test-lib: reach Redis with a standalone client where the server is not clustered - #2207
Merged
Merged
Conversation
yaroslavmokflmg
marked this pull request as draft
September 15, 2026 20:51
yaroslavmokflmg
force-pushed
the
feat/memorystore-test-client
branch
2 times, most recently
from
September 17, 2026 12:08
8e39059 to
c534ba5
Compare
yaroslavmokflmg
marked this pull request as ready for review
September 17, 2026 12:08
Contributor
🦩 Flamingo Code Review2 finding(s) — 0 action required · 2 recommended · 0 informational Mode: advisory · Rules cited: Inline comments: 2 new Need another pass? Commits pushed after this review are not reviewed automatically.
Prefer typing? Comment React 👍/👎 on inline comments to teach the reviewer. Started 2026-09-17 12:08 UTC · updated 2026-09-17 12:08 UTC · workflow run |
giokur
approved these changes
Sep 22, 2026
Memorystore publishes one discovery endpoint instead of per-pod addresses, so probing seed nodes one at a time no longer reaches the node that owns the slot. Every pwdreset key carries the same hash tag, and Jedis routes a cluster SCAN by the slot of the MATCH pattern, so a cluster client lands on that node directly; the batch is then read with one MGET rather than a GET per key. TLS is enabled only when a CA is published - from the service config or REDIS_SERVER_CA - and the CA is loaded into a trust store of its own, because a managed Redis signs with a private CA the JVM has never seen. With no CA the client connects in plain text exactly as before, so OSS installations running an in-cluster Redis are untouched. Failures still return null, which is the contract callers poll against, but the cause is now logged with its stack: a TLS or routing mistake used to be indistinguishable from a miss.
Auth and TLS are independent, so build the client config incrementally instead of branching on the CA alone.
Dev runs IAM auth, where the credential is a short-lived token the client has to fetch itself. An environment variable cannot carry that, so the TLS support stays and the token wiring goes.
The cluster hands out an access token that expires within the hour, so the credentials go in through a Supplier that Jedis calls per connection rather than a string resolved once. Identity comes from Workload Identity, so a pod needs no key material. Opt-in, like TLS: with REDIS_IAM_AUTH unset no credentials are sent and an in-cluster Redis is reached exactly as before.
yaroslavmokflmg
force-pushed
the
feat/memorystore-test-client
branch
from
September 22, 2026 17:56
fa5bf53 to
e01df91
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The test library reads password-reset tokens straight from Redis with
JedisCluster. Dev now runs asingle Memorystore instance, where cluster mode is disabled server-side and topology discovery fails.
getResetTokenbuilds aUnifiedJedisinstead —JedisClusterwheretest.redis.clusteris true,JedisPooledwhere it is false. The SCAN + MGET loop is the same either way: on a cluster the hash tagis load-bearing, since Jedis routes a cluster SCAN by the slot of the MATCH pattern, and on a single
instance it is just part of the key name.
The flag defaults to true, so base, qa, stage and prod keep the cluster client — including
ReportCredentialRotator, which reads this connection on every production tenant-report run. Onlyconfigs/dev/openframe-saas-test.ymlturns it off.Also adds an optional AUTH string and optional TLS against a published CA, both unset for a plain
in-cluster Redis.
Consumed by flamingo-stack/openframe-saas-shared#2136, which bridges
test.redis.passwordandtest.redis.clusterinto the library.