Mosquitto: 4. GitHub Actions

This documentation is part of the GitHub Actions & GitLab CI guide. View the full guide here: Spin up a real Mosquitto service from your GitHub Actions or GitLab CI pipeline, run your tests against it, and tear it down automatically.

👋 Welcome to the Stackhero documentation!

Stackhero gives you a fully managed Mosquitto MQTT cloud environment designed for reliability and flexibility:

  • Unlimited message throughput and data transfers, so your workflows never hit artificial limits.
  • Unlimited device authentication through your own external API, making onboarding and access management seamless.
  • Advanced ACLs for fine-grained control over topics, users, and actions.
  • A custom domain name with built-in HTTPS for secure, branded endpoints (for example: https://mqtt.your-company.com).
  • Zero-hassle updates: apply improvements or security patches with a single click.
  • Consistent performance and strong security, with every instance running on a private, dedicated infrastructure.

Accelerate your IoT projects and reduce operational overhead. You can have a secure, production-ready Mosquitto MQTT cloud hosting instance up and running in just a few minutes.

To get started, you can save the following as .github/workflows/ci.yml. From now on, every push and pull request will run tests against a real Mosquitto instance.

name: CI with Mosquitto

on: [push, pull_request]

jobs:
  test:
    runs-on: ubuntu-latest
    env:
      STACKHERO_TOKEN: ${{ secrets.STACKHERO_TOKEN }}
      STACK_NAME: ci-mosquitto-${{ github.run_id }}-${{ github.run_attempt }}
      INSTANCE: "200"   # Change this as needed (see step 3)
      REGION: europe
    steps:
      - uses: actions/checkout@v4

      - name: Install the Stackhero CLI and the client
        run: |
          curl -fsSL https://www.stackhero.io/install.sh | sh
          apt-get update && apt-get install -y --no-install-recommends jq curl mosquitto-clients

      - name: Create the Mosquitto service
        run: |
          set -euo pipefail
          STACK_ID=$(stackhero --format=script stack-create --name="$STACK_NAME")
          echo "STACK_ID=$STACK_ID" >> "$GITHUB_ENV"
          SERVICE_ID=$(stackhero --format=script service-add \
            --stack="$STACK_ID" \
            --service-store="mosquitto" \
            --instance="$INSTANCE" \
            --region="$REGION")
          echo "SERVICE_ID=$SERVICE_ID" >> "$GITHUB_ENV"
          stackhero service-wait-for --service="$SERVICE_ID"

      - name: Run tests against Mosquitto
        run: |
          set -euo pipefail
          config=$(stackhero service-configuration-get --service="$SERVICE_ID" --format=json)
          host=$(echo "$config" | jq -r '.configuration.domain')
user=$(echo "$config" | jq -r '.configuration.authenticationUsers[0].login')
password=$(echo "$config" | jq -r '.configuration.authenticationUsers[0].password')
          # Publish a test message to a topic.
          mosquitto_pub -h "$host" -p 8883 -u "$user" -P "$password" --capath /etc/ssl/certs -t "stackhero/ci" -m "hello"
          echo "✅ Mosquitto is reachable from CI."
          # You can run your own test suite here using the credentials above ...

      - name: Tear down (always, even on failure)
        if: always()
        run: |
          if [ -n "${SERVICE_ID:-}" ]; then
            stackhero service-delete --service="$SERVICE_ID" --confirm
            stackhero service-wait-for --service="$SERVICE_ID"
          fi
          if [ -n "${STACK_ID:-}" ]; then
            stackhero stack-delete --stack="$STACK_ID" --confirm
          fi

The teardown step is configured with if: always() so it runs no matter what, making sure your Mosquitto instance is deleted and you are not billed for unused resources.