Skip to content

Provisioning RabbitMQ#

Ametnes-managed RabbitMQ is a private, TLS-only message broker. The management console is served over HTTPS and every AMQP client connects over AMQPS on port 5671 — the plaintext 5672 listener is disabled.

Prerequisites#

  1. A service location (see Service Location).

Networking is automatic by default

Creating a network access resource is optional. If you do not create one, Ametnes manages network access for the location — a shared load balancer publishes the endpoints for the services deployed there, scoped to the location or project — and your service attaches to it automatically. Create your own only if you want to control exposure (see Network Access Resources).

Create the RabbitMQ service#

Kinds: service/rabbitmq:4.3 and service/rabbitmq:4.2. The administrator credentials are required.

  1. Navigate to Services and click New Service.
  2. Name it (for example RabbitMQService).
  3. Kind: RabbitMQ 4.3 Message Broker.
  4. Location: your data service location. Leave Network unset to let Ametnes manage it.
  5. Architecture: Starter for evaluation, Basic+ for a clustered, highly available broker.
  6. Set Admin User (lowercase, 5+ characters, e.g. admin) and Admin Password.
  7. Click Create Service and wait for ready.
service.tf
resource "ametnes_service" "rabbitmq" {
  name    = "RabbitMQService"
  project = ametnes_project.project.id
  location = data.ametnes_location.location.id
  kind    = "service/rabbitmq:4.3"
  nodes   = 3
  capacity {
    storage = 50
  }
  config = {
    "architecture"   = "Basic"
    "admin.user"     = "admin"
    "admin.password" = "change-me"
  }
}

output "connections" { value = ametnes_service.rabbitmq.connections }

Connect#

The service publishes two connections:

Connection Port Use
https 443 Management console / HTTP API (TLS terminated at the ingress).
amqps 5671 AMQP clients. TLS terminates at the broker using the zone certificate.

Clients must use amqps:// (Let's Encrypt certificates are publicly trusted):

amqps://admin:<password>@<host>:<port>/
import pika, ssl
params = pika.ConnectionParameters(
    host="<host>", port=<port>,
    credentials=pika.PlainCredentials("admin", "<password>"),
    ssl_options=pika.SSLOptions(ssl.create_default_context(), server_hostname="<host>"),
)
pika.BlockingConnection(params)

The shovel plugin (used by disaster recovery) ships with the broker and is enabled by default.

Queue type

Queues default to quorum (default_queue_type = quorum), so a clustered tier replicates them across its nodes automatically. Clients can still pin a type per queue with arguments={"x-queue-type": "quorum"} (or classic); the type is immutable once the queue is declared.

Next#

  • Disaster recovery — replicate to a standby cluster and fail over.
  • Scaling — tiers, cluster size and version upgrades.