Skip to content

Bump RabbitMQ containers from 4.2.x to 4.3.0-management - #84

Draft
niemyjski wants to merge 1 commit into
mainfrom
upgrade-rabbitmq-4.3.0
Draft

niemyjski wants to merge 1 commit into
mainfrom
upgrade-rabbitmq-4.3.0

Conversation

@niemyjski

Copy link
Copy Markdown
Member

Summary

  • Upgrade the standard Docker container (docker-compose.yml) from 4.2.5 to 4.3.0-management
  • Pin the Aspire AppHost AddRabbitMQ resource to 4.3.0 via .WithImageTag("4.3.0")
  • Upgrade chaos cluster nodes from 4.2.2-management to 4.3.0-management
  • The delayed exchange container (build/Dockerfile) remains on 4.2.5 since the rabbitmq_delayed_message_exchange plugin is incompatible with RabbitMQ 4.3 (Mnesia removed)

Supersedes #74 (dependabot PR that only touches docker-compose.yml).

Notes

The existing code already handles 4.3 compatibility:

  • _delayedExchangePluginIncompatibleVersion gates the plugin probe on >= 4.3
  • _globalQosRemovedVersion handles per-channel QoS changes
  • Features like ConsumerTimeout, DelayedRetries, MessagePriority already validate server version >= 4.3

No source code changes needed -- this is purely a container version bump.

Test plan

  • dotnet build succeeds with 0 warnings
  • dotnet test passes all non-infrastructure-dependent tests (118 passed, 0 failed)
  • CI passes with the new 4.3.0 containers (integration tests)

…ructure

- Upgrade Aspire AppHost and chaos cluster to RabbitMQ 4.3.0-management
- Remove docker-compose.yml (Aspire AppHost handles all container orchestration)
- Remove build/Dockerfile and delayed_message_exchange plugin (incompatible with 4.3)
- Remove delayed exchange test classes and fixture wiring
- Remove --delayed CLI option from sample apps
- Clean up dependabot, solution items, and VS Code tasks
@niemyjski
niemyjski force-pushed the upgrade-rabbitmq-4.3.0 branch from 002572a to 92ce2fb Compare May 28, 2026 21:44
@niemyjski
niemyjski requested a review from Copilot May 28, 2026 21:47
@niemyjski niemyjski self-assigned this May 28, 2026
@niemyjski
niemyjski marked this pull request as draft May 28, 2026 21:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the test/apphost RabbitMQ container versions to RabbitMQ 4.3.0 and removes the repository’s docker-compose + delayed-exchange Docker image/test harness paths (including the delayed-exchange sample CLI switches), consolidating container orchestration around the Aspire AppHost.

Changes:

  • Pin Aspire AppHost RabbitMQ resource to 4.3.0 and bump chaos-cluster nodes to 4.3.0-management.
  • Remove the delayed-exchange container wiring from the Aspire test fixture/AppHost and delete the delayed-exchange “shim” test classes.
  • Delete local Docker assets (docker-compose.yml, build/Dockerfile), remove the VS Code “docker: rabbitmq” task, and remove Dependabot Docker update configs.

Reviewed changes

Copilot reviewed 11 out of 12 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
tests/Foundatio.RabbitMQ.Tests/Messaging/RabbitMqMessageBusDelayedExchangeTests.cs Deleted delayed-exchange fixture-based test entrypoint.
tests/Foundatio.RabbitMQ.Tests/Messaging/RabbitMqMessageBusClassicDelayedExchangeTests.cs Deleted classic delayed-exchange fixture-based test entrypoint.
tests/Foundatio.RabbitMQ.Tests/AspireFixture.cs Removes delayed-exchange connection string/resource wait; retains core messaging + chaos availability.
tests/Foundatio.RabbitMQ.AppHost/Program.cs Pins RabbitMQ to 4.3.0 and bumps chaos nodes to 4.3.0-management; removes delayed container.
samples/Foundatio.RabbitMQ.Subscribe/Program.cs Removes --delayed option and port-rewrite behavior.
samples/Foundatio.RabbitMQ.Publish/Program.cs Removes --delayed option and port-rewrite behavior.
Foundatio.RabbitMQ.slnx Removes docker-compose/Dockerfile from Solution Items.
docker-compose.yml Deleted.
build/Dockerfile Deleted (previously built delayed-exchange plugin image).
.vscode/tasks.json Removes the “docker: rabbitmq” task.
.github/dependabot.yml Removes Docker/docker-compose update configurations.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines 5 to 8
builder.AddRabbitMQ("messaging")
.WithImageTag("4.3.0")
.WithManagementPlugin();

