Start typing to search across invoices, services, domains, tickets, and more...
A hardware exporter selling smart-home devices, GPS trackers, EV chargers or POS terminals worldwide should run an IoT device cloud as a set of regional MQTT brokers close to the devices, not one broker in one country. IMIDC provides the servers for that pattern in Los Angeles (Americas), Hong Kong and Singapore (Asia), Moscow (Russia/CIS) and Johannesburg (Africa), with DDoS protection, CDN for firmware delivery and CN2 routes back to a China-based headquarters.
MQTT connections are long-lived TCP sessions, so every extra 100 ms of round trip and every lossy intercontinental link turns into reconnect storms and drained batteries.
The usual design is: devices resolve a regional hostname such as mqtt-ap.example.com via GeoDNS, connect over TLS on port 8883 to the local EMQX broker, and the broker forwards only the data you need (via MQTT bridge, Kafka or HTTP rule actions) to a central data platform.
Map each sales region to the closest IMIDC location and keep the firmware hard-coded with at least two fallback endpoints.
| IMIDC location | Device markets | Network notes | How to order |
|---|---|---|---|
| Los Angeles, USA | North America, Latin America | Unicom 9929/4837 and CN2 routes to mainland China; US native IPs | Dedicated from $499/mo |
| Hong Kong | Mainland China, Hong Kong, Greater China | CN2 GIA (AS4809) to mainland China; no ICP filing needed for hosting | VPS from $18/mo, dedicated from $139/mo |
| Singapore | Southeast Asia, India, Oceania | Submarine-cable hub for the region; local native IPs | Configured via sales |
| Moscow, Russia | Russia and CIS | CN2 route to mainland China; Russian IPs | VPS and dedicated servers |
| Johannesburg, South Africa | Southern and East Africa | South African native IPs (AFRINIC) | VPS from $18/mo |
| Tokyo, Japan / Seoul, South Korea | Japan, Korea | Native IPs; Japan VPS has a China-optimized CN2 option | Japan VPS from $28/mo |
IMIDC does not list a data center inside the EU. If your EU contracts require EU-resident data, keep that region with an EU provider and bridge only aggregated data to your other regions.
One EMQX container per region is enough for a pilot; expose only the TLS listeners to the internet.
# Regional EMQX broker on an IMIDC server (Docker installed)
docker volume create emqx-data
docker run -d --name emqx --restart unless-stopped \
--ulimit nofile=1048576:1048576 \
-p 8883:8883 -p 8084:8084 \
-p 127.0.0.1:1883:1883 -p 127.0.0.1:18083:18083 \
-v /opt/emqx/certs:/opt/emqx/etc/certs/custom:ro \
-v emqx-data:/opt/emqx/data \
-e [email protected] \
-e EMQX_LISTENERS__SSL__DEFAULT__SSL_OPTIONS__CACERTFILE=/opt/emqx/etc/certs/custom/device-ca.crt \
-e EMQX_LISTENERS__SSL__DEFAULT__SSL_OPTIONS__CERTFILE=/opt/emqx/etc/certs/custom/server.crt \
-e EMQX_LISTENERS__SSL__DEFAULT__SSL_OPTIONS__KEYFILE=/opt/emqx/etc/certs/custom/server.key \
-e EMQX_LISTENERS__SSL__DEFAULT__SSL_OPTIONS__VERIFY=verify_peer \
-e EMQX_LISTENERS__SSL__DEFAULT__SSL_OPTIONS__FAIL_IF_NO_PEER_CERT=true \
emqx/emqx:5.8.0
# Dashboard stays on localhost; reach it through an SSH tunnel:
# ssh -L 18083:127.0.0.1:18083 [email protected]
emqtt-bench from a second server, simulating your real connection count and message rate.Mutual TLS with a per-device certificate is the most robust way to stop cloned or stolen credentials from taking over your fleet.
