feat(synapse): update ingress to use traefik ingress class and bump version feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration fix(taiga): update liveness and readiness probes to use tcpSocket for health checks fix(taiga): change PVC access mode to ReadWriteMany for media and static storage feat(traefik): add icon and ignore rules for traefik service docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments feat(ushahidi): implement dedicated Redis deployment for Ushahidi fix(vllm): update deployment strategy and readiness/liveness probes for improved stability fix(writefreely): pin writefreely image version to v0.15.1 for consistency docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
34 lines
975 B
Markdown
34 lines
975 B
Markdown
# Redis
|
|
|
|
## Authenticated Redis URL
|
|
|
|
Wild Cloud's Redis requires a password. Apps that take a Redis URL must embed the password. Use Kubernetes env var expansion so the password isn't hardcoded:
|
|
|
|
```yaml
|
|
requiredSecrets:
|
|
- redis.password
|
|
|
|
# In deployment env:
|
|
- name: REDIS_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myapp-secrets
|
|
key: redis.password
|
|
- name: REDIS_URL
|
|
value: "redis://:$(REDIS_PASSWORD)@{{ .redis.host }}:6379"
|
|
```
|
|
|
|
`$(REDIS_PASSWORD)` is evaluated by Kubernetes at pod start from other env vars in the same container spec.
|
|
|
|
## Apps that don't support Redis passwords
|
|
|
|
Some apps only accept `REDIS_HOST` and `REDIS_PORT` with no password option (e.g. Ushahidi). Deploy a dedicated unauthenticated Redis sidecar for those apps and remove `redis` from `requires` in `manifest.yaml`:
|
|
|
|
```yaml
|
|
- name: redis
|
|
image: redis:7-alpine
|
|
args: ["--save", ""] # disable persistence
|
|
```
|
|
|
|
Point the app's `REDIS_HOST` at the sidecar's service name.
|