RabbitMQ自定义用户角色求助:创建仅可新增用户不可删除的角色失败
Hey there! Let's work through this RabbitMQ permission problem together. I’ve dealt with exactly this scenario before, so I know where to focus. The key mistake many people make is trying to use regular Policies (which control queue/exchange behavior) for user management permissions—instead, we need to leverage RabbitMQ's management plugin permissions and user tags.
Here's a step-by-step solution:
Step 1: Create Your Target User
First, let's create the user that will have create-only access. Replace user_creator and secure_password_123 with your preferred credentials:
rabbitmqctl add_user user_creator secure_password_123
Step 2: Add the Required User Tag
This user needs the management tag to access RabbitMQ's management API (the only way to create other users via UI or API):
rabbitmqctl set_user_tags user_creator management
Important: If you previously added higher-privilege tags like
administrator, remove them first—those override granular permissions. Use the same command above, only includemanagementto reset tags.
Step 3: Configure Granular Management Permissions
This is the critical part. We'll explicitly grant permission to create users while blocking the delete operation. Use the set_management_permissions command:
rabbitmqctl set_management_permissions user_creator "" "user" "create"
Let's break down the parameters:
- First empty string: Applies to all virtual hosts (user management is a global operation)
"user": Targets theuserresource type"create": Only allows thecreateoperation (excludesdelete,update, etc.)
Step 4: Verify the Permissions
Test to make sure everything works as expected:
- Log into the RabbitMQ management UI using
user_creator's credentials - Try creating a new user: This should succeed without issues
- Try deleting any user: You should get a 403 Forbidden error (permission denied)
If You're Using an Older RabbitMQ Version
If set_management_permissions isn't available (older versions pre-3.8), use the management UI instead:
- Log in with an admin account
- Go to Admin > Users and select your
user_creator - Scroll to Management Permissions
- Set:
- Configure regex:
"" - Write regex:
"user" - Read regex:
"create"
- Configure regex:
- Save changes and test again.
Remember: Regular RabbitMQ Policies are for queue/exchange settings (like mirroring or TTL)—they don't control user management permissions. That's why your earlier attempts with Policies weren't working!
内容的提问来源于stack exchange,提问作者frodo

