feat: Support Redis mTLS connections - #906
Open
HarleyRossetto wants to merge 3 commits into
Open
HarleyRossetto wants to merge 3 commits into
HarleyRossetto wants to merge 3 commits into
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.
Reviewed by Cursor Bugbot for commit a972548. Configure here.
This commit adds in the ability for relay users to specify client certificates and keys, as well as the ability to provide a Certificate Authority file for verify cert trust against.
HarleyRossetto
force-pushed
the
redis-tls
branch
from
October 4, 2026 08:48
a972548 to
9b03cd7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Requirements
Related issues
This has some overlap with #547 (SDK-1527?), in supporting Redis mTLS connection configuration we also expose a custom CA cert support.
Context/Solution
I run a centralised Valkey-based persistent store within my (large) org. We do this to reduce the efforts required by teams wishing to leverage primarily Big Segments. We are shifting to enable mTLS and Common Name to ACL user matching to ensure teams/products can only access keys scoped to their certificates.
As part of this effort I want to shift our relay fleets to also communicate with the persistent store via mTLS, ideally doing away with any username+password auth methods.
This PR is an attempt to kickstart the feature.
Adds Client cert, key, and Root CA support to
autoconfigcache,internal/bigsegments, andinternal/sdksredis configuration.Via new configuration variables to the
RedisConfigstruct:ClientCertificateFile ->
REDIS_CLIENT_CERT_FILEClientKeyFile ->
REDIS_CLIENT_KEY_FILECAFile ->
REDIS_CA_FILEI've attempted to add some tests/integration tests, however I'm unsure the approach you might like to take here, have a look.
I'll get this tracked as a feature request via our Solution Architect (@LD-Sfalzon).
Redis TLS behaviour
• New options REDIS_CLIENT_CERT_FILE , REDIS_CLIENT_KEY_FILE and REDIS_CA_FILE (TOML: ClientCertificateFile , ClientKeyFile , CAFile ). They apply to the SDK data store, big segments and the auto-config cache.
• TLS is enabled if REDIS_TLS is set or the Redis URL scheme is rediss:// . This is the new RedisConfig.TLSEnabled() , shared by all three Redis clients.
• When TLS is enabled, the resulting TLS config is TLS 1.2 or later. It uses REDIS_CA_FILE as the root CA if set, and otherwise the system trust store. It presents the client cert and key if both are set.
• go-redis's
ParseURLinstalls a default TLS config forrediss://URLs, with no custom CA or client cert. Relay now replaces it.• A
redis://URL without REDIS_TLS stays plaintext, and the TLS files are ignored with a warning.• Config validation errors if only one of cert or key is set. It warns if any cert, key or CA file is set while TLS is not enabled.
• Tests added: config parse and validation, CreateTLSConfig , real mTLS handshakes for big segments and the auto-config cache, and Docker integration cases with --tls-auth-clients yes .
• Server-side note: with ACL matching on certificate CN ( tls-auth-clients-user CN ), Redis or Valkey needs a user named after the cert CN, for example user on nopass ~* +@ALL .
Note
Overview
Adds mutual TLS for Redis by introducing
REDIS_CLIENT_CERT_FILE,REDIS_CLIENT_KEY_FILE, andREDIS_CA_FILE, plusRedisConfig.TLSEnabled()so TLS applies whenREDIS_TLSis set or the URL usesrediss://.Shared
sdks.CreateTLSConfigloads the client key pair and custom CA and is used for the SDK Redis data store, internal big-segments Redis client, and auto-config cache—replacing ad hoctls.Configsorediss://defaults do not hide configured certs. Config validation rejects a client cert without a key and warns when cert/CA paths are set without TLS.Tests cover
TLSEnabled, TLS config building, mTLS handshake behavior for cache and big segments, and Docker integration tests that mount generated certs into a TLS Redis requiring client auth.Reviewed by Cursor Bugbot for commit 92c5abf. Bugbot is set up for automated code reviews on this repo. Configure here.