Hardening a self-hosted operations console
The order of decisions after install — broker credentials, environment policy, roles, the brokers' own authorisation, TLS at the edge, the key you cannot lose, and the trail you can stand behind.
Practical writing about running Kafka, Redis, RabbitMQ and Apache Artemis (formerly ActiveMQ Artemis) side by side: investigation paths, permission models, deployment posture and the operational habits that keep production quiet.
The order of decisions after install — broker credentials, environment policy, roles, the brokers' own authorisation, TLS at the edge, the key you cannot lose, and the trail you can stand behind.
The order of decisions after install — broker credentials, environment policy, roles, the brokers' own authorisation, TLS at the edge, the key you cannot lose, and the trail you can stand behind.
Four containers, one port, one volume, one irreplaceable key. What to settle before the first `docker compose up -d` in production, and what restart, upgrade and restore look like afterwards.
A sealed trail does not stop anyone changing a record. It makes a change visible to whoever holds a copy the changer could not reach — what BROKA seals, how to check it with a tool that is not BROKA, and where the proof stops.
On Apache Artemis a message is sent to an address, not to a queue. Where it went — routed nowhere, shared, copied, filtered, held for a time, held by a consumer or dead-lettered — is read from the address down, and each answer has its own safe action.
A Memcached node can evict with half its memory apparently free. Memory is committed to slab classes a page at a time and stays with its class until something moves it, so the answer to "why is it evicting" is one node's per-class table, not the totals.
RabbitMQ policies do not combine. One user policy governs a queue or exchange — the highest-priority match — the rest contribute nothing, and an operator policy sits on top as a separate layer. Read which one applies from the broker, not from the list.
The first hour with an inherited Kafka cluster, in the order that answers the most: is it whole, what does it really run, how are its brokers set up and loaded, what do its topics hold, who reads them, and who may do what — all read without changing anything.
Which subject a consumer looks for, which version a record was written with, which rule a new version must pass, and what delete really removes — read from the registry instead of guessed.
Read offset lag for what it counts, time lag for what it measures, find the stuck member, and preview a reset before applying it.
Map teams once, scope roles per environment, and let each broker keep its own native enforcement underneath.
A backlog is two numbers, not one — waiting and in flight — and the split decides whether you let it drain, divert it, or purge it. The same read works on RabbitMQ, Kafka and Redis Streams.
Delivered is not acknowledged. Read owner, idle time and delivery count, then acknowledge, claim behind the interlock, or go and fix the consumer.
A message that did not arrive was usually discarded at the exchange, not lost from a queue. The diagnosis runs from the routing graph out, and ends with a publish the broker answers — confirmed, returned or refused.