AereA GmbH
Discuss your project

Project report: industrial automation

Industrial data platform for plant engineering

Architecture, technology selection, security concept and arc42 architecture documentation - for a leading international plant manufacturer in the metals industry.

Industry
Plant engineering, metals industry, international leader
System type
Industrial data platform, distributed
AereA's role
Architecture, implementation, security concept, training
Period
4 years, ongoing

Starting point

Exchanging machine and plant data across sites without carrying the communication unsecured beyond factory boundaries.

Approach

A new build rather than an extension of the existing estate: scalable platform with an MQTT broker (EMQX), central identity and access management via Keycloak and containerised operation.

Result

End-to-end secured communication, architecture documented to arc42 and the client's development teams trained - in operation for 4 years.

Results at a glance

  • 4 years in operation, still running and being extended
  • A new build rather than an extension of the existing estate - real-time capability as a design goal, not a retrofit
  • Connectivity for several sites across factory and national boundaries
  • Security concept with certificate and identity management via Keycloak
  • arc42 architecture documentation as the handover basis for the client teams
  • Polyglot stack - Java, C#, Go and Python - chosen by fit per component, argued in the architecture documentation

Starting point

An internationally active plant manufacturer operates machines at customers worldwide. Their operating data is valuable for service, optimisation and further development - but it has to travel across factory and national boundaries without creating unsecured channels.

The task

A platform for industrial data exchange that scales with the number of connected installations, separates data classes cleanly and secures communication end to end. Plus documentation that enables the client’s own teams to operate and evolve it.

Architectural decisions

At the core is an MQTT broker (EMQX) as the transport layer, complemented by services implemented in Java, C#, Go or Python depending on requirements. Identity and access run centrally via Keycloak, operation via Docker. Persistence uses PostgreSQL and MongoDB, depending on data structure.

Each of these decisions is recorded in the arc42 architecture documentation with its rationale and the rejected alternatives - exactly the part that makes the difference at handover to client teams.

Implementation and knowledge transfer

Alongside architecture and implementation, training the client’s development teams was part of the assignment. A platform only its author can operate does not solve the problem durably.

Conclusion

The engagement continued at the same client: the data platform was followed by the migration of the condition monitoring backend from C++ to .NET Core.

Technologies

  • Java
  • C#
  • Go
  • Python
  • EMQX
  • Keycloak
  • Docker
  • PostgreSQL
  • MongoDB
  • arc42

Frequently asked questions

Why several programming languages?

Because the components had different requirements: throughput-critical services in Go, business services in Java and C#, data analysis in Python. The decision is argued in the arc42 documentation rather than left to taste.

What was the security core?

End-to-end encryption of machine communication, certificate management and central identity and access management via Keycloak, so permissions do not have to be maintained per service.

Contact

Your contact

Sören Sprenger
Software architecture & technical project management

Wüstenstein 18, 91346 Wiesenttal · Mon-Fri 9:00-18:00 CET