Prerequisites
- An account on the target cloud with permission to launch VM instances (no special IAM roles are required by this product unless stated below — IAM required: none).
- An SSH key pair registered in the target cloud (all access is key-only; password SSH is disabled).
- Instance size ≥ 4 vCPU (pricing floor; 8 vCPU recommended).
- No internet access or external dependency is required at deploy time — the image is self-contained.
Google Cloud
- Deploy from the Google Cloud Marketplace listing (or its deployment package): at least 4 vCPU and 16 GB RAM (default n2-standard-8, 50 GB balanced boot disk). Leave the tcp:5672 and tcp:15672 firewall toggles off for now.
Expected result The VM DEPLOYMENT-vm is RUNNING; on it, sudo rabbitmq-diagnostics -q ping succeeds. - Tunnel port 15672 and sign in to http://localhost:15672/ with the credential in /root/rabbitmq-admin-credentials.txt.
Expected result The management UI opens; guest/guest is refused. - For AMQP clients in your VPC: add a listener on the VM's internal IP in /etc/rabbitmq/rabbitmq.conf, restart rabbitmq-server, then allow tcp:5672 from your client range only.
Expected result sudo rabbitmq-diagnostics listeners shows the new listener; clients in that range connect with their own users.
Validate
sudo rabbitmq-diagnostics -q ping → succeeds (exit status 0)
First boot: rabbitmq-firstboot.service mints the Erlang cookie and the administrator password before the broker first starts; rabbitmq-admin-firstboot then creates admin (tag administrator, full permissions on /), deletes guest, and proves admin signs in while a wrong password and guest/guest are refused, the versions are 4.3.6 / 27.3.4.18 and every listener is loopback-only, then writes /var/lib/dca-firstboot/rabbitmq.verified.
First login / credentials
- Connect with OS Login and forward the management UI: gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap -- -L 15672:127.0.0.1:15672 (reading the credential file needs sudo, i.e. roles/compute.osAdminLogin).
- Read this VM's administrator: sudo cat /root/rabbitmq-admin-credentials.txt (root-only, 0600). The guest account no longer exists.
- Open http://localhost:15672/ and sign in as admin; on the VM, sudo rabbitmq-diagnostics status shows the node. Create one user per application before anything connects.
Secure it
- Restrict SSH (22) to your own IP range in the cloud firewall/security group.
- Open application ports only per the ports table — closed-by-default is deliberate.
- Volume encryption: use your cloud's native volume encryption (enabled by default on most accounts); the image adds no proprietary encryption layer.
Costs & quotas
Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed
by your cloud at its standard rates. The recommended size fits default service quotas in most accounts —
if you scale out, review your cloud's quota console before launch.
Next: configuration · troubleshooting · security notes
This product is based on the open-source RabbitMQ software (MPL-2.0). RabbitMQ is a trademark of its owner, Broadcom; Derek Coleman & Associates Inc is not affiliated with or endorsed by Broadcom.