---
title: Google Cloud Pub/Sub Integration Guide
slug: manufacturing-connect-edge/google-cloud-pubsub-integration-guide
docTags: 
createdAt: 2022-11-24T18:24:54.000Z
---

Review the following guide for setting up an integration between Manufacturing Connect Edge and [Google Pub/Sub service](https://cloud.google.com/pubsub/docs/overview).&#x20;

Once the integration is set up, you can use it for the following:&#x20;

- Publishing data from a topic in your edge device to a *Subscription&#x20;*&#x74;opic in the Google Cloud Platform
- Subscribing to data published by a *Publication&#x20;*&#x74;opic in the Google Cloud Platform

:::hint{type="info"}
**Note**: You can use the following authentication methods to configure the Google Cloud Pub/Sub connector:

- Using GCP Auth type Service Account Key
- Using GCP Auth type Workload Identity Federation

See [Configuring Workload Identity Federation Authorization](docId\:lbp47ysLPMUWTTX2lK4aR) to learn more.&#x20;
:::

# Before You Begin

- You need to create a Google Service Account. Make sure the account has the correct roles and permissions required for setting up the connection.&#x20;
- Refer to the following Google resources for learning more about Pub/Sub and configuring connections:
  - [Google Pub/Sub service](https://cloud.google.com/pubsub/docs/overview)
  - [Configure Private Google Access for on-premises hosts > Domain Options ](https://cloud.google.com/vpc/docs/configure-private-google-access-hybrid#config-choose-domain)(information regarding private access to GCP services)
  - [Supported products and limitations > Pub/Sub ](https://cloud.google.com/vpc-service-controls/docs/supported-products#table_pubsub)(information regarding private access to GCP services)
  - [SDK on Publish Settings](https://pkg.go.dev/cloud.google.com/go/pubsub#PublishSettings)
  - [Publish messages to topics](https://cloud.google.com/pubsub/docs/publisher)

# Service Account Key Credentials

You have two options for configuring the service account key parameter in the Google Pub/Sub connector: GCP SA Key Authentication and GCP Workload identity federation (OIDC).&#x20;

See [Configuring Workload Identity Federation Authorization](docId\:lbp47ysLPMUWTTX2lK4aR) to learn more.&#x20;

## Service Account Keys

Each Google service account is associated with a public/private RSA key pair. The Service Account Credentials API uses this internal key pair to create short-lived service account credentials, and to sign blobs and JSON Web Tokens (JWTs). This key pair is known as the *Google-managed key pair*.

In addition, you can create multiple public/private RSA key pairs, known as *user-managed key pairs*, and use the private key to authenticate with Google APIs. This private key is known as a *service account key*.&#x20;

See [Service account keys](https://cloud.google.com/iam/docs/service-account-creds#key-types) to learn more.&#x20;

## Workload Identity Federation

Workload Identity Federation allows you to can grant on-premises or multi-cloud workloads access to Google Cloud resources without using a service account key. You may select to use this option because service account keys are powerful credentials, so they can present a security risk if they are not managed correctly.

With identity federation, you can use Identity and Access Management (IAM) to grant external identities IAM roles, including the ability to impersonate service accounts. This approach eliminates the maintenance and security burden associated with service account keys.&#x20;

### Workload Identity Pools

A *workload identity pool* is an entity that lets you manage external identities. You will review and have the option to customize this parameter when setting up these credentials.&#x20;

### Workload Identity Pool Providers

A *workload identity pool provider&#x20;*&#x69;s the entity that describes the relationship between Google Cloud and your identity provider (IdP).&#x20;

Workload identity federation follows the [OAuth 2.0 token exchange](https://tools.ietf.org/html/rfc8693) specification. You provide a credential from your IdP to the [Security Token Service](https://cloud.google.com/iam/docs/reference/sts/rest), which verifies the identity on the credential, and then returns a federated token in exchange.&#x20;

See the following to learn more:

- [Workload identity federation](https://cloud.google.com/iam/docs/workload-identity-federation)
- [IAM roles](https://cloud.google.com/iam/docs/overview#roles)

# Set up the Outbound Connection (Publish to Google Pub/Sub)

Follow the steps below to set up the outbound connection.&#x20;

## Step 1: Create Publication Topic in Google Cloud Platform

In the Google Cloud Platform, create a *publication&#x20;*&#x74;opic. A matching *subscription&#x20;*&#x74;opic is created automatically, with the *-sub* suffix appended to the topic name.

