The rabbitmq-bootstrap is a proxy provisioning service designed as part of the CZERTAINLY platform. Its primary purpose is to provision and decommission RabbitMQ queues and bindings for proxy instances, and to generate signed JWT configuration tokens with installation instructions for those proxies.
The service runs as a web application and exposes REST endpoints for:
All endpoints require authentication via the X-API-Key header.
All endpoints return JSON responses for errors. Authentication is required via X-API-Key header.
POST /api/v1/proxiesProvisions a new proxy instance by creating the required RabbitMQ queue and bindings.
Headers:
X-API-Key (required) - API key for authenticationRequest Body:
{
"proxyCode": "MY_PROXY_1"
}
Responses:
201 Created — proxy provisioned successfully (empty body)400 Bad Request — invalid request401 Unauthorized — missing or invalid API key409 Conflict — proxy already existsDELETE /api/v1/proxies/{proxyCode}Decommissions an existing proxy instance by removing its RabbitMQ queue.
Headers:
X-API-Key (required) - API key for authenticationPath Parameter:
proxyCode — unique proxy code identifierResponses:
204 No Content — proxy decommissioned successfully401 Unauthorized — missing or invalid API key404 Not Found — proxy not foundGET /api/v1/proxies/{proxyCode}/installationReturns installation instructions for an existing proxy. Generates a signed JWT configuration token and renders it into the requested install format.
Headers:
X-API-Key (required) - API key for authenticationPath Parameter:
proxyCode — unique proxy code identifierQuery Parameters:
format (required) — installation format; currently supported: helmResponse (Success - 200 OK):
{
"command": {
"shell": "helm repo add czertainly https://cloudfieldcz.github.io/CZERTAINLY-Helm-Charts\nhelm repo update\n\nhelm install proxy czertainly/proxy --set token=\"<jwt-token>\""
}
}
Responses:
200 OK — installation instructions returned401 Unauthorized — missing or invalid API key404 Not Found — proxy not foundError response format (all endpoints):
{
"error": "descriptive error message"
}
The application is configured via application.yml and environment variables.
| Variable | Description | Required | Default value |
|---|---|---|---|
PORT | Application port | 8080 | |
RABBITMQ_HOST | RabbitMQ hostname | localhost | |
RABBITMQ_PORT | RabbitMQ AMQP port | 5672 | |
RABBITMQ_USERNAME | RabbitMQ username with permission to manage queues and bindings in the virtual host | provisioner | |
RABBITMQ_PASSWORD | RabbitMQ password | N/A | |
RABBITMQ_VIRTUAL_HOST | RabbitMQ virtual host | czertainly | |
SECURITY_API_KEY | API key required in the X-API-Key header for all requests | N/A | |
PROXY_AMQP_URL | External AMQP URL that provisioned proxies use to connect (may differ from internal host) | amqp://localhost:5672 | |
PROXY_RABBITMQ_USERNAME | AMQP username embedded in the proxy configuration token | same as RABBITMQ_USERNAME | |
PROXY_RABBITMQ_PASSWORD | AMQP password embedded in the proxy configuration token | same as RABBITMQ_PASSWORD | |
PROXY_EXCHANGE | Exchange name used for proxy communication | czertainly-proxy | |
PROXY_RESPONSE_QUEUE | Core response queue name | core | |
TOKEN_SIGNING_KEY | HMAC-SHA256 signing key for JWT configuration tokens (minimum 32 characters) | N/A |
mvn clean package
# Set required environment variables
export RABBITMQ_USERNAME=provisioner
export RABBITMQ_PASSWORD=provisioner
export SECURITY_API_KEY=my-secret-api-key
export TOKEN_SIGNING_KEY=my-signing-key-at-least-32-characters-long
# Run the application
java -jar target/rabbitBootstrap-1.0-SNAPSHOT.jar
The application will start on port 8080 (configurable via PORT environment variable).
Provision a proxy:
curl -X POST "http://localhost:8080/api/v1/proxies" \
-H "X-API-Key: my-secret-api-key" \
-H "Content-Type: application/json" \
-d '{"proxyCode": "MY_PROXY_1"}'
Get installation instructions (Helm):
curl "http://localhost:8080/api/v1/proxies/MY_PROXY_1/installation?format=helm" \
-H "X-API-Key: my-secret-api-key"
Example response:
{
"command": {
"shell": "# Add the Helm repository\nhelm repo add czertainly https://cloudfieldcz.github.io/CZERTAINLY-Helm-Charts\nhelm repo update\n\n# Install the chart\nhelm install proxy czertainly/proxy --set token=\"<jwt-token>\""
}
}
Decommission a proxy:
curl -X DELETE "http://localhost:8080/api/v1/proxies/MY_PROXY_1" \
-H "X-API-Key: my-secret-api-key"
docker build -t czertainly/rabbitmq-bootstrap:latest .
docker run -d \
--name rabbitmq-bootstrap \
-p 8080:8080 \
-e RABBITMQ_HOST=rabbitmq \
-e RABBITMQ_USERNAME=provisioner \
-e RABBITMQ_PASSWORD=provisioner \
-e RABBITMQ_VIRTUAL_HOST=czertainly \
-e SECURITY_API_KEY=my-secret-api-key \
-e PROXY_AMQP_URL=amqp://rabbitmq:5672 \
-e TOKEN_SIGNING_KEY=my-signing-key-at-least-32-characters-long \
czertainly/rabbitmq-bootstrap:latest
The service expects an external RabbitMQ instance. Create a .env file with your connection details:
RABBITMQ_HOST=your-rabbitmq-host
RABBITMQ_USERNAME=provisioner
RABBITMQ_PASSWORD=provisioner
RABBITMQ_VIRTUAL_HOST=czertainly
SECURITY_API_KEY=my-secret-api-key
PROXY_AMQP_URL=amqp://your-rabbitmq-host:5672
TOKEN_SIGNING_KEY=my-signing-key-at-least-32-characters-long
Then run with Docker Compose:
docker-compose up -d
Check logs:
docker-compose logs -f rabbitmq-bootstrap
Stop the service:
docker-compose down
Content type
Image
Digest
sha256:bb62c264e…
Size
66.4 MB
Last updated
5 months ago
docker pull czertainly/provisioning-rabbitmq:develop-964c71f62994019674816d390942b2ac78eb0938