Lamassu IoT Docs

Platform architecture

Lamassu components and how control, keys, issuance and devices relate.

Lamassu deploys as a set of independent services. This separation keeps every component from needing direct access to private keys and lets each capability scale according to load.

Switch to the low level to see the internals of the Lamassu platform box (CA, KMS, DMS, Device Manager, VA, Alerts, AWS IoT connector, Job Manager and the console/API), and to medium to see it as a single platform alongside its external dependencies.

Control plane

The console and the APIs manage authorities, certificates, DMSs, devices, alerts and configuration. Domain events allow connectors and automations to react to changes without continuously polling the platform.

Key custody and cryptographic operations

The KMS offers a common interface over software engines, PKCS#11 and cloud providers. The selected engine keeps the key or delegates the cryptographic operation without the other services knowing its implementation.

Issuance and enrollment

The CA service issues certificates and maintains the relationship with its authority. The DMS applies the enrollment rules and exposes the EST flows so a device can request or renew an identity.

Status and validation

Device Manager keeps the operational view of the device and its history. The Validation Authority publishes OCSP and CRLs so other systems can decide whether to trust a presented certificate.

Platform dependencies

In a self-managed deployment, Lamassu uses PostgreSQL for persistence, RabbitMQ for messaging and an OIDC provider for authentication. See the deployment architecture for how the services are published on Kubernetes.

On this page