa1RFcQeklSFronu/5NE+PdO0Zl63VGUcH1z/s3\r\ngGg30H8TehZRW2Znb4foBzHKSbda0DiKv3Xe5GdeeoVtdDsrVK/o65hoaS2P\r\nSEFutYsnKiVON3Iz+y8L69+lHFvYFpEpKss=\r\n=QNY3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function pushes identifiers for these entities to balena device environment variables. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Tools setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"b84844cbb9989f05c5df7530882c28615aa5c84d","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-20T13:45:19.112Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.3-dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d_1655732876897_0.6611798892240315","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.3-doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2":{"name":"aws-iot-provision","version":"0.4.3-doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.3-doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"53d4aa9a4f1c81e58c42b6f0b493e5683ed45cb0","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.3-doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2.tgz","fileCount":18,"integrity":"sha512-UeRvV2l8LBj5fBZaK/hmFQ0LBqKet+git1zgn0KWtbmys/LDRhNersl7z0wcEQ3Hrw2Je3VjLfWyTMHCYVLF0g==","signatures":[{"sig":"MEYCIQCy0TTvNyYaPNnaS6Iy29LH0qfc1lxFAcncTTXPF/MclwIhANfj1qQAMDZwxc2LkEMHsoQtECMYECdt3rDarI1ZC7GB","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676520,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJis3IbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqn+Q/8Dk+HVMpXFfKoc2/kGt7JF151KJ07i43gJGOI+NSuAns64Lch\r\nqjPkflc8dd0DKp/XopzuXx6jsDmVytlT8KTv8LpiyMbup4JeK7NYYci+755m\r\ndlczr19X6B1ZPVUFWNH65i8S4IepNFROW+lsSSkb2Ql7R9ePRzqH9u09eNv4\r\nEAX40bGxFuw5wxd81URHsDnM1fgAYp2SF55gm6hEygUbu0Au6BnJJUo+ULT3\r\ntJxPoFz+rDfDpZawczCKE/96zI8SNLa7apzkPOCFjdpqA1yJmPvUQiZuXqQ+\r\nk1YO2wD0Tdij0afZWeFCt9BSjXRvKJ5O/AxVs3rFS+Eu1ZfkxBJioNPAehtV\r\nTrfZNcHSZwUNTqCMDP4UrBJwIt8l+54m6FmEzbAeysE/OkQEayT/HVyfbIk6\r\nn7lOS46F0dksatEjwAC2tC5LHwwk9VABMs773dr7z+Hl9Bk2WwxHaOpibLSS\r\n7MPvTwfbiXlACzCD/SuRYI9CFdAx6n7u6HOk+gtGgYC1SQNWCzlpXH5fPk3L\r\ng6AtVsmXdKSjBD8uvhOngLXE8ELokMH0Ai+LzjMhqt2juIESxwzoOs9gzLsn\r\n5Wz9mXLLzEJCeCaPAp4PRk7g+UNhBtJ0rSLgipWJZDabC2KTPj2KJybZFtRm\r\nGtuAOSyU6rLzOXF9rwwUWRLUV7B1AE0oX5A=\r\n=QWvl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Tools setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"feb82eb4130d359fe65f28dfaa9360272620aee2","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-22T19:46:16.478Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.3-doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2_1655927322943_0.6140668603077399","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.3":{"name":"aws-iot-provision","version":"0.4.3","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.3","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"ec8a70e81a1079a90243a9127e4543094e327d1b","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.3.tgz","fileCount":18,"integrity":"sha512-l+xsosTQx1R3Eada96HsLZjjL/gy4XrJzfBfGqShQTOTDYKa5iPe9qx4VPIK94bYEAP/DD/W7Lk2p/SShcEiYQ==","signatures":[{"sig":"MEUCIQDS8kw/qTXf8HwpPeGhSfKGeNliuficNtSk8gZLeXdA7AIgZLU4ZsM8P4V+L62QSYYt8qr7WW9L9f4lLaEq+v7ReyM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676461,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJis6G1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqGZw//a76KNSy3Pfl3KgOy7npn95T6EloZoRCEM3YjSO9eyRC8ULYl\r\nlDpQJ3/JdQjdxvjlDinf8bmdAICy2l8PktgZQfI9R99XQcQAbhq9lxWmR1Fx\r\nnqTGr5HrfRork96Zjl1guOm23XfTfO0dyhgZMMLRUDIpkH1O/a8oxwmgDukY\r\np9UU5++eqVXs+Z773UEVaJOOeReK/liJb+Fa5K8rkn5GVMxx3VM1OBcTEBZW\r\nwDNstKfSeUiAxTZE6oRIQy1sbM7Q8rd+B13Zxs//lGw+Mqm9+HuBPvM1gD9r\r\n1QUqJps+tTQmUx8r4DPhy7SGjxWCmJJJrIMQe8DDFuF9XdoRZXuKyr0PMggM\r\nPJ6uZMSHkKQM5WUVgBj1ZdpihpjJqjSFZdH5pee6Ga+xso3AxVKNATBXCMOv\r\nPyLhaFduYEmeL3AUdTvKUfbDO7ajtaIs4sPn1uNu300j6CxzC1RJzaeFiROG\r\nEPhh139YS6QKEzzZvZ6dhRUZFWDy17k8wdaS39lz1i5GWL0/9y76piac6xE0\r\nK70AR+fJHKz+Zu9nlA5Ph87wnVogO9emZn647CSFI2cMWsury/zaSZP5YVrr\r\nhHtLITx2CVDxgZQG4ZoaYg1iO1Ud9hs+cItDagqWN51F6hKTr8O2iRL541Bt\r\n5rXo7IamzwQ9O7fqFyg3MDZeEHMisyXfi0c=\r\n=XdAh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"f9d5f52d4ef84c2cee1a0e1c95bd94895d72d9c1","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-22T23:09:56.093Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.3_1655939509387_0.4814225104334231","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc":{"name":"aws-iot-provision","version":"0.4.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"fea137c06509502036ec6586b812ebbc38e44b62","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc.tgz","fileCount":18,"integrity":"sha512-j9rUKOxyeuafCjcjDW2AaG6tYa2Mp484bX7onGlNh6urR1oUFoUU3YvRpfqedOEictyQNOp46ZjdtLR/Qe2fRA==","signatures":[{"sig":"MEUCIAcWMITCrQwuJONnQILWzNH1Cmhx6bKKY2u51LOf1TeFAiEAg2aeClFA12M/Wine0TBKd47PSaXxsi4vME1or9gCEZ4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676639,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiub2RACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpPhA//YhZMCAuhmDqX5pulPppJm4VMhaOmqfWOCp1veKG7tQyMoW6n\r\nDKlGfD1KNOYhZ9XcfbJpP66MQDOXRn9/TMLwhbeBb5OtbrUaIIwpyqvg3lxS\r\n5Aknc8F4/MpIPZIGm/I4pb/g3x00w2358l2StXVKlL7eRKy9S7GY8pEoc8Vp\r\nk8uhOy6PdP46MIhISxIy3M/TWR+btVQFhvbK2k9zx77m5CiYRbVWxHfMV3tS\r\n9xY7hars4F55TN859sc+pNxbIAtiuQ2N0o+M+x9JpncRaCWK3TR2ISjeLfcw\r\ndNEzxQLAFBqk+cz+PBwxHOHIaxKz3mUOx+G1TVqy3RJLMzqQqN3gjv63l2cY\r\n3DoxeOKRdZMJLwMCD4n5S5bFt90rF7uMZ3Mq6Nj/SBRKNSpEZgXMjgEgBULr\r\nGb0UH54J0v/SgXloKMP0FE9Rn/2PIBVcsnHwslDAX+dqAoUXte1mFtaMlJZ5\r\nuyJfDrv0GS6FIMvsHrOnSimqaNI7nOT7FCaQXJQfn4/wMGdFvQzvd5oBh5lE\r\nfFQMWkNi+Hy9BuiXGOtEa0ujSzzueVvK5W6aRyz2Qw/n1OJFRY2Y0kXhVoVV\r\nVztQMPjIIE1P++UrOnrd8yPzd3fPeQBNhO/+5l70n4FP211e2YYNW2v0X8sh\r\nYVFPCtngoo4jnplBQqbY1O5AsN/VzkVDw08=\r\n=QT8I\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Tools setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-06-27T14:22:03.628Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc_1656339857585_0.7751022549172577","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.4-uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f":{"name":"aws-iot-provision","version":"0.4.4-uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.4-uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"d2c46a0231bed49842fd959acd840d19c963a608","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.4-uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f.tgz","fileCount":18,"integrity":"sha512-EGAJTYtTqw2k4O/IRsY8vU6MxLWGMG5K6wRIPZjE3bYN/eOVOeOVvRHti7klOOYlToPWjWmipIh4zehn4atgnQ==","signatures":[{"sig":"MEYCIQCg7MXJsxmMA+0CBxO1FKQS70aakghwqFRmz3nidupGBQIhANmwQiChVuVkFY0RtUP4tbUY6ga5b1LNLQUDbEbi4p3L","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676628,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiwFAQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqeERAAlh8VetfgcvEGqxa/uFLMAh79FPszQboka4y/yjF6mcybONHp\r\nDX+iha+U35t5RWe2IhIkm0lf9uhx1dXlNVyADIPw2L5QFsBLNYGhgSatlOln\r\nwoyXcuXhwoqjDhBU5cSwgCEM3BJ1XFBDeZB8Pz/Emm1fntxPdCx2kWTadTfW\r\nN5d1G0VPFTZwksf01OjJ4ppB6pfAub261ZbK7BcXkdjh6I18ZBJO2Avt9Zps\r\n5EQJb8a0E0S/H/uIiAegrV4+LrgjT2E6yrSODtNPas99Zk40fXOFmSkGKVzM\r\nkX/c3YGr1yYtNm1Xum9XN2+siKv53n3MJhUWp7slG+4wg1rSLet2Ns/bzvWJ\r\nHoEyDzpcDUVadYEMGFNDHQcf1bM5dD/ZAJ6WlDdPpIyXHibGNollC7NvO5jh\r\nu7xY6SkTE4ABHj5qU8aWPcPh8Irs9moI2+quQ132Od60P6qFh4u4jjcizCs6\r\nEypDhz15ApuWJmKGQ7VG33EM4jy4XCXkY6lu/s1jbOcKotU1EsEf/d97DOaP\r\nKdP+RztgRTMxQiZmV/Rld3W9/ucIyLhFyd6tuEM5iPYep9FmYgwSyXJvdgFC\r\n909mTr+sZAxXnKU0B+Fwk/fd3cXlyqO28/41liRD2WwUtUjtc21+UBZp+k+M\r\ncrHYFQzJLpkBew/sVOwK3gdrjhKGNY+kA2c=\r\n=7GDp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"f6012f680034ce5e579607dce7959b602978