A broker for a fleet of devices has an awkward job at upgrade time. When a node restarts, thousands of devices reconnect at once, and the next node can fail under the load. Cairn drains its nodes one at a time so that does not happen, and gives every device an identity that can be revoked.
Product · Alpha
Cairn
Cairn is a self-hosted MQTT 5 broker cluster for IoT fleets, with a device registry, a private certificate authority, device shadows, a rules engine and an admin console. A node can be drained for an upgrade without a reconnect storm.
Who it is for
Companies with device fleets that want the features of a cloud IoT service on their own Kubernetes or bare metal, and that cannot afford to have the whole fleet reconnect at once every time a broker is updated.
Works with
What it does
MQTT 5 and 3.1.1
Standard protocols over mutual TLS, so devices keep using the MQTT clients they already have.
Graceful drain
When a node is taken out of service, its devices are sent to the other nodes at a controlled rate, without a reconnect storm or false last-will messages. It is wired into Kubernetes rolling updates.
Clustering
Brokers share state through NATS and Valkey. Shared subscriptions and retained messages work across nodes, and each client ID belongs to one node at a time.
Device identity
Each device gets its own certificate from a private CA, enrolled once with a one-time claim token. Revoking a device also ends its live connection, and a device can only use its own topics.
Shadows and rules
A shadow document holds the desired and the reported state of each device, in the format users of cloud IoT services know. Rules match messages with regular expressions and republish them or call signed webhooks, with retries and a dead-letter queue.
Console and metrics
Overview, devices, certificates with an expiry view, cluster status, rules and a live topic viewer, in English and Turkish, plus Prometheus metrics and runbooks.
How it works
- 01
Enroll
An admin issues a one-time claim token. The device creates its own key, sends a request, receives its certificate and pins the root CA.
- 02
Connect
The device connects over mutual TLS. Its client ID has to match its certificate, it can only use its own topics, and the nodes pass messages between each other so devices and services reach each other whichever node they landed on.
- 03
Upgrade
To upgrade, drain a node. Its devices reconnect to the other nodes, and the node can restart.
Cairn is in alpha
See Cairn with your own setup in mind.
Tell us what you run today and we will show you what it does. Pricing and licensing are discussed with each company.
Request a demo