AlphaApache 2.0Image CI

Mosquitto Control Manager

Mosquitto configuration, from your browser.

MCM aims to let you import, edit, validate, apply and recover the configuration of a Mosquitto broker from a web interface. Mosquitto remains your MQTT broker.

Alpha today: MQTT users, basic ACLs and observed traffic. Full broker configuration editing is still in development.

What MCM is

One broker. A clear administration workflow.

The goal is to configure one Mosquitto instance without hand-editing files during routine administration. Guided forms and an advanced editor will cover explicitly supported broker versions, while preserving existing configuration and showing the effect of every change.

Today, MCM manages MQTT users and basic ACLs through generated files. It also provides operator access control, audit views and traffic inspection. Editing listeners, certificates, bridges and general broker settings remains planned work.

Stack

  • Go 1.25
  • net/http + slog
  • SQLite (pure Go)
  • paho MQTT
  • Prometheus
  • OpenAPI 3.1
  • React 19 + Vite 8
  • Tailwind 4

MCM packages its backend and dashboard in one application image. Mosquitto runs separately in the Compose stack. SQLite is the only implemented management database.

What works today

Available now, with a defined scope.

The configuration-manager MVP is not complete. These capabilities exist today; the roadmap tracks the remaining configuration coverage, activation checks and recovery work.

Administration

MQTT users and basic ACLs

Create, disable and rotate MQTT credentials. Edit user/topic permissions, then review and apply their password and ACL files.

Deployment review and history

Preview password/ACL differences and track apply attempts. Verified activation and recovery after partial failures are still being improved.

Operator access and audit

Separate dashboard accounts, role-based access, two-factor authentication, and administrative audit and security events.

Diagnostics

Observed MQTT traffic

Inspect topic names and bounded payload previews received by MCM. This is observed traffic, not a complete client inventory.

Connection events

Follow MCM connection transitions and operational events. Full Mosquitto log ingestion and broker metrics are planned.

Optional message diagnostics

Sparkplug B inspection and JSON Schema results help inspect messages. They do not configure the broker or enforce payload rejection.

Operations

One managed broker

A Go application image with its embedded React UI, SQLite management state, and a separate Mosquitto broker container.

Administration API

REST and authenticated WebSocket interfaces accompany the dashboard. Broker configuration editing is a planned extension.

Development and verification

Docker Compose and Taskfile support local development. Production activation and complete backup/restore remain tracked work.

Planned configuration workflow

Import. Review. Apply. Recover.

These features are planned, not available controls in the current alpha. Compatibility will be defined and tested for specific Mosquitto versions.

Next capabilities

Import and edit configuration

A version-aware editor for mosquitto.conf and included files, preserving existing settings, comments and advanced directives.

Listeners, TLS and bridges

Guided configuration of MQTT and WebSocket listeners, broker certificates, authentication and connections between brokers.

General settings and plugins

Persistence, limits, sessions, logging and supported plugins, including Dynamic Security, with explicit version compatibility.

Verified changes and recovery

Review an immutable revision, see whether it needs reload or restart, verify activation and recover the previous configuration.

Before relying on production changes

Activation verification, recovery after partial writes and production file permissions need work. The existing volume backup and restore recipes also have known limitations. Review the deployment guide before enabling writes on an existing broker.

Sparkplug and JSON Schema remain optional diagnostics. Multi-broker administration, fleets, SSO and high availability are deferred while the one-broker configuration workflow is completed.

Quick start

Try the current alpha locally.

Requires Git, Docker with Compose, and Task. This starts the development stack; it is not a production setup.

  1. 01
    Clone and buildgit clone https://github.com/fgjcarlos/mcm.git && cd mcm && task build
  2. 02
    Start the stacktask up
  3. 03
    Capture the bootstrap admintask logs # look for 'bootstrap admin created' — username + password
  4. 04
    Open the dashboardhttp://localhost:8080

For deployment requirements, TLS and known backup/recovery limitations, readdocs/production.md.