RabbitMQ rollback limits after an upgrade: what can definitions export actually restore?
0 reputation · 02 May 2025, 13:23 UTC
0 reputation · 02 May 2025, 13:23 UTC
We are planning an in-place RabbitMQ upgrade and need a rollback plan before we proceed. From the documentation, a node whose data directory has been migrated by a newer version cannot simply be downgraded, and many feature flags cannot be disabled once enabled. So a binary rollback of the same cluster appears to be off the table.
Our current thinking is to rely on a definitions export (vhosts, users, permissions, exchanges, queues, bindings, policies) taken before the upgrade, and rebuild on a fresh cluster running the old version if the upgrade goes wrong. What is unclear is where the real limits of that approach are.
Specifically, definitions export does not carry message payloads or quorum queue replicated state, so any durable messages sitting in the old cluster at rollback time seem unprotected. Blue/green cutover solves topology but apparently not in-flight data.
Questions:
29275 reputation · 03 May 2025, 00:42 UTC
A definitions export is a snapshot of the broker's configuration (topology), not its state (data). If you rebuild a fresh cluster on the old version and import a definitions file, you restore the structural blueprint—vhosts, users, exchanges, queues, and bindings—but you start with empty queues. There is no supported way to use a definitions export to preserve or migrate message payloads or the replicated state of quorum queues.
The confirmed behavior is that definitions capture only metadata: exchange, queue, and binding declarations, users, permissions, and vhost configuration. What is less certain—and worth testing in your environment—is how far back a given definitions file can be imported without schema conflicts, since that varies by version pair.
| Component | Restorable via Definitions? | Behavior on Fresh Cluster |
|---|---|---|
| Exchanges/Queues/Bindings | Yes | Re-created as declared in the JSON. |
| Users/Permissions/Vhosts | Yes | Re-created; password hashes are preserved. |
| Message Payloads | No | Queues are initialized empty. |
| Quorum Queue Raft State | No | A new consensus group forms; prior replicated data is lost. |
rabbitmqadmin export.400 Bad Request or validation errors indicating incompatible definitions.One detail that would change this recommendation: are you using stream queues or version-specific plugins? Those have their own storage and compatibility rules that can narrow the rollback window further.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.