Skip to content
© 2026 The ThingsBoard Authors
Try for free

ThingsBoard Cloud

Choose your data region

Your data stays in the region you choose, for residency and compliance. No credit card required.

Rather run it yourself? Install on your own servers

GKE Microservices Setup

This guide walks you through deploying ThingsBoard in microservices mode on Google Kubernetes Engine. We use Google Cloud SQL for managed PostgreSQL.

Install kubectl and gcloud. See before you begin for more info.

Create a new GCP project (recommended) or choose an existing one:

Terminal window
gcloud init
Terminal window
gcloud services enable container.googleapis.com sql-component.googleapis.com sqladmin.googleapis.com

Verify that you can pull the images from Docker Hub:

Terminal window
docker pull thingsboard/tb-node:4.4.0
docker pull thingsboard/tb-web-report:4.4.0
docker pull thingsboard/tb-web-ui:4.4.0
docker pull thingsboard/tb-js-executor:4.4.0
docker pull thingsboard/tb-http-transport:4.4.0
docker pull thingsboard/tb-mqtt-transport:4.4.0
docker pull thingsboard/tb-coap-transport:4.4.0
docker pull thingsboard/tb-lwm2m-transport:4.4.0
docker pull thingsboard/tb-snmp-transport:4.4.0
docker pull thingsboard/tb-integration-executor:4.4.0

Step 1. Clone ThingsBoard K8S Scripts Repository

Section titled “Step 1. Clone ThingsBoard K8S Scripts Repository”

Clone the repository containing the Kubernetes deployment scripts:

Terminal window
git clone -b release-4.4.0 https://github.com/thingsboard/thingsboard-pe-k8s.git --depth 1
cd thingsboard-pe-k8s/gcp/microservices
Terminal window
export GCP_PROJECT=$(gcloud config get-value project)
export GCP_REGION=us-central1
export GCP_ZONE=us-central1
export GCP_ZONE1=us-central1-a
export GCP_ZONE2=us-central1-b
export GCP_ZONE3=us-central1-c
export GCP_NETWORK=default
export TB_CLUSTER_NAME=tb-msa
export TB_DATABASE_NAME=tb-db
echo "Project: $GCP_PROJECT, region: $GCP_REGION, zones: $GCP_ZONE1,$GCP_ZONE2,$GCP_ZONE3, network: $GCP_NETWORK, cluster: $TB_CLUSTER_NAME, database: $TB_DATABASE_NAME"
Variable Default Description
GCP_PROJECT (auto-detected) Your GCP project ID
GCP_REGION us-central1 Compute region
GCP_ZONE1/2/3 us-central1-a/b/c Availability zones for the regional cluster
GCP_NETWORK default GCP network name
TB_CLUSTER_NAME tb-msa GKE cluster name
TB_DATABASE_NAME tb-db Cloud SQL instance name

Create a regional cluster distributed across 3 zones. The example provisions one e2-standard-4 node per zone (3 nodes total). You can modify the machine type and node count to suit your workload. See GCP machine types for options.

Terminal window
gcloud container clusters create $TB_CLUSTER_NAME \
--release-channel stable \
--region $GCP_REGION \
--network=$GCP_NETWORK \
--node-locations $GCP_ZONE1,$GCP_ZONE2,$GCP_ZONE3 \
--enable-ip-alias \
--num-nodes=1 \
--node-labels=role=main \
--machine-type=e2-standard-4

Alternatively, see the regional cluster setup guide.

Terminal window
gcloud container clusters get-credentials $TB_CLUSTER_NAME --region $GCP_REGION

5.1 Google Cloud SQL (PostgreSQL) Instance

Section titled “5.1 Google Cloud SQL (PostgreSQL) Instance”

Enable service networking:

Terminal window
gcloud services enable servicenetworking.googleapis.com --project=$GCP_PROJECT
gcloud compute addresses create google-managed-services-$GCP_NETWORK \
--global \
--purpose=VPC_PEERING \
--prefix-length=16 \
--network=projects/$GCP_PROJECT/global/networks/$GCP_NETWORK
gcloud services vpc-peerings connect \
--service=servicenetworking.googleapis.com \
--ranges=google-managed-services-$GCP_NETWORK \
--network=$GCP_NETWORK \
--project=$GCP_PROJECT
Terminal window
gcloud beta sql instances create $TB_DATABASE_NAME \
--database-version=POSTGRES_16 \
--region=$GCP_REGION --availability-type=regional \
--no-assign-ip --network=projects/$GCP_PROJECT/global/networks/$GCP_NETWORK \
--cpu=2 --memory=7680MB

Note the IP address (YOUR_DB_IP_ADDRESS) from the command output.