492f","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-02T14:00:49.809Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.4-uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f_1656770576291_0.8468522589536276","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.4":{"name":"aws-iot-provision","version":"0.4.4","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.4","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"2159878a8639068d1f41cb66ab0c3a29b59d123a","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.4.tgz","fileCount":18,"integrity":"sha512-+9mZ/0OiO2YVlhgaCIWYEbV1TfdzrThEy7Z8i6U9WA1KPLwC0dd2k00tgSEKKgiRzj8K/mHfVzd07Nm7dn231Q==","signatures":[{"sig":"MEYCIQC5ztrUtH3KZ4sXCMwRf9PbFnkJcxg1I9jJbTpc/SUOGgIhAOv07hVjupEQHob+Qymi3JUbdIIszyhYU+BrrJInT5U7","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676563,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiwFEoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmod3g//RUqzVkKnDO8vuYEXEZuV/kOQTir+F0O3o7bLqRCR2NgO0RDR\r\nu9+qjQno8gWTvN/iglut+mF7m8dqh8619LA3d/glWH27LLxgc525AVfDRlci\r\nLXoyDW6lfBK4TKD/pfm5VoLWbR9j+g09cqefa6vXeDy77AulAo0WrYr9D+OE\r\nG2DctjRwfkT7eI6I4pM/hilunrbQLzEvzjqwvtTBN7FxosoTD5xZDgv7KD9G\r\nO0+Ox/ghvPivuBzsj3wFl80AJ7Y2ullst3EW3lR+plYCe1uN6B3EDdR5e62V\r\n1fvYHNsoxQRCYombT+tLMDD3AC26EJ6LpBrGaKdMvDdYr4hCMtk3lx0RA1k3\r\nsvBVDltKjB+8kEOBeIc9ZXXkYbgvhFxFIHPCd2ZlBYg+3RkYzGd3jdmB/son\r\nRm7xymWuNifehqnDps+hO8LBm1AGmv9jNK/qysQ74p04XQxvCSGDll+sW0f+\r\n7lLNOFMVJ6K8X7o4GO6kfVYiE2xVeyd/BsdLbnHTlVPojTislyYl2O247nrX\r\nxiif2u5oxIQUBlBqgsFt1KSOgvRfHWoYEcLZX/p72HD4ihpPnx7u3OkA6ngX\r\nE2lW9Bn4yx2aia34EMLRtpNDFCJqp9LGIe5feBZD0IkUHzEDlOrMbNmIMG2D\r\nKEW//DZXFts1RKrqkNUibsuhzY1h1zgRADA=\r\n=vjIL\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"7a9e5f583c111dce024776ed488e592c03f41c31","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-02T14:05:44.926Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.4_1656770856079_0.8809131684754068","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432":{"name":"aws-iot-provision","version":"0.4.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"8211224a8d46c75fb5bb5aca70a1ff254a208220","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432.tgz","fileCount":18,"integrity":"sha512-2sGpC0+Tc3/OwWTpClrVtSEI+it/hejm3jkVF6s3e1TaO8hidUQFY39MQUNuS6kH0ezsMFFIs9mgmGOFIOjPTA==","signatures":[{"sig":"MEQCIDVm3xNSqmsiBqMytWJ8yI0+A8vRIAdRw6BXCGEZMR6CAiBiSfLhz1I5fgxe3kzg+sTPHwV9raIKVqHQOWotrxdkoA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiwu4ZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpzAQ//XWn3xRCQYlIm41l3fFawsTEPlqSJnXHfbp6qmyotmAFUmeuI\r\nLb1MdF5lRqeC91DXCaZf28z4flMmjH0jc6VGRHnFKT1Bx09gPYnWbyii+uXX\r\npLVgMAkMMqPGFQh5kB4r/S9sEnzhQTBWEJKs8XPkTtP2CxHRsjRKTqV0J8u3\r\nfc5odZymL15f9eRtwDtW00JfBhfZMJS8JajGvjiYF29w/DdPHjaJ0tPGw4i1\r\nsLIIAcP0yPrsk6mXh1B0ndbxg5JVmDmgr6XzXe9Xkah9IsDbpX9OvulgZpwr\r\n4UJEmSPQw4RKoFbHeAcgJERgiOxC4zZhma/kHMtZqIyZLDNx8wD49AXIxtZa\r\nwRmCpQv9aIhWKB/HyLPluVE5fdhWsE8JEZYr/SR6qdSdPjIQZK3SDATHHk17\r\n4dOTu3xLDjZLQeh/WG55OOo+l5ZeSAJMtmD9sDBXisM7bgzymF5a5S77ZQIC\r\n+fsRZmL5qEHY/8GEl5Oya1QKRT1NDs/C6etpLAKCa+w1cwVfm7PEKn9JQJkq\r\nl2NUevKgQCaSmf54e6AAvecWstIRMZNIwz9tp3nHPYxmNgocGuvZqv/QQRoD\r\nGn8l1QtvPwsV1MaGbuK+IUXVs1kDVL3Ga8X6hGHvS0pewdRXIpLnIO2hApO5\r\nsgLAD9XNBDhJOlJ/XDasyte5XNb8fMHzUHQ=\r\n=4Zcs\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"50ab1b6727cabdb98e6333b04a87390094f20432","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-04T13:39:05.870Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432_1656942105427_0.03399307316574873","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.5-dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d":{"name":"aws-iot-provision","version":"0.4.5-dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.5-dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"92abb83ebaad9625f1d08b81d9812131eb2a9f81","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.5-dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d.tgz","fileCount":18,"integrity":"sha512-SE/EhACAv8NKIpKi+zFcXla0e2Hrm9/yDCxfL3POb3EE/SlszPI2gApq29wxUX5mr/5BVBBgMp8CShq/XHV+pQ==","signatures":[{"sig":"MEUCIC1XR7Q6mj4UW7Fy/40+F7sYFfRl8w9x3n/B9hMLbz3aAiEA5XgyMLSKqIkR7IzjS2kpnwpf4WsDyAyHWWabZ0D0gC4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676741,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizC6/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpN/Q/+JItag5lUDGmGoWsdW+kdY7C19RqZ7cLvTSt/iIZhi3fddPSK\r\nrvY1PadK3i8TIWMzAIFKAjZUL/w4FXuzmXO5spG/7st1NucjoZcztRjndMWz\r\nXJl6x+HHBL8xzmFddOZAk21aZcyb44dYhmfDYeqHBywfYCoSERgxrnxll4bI\r\nLbIG3wRY/WLVaeABRx6bMLSn14d1+Qpf4AkN61sgCNT6f+fP8wo1lF5AiNCJ\r\n+XqV8DSgsVxFcnBMWi5sf5IoJpktTIaFJwsCrNsjeuFRG+tWXZaSdlYxCVX4\r\n1ubgFIA/aCKP2ZxGwayLwmD1AyNesHOOmfIAxADiAXIwnSU9UcxvhxHk7PGg\r\ncTnZLm34WpRe+4DYQJ7K3NW+CY65jtlX6kAGDMr74l0RpqrtYuJpLWJw6qFk\r\nn/Yn4PDAnHOeIGB0Ryqw/OtiKxmCaEl1ObDamoNnbxaACoeXN3F2p+j77YKx\r\nQ1PuoDt0GEpUbNIVqIxt7M49xkwHvNSmbcsQKMS7+7AOvUvb4njEg9JFHIbg\r\n/7jGRJf7e7DaY3Gxkc/5oo4UW/PoKZf2UhVX3urSizyI5B5DM46ZXOlpO7T4\r\nw3bWmgTescoIDmSrkGdepgYSWf15UKLCf8aXkTmjahmtVJgriZ555oFW174X\r\nBlE3QSDJ09kfMbhtBwALUVpLkRPeUBR3eYA=\r\n=8yAV\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-11T14:05:39.469Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.5-dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d_1657548479630_0.27283909941247275","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.5-add-repo-yml-20781bed13ee981641d886b8ed625600026d7980":{"name":"aws-iot-provision","version":"0.4.5-add-repo-yml-20781bed13ee981641d886b8ed625600026d7980","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.5-add-repo-yml-20781bed13ee981641d886b8ed625600026d7980","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"748883338c9015a085eaffdb9b6f51aca298c3b2","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.5-add-repo-yml-20781bed13ee981641d886b8ed625600026d7980.tgz","fileCount":19,"integrity":"sha512-wmPLoOFAYCK6XSxdFvi9jJ14Eplt3FybDVH3BMbiM1H9DXBc6NAzFGwBErJsMMBdyVPyWsJsZ6MGuSKNFdrZyw==","signatures":[{"sig":"MEUCIQDgvvtmqTWfl8XCQG48JgGbzymiZlKhZ//kgdLKcqKBVQIgFkQIcaqbtNUeRtUDcW3sRcw/9sQHMjkpGfnELJ9atFs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676709,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi0EiWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmryhQ/9E+cYXLC4cCbQ8iXt/5jq+0o36wxuXkuuzkaRHsjxvY1EYDNm\r\nQSRcxIo0v69poYudPGMBBI0Vy6pS0o2Pz+rezrHXVHMk4+fX+oVfG9v8v2uo\r\na9B8vd4CK9evnRESOSXILq1KbKrUUP2bGM7fKwG1lbasCvu0ewT6gMM1MwXy\r\n2r1qho1HWtzZcFY9E9WL8/N/aHweomQg/YdWcOBkijy0vIeGISOUPjv0/zCE\r\nlpdO70oqZgnSruBPhgSSzKu9EPPq7c+6J4XAxXUV5/8KrWyqJhRSXn7n55SI\r\nPQhxWn61njpdb5wFhAc2naXo3f11lZy1r/MOxFgqocMAeXQFRCzvWwwPFi+0\r\nfprsIbbH6OJOqnXHFDncFGoBihi5608M6U8baO/A+MlRFqWjWfr2TPpFKBRM\r\n6w20WiS4i4Ypnz+uBmvvWWUs1rOsEzcf9dx3b1HGADYexSK8d2ZNGfptkD5A\r\nwlEoJXaWsQonbLKpghsz3a5F4+35FKc7BtDYXn6R5JBlbou+1p9ONrFP1tWx\r\n+JPHaMtrvpwILnWg4wiXF7wdJ0pWTYMoGpSxFVcZaqd7xWOLcd+mavjIs3Vx\r\nu+rmLOxoXt8xcMdhIzjsAX4AmdPMpgLxe/n7tHfDEE5DWChgWBpCDfr9mNeH\r\nK7Gy67W/stN2YRvGfOeBRK0yiOYuCUe+Wxg=\r\n=VrKt\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"20781bed13ee981641d886b8ed625600026d7980","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-14T16:45:02.682Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.5-add-repo-yml-20781bed13ee981641d886b8ed625600026d7980_1657817238084_0.9040004809473052","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.5":{"name":"aws-iot-provision","version":"0.4.5","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.5","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"bc4817414ac6eec3d084449605e4fabdcdb2d47d","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