Repository navigation
Redis over TLS: rediss:// and rediss-cluster:// URLs, and a private CA - #82
Merged
Merged
Conversation
fred was built without a TLS feature, so a rediss:// URL was dialled as plain TCP. Against a Redis that only speaks TLS - what ElastiCache with in-transit encryption, Upstash, Azure Cache and Redis Cloud require - the server exited at startup with "Failed to connect to Redis: Protocol Error: Expected string." Turning on fred's enable-rustls alone is not enough: fred then builds its connector with rustls's process-default crypto provider, and this binary compiles in two (aws-lc-rs through reqwest 0.13, ring through the reqwest 0.12 under openidconnect), so rustls panics instead of choosing. think_watch_common::redis_config builds the connector itself, with aws-lc-rs and rustls-platform-verifier - the stack reqwest already uses for upstream HTTPS - and every Redis client the server makes (the command client and the three Pub/Sub subscribers) takes its config from there. No new crates and no OpenSSL: the static musl image is unchanged, and the system roots it already ships for upstream HTTPS cover the managed services' public CAs. REDIS_CA_CERT names a PEM file for a Redis whose certificate a private CA signed; its certificates are then the only roots trusted, as with redis-cli --cacert. The Helm chart mounts it from a Secret (redis.caSecret). Client certificates are not supported. tests/redis_tls.rs runs the limit scripts, the gateway (limits, readiness, config notices) and a refused untrusted certificate against TEST_REDIS_TLS_URL, and skips without it. TEST_REDIS_CA_CERT lets the whole suite and the cluster tests run against TLS too. The config notice round-trip now resends the notice until it arrives: fred's subscribe can return before Redis holds the subscription, and a PUBLISH right after it was seen to reach no one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
rediss://URLs did not work: fred was built without TLS, treatedrediss://as plain TCP, and the server exited at startup (Failed to connect to Redis: Protocol Error: Expected string.). Managed Redis services usually require TLS (ElastiCache with in-transit encryption, Upstash, Azure Cache, Redis Cloud), so such deployments could not start.common::redis_config, which sets up rustls (aws-lc-rs, system CA store viarustls-platform-verifier, the same stack reqwest uses). Enabling fred's ownenable-rustlspanicked in the full build, because two rustls crypto backends are compiled in. No new crates in Cargo.lock, no OpenSSL; the Docker image needs no change.rediss://andrediss-cluster://work.REDIS_CA_CERT(a PEM path) trusts a private CA instead of the system store; Helm mounts it fromredis.caSecret. No client certificates..env.exampleand CHANGELOG [Unreleased] → Fixed.tests/redis_tls.rsruns withTEST_REDIS_TLS_URLand skips without it; the whole integration suite also passed over TLS. A flaky cluster config-notice test now re-sends until the subscriber receives it.Local: fmt, clippy (lib/bins and tests), 740 unit tests, 404 integration tests on plain Redis and again over TLS.
🤖 Generated with Claude Code