# 1) Private device CA (keep ca key offline / in an HSM)
openssl ecparam -name prime256v1 -genkey -noout -out device-ca.key
openssl req -x509 -new -key device-ca.key -sha256 -days 3650 \
-subj "/CN=Example Device CA" -out device-ca.crt
# 2) One key + certificate per device, CN = serial number
SN=SN000123
openssl ecparam -name prime256v1 -genkey -noout -out $SN.key
openssl req -new -key $SN.key -subj "/CN=$SN" -out $SN.csr
openssl x509 -req -in $SN.csr -CA device-ca.crt -CAkey device-ca.key \
-CAcreateserial -days 1825 -sha256 -out $SN.crt
# 3) Test mutual TLS like a device would
mosquitto_pub -h mqtt-ap.example.com -p 8883 --cafile server-chain.pem \
--cert $SN.crt --key $SN.key -i $SN -q 1 \
-t devices/$SN/telemetry -m '{"temp":21.5,"fw":"1.4.2"}'
peer_cert_as_username = cn) and an ACL so that device SN000123 can only publish to devices/SN000123/#.Use MQTT only to announce an update; let devices download the binary over HTTPS from a CDN.
devices/{model}/ota.https://fw.example.com/model-x/1.5.0.bin from the nearest CDN edge, verifies the signature, then installs into the inactive A/B slot.The arithmetic explains why: 100,000 devices × 8 MB of firmware is about 800 GB per release, which would saturate a broker's uplink. IMIDC CDN absorbs that burst while your brokers keep serving telemetry.
Connection count is rarely the bottleneck for EMQX; message rate, rule-engine work and the database behind it are.
| Fleet per region | Assumed traffic | Suggested broker | Steady bandwidth | OTA per release (8 MB image) |
|---|---|---|---|---|
| 10,000 devices | 1 msg / 60 s, ~200 bytes (~170 msg/s) | Single VPS, 4 vCPU / 8 GB RAM | About 1 Mbps incl. TLS and keepalive | ~80 GB via CDN |
| 100,000 devices | 1 msg / 30 s (~3,300 msg/s) | 3-node EMQX cluster (8 cores / 16 GB each) or two dedicated servers | About 10–20 Mbps | ~800 GB via CDN |
| 1,000,000 devices | Mixed telemetry and commands | Dedicated cluster per region plus Kafka; design with IMIDC sales | 100 Mbps and up | ~8 TB via CDN |
These are rule-of-thumb starting points, not guarantees. Measure with your own payloads, QoS level and retained-message usage, and keep 50% headroom for reconnect storms after a regional network outage.
A public MQTT endpoint is a TCP service like any other and will be scanned and attacked within hours of going live.
Treat data residency as a product requirement, and confirm it with local counsel for each market. This section is general information, not legal advice.
Start small per region and move to dedicated servers when message rates or compliance demand it.
Custom configurations, such as extra RAM for EMQX clusters, private networking between nodes or additional IP resources, are available through IMIDC sales.
IMIDC offers VPS and dedicated servers in all four locations, plus Singapore via sales, so a hardware exporter can run one EMQX broker per region with a single provider. Hong Kong, Moscow and Los Angeles also have CN2 routes back to mainland China.
A 4 vCPU / 8 GB server comfortably handles around 10,000 devices sending one small message per minute, and EMQX can hold far more idle connections than that. The real limits are message rate, TLS handshakes during reconnect storms and the database behind the broker, so benchmark with emqtt-bench before launch.
No, ICP filing applies to hosting inside mainland China, and IMIDC Hong Kong servers do not require it. You still need to follow Chinese rules on personal data and cross-border transfer; this is not legal advice.
No. Send a signed manifest over MQTT and let devices download the binary over HTTPS from a CDN, which avoids saturating broker bandwidth during a release. IMIDC CDN can serve as that distribution layer.
Planning a multi-region device cloud? Compare Hong Kong CN2 GIA VPS and Los Angeles dedicated servers, then contact IMIDC sales for Singapore nodes and custom broker clusters, or open a ticket to discuss your fleet size with an engineer.