.5.tgz","fileCount":19,"integrity":"sha512-f3TyoxWB86pBV4UG0+n2mV9TPgbK1Fu2l5seSbtS7k87brtGoFaiycTEEiS3x2+GDD3loMPTFXqp0t2G7Wo9/w==","signatures":[{"sig":"MEYCIQDL04DwDa85Lp3HxyCicVoDjhcU3SmCt7DeN0M3dybtLQIhALtc3AD4T6O23Y3IMs8Y93g8AIrao61vjmg/FPSrcTtf","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676655,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi0Jt9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrijA//Tr9uSbYGJM1xGrv0AIv6FaX5/YGeo5osIX7sQ/Yu4EcggZw2\r\naLgqZAI3UdX9GaikB9sSg0vvbNsx52HMm+b7hLVK2I2jznwThJD71ZGabTtD\r\nf8Jnn/5t3o8wxwc2ruwdBrorOiNnZ0+2t59giLR8PTza8AfucYbgc8VjVHAD\r\nxN7eHAG0JtDRhvL4/xA418lqJ88+ZwE3WhFpN9VO0rm3hYjz0lMtWgR8bZQY\r\nhFZw+jcFLy2uYn35u/8qgfMu9Rc8/tPinpqjv01vMbPIZ07FDiDMyoQAqDkj\r\ngYPFeg5QAu9hYTHPUCAJbW1jjq6THaJA0iw4aFBwJfMIaN4Wb5VmiB0KqqqH\r\nVObf98OPMRFovk0iYKtu70r+PkmOFvafxpsWwga6vfhpRptYCn2u4bgPHC8y\r\nvUFGzo+KLc8q+X2dmok+DQsA9smDJPKyzsC3VefVSB8vJmZvbABVa7HcHLCZ\r\naQ25yQjBVAc6VBuYLUNvRZW21/unVKdKUoozLWXikqYdQoTWiir9CnuYoLZq\r\nIddZw7ptyrKqaGk9ebPO1OYDaHq9kgIJ8PQwCJ8toMDw3gXKxK4kcayboJeB\r\n4/iJbh0buKutBQ9HFuDBJAbAfRfC/lR+OFAuRTS8MSb/cRAAP4KF1buPWa9A\r\n8xym08cc7gy9Vj59gJXACX9SgMc/J5QhLAk=\r\n=dpDR\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"770bc67c1c965ccab8cc870d37aa4fa60ef728c5","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-14T22:39:08.670Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.5_1657838461529_0.33428948388561186","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.6-dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116":{"name":"aws-iot-provision","version":"0.4.6-dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.6-dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"37427266217650d25bac95ec4746501182afa8b9","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.6-dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116.tgz","fileCount":19,"integrity":"sha512-okdBVhuCaHax+PziF0fohfD8hEVNBoFv22DFrNtzVtZ8r9GZTSBjhTr22dyXFJqIU9GCB9acLtHVv3ShdsmWCw==","signatures":[{"sig":"MEQCIArcliQmqu4nHKRfFTYX/zcXJUwEW0iL6FLbvr1L3qy1AiB716guYoe36tjB027WCEHU13/LJkYeU+CDLLbL6nhMng==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676819,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi0J6VACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoqMg//f5BNj7/vpMIERagLeKBqSPipe/kCfjGjO0SXrYH9OgLemOQj\r\ncIh1bQncAp93ccoEzc+HkqlTleIvcKpV+IBbgpNIgtM/UxDU40zwT0m9o/po\r\nvlX1QxBKoAQhEOvFvIgnK1n87GruValj47PicsiOiyacMiWzMz4recg4gLN1\r\nOHyLIuuS9SAs1BrZjsch8BZmSd4U1Rzg7VBzKrI4yK0KRbQLfD2P/vq8QsiH\r\nNJiBiUe/AEMwzJlWsGek7FTe0AidJ7I/SCg4Z47tie1m9h/5cGJl0leE4o9R\r\n53loU4SH2RLwyOHG3og86Ajqg+lA0SDkZjcgA85hGMb8964kmtDKyMgggV6K\r\nLjjDU9XKf1zvoJla140OUtKH4Kt20Cbb48ph4b2dASTZfV9My19nXvkCPm13\r\nae65jyWQOJucMCxi6jIPI8IAsq1NzTpulfU5Huq89j8g3XMqQ3vY7azbfrnT\r\n97AwSYtoFjZgNoLqC2zOxjc/6w4EbSfFwOikB0fj9AeCm0qpljvTcsGrwk5y\r\nUua+p3ifTTfXndMPXTEpC2pmaY+6v3AFztMyi8HHuLQ7BP434cl72KPFDtP2\r\nlX8roL2+dzZJxbBf+XnMArbDx/19zIMg991VFCyJz64ApLyAxGo9Xn0ktBKH\r\n25VcZc1DXLBKyLrBDLFJvGHxYOXBeZOxgtc=\r\n=VkPP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"2545289fc4e5599eaf1fb2c781a66b7ef018f116","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-14T22:51:47.213Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.6-dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116_1657839253367_0.5123532542654985","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb":{"name":"aws-iot-provision","version":"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"1dc6fd36339f6b866a3ad1d90651cae7bdb1c113","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb.tgz","fileCount":19,"integrity":"sha512-LPIIw+1cVF3xcmXbt6nCUEuZ0FYtJUGRk150NfJ0ZdrL+es5B3eoiZbNr7Gbt2O30SOoVrbJZOeeZducWTIx1g==","signatures":[{"sig":"MEQCIGVnjW91+jOtdI40vetny8EjRa3KuKlT5zfSIqPQsGRqAiAJayyJvk5+5oy24bnaZLCyPTagZskqxHNVTJLyIkjubg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676830,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi1WVhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrqThAAn7RYlcj4oh8tjIsfuzr7Rd7P0R1Vwu62e38rnHAaopEAa3p8\r\nkdxGwbvPFdtY+uNocYhl7VP7Djfjjq1Wp3ECK3UhFp7a8WsXNdkp7718EVTU\r\nEI1ZNLzsG+qCWW6AZSyTluClYi5B3U3fkHAjoNFf/Rutni6J7EbMaIaWFe+v\r\nbPWh79pt6JQVijnREj773Dgj/fkD/153uGJ2LmS5QMVP4xlUYHI6BJeLm45z\r\ne/KW1/0pYWBfluumjvEBld3iePBIrVxFh/BqklQ/7hXYhbMd0+rzDxwO4mes\r\nZDV6iCwWLPIjWy76z/+jQdU6N5pNeAkrSbasf1+u5Ee3BuQYKTTdYBhoW1KH\r\n08XZ6U0Mt1AyClNRUjkNAw+fBAjSjj7iIdz593nt3wAxRQ7PQGCGgYLZ+K2t\r\nMrvJ0Whj55XdOnUrpO2E0j24ovk2TnjblRyBpXIgpEVnfmZ2i/gF01SD/v2D\r\n4fT+7EmPzZUcv18QbGBfmtezn3N4XvGuhREDVpnh9NXtnmK+nDTfwVpyUxh+\r\nPmFA7Q+niuQGYv8rVLOvkJEXaR2zNzyOWIUZDSpriITJvQp/3cEIusgoiRNU\r\ntzq079iuk/PeWGJplyYhRqLZGfEqzQMw+ku1GoVP0QAEHNHwWnbWhannO4WB\r\nMiZPT00Tv7fFqAYwt7PMDN9BKGcGmTU7vUE=\r\n=JXYn\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"1107516ce226bc839fd638c84a6d71a0c9f1f9fb","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-18T13:48:54.143Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb_1658152289454_0.8187475794129815","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7":{"name":"aws-iot-provision","version":"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"95c067d4ac975d8ec16c112c0188f989fdf27b98","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7.tgz","fileCount":19,"integrity":"sha512-gvOHjK/ejdKROVepOhBW4BDie4UOcwf6waNidBQFf7IpZEb3xX7LQYlFp5XtEdhwBj7Wvj96+GmCSLFbd7Vd1g==","signatures":[{"sig":"MEUCIQD9C/7+e60noKoL+xJbjwQvAqwmckuEtmcjpc+mtbzNSAIgMxQ41J8hQpA8O2n9NOcDNUW3TwtXDNSKfjtUsp/FWM8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676830,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi3pybACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpzhxAAlQUWNWvvTX+epgDh/nSYziNrHmy5Z2Tlb7BTQ7oBG4QE2Owe\r\nC+R+0b48sFfxvHs+ye2FsuV79ski8Ba/TyaLKnpnsA82+2jAMhHzbT2Xgli+\r\nn+Bi+nnsHM9XS7XgZ3VKdQcUmJhoYvMGxQ22KL7ewnjdnARg0I0ftaL0Ua9S\r\nevlcuYgmpZCsHGSDCLrAi0n3bfdKA9KUIXVjeKzvyco1XU8mno69zDPuA1nh\r\n9fvjvB8fqDC/ZBhkuPeyNMiCuoUK8oMf5yHY/JDX42WPCTOEpBNh41vWVAEc\r\n3fggw4pe6Pgpy0aMwEe088yu49T2ZmhJ4EXvZkiuYW9ms2jKs6W62umyaYFz\r\nHCkXsKJfzPmoIdhkbvdIQLgbrY6MPWwh6skw4/UgMBJUSUBT06W3dHUIGnFB\r\nmJIHaWXWhX+koDMdvIZaBzwQDKQYWuR/yLAe9B6D2QNE6o3QRuy3jgxv8MHn\r\n6WhDV9bMm9AdEkXk3Zjehfy/XaHSyHAFRF8d4hw3MqIaxK7oPEj0wul0mEHK\r\nCFabOfgLYb5stwBDoc1t2igPtA0L4kMjAzyZuu7js68sb2mjBTl+NsJ26Ctn\r\nhiyY0cPTHRRdqNBcZqo6fVLtXgpg/ULWTab3fUaquTmCd+RH0nFDP6+D0Zjk\r\n9BbAk/UxDzUcmSg0LRYXhmgfOwY1AhllJJ0=\r\n=fZFa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-07-25T13:35:06.587Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7_1658756250744_0.9396100276189447","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03":{"name":"aws-iot-provision","version":"0.4.6-dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.6-dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"88fc40903e4a039264285576702755af7065caf8","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.6-dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03.tgz","fileCount":19,"integrity":"sha512-m49OXlXf6j0bcuVecDofOslEnBWnqK50ger4eaN6RaS+nifzxh77QpNjvdR6maMjyxOUCK131Mgrrg9ioFMx6w==","signatures":[{"sig":"MEUCIQC/JE09s77y5PJfRPM9QOGIXG7QP699c31wCwQn4UbGigIgF76qwNGJq4cC+ec5G4qLVHXIVoPZr/bijAlZfRmRkgo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676830,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi8Q6yACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqp5Q//acxZsdRsyXo412zjE9T3awOz0s29DsViM2QZfmsvUcfMB+JQ\r\n9QQgob7G20VWC1kUJOuj+gvWq+5vxam2ouIrokLFNhkqt8TUs5kf/fQSq9Qy\r\nFVLbt3gwrQfBnAIQttCxPuxcgQPQPcxwBxAcpS4v5ZeGDuJ8mNuepcjmclVW\r\nfULhoV87ttWRI/3dTvytTJOcRcVwahjK4Jira3kCT8/U/Nab/AQFn7wGHynN\r\nbwvzOzrnm653OU4/HoP35ayEPj+3w13ARrdHN7FFa63jw9CUxjo2QhII5txe\r\nM+eSFdY6rKHVDu3B1t6fuwMt/f/B0gZ3wqz+b0PCt/6Q7y0LbIf1Ea19JgOW\r\nPX3lHAIjGnPMdMXjObkS0hxjymlimKWFPqSIMF2ay2fhpoO7grgd4CbygXyA\r\nTHqELM4zcj8UKCNhrMwBQtXIYzFIT+tVF2hurA0PbBgfOCeUcrIi4b6QcI4U\r\nAklmSMtNPvJnIg0a3C3b9/eNdUsMD1umgkxLcBBRL84S17Xy6jcPtX1c59JE\r\nH6BAT7jmgKxh9becYb1t66sqOaLYjMrpRdjg4vDAloKRpWtehMOvBuCj/h6D\r\nNF8lZoDvzHghh6RnfQzEWqxr8ERZaiUCHXCn4mI6COn7GqWtLYmYbT7NANHm\r\naZ6rzNMYCfD6+5i2REf4LbiTuFfWrTWJFqU=\r\n=dbe4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\n#### IoT Core\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User\nIt is best to assign an IAM User with limited privileges to execute the Lambda function. