Role in the deployment¶
RabbitMQ is the message bus between iRODS and the DE. iRODS publishes data events to it; DE services consume them to keep search indexes and notifications current. It is also how a full search reindex is triggered.
It is a host service, not a Kubernetes workload — it is installed on the node in phase 1, before anything that depends on it. Sizing is modest: 1 core, 2 GB memory, 20 GB storage.
Install and configure¶
Run on the foundation node (core-1):
- Install
rabbitmq-serverwith the OS package manager. - Enable the management plugin and restart the service:
rabbitmq-plugins enable rabbitmq_management
systemctl restart rabbitmq-server
- Create an administrator account with a generated password, grant it full
configure, write, and read permissions, and tag it
administrator. - Delete the default
guestaccount. It ships with well-known credentials. - Create the vhost
/data-storeand grant the administrator full configure, write, and read permissions on it. - Create a separate account for iRODS with its own generated password and full
configure, write, and read permissions on
/data-store— iRODS should not authenticate as the administrator. - Create a
topicexchange namedirodson/data-store.
The iRODS account's credentials go into IRODS_AMQP_URI in
/etc/irods/server_config.json; see
iRODS provider.
The DE's own vhost, exchange, and accounts are created later, in phase 6, by
the deployment repository's rabbitmq_configure.yml playbook:
ansible-playbook -i /path/to/inventory rabbitmq_configure.yml
The existing Data Store playbooks (playbooks/amqp.yml,
playbooks/amqp_exchange.yml in the
Data Store collection) automate
steps 1 through 7 and are worth reusing rather than doing this by hand.
Ports¶
| Port | Purpose | Scope |
|---|---|---|
| 5672 | AMQP | Analysis nodes and in-cluster services |
| 15672 | Management UI and rabbitmqadmin download |
Administrators only |
Do not expose 15672 publicly. See
network requirements.
Operations: reindex search¶
A full reindex is requested by publishing an empty message with the routing key
index.all to the DE exchange, then restarting the indexer.
One-time: get rabbitmqadmin¶
rabbitmqadmin is served by the management plugin, so fetch it from the broker
host itself:
ssh <RABBITMQ_HOST>
mkdir -p ~/adm && cd ~/adm
wget http://localhost:15672/cli/rabbitmqadmin
chmod +x rabbitmqadmin
Trigger the reindex¶
Replace <VHOST>, <USER>, and <NAMESPACE> with the values for the
environment you are working in — the DE vhost and user come from the deployment
group variables, and the namespace is where the DE services run (prod in a
standard deployment).
# check the broker is healthy
systemctl status rabbitmq-server.service -l
# read the password into the environment instead of putting it in shell history
read -rs PASSWORD && export PASSWORD
# confirm you are pointed at the right vhost
./rabbitmqadmin -V <VHOST> list exchanges -u <USER> -p "$PASSWORD"
# request a full reindex
./rabbitmqadmin publish -V <VHOST> -u <USER> -p "$PASSWORD" \
exchange=de routing_key=index.all payload=""
# restart the indexer so it picks the request up
kubectl rollout restart deployment infosquito2 -n <NAMESPACE>
If infosquito2 is not deployed at all, deploy it rather than restarting it —
see cluster resources.
A reindex reads the entire catalog. On a large zone it takes hours and adds load to both PostgreSQL and the search cluster, so run it deliberately.