Deploy
Production checklist
Everything that must be true before KubeMQ takes production traffic: cluster shape, license, security, network, backups, monitoring and your applications.
Use this list before KubeMQ takes production traffic. Each item links to the page that shows how. The last group covers your client applications.
Cluster shape
- An odd number of servers, at least three, chosen for the long term (Requirements and supported setups).
- CPU and memory set per server, and servers spread across nodes (Deployment & High Availability).
- A storage class with room for every server's volume (Requirements and supported setups).
License
- A license key or an offline license file, not the evaluation or a trial key (Plans compared).
- The license check shows every server
active(Install on Kubernetes). - License expiry and license state monitored (How licensing works).
- On an air-gapped cluster, a reminder to renew the offline license file (Install air-gapped).
Security
- A management certificate from an authority you trust (Install on Kubernetes).
- The administrator password kept in your secrets manager (Install on Kubernetes).
- Client authentication on, and a test client with no credentials refused (Security (Auth · TLS)).
- Channel permissions set per client (Security (Auth · TLS)).
- TLS on the interfaces your clients use (Security (Auth · TLS)).
- Connectors you use secured: Kafka Authentication and TLS and mTLS; RabbitMQ Authentication and TLS and mTLS.
- Network policies that limit which workloads reach the server ports (Requirements and supported setups).
Network
- Outbound HTTPS to
license.kubemq.io, or an offline license file (Requirements and supported setups). - Your applications reach the interfaces they use (Install on Kubernetes).
- Only the interfaces you use exposed outside the cluster (Interfaces (gRPC · REST · API · HTTP)).
Data
- A backup method chosen and a restore tested (Back up and restore). Back up the Docker volume with the container stopped. For Kubernetes, contact support before relying on a restore.
Operations
- Metrics scraped and alerts set (Prometheus Metrics).
- Logs collected (Structured Logging).
- An upgrade plan written (Upgrade KubeMQ).
- With GitOps, the chart version pinned (Pin a version on Install on Kubernetes).
Your applications
- Clients reconnect with backoff after a server restart and handle each error category (Error Handling Patterns).
- A timeout on every command and query (Configure Timeouts & Retries).
- A dead-letter queue on every critical queue (Dead Letter Queue).
- Visibility timeouts matched to processing time (Configure Visibility Timeout).
- TLS on every client connection (Connect with TLS & mTLS).
- Traces and metrics from every client (OpenTelemetry Integration).
- Channel names and their lifecycle managed (Channel Management).
- Volumes sized for channel growth: retention limits apply only on the legacy storage engine (Storage Engines).
Related
Was this page helpful?
Install air-gapped
Install a KubeMQ cluster on Kubernetes with no internet access: download a verified bundle, mirror the images, apply an offline license file.
Upgrade KubeMQ
Upgrade KubeMQ to the latest release with kmq, Docker, Compose or Helm, check what you run, roll back safely and leave the old combined chart.