Terminal window
gcloud sql users set-password postgres \
--instance=$TB_DATABASE_NAME \
--password=secret
Terminal window
gcloud sql databases create thingsboard --instance=$TB_DATABASE_NAME

Using Cassandra is optional. We recommend it if you plan to insert more than 5K data points per second or want to optimize storage space.

Create 3 separate node pools with 1 node per zone. At least 4 vCPUs and 16 GB of RAM is recommended.

Terminal window
gcloud container node-pools create cassandra1 --cluster=$TB_CLUSTER_NAME --zone=$GCP_ZONE --node-locations=$GCP_ZONE1 \
--node-labels=role=cassandra --num-nodes=1 --min-nodes=1 --max-nodes=1 --machine-type=e2-standard-4
gcloud container node-pools create cassandra2 --cluster=$TB_CLUSTER_NAME --zone=$GCP_ZONE --node-locations=$GCP_ZONE2 \
--node-labels=role=cassandra --num-nodes=1 --min-nodes=1 --max-nodes=1 --machine-type=e2-standard-4
gcloud container node-pools create cassandra3 --cluster=$TB_CLUSTER_NAME --zone=$GCP_ZONE --node-locations=$GCP_ZONE3 \
--node-labels=role=cassandra --num-nodes=1 --min-nodes=1 --max-nodes=1 --machine-type=e2-standard-4

Create the namespace, then deploy Cassandra:

Terminal window
kubectl apply -f tb-namespace.yml
kubectl config set-context $(kubectl config current-context) --namespace=thingsboard
kubectl apply -f receipts/cassandra.yml
Terminal window
echo " DATABASE_TS_TYPE: cassandra" >> tb-node-db-configmap.yml
echo " CASSANDRA_URL: cassandra:9042" >> tb-node-db-configmap.yml
echo " CASSANDRA_LOCAL_DATACENTER: $GCP_REGION" >> tb-node-db-configmap.yml

Create the ThingsBoard keyspace inside Cassandra:

Terminal window
kubectl exec -it cassandra-0 -- bash -c "cqlsh -e \
\"CREATE KEYSPACE IF NOT EXISTS thingsboard \
WITH replication = { \
'class' : 'NetworkTopologyStrategy', \
'us-central1' : '3' \
};\""

We assume you have already chosen your subscription plan or decided to purchase a perpetual license. If not, navigate to the pricing page.

Create a docker secret with your license key:

Terminal window
export TB_LICENSE_KEY=PUT_YOUR_LICENSE_KEY_HERE
kubectl create -n thingsboard secret generic tb-license --from-literal=license-key=$TB_LICENSE_KEY

Edit tb-node-db-configmap.yml and replace YOUR_DB_IP_ADDRESS and YOUR_DB_PASSWORD:

Terminal window
nano tb-node-db-configmap.yml

Run the installation:

Terminal window
./k8s-install-tb.sh

After this command finishes you should see:

Installation finished successfully!

Deploy thirdparty components (Zookeeper, Kafka, Redis) and main ThingsBoard microservices:

Terminal window
./k8s-deploy-resources.sh

After a few minutes, call kubectl get pods. If everything went fine, you should see tb-node-0 pod in the READY state.

Deploy the transport microservices you need. Omit protocols you don’t use to save resources:

Terminal window
# HTTP Transport (optional)
kubectl apply -f transports/tb-http-transport.yml
# MQTT Transport (optional)
kubectl apply -f transports/tb-mqtt-transport.yml
# CoAP Transport (optional)
kubectl apply -f transports/tb-coap-transport.yml
# LwM2M Transport (optional)
kubectl apply -f transports/tb-lwm2m-transport.yml
# SNMP Transport (optional)
kubectl apply -f transports/tb-snmp-transport.yml

You have 3 options:

  • HTTP — recommended for development.
  • HTTPS — recommended for production. Uses Google-managed SSL certificate.
  • Transparent — forwards traffic to ThingsBoard HTTP/HTTPS ports. Requires your own SSL certificate.
Terminal window
kubectl apply -f receipts/http-load-balancer.yml

Check the status:

Terminal window
kubectl get ingress

Use the address to access the web UI and connect devices via HTTP API.

