diff options
| author | wrobell <wrobell@riseup.net> | 2026-06-14 17:57:57 +0100 |
|---|---|---|
| committer | Sharlatan Hellseher <sharlatanus@gmail.com> | 2026-06-28 23:38:21 +0100 |
| commit | bfb35abf16bb4aa52b143dd1eb31ddef16898b37 (patch) | |
| tree | 7cf18943cc25ccde62a98cd0c81d1e0e11d62e4a /gnu/services/high-availability.scm | |
| parent | 2983d36030ba74037667b28012c76d4bf35e459f (diff) | |
services: Update rabbitmq service
Update RabbitMQ default configuration to use localhost interface by
default and avoid listening on public interfaces.
Change the default configuration file to set inter-node communication
listener to localhost network interface (see also
https://www.rabbitmq.com/docs/networking#distribution). This requires
setting RabbitMQ node name to `rabbit@localhost`, so introduce
`node-name` RabbitMQ configuration field with such default value.
Path to the RabbitMQ environment configuration file was hardcoded.
Remove the hardcoding and allow to create such file with env-config-file
RabbitMQ configuration field.
Add new RabbitMQ service tests to check RabbitMQ broker startup and
status after the service is started.
* gnu/services/high-availability.scm (<rabbitmq-configuration>)
[<node-name>, <env-config-file>]: New fields.
(rabbitmq-shepherd-service): Use them.
(%default-rabbitmq-config-file): Update.
* gnu/tests/high-availability.scm (run-rabbitmq-test): Add new tests.
* doc/gnu.texi (High Availability Services): Document new fields and
provide information about local interfaces.
Merges: guix/guix!9360
Signed-off-by: Sharlatan Hellseher <sharlatanus@gmail.com>
Diffstat (limited to 'gnu/services/high-availability.scm')
| -rw-r--r-- | gnu/services/high-availability.scm | 23 |
1 files changed, 18 insertions, 5 deletions
diff --git a/gnu/services/high-availability.scm b/gnu/services/high-availability.scm index 7b57d9a613e..73d534cf020 100644 --- a/gnu/services/high-availability.scm +++ b/gnu/services/high-availability.scm | |||
| @@ -1,6 +1,6 @@ | |||
| 1 | ;;; GNU Guix --- Functional package management for GNU | 1 | ;;; GNU Guix --- Functional package management for GNU |
| 2 | ;;; Copyright © 2018 Christopher Baines <mail@cbaines.net> | 2 | ;;; Copyright © 2018 Christopher Baines <mail@cbaines.net> |
| 3 | ;;; Copyright © 2025 Artur Wroblewski <wrobell@riseup.net> | 3 | ;;; Copyright © 2025-2026 Artur Wroblewski <wrobell@riseup.net> |
| 4 | ;;; Copyright © 2026 Mathieu Lirzin <mthl@gnu.org> | 4 | ;;; Copyright © 2026 Mathieu Lirzin <mthl@gnu.org> |
| 5 | ;;; | 5 | ;;; |
| 6 | ;;; This file is part of GNU Guix. | 6 | ;;; This file is part of GNU Guix. |
| @@ -32,19 +32,25 @@ | |||
| 32 | 32 | ||
| 33 | #:export (rabbitmq-configuration rabbitmq-configuration? | 33 | #:export (rabbitmq-configuration rabbitmq-configuration? |
| 34 | rabbitmq-configuration-rabbitmq | 34 | rabbitmq-configuration-rabbitmq |
| 35 | rabbitmq-configuration-node-name | ||
| 35 | rabbitmq-configuration-config-file | 36 | rabbitmq-configuration-config-file |
| 37 | rabbitmq-configuration-env-config-file | ||
| 36 | rabbitmq-configuration-plugins | 38 | rabbitmq-configuration-plugins |
| 37 | rabbitmq-service-type)) | 39 | rabbitmq-service-type)) |
| 38 | 40 | ||
| 39 | ;; By default, start on local ipv4 and ipv6 interfaces only, see also: | 41 | ;; By default, start messaging and inter-node RabbitMQ listeners on local |
| 42 | ;; interfaces only, see also: | ||
| 40 | ;; | 43 | ;; |