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/im-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"23a10e89b421e59a2da3733e3f1e046bf9e9dc03","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-08T13:22:29.881Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.6-dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03_1659965106388_0.9365512766851778","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.0-add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49":{"name":"aws-iot-provision","version":"0.5.0-add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.0-add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"6fe064e6b90fbf893336cfe1e9934c29a530dd52","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.0-add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49.tgz","fileCount":20,"integrity":"sha512-FjtO1v4tfpWX5OcZ4O/Yz2rHYPbt5nBVnieh2L6al1Rkn7segJq+7r/CZd3HMCWKrZB5ZR+178ZfwJrwKtvuUw==","signatures":[{"sig":"MEUCIA7b8k76ocMaK6mb3YLf4OabrcD6GNXLBi4Tbc36V94aAiEAy9Vfrqsv31/P8aygUM+KGXAoDnfjCTeQNA2CxhrNPZ8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711623,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi8UW1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqWHA/+P9RAgtoXHIaSfvHzHO2zt6GIzwb+4cD9xx1N0ICUEoyeJRRK\r\npuzjleCD8rsT7njqHYQtxKbJbgFeG3Yw0iQuwxk2szSR3f7MFhkebph5sYPb\r\navYF35BJTRU2w8LlgOZAcVoIg0VUAejZ9T2e2p145jR6OuqWfCIG/OIA/xlX\r\nvGlm6VHhVJhvT/Rx9tBA5bR2YHwyaDZELAYseK+rJQfpzosTb/J4NZYNsMAd\r\nmyiqlU18mSSAmG/IIw3pkliBQgBpyuwXAP2ZcKi4ox71unTZi+UMox8swCN2\r\nj+eofUXipz2eLogpM9vKc1NHg9Xalqml9qd2aoPLD2cymJqNCUKDIMzAPNz7\r\nC8ndx/9aCT3Bp1oBuCoHyt5s5Ao5ECLEFf3G1tU52PPIg3BqXLoYFA8UbvHb\r\nDjVSzsXdPR3zS6dUkbfnM9q/L+0uYycvO97Z4AEJBe1GrrZAHLp3bcgJVOXg\r\nXpr8ja0wZ/0u/IlAhyoJbbfyd3DX49T+3ZY3/km2d6YIdHvjZJZSS2b0j0ym\r\nX3Ep6yVWfCCtiYeq7apFke2gF1isAFodAn0HAtUasTPxQ/V6cnb/2om64cE+\r\nqj2eT1yobtZfBLcbKCnRyS+TEll67j4Ph3Lr9V9CG4D65orWcHileWaMJm6A\r\nm14eVPes21k2gPZ7j+wTXobCbwGQwxoUJcY=\r\n=RdKB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"bed40e82c7563c0dd63f657c72f8f60a25a0ff49","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-08T17:17:43.652Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.0-add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49_1659979188703_0.9686631476448682","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.4.6":{"name":"aws-iot-provision","version":"0.4.6","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.4.6","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"f17851816e9dda77e3e54dccb56e5f5cfbf88974","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.4.6.tgz","fileCount":19,"integrity":"sha512-EHaQwY3fAYk3oZKGqWmCN8SazF7HtoQIBnx+01o52m/nVEoB9AuAZ0/PYPbWUfisswbQU2kSURpu8AhKGO7+kw==","signatures":[{"sig":"MEUCIQCtYFkMTZCmU8N8ai0SllF7aD7IvHVCOMaySJuReb0BPwIgIaEJkQW2/cqrHtJOh9oVlsUET6isDWl6Yl70Nw5kAyA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":676740,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi8UXqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrdZg/7Bx8VVw2xp3curLdTCfVD4rffMDJg4T7R9iKmIj1hvWpNB5s+\r\nVhD6+fr6B5eCS7Pl/BpQWpKlyHWojlS52F4vBtsRJwpmnPJRW5FM+QgidztJ\r\nnMbcL6LHgEPbCOUA8HuSJeLbkY/pGZYwfX6Yij8FSvC+NcQ/SUVez31fGZnI\r\nboBcX/TOSEmWQV4JJnnEtVk4/o226i1mBTBw1etLEkjaB2Azh4BW5WoM0+Qr\r\nzniZIzkgnrjR4aDrawianpZBMiix1CsliOxmBGdxvv69wbP5/WDvOMbO3+w4\r\nuaJhD537hmI5xzxZMV3o19N6UPg8nw0PAts8Cl/WEJQr8fFI0R9edl2BOom3\r\naFf9Rexd8c3jzpbsuiMI4b77ItqrH9nHCrqniimTJsB3pwl6hM5dR5LRkiiy\r\nJ13dtS5Q9OYm8iNq/ZmEgPiKHKWQ1fpZIcLcXw4+Hsn9J1RQQy/gtckD36rs\r\nZ3wWb68ABlMBiBh+nlVZ+E+0/VWP5rgLf8tdEo67QFMCEJiEd4+bMB0fpu5X\r\n+te9jqQ3GmdMtmWYt21/d0+gjhHuIx5KJwpDZ3Wa/HnG4KHbd0l/oUAz3KgG\r\nvjduHrXyLICq8nzy/3JaqNGczuL0b5utC5abPORg69ah8Aw21ieZO4opB2lv\r\n7GR5/ge0d+lllik6ncEbUn5R6rsN3WcN74Y=\r\n=+YYf\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"e63ca99c6dfcf5576678e9293bc3256983144e31","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-08T17:18:45.870Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.4.6_1659979242224_0.47747001634153063","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.0-add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e":{"name":"aws-iot-provision","version":"0.5.0-add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.0-add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"deaf99379fe3563db083c82ecf3c795d5d983304","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.0-add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e.tgz","fileCount":20,"integrity":"sha512-cYrmwR+auuc70hVIuht3gfBRX/FSjdPs3O84zPrO+VCKLd4Lo6OG56kOVrITrGlKagThyHhYFZ2Rxf+WN8h+3g==","signatures":[{"sig":"MEUCIBWP9P8NXOpiWNvVKPHXasXrzBRd3KYi9Fd1dsTkhNNLAiEAtQim+SX0wxrkZ/eJe/l2AQwK68yISDqoC5Q9DnuYlJM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711708,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi8UaOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmoh8w/8CXbFboIV2T3HUzX51ieCWksTFa1zUi7PmMocLEiZqyubhIVN\r\n+dx6fN75mw+BaV72+7CaaYEed79B7d5hE+Bref5dg/nv9ZB8++AMkk/NBU7/\r\n4C2kkNyp8XXgDzHVM+AOJuD0YuDntFytC2vermov0y9ztARQYC4h/t370Hvv\r\nvR0G63w+WqMuHYIFUQwHLoPxJ5kvvCCHb6AqLxeM3l9/5S+taYwtc8w3sec9\r\nWD251ZY39ROOZ9wEWBoxtRVuRnQkXK803SIekuab/DbvaNZQX+Nh6avKiVAM\r\nG0Mn+dcn/hnZpXUPCEyTMvfF0PBJAI5xWK/4sUv9JafLyht8fpsnbCHjQ6Ef\r\nvL1YGTyan9sPxXoenePjyK5zXBQwA81etGPy7e1tsEK18cpU+9M5fvpLcOGg\r\nrZz0EA4sFS0M75TTJYeCVzn+LTdqncq3NsoHuZsyNMJ5nrvBwwa4metKhWyx\r\nVzk+Mlg7mvntcqpCKCHzj+O6wBfddJbShjXyx1TALBjRb5K7MnJoFF0gkuyV\r\nExy0Mhdzdzgav0gpUrr42JaF2kHERN2k3el/CysudlHeaqcKz8TYhLZVYe3a\r\nSpMcwnexK65Ukkxh10fX138tHzXWoJ9RBXHf4cZPnMqVLhJCp7AbtYsnQvPw\r\nOgLyTn6Vr+4SpZVJOUb0ruWZTJpY0X0W8ZI=\r\n=NHJe\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-08T17:20:54.871Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.0-add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e_1659979406555_0.8702412120388325","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.0-add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d":{"name":"aws-iot-provision","version":"0.5.0-add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.0-add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"62ae5238e87986fecae6db33547f041f90831d98","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.0-add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d.tgz","fileCount":20,"integrity":"sha512-odNKtOQX8MXs09Etkk4cQO6YyfoBmmEpTtctL84sb4eDKIaK5Lr+EtIMRBZyOwnQiydpKDhPthN30CrM/E+0/w==","signatures":[{"sig":"MEUCIQDFsb/dqy6Ge1Ou6q7fHzZRZZq6Lo1YczEGX1VJJELPVAIgTMJk4FIqQhcBLa4TJoeM5G8fPefriWeoaLdKjsUkQXA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711708,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi8UnkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmormhAAnXd9YVLl8vYRA2Z0WgPa02VgDF7sRt0JpuKmTbvtEYwq5hur\r\n9K7dJjwrp+2qulgeCCyDB3BwJu0x1+sRtj+YtScMdllj8MO84MMn+xXzRkCD\r\nOA8O/CtrPsec0U/Y/yR0DbMQcPogo393cBlPEqd7BCCt3EAQcYx7m6hvGjQe\r\nT+k2X/CTlrj06SMAco4NgDsx+ZVaeZ4rAMhkhJSppUFvOd2djxT6VEh4ywSQ\r\n5Kl+8JatS2R5W1RQMwS4rsPLjqXH7Oz29cSAEKqOzDu/Ygpvik6UGCO58ntb\r\nHm5LV1QLYJ8l1u47JfNTqagtiKC8bB+czu+