Administrator account creation on first access is covered next, in Step 10. Create Your Administrator Account.

9.2 Configure MQTT Load Balancer (Optional)

Section titled “9.2 Configure MQTT Load Balancer (Optional)”
Terminal window
kubectl apply -f receipts/mqtt-load-balancer.yml

The load balancer forwards all TCP traffic for ports 1883 and 8883.

For MQTT over SSL, follow the MQTT over SSL guide to configure transport/tb-mqtt-transport.yml.

9.3 Configure CoAP Load Balancer (Optional)

Section titled “9.3 Configure CoAP Load Balancer (Optional)”
Terminal window
kubectl apply -f receipts/coap-load-balancer.yml

The load balancer forwards UDP traffic for ports 5683 (CoAP non-secure) and 5684 (CoAP secure DTLS).

For CoAP over DTLS, follow the CoAP over DTLS guide to configure transport/tb-coap-transport.yml.

9.4 Configure LwM2M Load Balancer (Optional)

Section titled “9.4 Configure LwM2M Load Balancer (Optional)”
Terminal window
kubectl apply -f receipts/lwm2m-load-balancer.yml

The load balancer forwards UDP traffic for ports 5685–5688.

For LwM2M over DTLS, follow the LwM2M over DTLS guide to configure transport/tb-lwm2m-transport.yml.

9.5 Configure Edge Load Balancer (Optional)

Section titled “9.5 Configure Edge Load Balancer (Optional)”
Terminal window
kubectl apply -f receipts/edge-load-balancer.yml

The load balancer forwards all TCP traffic on port 7070.

Step 10. Create Your Administrator Account

Section titled “Step 10. Create Your Administrator Account”

After launching ThingsBoard, open the web UI at the load balancer address. ThingsBoard prompts you to create your System Administrator account — the account that manages the platform itself (tenants, system settings, platform-wide resources).

  1. Enter Email, Password, and Confirm password.
  2. The Set up a demo tenant option is selected by default: it creates a ready-made tenant with dashboards, devices, and rule chains for exploring the platform before building your own solution. Clear it if you want to start with an empty platform.
  3. Click Create account. You are signed in as the system administrator.

Your ThingsBoard instance is now installed and running.

Confirm that the load balancers created in Step 9 are provisioned and reachable, and note their addresses — you need them to open the web UI and to connect devices.

Check the status of the ingress you created for the HTTP(S) load balancer:

Terminal window
kubectl get ingress

Once an external IP address is assigned, use it to open the ThingsBoard web interface in your browser.

List the cluster services to find the external IP addresses assigned to the transport load balancers you configured:

Terminal window
kubectl get service

Use the external IP of each load balancer to connect devices over MQTT, CoAP, LwM2M, or Edge.

Pull the Trendz images from Docker Hub:

Terminal window
docker pull thingsboard/trendz:1.16.0
docker pull thingsboard/trendz-python-executor:1.16.0

Create a Trendz Database in the Existing Cloud SQL Instance

Section titled “Create a Trendz Database in the Existing Cloud SQL Instance”

Edit trendz/trendz-secret.yml and replace YOUR_DB_IP_ADDRESS and YOUR_DB_PASSWORD, then apply:

Terminal window
kubectl apply -f ./trendz/trendz-secret.yml
kubectl apply -f ./trendz/trendz-create-db.yml

Check logs:

Terminal window
kubectl logs job/trendz-create-db -n thingsboard
Terminal window
./k8s-deploy-trendz.sh

After this command finishes you should see:

Trendz installed successfully!

Stream the logs of the ThingsBoard node pod to diagnose startup or runtime issues:

Terminal window
kubectl logs -f tb-node-0

See the kubectl Cheat Sheet for more details.

Delete ThingsBoard pods and load balancers:

Terminal window
./k8s-delete-resources.sh

Delete all data including database:

Terminal window
./k8s-delete-all.sh

With ThingsBoard running, these concept guides help you build your first solution: