Skip to content

Conversation

@arielr-lt
Copy link
Collaborator

@arielr-lt arielr-lt commented Jan 15, 2026

Adds the Redis hardening changes across every environment: each redis-configmap.yaml now includes a secret-sourced requirepass snippet, the StatefulSet mounts a redis-auth Secret to pass --requirepass to redis-server and authenticate its probes, and the environment’s external-secrets-operator.yaml defines the redis-auth ExternalSecret that pulls redis-password from the existing AWS Secrets Manager entry.

Contributes to: #975

@arielr-lt arielr-lt self-assigned this Jan 15, 2026
@arielr-lt arielr-lt requested review from edgarf and rohit-joy January 15, 2026 15:01
@rohit-joy
Copy link
Contributor

rohit-joy commented Jan 15, 2026

@arielr-lt Is this Redis StatefulSet for Registry or for Argo?

@arielr-lt
Copy link
Collaborator Author

@rohit-joy this is for the Registry, Argo does not use Redis

@rohit-joy
Copy link
Contributor

@arielr-lt Can you please separate the PRs? Please don't mix Argo files with Redis changes.

@arielr-lt
Copy link
Collaborator Author

arielr-lt commented Jan 16, 2026

@arielr-lt Can you please separate the PRs? Please don't mix Argo files with Redis changes.

oh gosh! I made by mistake, not meant to do it like that, I will fix it

@arielr-lt
Copy link
Collaborator Author

@rohit-joy can you review/approve this PR?

effect: "NoSchedule"
containers:
- name: redis
image: redis:7.2-alpine # Official Redis image
Copy link
Contributor

@rohit-joy rohit-joy Jan 21, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should be on 8.x, the latest image. See docker-compose for reference.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can get staging to redis 8.x for initial test and then deploy to sandbox and prod, how does it look like @rohit-joy @edgarf ?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@arielr-lt that is great, please deply first to sandbox.

Copy link
Contributor

@rohit-joy rohit-joy Jan 23, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, deploy to staging, sandbox, then prod. Just to ease everybody's mind about this, we already use 8.x on our end, so we know it works. So this testing should just be a Smoke test. We should try to quickly roll out all the way to prod.

@arielr-lt
Copy link
Collaborator Author

@rohit-joy @mparsons-ce @jeannekitchens @excelsior @edgarf Redis has just been updated to redis:8.0-alpine, in Sandbox, please let me know if that works fine so I can proceed with other EKS environments

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

4 participants