9OsuaK7QG0uw1GJcsyrgboODQ\r\nSlq62HpMiOrJgaarwNkH6LbuLPKMomF1cgK0S323kbGZrfM9ghu5Pn1y54/w\r\nDKoLlVgnJmMBd8283m56WGGQy7qPd5ULFsTPnS2Av/6wr99BpEnZ+yWcIZWP\r\nqgxcmzgUy+6hIlm5+LwTpcxdIwhoSqZiwGS7lZuFvIEEoQwoS5ShU58BDjbi\r\n08zB0TdyxFVp3SqexUaTySLOvEpe64zJFyHFZvSQYBjtZ8Caj40XcRAyJfRx\r\njWw46Nom6MdDIDqg1PCM6twkS/VUNuDtrvHPDq8JPFpqlvQwnTkN4d2A8M4L\r\nuOBNUKEktnn+zffpEMajPiFNqAK642ARn1A=\r\n=UPI2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"aaf67b2a7244279b299d171347446b9415078c5d","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-08T17:35:40.232Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.0-add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d_1659980259741_0.8183920007357779","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.0":{"name":"aws-iot-provision","version":"0.5.0","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.0","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"1d65ab83b54090928b4438a07c2b83bdfe938cb5","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.0.tgz","fileCount":20,"integrity":"sha512-asyOccc0jpCsTGlX96IK99EqQS0LPmUqWHlBwsAuyM8Yp4aD6hSxAGYMNgI4LmxLtEE5AbUKISGWb6lchKcmpQ==","signatures":[{"sig":"MEQCIEEgmAvtKN2Vg2hP0iTV5lyg+FcNjpnYE3NdK43cp4GKAiATdy+j3HvLx1Z3rLaNmt3gZN/JvfJgIdAC2bq2FnIDDQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711645,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi8UshACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoPzw/+IA8smj9Z/kKWFiGhU9O2PNRosaWVMWg3gXmDBVQaAVCaRFF/\r\nvHcQTX6JVGb25JD2vi8xTBCsZaB7hcWJuRKBfXAgfwIrMrvId4393YTdnwz1\r\nMUAvM0gG0gssdMot8XfBoytdW3iri9aXVJFs3DVCx50vxOO7MaHPxFQFQD8f\r\nAA2jUPHVwTiP69U8f+FZy2Vzqd1RWGvrdfOzUcciDLGdw8PmwWWBWHI6fZQy\r\nxmoLoamtVHP127nOSBFq/60ZPKARKIjsYbDRzWthf3G3crvucgJg7YyPz5Cn\r\nNtwo2AgQaUzQgcYWhNmWHg0h9j2gnjrE05CD51xd60fERfKigvapaDAdoo/a\r\nP6EQWwdQyyQ2vd4zohxF3YTXz1n6S1onTQ+VLdCdjQbFSKuOdpWNhybrjpWO\r\nTQYNv1vCHSWSrwAdb/DTfjpIYzm4BcW4FLQqbCdWVlRe4pQndWH+cQ3qpxNe\r\nFAcylK83Q86/km9jGtBME9gAMmYT/386ZEyZfwUhH85M3TYyOKCyRCD4Bk4D\r\nfe/gvufO5B0oBZwQUu294v4HgYwiw4nJ/n9+UG/jadDcxKr5c2GHjVL4sVZo\r\nkUCGnGMclkEUPUkXVQn/7LcZQ60Lp9NzoB3fFXrxSoQYudfYKSL1vSQrm47E\r\ncr5St1orZQLEdxvBj3YS1TcPljj4sahjvwg=\r\n=+1sb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"8616fc17cba7b8cd188caaf501e0d21421bdbe38","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-08T17:41:04.388Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.0_1659980577316_0.30450524343083796","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"d5cc2cce0bfcbc1949cf1c18ad8ac4b1e41d5d29","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e.tgz","fileCount":20,"integrity":"sha512-4zXU5Re6YiLdWm62IAHJzF+mbNnJpZ5Pz5Jc8p0YrShMmpTf/+9zHlUegNpqyRbpXdPNzBmZ1cI9zAgWuwBJYQ==","signatures":[{"sig":"MEQCIH5ncOh2ZLBZQlzSkTfaU63Z7KotiHtVX9YTsZImDwWKAiA/YjeOwXeaqCWZsfHTRCZZLuHU6GrlYgHwPxBSCkAEIg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi+kjaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrDhBAAgEraIPj9uLQzoMC/8xzevQJji3k0XIqRJTxbk19/hyosYLjZ\r\nmd3kpiPa6SWhNquTWErJXawKaiFE0QuluDoJix7eegg6UlZmq/CShqbeDyVA\r\nWlpTz2BpqDMgojvsrKW1W3Wr1M8HXg+xvBBBmBhR/PDKra3aBs03/oPlc4zu\r\nAoaQ06ex4wQJUw94eaB64XScC8RKGsXZit9gAGBxnfuQT6MMLwrqYCJyu5fk\r\nn3rYsH8gr9n1Z23H+w5sWK5jF+N9TMq9v9HwBFR8WnKkSHQ0Su6AM5vvtJtm\r\nh1Q42IbQDZ0gN4Zy0GwBuwO5yDbCvqNr642SJO+GI+1aPy7hn4wSPrPrJRYh\r\n14vjyt8Vyl4/7ehLQch1p5bzpo6wShlU2lwOjhfFQ7XmsOIHZ93FCUFLnubb\r\n+pVMcdoSTS83b0VJJYTisEAtFaYE+1F4N8G8ZPTqxRNKas1Ea6u+KRSzN6H9\r\nIlR6rioi0gnlflyOCNecxLM8wBEhzii6jsv4Iq1w7LE/iTD1MUN4q9OsEofw\r\noNyLgUoouF7kAygCz6PsfQYDTSF3JlsGGyyCnuu+HKyTK9TPpDD04+7iO7/b\r\nXjfjCK6UI3BLtWNeocYgblbqYcA53CPyUT8ZicOknTFHE8VKy87SSyq9/Nw7\r\noQHOB24DK6emnhy+Vuiwictf4vVttEz+qq4=\r\n=kdtN\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"b8758e6c8bb3b785fa5ce6b5158b741734bdb02e","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-15T13:21:02.349Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e_1660569817849_0.6983370053485296","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"3033f5af17ea986bb5c55d6250dfce02dbb84c29","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a.tgz","fileCount":20,"integrity":"sha512-xcaAV5960O+yeOsKi1DXyINz3Na7vFANdR2+2O0qPlceXG3Wc/Aa6AmyJDdfs09e8XB5x7fg5fEtE/kRDQf0xA==","signatures":[{"sig":"MEUCIEbC12LVfPBOo8fjDSIW0z+zxGrv76pG1/IPdQhqTHYbAiEA3hhggHFOcwRNCTYFnn3hMuziY8X86R20XGUBdgtVpnQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjDMIYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqDdg/9FmF/YjArWfvd4mUj8bicLMmMeW8ffZXSDwHpKc/gcN3splzz\r\n7HnruLMHi67/E6CDrcA069AELYsuWo+Mwh++iES34jt0h2oeJ5tD6wEkrrUW\r\n/LFsc0ie5wgdDIvaNyJ97fz3MvLXZ6KiAqA1WvfD0gbDy0iYPcLJ1FXDtm7B\r\nJWvAWN4im9lG5L1fNLv+a72NqCqN51jVWwU9rNFG+2Ru0pVg8UOvRmoXsVIo\r\nM/+1RTQKvdqTjJ64O40ce0MCC+MzIv84iWopQGQ/9pPd2XvBfEKNlayRNgUg\r\nN79tBr9y6++xuXlxV9ty6vHlEFfp2eqy55MIKY1JNp/AM7QOM3YLN6aYpGnB\r\nYzcROUgNQiEVEuE0wZyYus/tt9E2uv3sDs5DC99iabDlKcbAT25w/1ek4J4Z\r\n44JX53fN2e/mrIvomForKdNHl1zUQNcDN9G38djM/yxQyIwetdopXLm5MnvJ\r\nVi5oZzuqp09UahucW99sAKyz1mUNYkzgkiDgQw7AyjG6mZOCcpmshewWtokr\r\nmquqgIqheIxQKj+kLLUfb6UkkSIZT7VJ0p1wFG0Ci/qMOcnkn63L+J5e8zJC\r\n99TW1q70yC/Vlo+rYW3CS11WzZPUo3CLkAr9ZrR/1GtcA49m2sQIs6brMa7d\r\nxVZFjaMSIx/URVR0Rh8q1Nl/SLdHXdGN9Ls=\r\n=LuPp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"d0d0f710eef0b1749c98d821028926e24ec4ab9a","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-08-29T13:38:57.409Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a_1661780503767_0.782190954955243","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"d291537bc984a79b7138d7158a40bbbb8af173f4","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4.tgz","fileCount":20,"integrity":"sha512-cj1tZAH96iQN/wU5tVSGJ2kJK404qjmR8zKTsfbMmQ9IRbpGq2LtLi/6mH3+NjkBimzXUYTZC0fr3lGq6q+ulQ==","signatures":[{"sig":"MEYCIQD8kiqklM0O4ztKWZnVTNoqpcj0UKrq2e2flEx9hO08cAIhAKafqe50kmMGBjeGw1104FAqxEj61dTcqZ0gughr8iMC","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjHzXQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpJqQ//ahU8w5OvKS1Ne/fGqYq4uHPyEQb8TfuTCCOvI3TsTjV4sckT\r\nSkIYJktRaRF0wHjuaKzpzwekL8urPverd49b4Oooq7JE6tZrrh5SxaIuI3tw\r\nYHdbkV0vFtAYr0uRwIkNbfz9juRf4eQ4zgOKxaMUeWNix0xv7kInrr40YRUr\r\nEoz/sLKxHoxpoOxLw8Y8q6R0aYFvhOqu+Hntn1sPATKR4PPFqGIWo5OvL+cS\r\nKea8dXIlymxqLCp25u4xJeysxSioTQuRJq9uGmJhmy/yMOMLX+qzMf4u6W71\r\n1qdBw05jODlhM+hcsa3Y1yzAsoDRX2mkllOAPsYLigaFB+aAJIcLFuvz+0ty\r\n/E85tY9A43s3PtzIL0mRGIBYPws6uMaYg+chA67vD1ssFneusk3RuvqOVbST\r\nt0mPyHN8Ualr9PM5sc8wEb5syOwILhoQA311vAFhfjKi1WQe49gWAJxFZiLh\r\nGShdelDFSWxTjGygTaqJPIHXy0JjItubGTYaQrHUHnW5+B6j5MCWN1iB9bqW\r\nyVnbcRhIsRtIJF3/63kghITgSfO5UC4hyolNLpEjhWUZODRNPSYpDMp0kAJF\r\nc6lJAVfEYpZeeP0aXmQd2W5GgtUWaLIl5ms1x/f0DQLhOJY8Db9w6oF1Gesl\r\nP/qI0hoJ9bEOy/EAlcd3+8UUlVErLZ/P9Ac=\r\n=ygyh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"bda2096544606860e07b08ab000c2f733b17a3f4","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-09-12T13:33:02.144Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4_1662989776619_0.7498820604345575","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"0a1c34432a314a3e79684f2b6a1b9fa496c5be2c","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714.tgz","fileCount":20,"integrity":"sha512-vkCZDOAHCP87882ja7tuifInBf7l9igtW++69YwTCoajZtBVSqinBfQiGVquxdn6Xil5seu4hC7E0hrszkBpuQ==","signatures":[{"sig":"MEQCIFh2nFuN7VgcuuvMHN8fa1lqhH0qobfhR3+KCbU64587AiBGQyUEcaUruYzbRJ4JRzdIDBPTJMbe4dSdpsYt6wdPdA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjMaoRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvXQ/8CYhJ8CvPOjqJO3OKatt6/+6N6ZdjQlqLW3gdf+RdyRIuWeuh\r\ncEfRKfpwCxfBLE+ybnlVHX5fU8h7mR3EmSoOq8uWueh7JxGlsEDIWVifeQog\r\nrrdDdKs/j4k4UewxO3KJ6eD4SamOgjY4fGUBEUefzn3obtuDuhOaZuJlcG++\r\nMiejzQl/kPK