Skip to content

test-lib: reach Redis with a standalone client where the server is not clustered - #2207

Merged
yaroslavmokflmg merged 5 commits into
mainfrom
feat/memorystore-test-client
Sep 22, 2026
Merged

yaroslavmokflmg merged 5 commits into
mainfrom
feat/memorystore-test-client

Conversation

@yaroslavmokflmg

@yaroslavmokflmg yaroslavmokflmg commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

The test library reads password-reset tokens straight from Redis with JedisCluster. Dev now runs a
single Memorystore instance, where cluster mode is disabled server-side and topology discovery fails.

getResetToken builds a UnifiedJedis instead — JedisCluster where test.redis.cluster is true,
JedisPooled where it is false. The SCAN + MGET loop is the same either way: on a cluster the hash tag
is load-bearing, since Jedis routes a cluster SCAN by the slot of the MATCH pattern, and on a single
instance it is just part of the key name.

The flag defaults to true, so base, qa, stage and prod keep the cluster client — including
ReportCredentialRotator, which reads this connection on every production tenant-report run. Only
configs/dev/openframe-saas-test.yml turns it off.

Also adds an optional AUTH string and optional TLS against a published CA, both unset for a plain
in-cluster Redis.

Consumed by flamingo-stack/openframe-saas-shared#2136, which bridges test.redis.password and
test.redis.cluster into the library.

@yaroslavmokflmg yaroslavmokflmg self-assigned this Sep 15, 2026
@yaroslavmokflmg
yaroslavmokflmg marked this pull request as draft September 15, 2026 20:51
@yaroslavmokflmg
yaroslavmokflmg force-pushed the feat/memorystore-test-client branch 2 times, most recently from 8e39059 to c534ba5 Compare September 17, 2026 12:08
@yaroslavmokflmg
yaroslavmokflmg marked this pull request as ready for review September 17, 2026 12:08
@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

🦩 Flamingo Code Review

2 finding(s) — 0 action required · 2 recommended · 0 informational

Mode: advisory · Rules cited: OFJAVA-018 · 1 defect(s) outside any rule

Inline comments: 2 new


Need another pass? Commits pushed after this review are not reviewed automatically.

  • Review the new commits — the commits added since this review
  • Review the whole diff again — ignoring what was already reviewed

Prefer typing? Comment @flamingo-review, or @flamingo-review full. To review every push on this pull request, add the flamingo-review-always label.

React 👍/👎 on inline comments to teach the reviewer.

Started 2026-09-17 12:08 UTC · updated 2026-09-17 12:08 UTC · workflow run

@yaroslavmokflmg yaroslavmokflmg changed the title test-lib: reach Redis through a cluster client with optional TLS test-lib: reach Redis with a standalone client where the server is not clustered Sep 21, 2026
Memorystore publishes one discovery endpoint instead of per-pod addresses, so probing seed
nodes one at a time no longer reaches the node that owns the slot. Every pwdreset key carries
the same hash tag, and Jedis routes a cluster SCAN by the slot of the MATCH pattern, so a
cluster client lands on that node directly; the batch is then read with one MGET rather than a
GET per key.

TLS is enabled only when a CA is published - from the service config or REDIS_SERVER_CA - and
the CA is loaded into a trust store of its own, because a managed Redis signs with a private CA
the JVM has never seen. With no CA the client connects in plain text exactly as before, so OSS
installations running an in-cluster Redis are untouched.

Failures still return null, which is the contract callers poll against, but the cause is now
logged with its stack: a TLS or routing mistake used to be indistinguishable from a miss.
Auth and TLS are independent, so build the client config incrementally
instead of branching on the CA alone.
Dev runs IAM auth, where the credential is a short-lived token the client
has to fetch itself. An environment variable cannot carry that, so the
TLS support stays and the token wiring goes.
The cluster hands out an access token that expires within the hour, so the
credentials go in through a Supplier that Jedis calls per connection rather
than a string resolved once. Identity comes from Workload Identity, so a pod
needs no key material.

Opt-in, like TLS: with REDIS_IAM_AUTH unset no credentials are sent and an
in-cluster Redis is reached exactly as before.
@yaroslavmokflmg
yaroslavmokflmg force-pushed the feat/memorystore-test-client branch from fa5bf53 to e01df91 Compare September 22, 2026 17:56
@yaroslavmokflmg
yaroslavmokflmg merged commit bee3b23 into main Sep 22, 2026
15 of 16 checks passed
@yaroslavmokflmg
yaroslavmokflmg deleted the feat/memorystore-test-client branch September 22, 2026 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants