Skip to content

redis: support credential files at client startup - #1240

Draft
NVGreg wants to merge 2 commits into
envoyproxy:mainfrom
NVGreg:feat/redis-auth-file
Draft

NVGreg wants to merge 2 commits into
envoyproxy:mainfrom
NVGreg:feat/redis-auth-file

Conversation

@NVGreg

@NVGreg NVGreg commented Sep 13, 2026 •

Copy link
Copy Markdown

Problem and impact

Mounted Redis secrets currently need a shell wrapper to copy credentials into environment variables. This draft lets the Redis client read the credential file at startup, which supports a direct distroless entrypoint without placing the credential value in an environment variable.

Scope

  • Add REDIS_AUTH_FILE and REDIS_PERSECOND_AUTH_FILE for password or username:password authentication to Redis master/replica nodes.
  • Preserve spaces and embedded colons in passwords; remove only trailing CR/LF. Reject unreadable or empty files and conflicts with the corresponding inline setting.
  • Use the existing Redis dialer for single, cluster, sentinel-backed master/replica, and TLS connections. Sentinel-node authentication remains a separate setting.
  • Avoid logging the username or password during client setup.

Verification

  • Local: go test -race ./src/redis ./src/settings ./test/redis and go test ./... passed.
  • Local miniredis tests exercise ACL authentication with password spaces and an embedded colon, a real TLS handshake, and the startup credential snapshot after file rotation.
  • go test -tags=integration -run '^$' ./test/integration compiled the added TLS and cluster cases. The external Redis/stunnel/cluster integration environment was not run locally.

Limits and review state

The file is read when the Redis client is constructed; rotation requires a process restart. This does not add IAM authentication or per-dial refresh. #1224 covers those broader features and can be compared or consolidated with this smaller change.

This remains Draft. The feature diff was also replayed and tested against upstream main 0482748; its stable patch ID is identical. The published fork branch is still based on 8fe6ea4 because the current-main rebase includes workflow changes that the fork's OAuth token cannot publish. No image was built or deployed.

Signed-off-by: Gregory Giecold <ggiecold@nvidia.com>
Signed-off-by: Gregory Giecold <ggiecold@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant