RabbitMQ and Qpid both work on AMQP for interprocess communication. Message queue is used to decouple the architecture.
The best part about message queues in OpenStack is, after permitting queue access, there is no additional authorization check that happens. Services accessible using message queue only validate the token within the actual message payload. Here, one must consider the token expiration time. Because queues can be replayed and they also authorize other services in the infrastructure.
In the OpenStack message, signing is not available. For high availability configuration, one must have complete queue-to-queue authentication and encryption.
Now, let's see the way to secure the message queue or AMQP:
- AMQP services such as RabbitMQ and Qpid both support TLS. So, we must enable TLS-based...