Comment on lines 15 to 19
private DistributedApplication? _app;
public DistributedApplication App => _app ?? throw new InvalidOperationException("Fixture not initialized - Aspire AppHost failed to start");
public string? MessagingConnectionString { get; private set; }
public string? MessagingDelayedConnectionString { get; private set; }
public bool ChaosClusterAvailable { get; private set; }
public bool IsAvailable => _app is not null && MessagingConnectionString is not null;
Comment thread Foundatio.RabbitMQ.slnx
Comment on lines 6 to 11
<Folder Name="/Solution Items/">
<File Path=".editorconfig" />
<File Path="build/common.props" />
<File Path="build/Dockerfile" />
<File Path="docker-compose.yml" />
<File Path="README.md" />
<File Path="tests/Directory.Build.props" />
</Folder>

Copy link
Copy Markdown
Member Author

Broker-version security follow-up from the final audit of #100 — September 22, 2026

The currently proposed 4.3.0 target is no longer an appropriate production patch baseline. The official release/support catalog currently lists 4.3.6 (September 16, 2026), and the 4.2 line has left community support. Do not merge an old major/minor upgrade target without refreshing its patch/security review.

The completed #100 integration/TLS evidence records primary broker 4.3.6, delayed-plugin broker 4.2.5, chaos nodes 4.2.2, and TLS-only broker 4.2.0. The older 4.2 fixtures fall within published rabbitmq-server affected ranges, including GHSA-5cq3-v9jx-p3x3 and GHSA-w9hf-476r-443x. Later advisories such as GHSA-3526-xvv4-q9mr have additional patch requirements. These are broker-server findings, not a claim that RabbitMQ.Client 7.2.2 is affected or that any deployed system has been compromised.

Required follow-up for this broker-upgrade PR:

  1. Rebase/merge the current main as appropriate and re-audit the actual diff; refresh standard, chaos, and TLS fixture images to a verified available patched target. Pin exact versions/digests for repeatability and record them in execution artifacts.
  2. Treat the delayed-plugin fixture separately. Preserve the current compatibility tests; do not simply move that image to 4.3, suppress plugin failures, drop its cases, or claim the legacy 4.2 tag is production-approved. Establish a supported patched artifact/support route or document a deliberate, isolated legacy-compatibility exception. The retired plugin's wider durability replacement remains separate work in Harden RabbitMQ delivery safety, recovery, and verification #99.
  3. Execute full required integration plus the twelve explicit TLS cases on the resulting candidate. Check actual cluster membership/readiness and message IDs rather than counting startup success as recovery verification. Reconcile the complete discovered/pass/fail/skip inventory after the branches are combined.
  4. Keep compatibility fixtures separate from production deployment guidance. Confirm current advisories, actual deployed broker versions, and upgrade/rollback requirements before a production rollout.

No image tags, branch contents, or production infrastructure were changed by this comment. #100's scoped code/CI verification is complete; broker-image refresh and production security approval are not implied by those test passes.

Copy link
Copy Markdown
Member Author

Maintainer direction supersedes the earlier upgrade recommendation: keep all broker/runtime/CI fixtures on exactly RabbitMQ 4.2.5. Do not merge the 4.3.0 upgrade or introduce floating 4.3 tags as part of #99. Work on #100 is being revalidated against 4.2.5, including the actual broker-reported versions and the two-tier quorum priority contract. The separately versioned delayed-exchange plugin remains the compatible 4.2.0 plugin on a 4.2.5 server; the plugin version is not a server image version. Security/support caveats remain recorded, but do not authorize a broker-version upgrade. No production infrastructure has been changed.

Copy link
Copy Markdown
Member Author

Broker upgrade explicitly on hold

The maintainer's current requirement is RabbitMQ 4.2.5 for every broker fixture and configuration. The 4.3.0 upgrade proposed here is not authorized for the current reliability work. PR #100 now pins primary, Compose, chaos, and TLS brokers to 4.2.5 and retains the delayed-plugin broker on 4.2.5.

Please do not merge this upgrade as a dependency of #99/#100. Any future move beyond 4.2.5 requires a separate decision and fresh compatibility/security review. The plugin artifact's version is separate from the broker version. No production environment was changed by this update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants