Repository navigation
Conversation
…ructure - Upgrade Aspire AppHost and chaos cluster to RabbitMQ 4.3.0-management - Remove docker-compose.yml (Aspire AppHost handles all container orchestration) - Remove build/Dockerfile and delayed_message_exchange plugin (incompatible with 4.3) - Remove delayed exchange test classes and fixture wiring - Remove --delayed CLI option from sample apps - Clean up dependabot, solution items, and VS Code tasks
002572a to
92ce2fb
Compare
There was a problem hiding this comment.
Pull request overview
This PR updates the test/apphost RabbitMQ container versions to RabbitMQ 4.3.0 and removes the repository’s docker-compose + delayed-exchange Docker image/test harness paths (including the delayed-exchange sample CLI switches), consolidating container orchestration around the Aspire AppHost.
Changes:
- Pin Aspire AppHost RabbitMQ resource to 4.3.0 and bump chaos-cluster nodes to 4.3.0-management.
- Remove the delayed-exchange container wiring from the Aspire test fixture/AppHost and delete the delayed-exchange “shim” test classes.
- Delete local Docker assets (docker-compose.yml, build/Dockerfile), remove the VS Code “docker: rabbitmq” task, and remove Dependabot Docker update configs.
Reviewed changes
Copilot reviewed 11 out of 12 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| tests/Foundatio.RabbitMQ.Tests/Messaging/RabbitMqMessageBusDelayedExchangeTests.cs | Deleted delayed-exchange fixture-based test entrypoint. |
| tests/Foundatio.RabbitMQ.Tests/Messaging/RabbitMqMessageBusClassicDelayedExchangeTests.cs | Deleted classic delayed-exchange fixture-based test entrypoint. |
| tests/Foundatio.RabbitMQ.Tests/AspireFixture.cs | Removes delayed-exchange connection string/resource wait; retains core messaging + chaos availability. |
| tests/Foundatio.RabbitMQ.AppHost/Program.cs | Pins RabbitMQ to 4.3.0 and bumps chaos nodes to 4.3.0-management; removes delayed container. |
| samples/Foundatio.RabbitMQ.Subscribe/Program.cs | Removes --delayed option and port-rewrite behavior. |
| samples/Foundatio.RabbitMQ.Publish/Program.cs | Removes --delayed option and port-rewrite behavior. |
| Foundatio.RabbitMQ.slnx | Removes docker-compose/Dockerfile from Solution Items. |
| docker-compose.yml | Deleted. |
| build/Dockerfile | Deleted (previously built delayed-exchange plugin image). |
| .vscode/tasks.json | Removes the “docker: rabbitmq” task. |
| .github/dependabot.yml | Removes Docker/docker-compose update configurations. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| builder.AddRabbitMQ("messaging") | ||
| .WithImageTag("4.3.0") | ||
| .WithManagementPlugin(); | ||
|
|
| private DistributedApplication? _app; | ||
| public DistributedApplication App => _app ?? throw new InvalidOperationException("Fixture not initialized - Aspire AppHost failed to start"); | ||
| public string? MessagingConnectionString { get; private set; } | ||
| public string? MessagingDelayedConnectionString { get; private set; } | ||
| public bool ChaosClusterAvailable { get; private set; } | ||
| public bool IsAvailable => _app is not null && MessagingConnectionString is not null; |
| <Folder Name="/Solution Items/"> | ||
| <File Path=".editorconfig" /> | ||
| <File Path="build/common.props" /> | ||
| <File Path="build/Dockerfile" /> | ||
| <File Path="docker-compose.yml" /> | ||
| <File Path="README.md" /> | ||
| <File Path="tests/Directory.Build.props" /> | ||
| </Folder> |
Broker-version security follow-up from the final audit of #100 — September 22, 2026The currently proposed The completed #100 integration/TLS evidence records primary broker 4.3.6, delayed-plugin broker 4.2.5, chaos nodes 4.2.2, and TLS-only broker 4.2.0. The older 4.2 fixtures fall within published rabbitmq-server affected ranges, including GHSA-5cq3-v9jx-p3x3 and GHSA-w9hf-476r-443x. Later advisories such as GHSA-3526-xvv4-q9mr have additional patch requirements. These are broker-server findings, not a claim that RabbitMQ.Client 7.2.2 is affected or that any deployed system has been compromised. Required follow-up for this broker-upgrade PR:
No image tags, branch contents, or production infrastructure were changed by this comment. #100's scoped code/CI verification is complete; broker-image refresh and production security approval are not implied by those test passes. |
|
Maintainer direction supersedes the earlier upgrade recommendation: keep all broker/runtime/CI fixtures on exactly RabbitMQ 4.2.5. Do not merge the 4.3.0 upgrade or introduce floating 4.3 tags as part of #99. Work on #100 is being revalidated against 4.2.5, including the actual broker-reported versions and the two-tier quorum priority contract. The separately versioned delayed-exchange plugin remains the compatible 4.2.0 plugin on a 4.2.5 server; the plugin version is not a server image version. Security/support caveats remain recorded, but do not authorize a broker-version upgrade. No production infrastructure has been changed. |
Broker upgrade explicitly on holdThe maintainer's current requirement is RabbitMQ 4.2.5 for every broker fixture and configuration. The 4.3.0 upgrade proposed here is not authorized for the current reliability work. PR #100 now pins primary, Compose, chaos, and TLS brokers to 4.2.5 and retains the delayed-plugin broker on 4.2.5. Please do not merge this upgrade as a dependency of #99/#100. Any future move beyond 4.2.5 requires a separate decision and fresh compatibility/security review. The plugin artifact's version is separate from the broker version. No production environment was changed by this update. |
Summary
AddRabbitMQresource to 4.3.0 via.WithImageTag("4.3.0")build/Dockerfile) remains on 4.2.5 since therabbitmq_delayed_message_exchangeplugin is incompatible with RabbitMQ 4.3 (Mnesia removed)Supersedes #74 (dependabot PR that only touches docker-compose.yml).
Notes
The existing code already handles 4.3 compatibility:
_delayedExchangePluginIncompatibleVersiongates the plugin probe on >= 4.3_globalQosRemovedVersionhandles per-channel QoS changesConsumerTimeout,DelayedRetries,MessagePriorityalready validate server version >= 4.3No source code changes needed -- this is purely a container version bump.
Test plan
dotnet buildsucceeds with 0 warningsdotnet testpasses all non-infrastructure-dependent tests (118 passed, 0 failed)