## Step 2: Add Device

Follow the steps to [Connect a Device](docId\:RFVIJdxz7DBAd8mwbismA). The device will be used to store tags that will be eventually used to create outbound topics in the connector. Make sure to select the **Enable Data Store** checkbox.&#x20;

## Step 3: Add Tags

After connecting the device in Manufacturing Connect Edge, you can [Add Tags](docId\:iOaNZd2AwqnkuppgeE3Eh) to the device. Create tags that you want to use to create outbound topics for the connector.&#x20;

## Step 4: Add Connector

Follow the steps to [Add a Connector](docId\:M2niFNAAdyPHcvZWMCOTo) and select the **Google Cloud Pub/Sub Connector** provider.&#x20;

For more information about message publication settings, see the [SDK on Publish Settings](https://pkg.go.dev/cloud.google.com/go/pubsub#PublishSettings).&#x20;

Configure the following parameters.&#x20;

- **Name**: Enter a name for the connector.&#x20;
- **Service Account Key (.json)**: Create a service account key in your Google Cloud Platform in JSON format. Copy or save all the content from the JSON file and paste or upload it here.&#x20;
  - You have the option to use Workload Identity Federation authorization in the service-account key file. See [Configuring Workload Identity Federation Authorization](docId\:lbp47ysLPMUWTTX2lK4aR) to learn more.&#x20;
- **The project ID of the cloud project**: Copy the ID from your Google Cloud Platform and paste it here.&#x20;
- **The private key ID of the cloud project**: Copy the key ID from your Google Cloud Platform and paste it here.&#x20;
- **The client email of the cloud project**: Enter the email from your Google Cloud Platform.&#x20;
- **Integration Topic**: Copy the name of the *Publication&#x20;*&#x74;opic (without the "-sub" suffix) from your Google Cloud Platform and paste it here.
- **Custom Attributes**: You can add custom attributes in key/value pairs for further data processing. Refer to the following to learn more:
  - [Use Custom Attributes in the Google Cloud Pub/Sub Connector](docId\:iYQiAu-mqkBpue8dMRkpW)
  - Google documentation for [Using attributes](https://cloud.google.com/pubsub/docs/publisher#using-attributes)****
- **Parallel Publish Count**: The number of messages being published simultaneously. The default value is **100**. &#x20;
- **Parallel byte threshold**: The minimum size of a batch (in bytes) for the batch to be published. The default value is zero, which means that there is no threshold (limit).&#x20;
- **Publish count threshold**: The minimum number of messages in a batch for the batch to be published. The default value is zero, which means that there is no threshold (limit).&#x20;
- **Publish delay threshold (Milliseconds)**: The maximum time that the client will attempt to publish a batch of messages. The default value is zero, which means that there is no threshold (limit).&#x20;
- **Throttling limit**: The maximum number of messages per second to be processed. The default value is zero, which means that there is no limit.&#x20;
- **Persistent storage**: When enabled, this will cause messages to undergo a store-and-forward procedure. Messages will be stored within Manufacturing Connect Edge when cloud providers are online. &#x20;
- **Queue Mode**: Select the queue mode as **lifo&#x20;**(last in first out) or **fifo&#x20;**(first in first out). Selecting **lifo&#x20;**&#x6D;eans that the last data entry is processed first, and selecting **fifo&#x20;**&#x6D;eans the first data entry is processed first.&#x20;

## Step 5: Enable the Connector

After adding the connector, click the toggle in the connector tile to enable it.&#x20;

