Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened Message Broker / Security

DCA Hardened Message Broker — security notes

Network exposure

PortPurposeState
22SSH — key-only, OS Login (IAM); the deployment package adds no SSH ruleyour VPC's firewall rules
5672AMQP — bound to 127.0.0.1 (listeners.tcp.default)customer-must-open (config + firewall toggle)
15672Management UI and HTTP API — bound to 127.0.0.1 (management.tcp.ip)customer-must-open (config + firewall toggle)
25672Erlang distribution — 127.0.0.1loopback only (never exposed by the package)
4369epmd — 127.0.0.1 and ::1loopback only (never exposed by the package)

"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.

Shared responsibility

We maintainThe hardened image: package selection, hardening baseline, CVE rebuilds, listing freshness, and these docs.
You controlThe running instance: OS patching between image versions, network exposure, IAM, data, and backups.
Your cloud providesPhysical/hypervisor security, marketplace billing, and the firewall primitives this design relies on.

This product is based on the open-source RabbitMQ software (MPL-2.0). RabbitMQ is a trademark of its owner, Broadcom; Derek Coleman & Associates Inc is not affiliated with or endorsed by Broadcom.