| 41 | ;; https://www.rabbitmq.com/docs/networking | 44 | ;; https://www.rabbitmq.com/docs/networking |
| 42 | ;; | 45 | ;; |
| 43 | ;; NOTE: How to enable plugins to listen on localhost only? | 46 | ;; NOTE: Enabling a RabbitMQ plugin will make it usually listen on a public |
| 47 | ;; interface. | ||
| 44 | (define %default-rabbitmq-config-file | 48 | (define %default-rabbitmq-config-file |
| 45 | (plain-file "rabbitmq.conf" " | 49 | (plain-file "rabbitmq.conf" " |
| 46 | listeners.tcp.1 = 127.0.0.1:5672 | 50 | listeners.tcp.1 = 127.0.0.1:5672 |
| 47 | listeners.tcp.2 = ::1:5672 | 51 | listeners.tcp.2 = ::1:5672 |
| 52 | |||
| 53 | distribution.listener.interface = 127.0.0.1 | ||
| 48 | ")) | 54 | ")) |
| 49 | 55 | ||
| 50 | (define-record-type* <rabbitmq-configuration> rabbitmq-configuration | 56 | (define-record-type* <rabbitmq-configuration> rabbitmq-configuration |
| @@ -52,8 +58,11 @@ listeners.tcp.2 = ::1:5672 | |||
| 52 | rabbitmq-configuration? | 58 | rabbitmq-configuration? |
| 53 | (rabbitmq rabbitmq-configuration-rabbitmq | 59 | (rabbitmq rabbitmq-configuration-rabbitmq |
| 54 | (default rabbitmq)) | 60 | (default rabbitmq)) |
| 61 | (node-name rabbitmq-configuration-node-name | ||
| 62 | (default "rabbit@localhost")) | ||
| 55 | (config-file rabbitmq-configuration-config-file | 63 | (config-file rabbitmq-configuration-config-file |
| 56 | (default %default-rabbitmq-config-file)) | 64 | (default %default-rabbitmq-config-file)) |
| 65 | (env-config-file rabbitmq-configuration-env-file (default #f)) | ||
| 57 | ;; It can be a mnesia database or a khepri database, so use "data" instead | 66 | ;; It can be a mnesia database or a khepri database, so use "data" instead |
| 58 | ;; of the traditional "mnesia". | 67 | ;; of the traditional "mnesia". |
| 59 | (data-directory rabbitmq-configuration-data-directory | 68 | (data-directory rabbitmq-configuration-data-directory |
| @@ -102,7 +111,7 @@ listeners.tcp.2 = ::1:5672 | |||
| 102 | 111 | ||
| 103 | (define (rabbitmq-shepherd-service config) | 112 | (define (rabbitmq-shepherd-service config) |
| 104 | (match-record config <rabbitmq-configuration> | 113 | (match-record config <rabbitmq-configuration> |
| 105 | (rabbitmq data-directory config-file plugins) | 114 | (rabbitmq node-name data-directory config-file env-config-file plugins) |
| 106 | (with-imported-modules | 115 | (with-imported-modules |
| 107 | (source-module-closure '((gnu build shepherd))) | 116 | (source-module-closure '((gnu build shepherd))) |
| 108 | (list | 117 | (list |
| @@ -119,10 +128,14 @@ listeners.tcp.2 = ::1:5672 | |||
| 119 | #:group "rabbitmq" | 128 | #:group "rabbitmq" |
| 120 | #:environment-variables | 129 | #:environment-variables |
| 121 | (append | 130 | (append |
| 131 | (if #$env-config-file | ||
| 132 | (list (string-append "RABBITMQ_CONF_ENV_FILE=" | ||
| 133 | #$env-config-file)) | ||
| 134 | (list)) | ||
| 122 | (list | 135 | (list |
| 136 | (string-append "RABBITMQ_NODENAME=" #$node-name) | ||
| 123 | (string-append "RABBITMQ_CONFIG_FILE=" #$config-file) | 137 | (string-append "RABBITMQ_CONFIG_FILE=" #$config-file) |
| 124 | "RABBITMQ_PID_FILE=/var/run/rabbitmq/pid" | 138 | "RABBITMQ_PID_FILE=/var/run/rabbitmq/pid" |
| 125 | "RABBITMQ_CONF_ENV_FILE=/run/current-system/profile/etc/rabbitmq/rabbitmq-env.conf" | ||
| 126 | (string-append | 139 | (string-append |
| 127 | "RABBITMQ_ENABLED_PLUGINS_FILE=" | 140 | "RABBITMQ_ENABLED_PLUGINS_FILE=" |
| 128 | #$data-directory | 141 | #$data-directory |