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/0TEw20u8tt1m28KP88rrG_image.png" size="60" width="498" height="269" caption="Toggle to enable connector" position="center" showCaption="true"}

If you see a *Failed&#x20;*&#x73;tatus, you can review the [Connector Logs](docId\:Zz28hZtQBK7oD_Xsj81O8) and relevant error messages.&#x20;

## Step 6: Create Outbound Topics for Connector

You will now need to import the tags you added in Step 2 to the connector as topics.&#x20;

**To create outbound topics:**

1. Click the connector tile.
   The connector *Dashboard&#x20;*&#x61;ppears.&#x20;
2. Click the **Topics&#x20;**&#x74;ab.&#x20;
3. Click the **Import from DeviceHub tags** icon.&#x20;
   The *DeviceHub Import* dialog box appears.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/QUo-NUFfBj7F2BbnlBBj3_importdevicehub.png" size="80" width="1218" height="567" caption="Import from DeviceHub icon" position="center" showCaption="true"}
4. Select all the tags to import and click **Import**.&#x20;

After importing the tag(s), do the following:

- Edit the tag and configure the **Remote Data Topic**. Copy and paste the name of the *Subscription&#x20;*&#x74;opic  (with the `-sub` suffix) from your Google Cloud Platform. &#x20;
- Make sure the connector has a CONNECTED status.&#x20;

## Step 7: Enable Topics

Because you imported DeviceHub tags for a *CONNECTED* connector, all topics will be disabled.&#x20;

To enable the topics, return to the *Topics&#x20;*&#x74;ab and click the **Enable all topics** icon.&#x20;

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/TVoDws1Bpm9no52jpv8-4_image.png)

## Step 8: Verify Connection in Google Cloud Platform

**To verify the connection in Google Cloud Platform:**

1. Pull the *subscription&#x20;*&#x74;opic to see messages it receives from the Manufacturing Connect Edge outbound topics created previously.&#x20;
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/-VdXPYXn3ue8QmzOVGPMD_pubsubmsg1000x272.png" size="80" width="1000" height="272" caption="List of Manufacturing Connect Edge outbound topics" position="center" showCaption="true"}
2. View the *subscription&#x20;*&#x73;tatistics.&#x20;
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/u-2c_cHty2BoX6BGFJBKN_pubsubgraph1000x235.png "Graph of subscription statistic")

# Set up the Inbound Connection (Subscribe to Google Pub/Sub)

Follow the steps below to set up the inbound connection.&#x20;

See [Publish messages to topics](https://cloud.google.com/pubsub/docs/publisher) to learn more about publishing messages in Google Pub/Sub.&#x20;

## Step 1: Create Publication Topic in Google Cloud Platform

In the Google Cloud Platform, create a *publication&#x20;*&#x74;opic.

## Step 2: Add Connector

Follow the steps to [Add a Connector](docId\:M2niFNAAdyPHcvZWMCOTo) and select the **Google Cloud Pub/Sub Connector** provider.&#x20;

Configure the following parameters.&#x20;

