Home / Docs / DCA Hardened Message Broker / Security
| Port | Purpose | State |
|---|---|---|
| 22 | SSH — key-only, OS Login (IAM); the deployment package adds no SSH rule | your VPC's firewall rules |
| 5672 | AMQP — bound to 127.0.0.1 (listeners.tcp.default) | customer-must-open (config + firewall toggle) |
| 15672 | Management UI and HTTP API — bound to 127.0.0.1 (management.tcp.ip) | customer-must-open (config + firewall toggle) |
| 25672 | Erlang distribution — 127.0.0.1 | loopback only (never exposed by the package) |
| 4369 | epmd — 127.0.0.1 and ::1 | loopback only (never exposed by the package) |
"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.
| We maintain | The hardened image: package selection, hardening baseline, CVE rebuilds, listing freshness, and these docs. |
|---|---|
| You control | The running instance: OS patching between image versions, network exposure, IAM, data, and backups. |
| Your cloud provides | Physical/hypervisor security, marketplace billing, and the firewall primitives this design relies on. |
This product is based on the open-source RabbitMQ software (MPL-2.0). RabbitMQ is a trademark of its owner, Broadcom; Derek Coleman & Associates Inc is not affiliated with or endorsed by Broadcom.