/6RylH1H2om4/uJwaaoklaO4YYZke9RMeTyLWU8U4Trjtzgim\r\nh07tVf8xoSA7DY76NYgkEeFjO3zxxs8javysrfijmWjW9ZJ4VmzhVBN/xMXq\r\nVYi+88uhT+hQsTnV/CglcCuAkllgo/S63VHAte4AdpOmTrAfir0s9zHWpMHF\r\nIqC4bQf1sHqZE9fC5Zor6HrN0kwCwLWG43BUYCkAkHlyGkvXit1lX5kS+bo6\r\nWT5Nconp26TPGv6FQzT1QB98zTHtqoyP5symCPoGz//j6vjGrfimp6fU7xru\r\nNKG/IVgglweO3UwTqdtiHmxOQbeM6Wz0J3PfSfC0hPX2anxHLAglD1Z7UB96\r\nIKNzYwSJv1BRdnUjJZDURDnMJPAXl7BmT+MtAfS3pYr40OodoI568iG/QCpI\r\nakHbKGnQFKZDaDlk4VFE3Jkm3P+CoeFo1Z964AkNpCLpKUNn1WkPY7kSDiEg\r\nPDHee1vYjw90CiwaQBqONCVT1hW6JT6h56U=\r\n=4GDg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"10275f8fb7345c13020ededade3e0e55faf42714","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-09-26T13:29:46.471Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714_1664199184829_0.4608633636691024","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"9e047d0136193a895034cdc68d8db34ca35c1b07","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b.tgz","fileCount":20,"integrity":"sha512-9Y3bDO+fkoboDD0ZUuXaSee1MEwbZiLEx6SMMd6g7dWejMvkgy2LrOZL7YNEeWMVGGGuu7iac/jXaNhvsMB1kg==","signatures":[{"sig":"MEUCIQDjLq6ib/nZkfcA7WJgaTrEe8KW3LYxgIg3tWMoZpZnXQIgZFmlog6i0fF9M+z7Tx3YF2rclwqjupJV/C6sGXaKJjU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjNFlrACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrWVQ/+Prn6MEoKt/iOOdxhWvGGmn90/2RJIZtfhxUs1kf3ABQzCJXq\r\nHK/vT1p+WT25J2mZa6BUPW2A6kSM3YaSE2Er1InnMaRe6ppvYK3BdMiWQueg\r\nlMEUb3cND78PMug/fXqJeLfQzVha+Ut5ZYQ8ySSRXwhAJaJXwRGM2SiisC4J\r\nPjEs2H8xc6kaGc6amk2CWt8jetaAi4nJTQtOpK8HgL/PWGjLAjyJ+AdvT9ri\r\nHewnnzPSw1pB1Ji84hgiyZm8UburzMfFLMrsvczqqmivpkqI3WdyCV/xyN4X\r\n3kNVw9cvjGXOx4hU5tZpqn1lYirr1tddDRaO4ruWGXfmJNY4OlgI0MldE+yp\r\nFonH8H1p3PHYY/Up7F+w83VormiQnKjIJLyTylQcFDUzObkI0CX3zZ2Fr42R\r\nLhJrFWD8AtmsE1sZUF14H0mlTQCYASrDC4upRwoajJHDUx+hE2dldXZeZwzc\r\nGowb5uEk8JpSuC3AOuAEEO0v7OOjw+OlYTsxrb5wGLDFquhN+yEwJjeCvTu/\r\n7qKOG4GYB1tYLHk+coydMI3JWEZG+OxVeNJY0HAL6lcV2lG1IoYr9fBPHg3I\r\nOkeTF0zK87aHcU/GWLwUW5omv7/pPuAAgyYNQSq7HDgAMHRnax5oHScjhozW\r\nt9a7Op01MvYlu1w976Z4VQOnpbZWzSGEhaM=\r\n=TqLF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"2446e86514eb69f99138d51e1adb43436366cf3b","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-09-28T14:22:51.976Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b_1664375147406_0.3830600528974777","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"42e5d7cbdc813a664cbffea06ea784a20bad79d3","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42.tgz","fileCount":20,"integrity":"sha512-Al4PyfEL+GH6h/L1Ns1Jf99bUtjtX7aYgkrCzEwPIbM1KAcQbb4ByTX7x1FAIw7zv7ww9D4VZpxHydd9xX590g==","signatures":[{"sig":"MEUCIQCv5cvEM2WfwRjpPrhysV5rt7XkW4kOpWtO/kc3VlGYTgIgOunGHCjC5QPChQeo1CIIvhc51OzWUfjw7HNITjLMq58=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjRCnQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpFOA/+M1Ng/Pt6KYWiHQP5Ex5e32EHIFXgxl644ybiwjw5Cl1OzA9T\r\njVGQYpHm8GkEKjck/IA7EGhWWkM2UOhtstLUSAUOOllC0DlaHEhXiHW8obJ9\r\nYXij1MRbZY4wB/Mq5dVsA6zgVi3km5LAqW4WjbpKVIoucgtoUVfDOxUo+zOl\r\njVckSk2S73oRD/T/EfHJFmk9vQdTQ3PQHcOOYXpClCgyC+83Y7+aOdnPjCvb\r\nUqKFdmfKoewQhKLKD//p49DHVHcSA0MHa2+IL8VjFA5QjbHnBb1lLfQaHaT2\r\njidKiAXrh6M5OfKhyFFVhB4XZL3LvxMuuZki5/vDt/TJl+33j887Od9/6na9\r\ngzRgefG92+FKaDPH82NGrQL7d+wNEVGWm0ARKMDMqWBmh0h7jPDh3A2uFZho\r\nwkbXMKjcNSka/B/+D5EgRcFxLmTisr4rdbkgP0Kc9Q0Raeyg1CFw9j8CN51i\r\n1XmReQQubKlZL4nyBqgVzMCgrlo95ykKOm6NZaT+OW4X7G6Gmyq4r5ECsCXN\r\nGGSk9RPTawPOrFjul0x2PqG4cOLVMFPdBBIjm2gr8M09ATYCngynDeHaMw/D\r\n/QrpAxkmuZ2PLMryaxlXd7LJJEsYuvvWuRNADV+unj98D+OXTI4njBn/9kzm\r\n/cMkY69rfB3s6V6gkcHm61LPEL/Nl2JYKBM=\r\n=8b/h\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"dea4387824f68666d3332653d2ae8632e53f0a42","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-10-10T14:11:41.525Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42_1665411535812_0.7189221473321945","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"76f5e2a4870ebe190651f0210ed900ac1d46b0b4","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1.tgz","fileCount":20,"integrity":"sha512-Qi7Zi0a7V/n+Ole+xFfqa8VDUUFSno9V1cQ5sBdLS9qGIpjxOUTqWI2bVZLTJ5nNjtyN4djM7st9yv5hZKeQzw==","signatures":[{"sig":"MEYCIQCqfLjykpXranbJKoeTY1yFdNgLDTCIoLaaZpb7bVkzVwIhAK7e5lHdAUHcHO1QXBdDvoiSqvx8TBBDAVhzqo+iHMub","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjTV8DACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo3Pw//Vh97yBy6yocI+vvIfPfruLP4cSOoIq6OE7HgNCu6eSXHU60d\r\nQ+Lj3167+btKhJqyRZSCtmevb/6aCUZ6r/HJcbeH9PKk+cN+a5p/ACucv9HX\r\nfrFRH4KF3+r8R3gElHhBgVu98NzXKcdBVOsdCo3CCSNg8pkWvnp3zDxFaLuO\r\n4VUt32Uii8gxLqq9XWUORWt3wBAfv5skjQHEKsNjQQS2c69Vh5rhJjqytoFq\r\nsTsqsaZ3JheCEVgpUdqKeo4fcR+m0mPkFAo7hl2GJMIzA740AUH/CY2B9WLH\r\niTl1DLCMxY8tf73DNn+fntFWcUlqkCZ1zTJPiWq9GVvhGotqEe2dvQ7YQTs2\r\nIUTuRTODeV1voLahURF2MGEEPi1OiFAmZyrpqH2PY/McwQr8tj/bPW+aTIyZ\r\ntLTWwRUTUD9HqFShKZLClIyNB/DxK6Uiff35q6ojCyHlmSpdPzxu9cf/OFTV\r\nlRkcktjeCnzuPOd4sfBEgXrdvVKY5YQOo+x7tP+wEkTnO6IcjzsTJHOXcNlm\r\nwnHgosh4Y3BvVg8yrqqZ5xEHVdzbwkWOdCz4DRyvybab7P9weHpdGidiaQWw\r\nI79DXZIGmuBgptpXF2jFiwzfxt5VfnXRbEf/2bD+1R7StxyfVmax8bG3FqHL\r\nNVFhqzXaJ4hZOf2kv1AYKOaXDeblxrYiXQA=\r\n=fisi\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"8f74a4b5949ed60d203b355dea0cf20bed3be9b1","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-10-17T13:50:00.544Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1_1666014979149_0.42230852881543046","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"fbbba4730d91a993bcb3db38a1f246a3e5ea9834","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd.tgz","fileCount":20,"integrity":"sha512-scA8SRPImo81rA1ce4X3toCv2I/5Ngsz5mgQeszc+Ri7EXp9BWNjycuUQW7kkDjYeLlDYbXHAzrJ9k8J17lC5g==","signatures":[{"sig":"MEYCIQDJnVKs3QBfpcZn3OtkNKTbCmiKX70r+P57oEfqFbD4MAIhAOXNGPv3hUXhhJu7Xmvh4Iw5XB8Y+79oLNXC7lI/1hKk","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjX86oACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpx/hAAmB2jnWnE90AcOqzcooFVEYYbFS+/wXm92lgfSC4d5RjBqwMk\r\nf0Jv2erDOWTJk/ilE0mnM4iqikZiF/1Vy9Vlm7wMxW+tcAgVGdHZ0AnBJxIQ\r\nwEkfax9Q0fjeAsNdlEHc27Ank95h9598nrRocuUTYSwGtoawb4cB+seSnyXr\r\n8wxi06NoKkc726lubk4uaiVN5Et9w4cdUg0BVIebClmfOYgNhmcc+VtKwZ/d\r\n19Rb3nIVNZLiO2MvIrHxLBJJJhUfOfP5gzsdBr1/wjP3U2FC7OU0Fr2c0nUK\r\nN2AOugS0AFEPqzQgwVgXH47wUVb4uibB/6UeOXffjyqWbuoEX6pSvbY44hek\r\nLb+IJGrwWqS+ev3HKEKk8B5TWrmqcPYr4KxNxE0bswu+qvKJZ/FD6WfGT0y2\r\nZ2lMGvIqD72yGcUj+uU7xJDEkhcNr1XumKyt+O+54wllYnuGQS9RhoGqvVAv\r\nzwzINaukWpDSjS0BcidsNUgEQSU3KacWlIsVh6ZNzBFxQOGZUVlGJbx0AidY\r\nHMBIWerS+X+NJgDsLC8S5gJrLFSK1AQvNxbyJmCfRDbHBMYApSQssztbZlN4\r\nyfToyQPr/dEhFdtj+HKwHkr/pa73ZPKz3yXH8j6KDynbUSboM8TAfnz6XVkj\r\nayOGjSKbC13Lxe+325FI0tRf4Wjrce4qkkw=\r\n=mXhy\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"b06c6c621ace65176f0be84e44a06696c36ed2dd","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-10-31T13:26:07.903Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd_1667223207862_0.6586728448584453","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."