- **Name**: Enter a name for the connector.&#x20;
- **Service Account Key (.json)**: Create a service account key in your Google Cloud Platform in JSON format. Copy or save all the content from the JSON file and paste or upload it here.&#x20;
- **The project ID of the cloud project**: Copy the ID from your Google Cloud Platform and paste it here.&#x20;
- **The private key ID of the cloud project**: Copy the key ID from your Google Cloud Platform and paste it here.&#x20;
- **The client email of the cloud project**: Enter the email from your Google Cloud Platform.&#x20;
- **Integration Topic**: Copy the name of the *Publication&#x20;*&#x74;opic from your Google Cloud Platform and paste it here.
- **Custom Attributes**: You can add custom attributes in key/value pairs for further data processing. Refer to the following to learn more:
  - [Use Custom Attributes in the Google Cloud Pub/Sub Connector](docId\:iYQiAu-mqkBpue8dMRkpW)
  - Google documentation for [Using attributes](https://cloud.google.com/pubsub/docs/publisher#using-attributes)****
- **Parallel Publish Count**: The number of messages being published simultaneously. The default value is **100**. &#x20;
- **Parallel byte threshold**: The minimum size of a batch (in bytes) for the batch to be published. The default value is zero, which means that there is no threshold (limit).&#x20;
- **Publish count threshold**: The minimum number of messages in a batch for the batch to be published. The default value is zero, which means that there is no threshold (limit).&#x20;
- **Publish delay threshold (Milliseconds)**: The maximum time that the client will attempt to publish a batch of messages. The default value is zero, which means that there is no threshold (limit).&#x20;
- **Throttling limit**: The maximum number of messages per second to be processed. The default value is zero, which means that there is no limit.&#x20;
- **Persistent storage**: When enabled, this will cause messages to undergo a store-and-forward procedure. Messages will be stored within Manufacturing Connect Edge when cloud providers are online. &#x20;
- **Queue Mode**: Select the queue mode as **lifo&#x20;**(last in first out) or **fifo&#x20;**(first in first out). Selecting **lifo&#x20;**&#x6D;eans that the last data entry is processed first, and selecting **fifo&#x20;**&#x6D;eans the first data entry is processed first.&#x20;

## Step 3: Enable the Connector

After adding the connector, click the toggle in the connector tile to enable it.&#x20;

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/k4lrcqf3ULWwfAkGqAjBs_image.png" size="60" width="498" height="269" caption="Toggle to enable connector" position="center" showCaption="true"}

If you see a *Failed&#x20;*&#x73;tatus, you can review the [Connector Logs](docId\:Zz28hZtQBK7oD_Xsj81O8) and relevant error messages.&#x20;

## Step 4: Create Inbound Topics for Connector

You will now need to create a topic in Manufacturing Connect Edge from the Google Cloud Platform publication topic created in Step 1.&#x20;

**To create inbound topics:&#x20;**

1. Navigate to **Integration**.&#x20;
2. Click the connector tile.&#x20;
3. Click the **Topics&#x20;**&#x74;ab.&#x20;
4. Click the **Add a new subscription** icon.
   The *Data Integration* dialog box appears.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/pBA5rmXF9A1BIauqwhvZ5_googleaddsubscriptionmce.png)
5. Configure the following parameters.&#x20;
   - **Data Direction**: Select **Remote to Local - Inbound**.&#x20;
   - **Local Data Topic**: Enter a name for the topic name in Manufacturing Connect Edge. &#x20;
   - **Remote Data Topic**: Copy and paste the *Publication&#x20;*&#x74;opic from your Google Cloud Platform.&#x20;
   - **Enable**: Select the toggle to enable the topic.&#x20;
6. Click **Yes&#x20;**&#x74;o add the topic.&#x20;
7. From the connector tile, ensure the connector is not disabled and still shows a CONNECTED status. Also verify the topic shows an *Enabled&#x20;*&#x73;tatus.&#x20;

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/_fQ4CQCHAY7SrsdWRF08n_image.png)

## Step 5: Send Messages in Google Cloud Platform

Start sending messages through the *publication&#x20;*&#x74;opic (created in Step 1) from the Google Cloud Platform. See [Publish messages to topics](https://cloud.google.com/pubsub/docs/publisher) to learn more.&#x20;

## Step 9: Verify Connection in Manufacturing Connect Edge

You can do one of the following to verify the connection in Manufacturing Connect Edge. When configuring the Flow or application, use the th&#x65;**&#x20;Local Data Topic** name configured in Step 4.&#x20;

- [Create a Flow](docId\:VeeOD3N3SLCAsdLEedZBr) to view the messages coming from Google Pub/Sub through the connector you created.&#x20;
- Visualize the incoming data using one of the dedicated [Applications](docId\:UPKtM_T_EFgGSsljZ6e7S).&#x20;

