SkillByAIOpen interactive version →

Lesson 18 / 25

Users, Permissions and TLS

Secure RabbitMQ with least-privilege users, vhost permissions and encryption.

Least privilege for messaging

RabbitMQ authorisation is per vhost: each user gets three regular-expression permissions on resource names, configure (declare and delete exchanges and queues), write (publish to exchanges, bind) and read (consume from queues, bind). A producer service might have write access to ^orders$ only; a consumer read access to ^billing\..*. Administrative tags (administrator, monitoring, management) control access to the management UI and API. Use TLS for client connections (port 5671 by convention) and between cluster nodes, and consider mutual TLS with certificate-based authentication. For centralised identity, the OAuth 2.0 plugin lets clients authenticate with JWTs from an identity provider, and LDAP is also supported. Store credentials in a secret manager, rotate them, avoid sharing one user across services, and keep the management interface off the public internet.

A least-privilege setup

The orders service can only publish to its exchange; billing can only consume its queues.

rabbitmqctl add_user orders-svc "$(cat /run/secrets/orders_pw)"
rabbitmqctl set_permissions -p shop orders-svc '^$' '^orders$' '^$'
#                                         configure  write      read

rabbitmqctl add_user billing-svc "$(cat /run/secrets/billing_pw)"
rabbitmqctl set_permissions -p shop billing-svc '^$' '^$' '^billing\..*'

# topology is declared by a deploy job with configure rights, not by every service
rabbitmqctl add_user topology-admin "$(cat /run/secrets/topology_pw)"
rabbitmqctl set_permissions -p shop topology-admin '.*' '.*' '.*'

rabbitmqctl delete_user guest

Declare topology in one place

If every service may declare queues with any arguments, mismatched declarations cause PRECONDITION_FAILED errors and surprise queues. Manage exchanges, queues, bindings and policies from a definitions file or infrastructure code.

Quick check: Which RabbitMQ permission is needed to consume from a queue?

  • read
  • configure
  • write
  • administrator tag
Answer

read — Read permission on the queue is required to consume messages from it.