Skip to content

feat: Support Redis mTLS connections - #906

Open
HarleyRossetto wants to merge 3 commits into
launchdarkly:v9from
HarleyRossetto:redis-tls
Open

HarleyRossetto wants to merge 3 commits into
launchdarkly:v9from
HarleyRossetto:redis-tls

Conversation

@HarleyRossetto

@HarleyRossetto HarleyRossetto commented Oct 4, 2026 •

Copy link
Copy Markdown

Requirements

  • I have added test coverage for new or changed functionality
  • I have followed the repository's pull request submission guidelines
  • I have validated my changes against all supported platform versions

Related issues

This has some overlap with #547 (SDK-1527?), in supporting Redis mTLS connection configuration we also expose a custom CA cert support.

Context/Solution

I run a centralised Valkey-based persistent store within my (large) org. We do this to reduce the efforts required by teams wishing to leverage primarily Big Segments. We are shifting to enable mTLS and Common Name to ACL user matching to ensure teams/products can only access keys scoped to their certificates.

As part of this effort I want to shift our relay fleets to also communicate with the persistent store via mTLS, ideally doing away with any username+password auth methods.

This PR is an attempt to kickstart the feature.
Adds Client cert, key, and Root CA support to autoconfigcache, internal/bigsegments, and internal/sdks redis configuration.

Via new configuration variables to the RedisConfig struct:

ClientCertificateFile -> REDIS_CLIENT_CERT_FILE
ClientKeyFile -> REDIS_CLIENT_KEY_FILE
CAFile ->REDIS_CA_FILE

I've attempted to add some tests/integration tests, however I'm unsure the approach you might like to take here, have a look.

I'll get this tracked as a feature request via our Solution Architect (@LD-Sfalzon).


Redis TLS behaviour

• New options  REDIS_CLIENT_CERT_FILE ,  REDIS_CLIENT_KEY_FILE  and  REDIS_CA_FILE  (TOML:  ClientCertificateFile ,  ClientKeyFile ,  CAFile ). They apply to the SDK data store, big segments and the auto-config cache.
• TLS is enabled if  REDIS_TLS  is set or the Redis URL scheme is  rediss:// . This is the new  RedisConfig.TLSEnabled() , shared by all three Redis clients.
• When TLS is enabled, the resulting TLS config is TLS 1.2 or later. It uses  REDIS_CA_FILE  as the root CA if set, and otherwise the system trust store. It presents the client cert and key if both are set.
• go-redis's ParseURL installs a default TLS config for rediss:// URLs, with no custom CA or client cert. Relay now replaces it.
• A redis:// URL without  REDIS_TLS  stays plaintext, and the TLS files are ignored with a warning.
• Config validation errors if only one of cert or key is set. It warns if any cert, key or CA file is set while TLS is not enabled.
• Tests added: config parse and validation,  CreateTLSConfig , real mTLS handshakes for big segments and the auto-config cache, and Docker integration cases with  --tls-auth-clients yes .
• Server-side note: with ACL matching on certificate CN ( tls-auth-clients-user CN ), Redis or Valkey needs a user named after the cert CN, for example  user on nopass ~* +@ALL .


Note

Overview
Adds mutual TLS for Redis by introducing REDIS_CLIENT_CERT_FILE, REDIS_CLIENT_KEY_FILE, and REDIS_CA_FILE, plus RedisConfig.TLSEnabled() so TLS applies when REDIS_TLS is set or the URL uses rediss://.

Shared sdks.CreateTLSConfig loads the client key pair and custom CA and is used for the SDK Redis data store, internal big-segments Redis client, and auto-config cache—replacing ad hoc tls.Config so rediss:// defaults do not hide configured certs. Config validation rejects a client cert without a key and warns when cert/CA paths are set without TLS.

Tests cover TLSEnabled, TLS config building, mTLS handshake behavior for cache and big segments, and Docker integration tests that mount generated certs into a TLS Redis requiring client auth.

Reviewed by Cursor Bugbot for commit 92c5abf. Bugbot is set up for automated code reviews on this repo. Configure here.

@HarleyRossetto
HarleyRossetto requested a review from a team as a code owner October 4, 2026 08:43

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.

Fix All in Cursor

Reviewed by Cursor Bugbot for commit a972548. Configure here.

Comment thread internal/autoconfigcache/redis_store.go Outdated
Comment thread internal/sdks/data_stores.go Outdated
Comment thread internal/sdks/data_stores.go
This commit adds in the ability for relay users to specify client
certificates and keys, as well as the ability to provide a Certificate
Authority file for verify cert trust against.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant