# Users, Permissions and TLS — RabbitMQ

Source: https://www.skillbyai.com/en/rabbitmq/o-security

> Secure RabbitMQ with least-privilege users, vhost permissions and encryption.

## Least privilege for messaging

RabbitMQ authorisation is per **vhost**: each user gets three regular-expression permissions on resource names, **configure** (declare and delete exchanges and queues), **write** (publish to exchanges, bind) and **read** (consume from queues, bind). A producer service might have write access to `^orders$` only; a consumer read access to `^billing\..*`. Administrative **tags** (`administrator`, `monitoring`, `management`) control access to the management UI and API. Use **TLS** for client connections (port 5671 by convention) and between cluster nodes, and consider **mutual TLS** with certificate-based authentication. For centralised identity, the **OAuth 2.0 plugin** lets clients authenticate with JWTs from an identity provider, and LDAP is also supported. Store credentials in a secret manager, rotate them, avoid sharing one user across services, and keep the management interface off the public internet.

## A least-privilege setup

The orders service can only publish to its exchange; billing can only consume its queues.

```bash
rabbitmqctl add_user orders-svc "$(cat /run/secrets/orders_pw)"
rabbitmqctl set_permissions -p shop orders-svc '^$' '^orders$' '^$'
#                                         configure  write      read

rabbitmqctl add_user billing-svc "$(cat /run/secrets/billing_pw)"
rabbitmqctl set_permissions -p shop billing-svc '^$' '^$' '^billing\..*'

# topology is declared by a deploy job with configure rights, not by every service
rabbitmqctl add_user topology-admin "$(cat /run/secrets/topology_pw)"
rabbitmqctl set_permissions -p shop topology-admin '.*' '.*' '.*'

rabbitmqctl delete_user guest
```

## Declare topology in one place

If every service may declare queues with any arguments, mismatched declarations cause `PRECONDITION_FAILED` errors and surprise queues. Manage exchanges, queues, bindings and policies from a definitions file or infrastructure code.

**Quiz:** Which RabbitMQ permission is needed to consume from a queue?

- [x] read
- [ ] configure
- [ ] write
- [ ] administrator tag

*Answer:* read. Read permission on the queue is required to consume messages from it.