},"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429":{"name":"aws-iot-provision","version":"0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429","keywords":["balena","balenaCloud","aws","iotcore","iot"],"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","_id":"aws-iot-provision@0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"homepage":"https://github.com/balena-io-examples/aws-iot-provision","bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"dist":{"shasum":"f6342f9be7f3f6a002d71a5c50dc1434e7d02653","tarball":"https://registry.npmjs.org/aws-iot-provision/-/aws-iot-provision-0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429.tgz","fileCount":20,"integrity":"sha512-PmMlJkV72qexyCieZlhAaFYn3kiDkgy3zRoV41F6x+ht87MiRqbUrctquoby9fopWT0EILxRBq9qJcmvx01KHw==","signatures":[{"sig":"MEQCIB5X1IEdphQp5fgHxUXFyMPFRSt0oq45h9aOJPkKYtJuAiAM0sFkgxGilMo+1hz7xBM6wy3BkgZJeUF8lT5ThXuCCQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":711820,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjaQfEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrcDxAAlCjJNN+FaaD6Qg+sUkP4ZBQronswlzWgbWeYAATI23FEc4ZA\r\ndbxsHL3bzferYSirtA+0FnptsSeiwTaaGlqYHZJO1RKkIlAUPBM36OGYZ83g\r\nihLvk0u/TB++tg4pzC7ErnY4rKJBmvzgIp2XHrV41XmFKEOajjP6Lw8OvmmE\r\nT7i9CFoLvqTdW1j1tsIf0F6hYx7rvZLFjyh0IgvpMm2f6vNFcMMtrPraUl26\r\n1gL8qTpJZ3kYQrCufCpqo1TE6XwMiD0XONjTICySB9cpHvQ5LwhwYhESsGbI\r\nunJkUKV9RR+vsCkULi9y3xs1oxzsa9DnYwN0kLfRFntf3Q2E9vnUJTZ5OSYM\r\nrXWSertIbvIRPi1RoaD/kcDF8cpM1CZ00fEvvjQNLIeknTlG3ZMLCjp690ds\r\n/4K+GghgXYy0d1EvFHZ1Tl1w1WXtXDOCfHFmM0MeIOxuwY/cYBwVXQ+7LknN\r\nG+IrcwGGv8QPV3ypOw15i95f40o1tC1eZTrT3rcElJheHT9Dji7WeHnzyoXw\r\nNs4Mjmair7WCeMsgLEavBWb+lD71y6WXzrbRbAMPZRRFR32pICmJZkqc/jgd\r\n6y8FMIATTZ6X8e3mCzOCStN95WfpidNpVQSOcoN9wgQdV3jLp3i0/oueS/jH\r\nTwX4IpW0VJlCfzos1YfBEUr2/s++6JedWnU=\r\n=i2EY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","readme":"# AWS Lambda for IoT Device Provisioning\n\nThis Lambda function allows you to provision and synchronize a balena device with AWS IoT Core in a secure and automated way via an HTTP endpoint. The endpoint may be called by a balena device, as seen in the [cloud-relay](https://github.com/balena-io-examples/cloud-relay) example.\n\n| Method | Actions |\n|-------------|--------|\n| POST | Provisions a balena device with IoT Core. First the function verifies the device UUID with balenaCloud. Then it creates a public key certificate, attaches a security policy, and registers an AWS Thing for the device. Finally the function sets balena device environment variables for these entities. |\n| DELETE | Removes the AWS Thing and certificate for the balena device and removes the balena device environment variables. Essentially reverses the actions from provisioning with POST. |\n\nThese instructions describe how to setup your AWS infrastructure for device provisioning, including tools to deploy and test the Lambda function and HTTP endpoint.\n\n## Device Environment Variables\nOnce the Lambda function has provisioned the device with AWS, it sets balena device environment variables as described below, which allow the device to connect to IoT Core.\n\n| Variable | Value |\n|----------|-------|\n| AWS_CERT | Public key certificate in PEM format, base64 encoded to eliminate line wrapping |\n| AWS_PRIVATE_KEY | Private key in PEM format, base64 encoded to eliminate line wrapping |\n\n## Setup and Testing\n### AWS setup\nWe assume you are somewhat familiar with AWS IoT. If not, AWS provides some focused, easy to follow documentation to help you get started. See the page, [Set up your AWS account](https://docs.aws.amazon.com/iot/latest/developerguide/setting-up.html).\n\nThe setup items below all are related to AWS [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/intro-structure.html) -- Identity and Access Management. Each item allows some principal (device/role/user) to perform an action on a resource. The diagram below shows the actions and AWS resources involved.\n\n![AWS Setup Overview](doc/aws-setup-overview.png)\n\n#### IoT Core (for Send data)\nYou must define an AWS IAM policy that allows your device to connect to IoT Core and publish MQTT messages. At runtime, provisioning attaches the public key certificate created for a device to this policy.\n\nSee the documentation, [Create AWS IoT resources](https://docs.aws.amazon.com/iot/latest/developerguide/create-iot-resources.html#create-iot-policy) for steps to follow. The result must allow the actions shown for the AWS_IOT_POLICY entry in the table below, like this [screenshot](doc/iot-messaging-policy.png). Your AWS account region and ID for the policy resource ARN are available in the dropdowns at the top right of the web page.\n\n#### Lambda role (for Provision)\nYou also must define an AWS IAM Role for the HTTP gateway endpoint to execute the Lambda function. See the documentation, [AWS Lambda execution role](https://docs.aws.amazon.com/lambda/latest/dg/lambda-intro-execution-role.html#permissions-executionrole-console). When creating the role, use the \"Lambda\" use case, which allows the HTTP endpoint to assume the role for a Lambda function. Also use the specific permissons policies shown for the AWS_ROLE_ARN entry in the table below. See example screenshots of the [Permissions](doc/iam-role-permissions.png) and [Trust relationships](doc/iam-role-trust.png) tabs.\n\n#### IAM User (for Test / Deploy)\nIn the Workspace setup section below, we use the node-lambda [package](https://github.com/motdotla/node-lambda) to test provisioning directly from your workstation and to deploy to AWS. It is best to assign an IAM User with limited privileges for these actions. See the documentation, [Creating IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html#id_users_create_console). The user requires Programmatic access. Attach existing policies as shown for AWS_ACCESS_KEY_ID in the table below. *After you select to create the user, be sure to save the Secret access key*, as shown in the [screenshot](doc/iam-user-created.png).\n\n### Workspace setup\nWe provide command line tools to deploy and test the Lambda function and HTTP endpoint. These tools must be configured to identify your account, policies and so on. Follow the steps below to create a workspace and define these values.\n\nThe setup depends on a Mac/Linux/WSL command line and NodeJS, which is easy to install with the [nvm](https://github.com/nvm-sh/nvm#installing-and-updating) utility.\n\n```\n# get the Lambda code and tools\ngit clone https://github.com/balena-io-examples/aws-iot-provision.git source\n\n# create workspace\ncp source/tools/template.env tools.env\ncp source/tools/setup-tools.sh .\n```\nEdit `tools.env` to provide your values from the table below, and finally setup the tools to use these values with this command:\n\n```\n./setup-tools.sh\n```\n\n| Variable    |    Value    |\n|-------------|-------------|\n| AWS_ACCESS_KEY_ID | For IAM User to run/deploy the Lambda. This user must include the `AWSLambda_FullAccess` and `AWSIoTConfigAccess` policies. See AWS IAM console  *Users -> Security Credentials* to create an access key. |\n| AWS_SECRET_ACCESS_KEY | For access key |\n| AWS_REGION | AWS region for registry, like `us-east-1` |\n| AWS_IOT_POLICY | Name of IAM policy with `iot:Connect` and `iot:Publish` permissions for device messaging to IoT Core |\n| AWS_ROLE_ARN | For IAM Role to execute the Lambda. This role must include the `AWSIoTLogging` and `AWSIoTConfigAccess` permissions policies. |\n| BALENA_API_KEY | for use of balena API; found in balenaCloud dashboard at: *account -> Preferences -> Access tokens* |\n\n### Test locally\nTo test the Lambda function without deploying it, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n\n./test-local.sh -u <UUID> <method>\n```\n\nAfter a successful POST, you should see the device appear as a Thing in your IoT Core registry like the screenshot below, as well as its public key certificate. If using a valid UUID, the corresponding `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n\n![IoT core device](doc/iot-core-device.png)\n\n## Deploy\nTo deploy to AWS Lambda, run this command in the workspace you created:\n\n```\n./deploy-func.sh\n```\n\nAfter deployment, visit the AWS Lambda console, and you should see an entry in the list of functions.