# Running RabbitMQ and the Management UI — RabbitMQ

Source: https://www.skillbyai.com/en/rabbitmq/f-run

> Start a local broker, use the management UI and the command-line tools.

## Your first broker

The quickest way to try RabbitMQ is the official container image with the **management plugin**, which adds a web UI and HTTP API. Port **5672** serves AMQP, **15672** the management UI, and **15692** Prometheus metrics when the Prometheus plugin is enabled (it is in the official image). The default **`guest`** user can only connect from **localhost**; create real users with passwords and vhost permissions for anything else. The management UI shows connections, channels, exchanges, queues with message rates and depths, and lets you publish and fetch test messages. On servers, use the CLI tools: **`rabbitmqctl`** for administration (users, vhosts, permissions, policies), **`rabbitmq-diagnostics`** for health checks and status, **`rabbitmq-plugins`** to enable plugins and **`rabbitmqadmin`** for scripting management API calls. In production on Kubernetes, the **RabbitMQ Cluster Operator** manages clusters declaratively.

## A local broker and basic administration

Container ports: 5672 for AMQP, 15672 for the UI.

```bash
docker run -d --name rabbit -p 5672:5672 -p 15672:15672 rabbitmq:4-management
# UI: http://localhost:15672  (guest/guest works only from localhost)

docker exec rabbit rabbitmqctl add_vhost shop
docker exec rabbit rabbitmqctl add_user app 'change-me'
docker exec rabbit rabbitmqctl set_permissions -p shop app '.*' '.*' '.*'

docker exec rabbit rabbitmq-diagnostics status
docker exec rabbit rabbitmq-diagnostics check_port_connectivity
docker exec rabbit rabbitmqctl list_queues -p shop name type messages consumers
```

## Never expose guest or the UI publicly

The management UI and default credentials are common targets. Remove or disable `guest` in non-local environments, put the UI behind a VPN or SSO, and use TLS for client connections.

**Quiz:** Which port does the RabbitMQ management web UI use by default?

- [ ] 5672
- [ ] 8080
- [x] 15672
- [ ] 443

*Answer:* 15672. 5672 is AMQP; the management UI listens on 15672.
