Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened Message Broker

DCA Hardened Message Broker — documentation & support card

An AMQP message broker based on the open-source RabbitMQ software 4.3 on Erlang/OTP 27: every listener on loopback, a per-VM Erlang cookie and administrator, and no guest account.

Install Configure Troubleshoot Security

At a glance

TypeHardened VM image
Upstream / licenseRabbitMQ (MPL-2.0) — see licenses
VersionRabbitMQ 4.3.6 on Erlang/OTP 27.3.4.18 (Team RabbitMQ's signed apt repositories, versions pinned), Ubuntu 24.04 LTS; Google Cloud image built 2026-10-07. Exact image version: see the listing. Current builds: release notes.
Architecturex86-64
SizingAny current-generation instance with ≥ 4 vCPU (pay-as-you-go floor); 8 vCPU recommended for production.

Marketplaces

Network ports

PortPurposeState
22SSH — key-only, OS Login (IAM); the deployment package adds no SSH ruleyour VPC's firewall rules
5672AMQP — bound to 127.0.0.1 (listeners.tcp.default)customer-must-open (config + firewall toggle)
15672Management UI and HTTP API — bound to 127.0.0.1 (management.tcp.ip)customer-must-open (config + firewall toggle)
25672Erlang distribution — 127.0.0.1loopback only (never exposed by the package)
4369epmd — 127.0.0.1 and ::1loopback only (never exposed by the package)

"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.

Access & credentials

No shared or default credentials are included in this image. Access uses the SSH key you supply at launch; any application credential is generated uniquely on your instance at first boot and stored only there — we never know it.

Log in: SSH in with OS Login and forward port 15672 (gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap -- -L 15672:127.0.0.1:15672), then open http://localhost:15672/ as admin. CLI tools run with sudo.

An administrator, admin, with a 32-character password, and the node's Erlang cookie — both generated on THIS VM's first boot. The password is in /root/rabbitmq-admin-credentials.txt (root-only, 0600); the cookie is /var/lib/rabbitmq/.erlang.cookie (rabbitmq, 0400). The default guest account is deleted. Nothing credential-like exists in the image.

sudo cat /root/rabbitmq-admin-credentials.txt

Rotation: Change it in the management UI (Admin → Users → admin) or with sudo rabbitmqctl change_password admin NEW_PASSWORD, then update /root/rabbitmq-admin-credentials.txt or your secret store. Create one user per application instead of sharing admin.

Step-by-step: first login / credentials.

Data & dependencies

Operate

Known limitations

Single node: clustering, TLS listeners and off-box Erlang distribution are deliberate customer steps. Based on the RabbitMQ software; not affiliated with or endorsed by Broadcom. The Marketplace product name is still being finalized.

Support

Email support@dcassociatesgroup.com — first response within 1 business day (US Eastern), most tickets same-day. To escalate an open ticket, reply "ESCALATE"; it is reviewed by the founder within 1 business day. Security reports: vulnerability disclosure.

Privacy: policy · Terms: terms · Security practices: security & trust · Vulnerability reports: disclosure policy

This product is based on the open-source RabbitMQ software (MPL-2.0). RabbitMQ is a trademark of its owner, Broadcom; Derek Coleman & Associates Inc is not affiliated with or endorsed by Broadcom.