\n\n### Create HTTP endpoint\nOn the console page for your function, you must create an API Gateway trigger (HTTP endpoint) from the `Add trigger` link in the *Function overview* section. See the [screenshot](doc/lambda-create-trigger.png) for the settings.\n\nThe result should be a Lambda and API Gateway like below.\n\n![Lambda trigger](doc/lambda-trigger.png)\n\n### Test the Lambda\nTo test the Lambda installed on AWS, run this command in the workspace you created:\n\n```\n# <UUID> must be for a valid device or 'test-provision'\n# <method> is POST or DELETE\n# <provision_url> is for the API Gateway HTTP endpoint\n\n./test-remote.sh -u <UUID> <method> <provision_url>\n```\n\nAfter a successful POST, you should see the device appear in your IoT Core registry. If using a valid UUID, `AWS_CERT` and `AWS_PRIVATE_KEY` variables appear in balenaCloud for the device. After a successful DELETE, those variables disappear.\n","gitHead":"0cd5c358917283ac37095db5ed1ffe2c707b7429","private":false,"scripts":{"test":"echo \"No tests yet\" && exit 0","start":"node index.js"},"_npmUser":{"name":"balena.io","email":"accounts+npm@balena.io"},"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"versionist":{"publishedAt":"2022-11-07T13:09:33.107Z"},"_npmVersion":"6.14.17","description":"AWS Lambda function to provision a balena device to IoT Core","directories":{},"_nodeVersion":"14.19.3","dependencies":{"balena-sdk":"^16.11.2","@aws-sdk/client-iot":"^3.47.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"node-lambda":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-iot-provision_0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429_1667827652478_0.3909175260598565","host":"s3://npm-registry-packages"},"deprecated":"Deprecated: no longer maintained. The GitHub repository has been archived and no further releases will be published."}},"time":{"created":"2022-05-18T15:28:47.146Z","modified":"2026-01-29T10:55:09.925Z","0.1.0-move-up-src-files-38cf947c56ec79b3672515e42a3f0dcb8561a2e5":"2022-05-18T15:28:47.453Z","0.2.0-add-dependabot-c4dbc6f137cc17b4d800c6f16f40d2033dd6dc42":"2022-05-18T19:48:26.905Z","0.2.0":"2022-05-18T19:53:42.329Z","0.2.0-dependabot-npm-and-yarn-balena-sdk-16-20-4-4e87b386b5bc6edda3cf0f4ccff5094017bd1465":"2022-05-18T19:57:58.630Z","0.2.1-dependabot-npm-and-yarn-moment-2-29-3-6083eab67d8c3141e01a972094cecd67957348a7":"2022-05-18T19:59:42.636Z","0.2.1":"2022-05-18T20:25:46.723Z","0.2.1-dependabot-npm-and-yarn-minimist-1-2-6-c80da8bcb6bdcad2785a57da444eeaea318533cd":"2022-05-18T20:27:25.739Z","0.2.2-dependabot-npm-and-yarn-minimist-1-2-6-4e248631bbbe37e433c5d290a1a0edee0a833114":"2022-05-18T20:34:17.490Z","0.2.2":"2022-05-18T20:42:57.639Z","0.3.0-add-balena-mfa-support-bdf4713c7cb26e0d4480dec81b3a45a3deffc6b5":"2022-05-21T15:55:16.110Z","0.3.0":"2022-05-21T15:59:50.289Z","0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-4-ecacb6b3398c36a9b4038e45758c0e927c7d3824":"2022-05-23T13:25:09.049Z","0.3.1-dependabot-npm-and-yarn-balena-sdk-16-20-5-c20e9b03eadbc52fa1f8c786594d36fa21d8f9ec":"2022-05-30T13:32:13.083Z","0.3.1-refine-aws-getting-started-59295383b7aad4c8eee41215b235ac119f1fa668":"2022-06-01T22:04:01.103Z","0.3.1":"2022-06-01T22:53:01.724Z","0.3.1-fix-aws-setup-c25048c65295950f6c38689a89a8003dc516d6e0":"2022-06-01T22:57:36.997Z","0.3.2-fix-aws-setup-750fb9a9a4c627a45ca5e2dd701b137d7e1951a4":"2022-06-02T00:56:23.376Z","0.3.2":"2022-06-02T00:59:33.883Z","0.3.3-fix-aws-setup2-90390092c0274d47b361aaa83b255fb25f71a011":"2022-06-02T12:02:17.539Z","0.3.3":"2022-06-02T12:10:25.920Z","0.3.4-dependabot-npm-and-yarn-balena-sdk-16-21-0-a57c9d254a6f4b9729609bbf5f04bb9814a191bb":"2022-06-06T13:41:54.684Z","0.3.4-fix-aws-setup3-89c108c0ebdec45a24f8dabc66b1f6d3f4b48b65":"2022-06-07T23:12:05.321Z","0.3.4":"2022-06-07T23:15:39.103Z","0.3.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-e98cac905171a88da240c038cdafba0778a9f595":"2022-06-07T23:19:36.456Z","0.3.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-8addb065b9e7c5a5d2f007a15cea06b5d5119609":"2022-06-13T13:34:02.547Z","0.4.0-unify-tools-setup-b1ab58cc0140f47e6a898327ec793ed12ff86561":"2022-06-14T13:02:39.574Z","0.4.0":"2022-06-14T13:56:39.607Z","0.4.1-allow-test-device-c6a0cc05554c8c3cddd5de3212aa2ecf018c9a30":"2022-06-14T19:07:01.683Z","0.4.1":"2022-06-14T21:05:41.931Z","0.4.2-define-user-25d845e82907a0e7dd1e3abc96d9ece07b69e5df":"2022-06-15T11:52:02.628Z","0.4.2":"2022-06-15T11:57:30.619Z","0.4.3-dependabot-npm-and-yarn-balena-sdk-16-22-0-b84844cbb9989f05c5df7530882c28615aa5c84d":"2022-06-20T13:47:57.162Z","0.4.3-doc-env-var-names-feb82eb4130d359fe65f28dfaa9360272620aee2":"2022-06-22T19:48:43.142Z","0.4.3":"2022-06-22T23:11:49.666Z","0.4.4-dependabot-npm-and-yarn-balena-sdk-16-22-0-96d4e510dbb1dbe8dda0fa8698721eb88a11bbbc":"2022-06-27T14:24:17.841Z","0.4.4-uniform-readme-sections-f6012f680034ce5e579607dce7959b602978492f":"2022-07-02T14:02:56.522Z","0.4.4":"2022-07-02T14:07:36.344Z","0.4.5-dependabot-npm-and-yarn-balena-sdk-16-22-0-50ab1b6727cabdb98e6333b04a87390094f20432":"2022-07-04T13:41:45.604Z","0.4.5-dependabot-npm-and-yarn-balena-sdk-16-24-0-e7aab5543ea15a26f5b0b9fba83bbb2dbeff183d":"2022-07-11T14:07:59.813Z","0.4.5-add-repo-yml-20781bed13ee981641d886b8ed625600026d7980":"2022-07-14T16:47:18.240Z","0.4.5":"2022-07-14T22:41:01.748Z","0.4.6-dependabot-npm-and-yarn-moment-2-29-4-2545289fc4e5599eaf1fb2c781a66b7ef018f116":"2022-07-14T22:54:13.643Z","0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-0-1107516ce226bc839fd638c84a6d71a0c9f1f9fb":"2022-07-18T13:51:29.668Z","0.4.6-dependabot-npm-and-yarn-balena-sdk-16-24-1-7f4df2b60c3713e4060f7fd0c9f3f3d08becf2b7":"2022-07-25T13:37:30.987Z","0.4.6-dependabot-npm-and-yarn-balena-sdk-16-25-1-23a10e89b421e59a2da3733e3f1e046bf9e9dc03":"2022-08-08T13:25:06.660Z","0.5.0-add-aws-setup-context-bed40e82c7563c0dd63f657c72f8f60a25a0ff49":"2022-08-08T17:19:48.974Z","0.4.6":"2022-08-08T17:20:42.509Z","0.5.0-add-aws-setup-context-4fd3c04c9b466b72cf35ec406fa0473cabf0fc5e":"2022-08-08T17:23:26.791Z","0.5.0-add-aws-setup-context-aaf67b2a7244279b299d171347446b9415078c5d":"2022-08-08T17:37:40.101Z","0.5.0":"2022-08-08T17:42:57.489Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-25-1-b8758e6c8bb3b785fa5ce6b5158b741734bdb02e":"2022-08-15T13:23:38.166Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-1-d0d0f710eef0b1749c98d821028926e24ec4ab9a":"2022-08-29T13:41:43.989Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-2-bda2096544606860e07b08ab000c2f733b17a3f4":"2022-09-12T13:36:16.830Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-26-5-10275f8fb7345c13020ededade3e0e55faf42714":"2022-09-26T13:33:05.047Z","0.5.1-dependabot-npm-and-yarn-vm2-3-9-11-2446e86514eb69f99138d51e1adb43436366cf3b":"2022-09-28T14:25:47.639Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-27-0-dea4387824f68666d3332653d2ae8632e53f0a42":"2022-10-10T14:18:56.094Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-1-8f74a4b5949ed60d203b355dea0cf20bed3be9b1":"2022-10-17T13:56:19.438Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-2-b06c6c621ace65176f0be84e44a06696c36ed2dd":"2022-10-31T13:33:28.084Z","0.5.1-dependabot-npm-and-yarn-balena-sdk-16-28-4-0cd5c358917283ac37095db5ed1ffe2c707b7429":"2022-11-07T13:27:32.760Z"},"bugs":{"url":"https://github.com/balena-io-examples/aws-iot-provision/issues"},"author":{"name":"Ken Bannister","email":"ken@balena.io"},"license":"Apache-2.0","homepage":"https://github.com/balena-io-examples/aws-iot-provision","keywords":["balena","balenaCloud","aws","iotcore","iot"],"repository":{"url":"git+https://github.com/balena-io-examples/aws-iot-provision.git","type":"git"},"description":"AWS Lambda function to provision a balena device to IoT Core","maintainers":[{"name":"balena.io","email":"accounts+npm@balena.io"}],"readme":"","readmeFilename":""}