This is the Experimental version (Latest). It is under active development and may change. For the most reliable documentation, use the version selector in the top-right to switch to Stable, or click here to go to the Stable version's homepage.
Redis for Opstella Installation
Last updated:
🟢 Management
Redis is a Pub/Sub Service and In-Memory Cache for Opstella
Prerequisites
Section titled “Prerequisites”- 💿Persistence Storage Access for Redis for Opstella
- On Kubernetes when requesting for a PVC, will request with Storage Class specified.
Preparation
Section titled “Preparation”Kubernetes Cluster Preparation
Section titled “Kubernetes Cluster Preparation”-
Connect to
🟢 ManagementKubernetes Cluster ; i.e w/ Kubeconfig File -
Prepare
🟢 ManagementKubernetes Cluster InformationEnsure
K8S_INTERNAL_DOMAIN,K8S_STORAGECLASS_NAMEare defined as per the Shell Variables guide.
Redis Preparation
Section titled “Redis Preparation”-
Set Redis Authentication Password
Recommended to enabled authentication for Redis (You can optionally disable it). (Password loaded from redis.vars.sh)
-
Create Redis manifest and secret
You will be creating Kubernetes Secret named
opstella-redis-credentials, RedisReplication CR namedredis-opstella, and RedisSentinel CR namedredis-sentinel-opstellaTerminal window cat <<EOF > $BASE_WORKING_DIR/kubernetes-manifests/redis-opstella-platform-full.yamlapiVersion: v1kind: Secretmetadata:name: opstella-redis-credentialsnamespace: opstella-systemtype: OpaquestringData:redis-password: "${OPSTELLA_REDIS_PASSWORD}"---apiVersion: redis.redis.opstreelabs.in/v1beta2kind: RedisReplicationmetadata:name: redis-opstellanamespace: opstella-systemspec:clusterSize: 3# Pod-level security contextpodSecurityContext:fsGroup: 1000fsGroupChangePolicy: "OnRootMismatch"runAsUser: 1000runAsNonRoot: trueseccompProfile:type: RuntimeDefault# Container-level security contextsecurityContext:runAsUser: 1000runAsGroup: 1000runAsNonRoot: trueprivileged: falseallowPrivilegeEscalation: falsecapabilities:drop: ["ALL"]seccompProfile:type: RuntimeDefaultkubernetesConfig:image: quay.io/opstree/redis:v7.4.7imagePullPolicy: IfNotPresentresources:requests:cpu: 100mmemory: 128Milimits:cpu: 250mmemory: 512MiredisSecret:name: opstella-redis-credentialskey: redis-passwordstorage:volumeClaimTemplate:spec:storageClassName: "${K8S_STORAGECLASS_NAME}"accessModes: ["ReadWriteOnce"]resources:requests:storage: 2GiredisExporter:enabled: falseimage: quay.io/opstree/redis-exporter:v1.44.0resources:requests:cpu: 50mmemory: 64Milimits:cpu: 100mmemory: 128Mi---apiVersion: redis.redis.opstreelabs.in/v1beta2kind: RedisSentinelmetadata:name: redis-sentinel-opstellanamespace: opstella-systemspec:clusterSize: 3# Pod-level security contextpodSecurityContext:fsGroup: 1000fsGroupChangePolicy: "OnRootMismatch"runAsUser: 1000runAsNonRoot: trueseccompProfile:type: RuntimeDefault# Container-level security contextsecurityContext:runAsUser: 1000runAsGroup: 1000runAsNonRoot: trueprivileged: falseallowPrivilegeEscalation: falsecapabilities:drop: ["ALL"]seccompProfile:type: RuntimeDefaultredisSentinelConfig:redisReplicationName: redis-opstellaredisReplicationPassword:secretKeyRef:name: opstella-redis-credentialskey: redis-passwordmasterGroupName: redis-opstelladownAfterMilliseconds: "10000"failoverTimeout: "10000"kubernetesConfig:image: quay.io/opstree/redis-sentinel:v8.4.0imagePullPolicy: IfNotPresentresources:requests:cpu: 50mmemory: 64Milimits:cpu: 100mmemory: 128MiEOF
Installation
Section titled “Installation”-
Install Redis
Terminal window kubectl apply -n opstella-system -f $BASE_WORKING_DIR/kubernetes-manifests/redis-opstella-platform-full.yaml
Post-Installation
Section titled “Post-Installation”Redis for Opstella Testing
Section titled “Redis for Opstella Testing”-
Get Pod Status - Redis for Opstella
Terminal window kubectl get pods -n opstella-systemRedis for Opstella should be
RunningNAME READY STATUS RESTARTS AGE... (deducted)redis-opstella-0 1/1 Running 0 XdXhredis-opstella-1 1/1 Running 0 XdXhredis-opstella-2 1/1 Running 0 XdXhredis-sentinel-opstella-sentinel-0 1/1 Running 0 XdXhredis-sentinel-opstella-sentinel-1 1/1 Running 0 XdXhredis-sentinel-opstella-sentinel-2 1/1 Running 0 XdXh💡 The Operator appends
-sentinelto the CR name, so the Sentinel Pods and Services areredis-sentinel-opstella-sentinel-*(verified with Redis Operator0.25.0). -
Verify that replication actually formed
Running Pods are not enough: the Operator reads the roles once, and if it does so before the Pods have an IP it backs off silently, leaving all three replicas as
masterwith no replication at all.Terminal window kubectl exec -n opstella-system redis-opstella-0 -- \redis-cli -a "$OPSTELLA_REDIS_PASSWORD" --no-auth-warning info replication | grep -E 'role|connected_slaves'💡 One Pod must report
role:masterwithconnected_slaves:2, the other tworole:slave.Terminal window kubectl exec -n opstella-system redis-sentinel-opstella-sentinel-0 -- \redis-cli -p 26379 sentinel master redis-opstella | head -n 12💡
flagsmust bemaster,num-slaves2andnum-other-sentinels2.If all three report
role:master, restart the Operator to make it re-read the CR — editing or annotating the CR does not bring it out of backoff:Terminal window kubectl rollout restart deploy/redis-operator -n ot-operators
Finished?
Use the below navigation to proceed