This is the Stable version of the documentation. The latest version is experimental and under active development. You can use the version selector in the top-right menu to switch versions for this specific page, or click here to go to the latest version's homepage.
Redis for Opstella Installation
🟢 Management
Redis is a Pub/Sub Service and In-Memory Cache for Opstella
Prerequisites
Section titled “Prerequisites”- 💿Persistence Storage Access for Redis for Opstella
- On Kubernetes when requesting for a PVC, will request with Storage Class specified.
Preparation
Section titled “Preparation”Kubernetes Cluster Preparation
Section titled “Kubernetes Cluster Preparation”-
Connect to
🟢 ManagementKubernetes Cluster ; i.e w/ Kubeconfig File -
Prepare
🟢 ManagementKubernetes Cluster InformationEnsure
K8S_INTERNAL_DOMAIN,K8S_STORAGECLASS_NAMEare defined as per the Shell Variables guide.
Redis Preparation
Section titled “Redis Preparation”-
Set Redis Authentication Password
Recommended to enabled authentication for Redis (You can optionally disable it)
export OPSTELLA_REDIS_PASSWORD="CHANGEME" -
Create Redis manifest and secret
You will be creating Kubernetes Secret named
opstella-redis-credentials, RedisReplication CR namedredis-opstella, and RedisSentinel CR namedredis-sentinel-opstellaTerminal window cat <<EOF > $BASE_WORKING_DIR/kubernetes-manifests/redis-opstella-platform-full.yamlapiVersion: v1kind: Secretmetadata:name: opstella-redis-credentialsnamespace: opstella-systemtype: OpaquestringData:redis-password: "${OPSTELLA_REDIS_PASSWORD}"---apiVersion: redis.redis.opstreelabs.in/v1beta2kind: RedisReplicationmetadata:name: redis-opstellanamespace: opstella-systemspec:clusterSize: 3# Pod-level security contextpodSecurityContext:fsGroup: 1000fsGroupChangePolicy: "OnRootMismatch"runAsUser: 1000runAsNonRoot: trueseccompProfile:type: RuntimeDefault# Container-level security contextsecurityContext:runAsUser: 1000runAsGroup: 1000runAsNonRoot: trueprivileged: falseallowPrivilegeEscalation: falsecapabilities:drop: ["ALL"]seccompProfile:type: RuntimeDefaultkubernetesConfig:image: quay.io/opstree/redis:v7.4.7imagePullPolicy: IfNotPresentresources:requests:cpu: 100mmemory: 128Milimits:cpu: 250mmemory: 512MiredisSecret:name: opstella-redis-credentialskey: redis-passwordstorage:volumeClaimTemplate:spec:storageClassName: "${K8S_STORAGECLASS_NAME}"accessModes: ["ReadWriteOnce"]resources:requests:storage: 2GiredisExporter:enabled: falseimage: quay.io/opstree/redis-exporter:v1.44.0resources:requests:cpu: 50mmemory: 64Milimits:cpu: 100mmemory: 128Mi---apiVersion: redis.redis.opstreelabs.in/v1beta2kind: RedisSentinelmetadata:name: redis-sentinel-opstellanamespace: opstella-systemspec:clusterSize: 3# Pod-level security contextpodSecurityContext:fsGroup: 1000fsGroupChangePolicy: "OnRootMismatch"runAsUser: 1000runAsNonRoot: trueseccompProfile:type: RuntimeDefault# Container-level security contextsecurityContext:runAsUser: 1000runAsGroup: 1000runAsNonRoot: trueprivileged: falseallowPrivilegeEscalation: falsecapabilities:drop: ["ALL"]seccompProfile:type: RuntimeDefaultredisSentinelConfig:redisReplicationName: redis-opstellaredisReplicationPassword:secretKeyRef:name: opstella-redis-credentialskey: redis-passwordmasterGroupName: redis-opstelladownAfterMilliseconds: "10000"failoverTimeout: "10000"kubernetesConfig:image: quay.io/opstree/redis-sentinel:v8.4.0imagePullPolicy: IfNotPresentresources:requests:cpu: 50mmemory: 64Milimits:cpu: 100mmemory: 128MiEOF
Installation
Section titled “Installation”-
Install Redis
Terminal window kubectl apply -n opstella-system -f $BASE_WORKING_DIR/kubernetes-manifests/redis-opstella-platform-full.yaml
Post-Installation
Section titled “Post-Installation”Redis for Opstella Testing
Section titled “Redis for Opstella Testing”-
Get Pod Status - Redis for Opstella
Terminal window kubectl get pods -n opstella-systemRedis for Opstella should be
RunningNAME READY STATUS RESTARTS AGE... (deducted)redis-opstella-0 1/1 Running 0 XdXhredis-opstella-1 1/1 Running 0 XdXhredis-opstella-2 1/1 Running 0 XdXhredis-sentinel-opstella-sentinel-0 1/1 Running 0 XdXhredis-sentinel-opstella-sentinel-1 1/1 Running 0 XdXhredis-sentinel-opstella-sentinel-2 1/1 Running 0 XdXh💡 The Operator appends
-sentinelto the CR name, so the Sentinel Pods and Services areredis-sentinel-opstella-sentinel-*(verified with Redis Operator0.25.0). -
Verify that replication actually formed
Running Pods are not enough: the Operator reads the roles once, and if it does so before the Pods have an IP it backs off silently, leaving all three replicas as
masterwith no replication at all.Terminal window kubectl exec -n opstella-system redis-opstella-0 -- \redis-cli -a "$OPSTELLA_REDIS_PASSWORD" --no-auth-warning info replication | grep -E 'role|connected_slaves'💡 One Pod must report
role:masterwithconnected_slaves:2, the other tworole:slave.Terminal window kubectl exec -n opstella-system redis-sentinel-opstella-sentinel-0 -- \redis-cli -p 26379 sentinel master redis-opstella | head -n 12💡
flagsmust bemaster,num-slaves2andnum-other-sentinels2.If all three report
role:master, restart the Operator to make it re-read the CR — editing or annotating the CR does not bring it out of backoff:Terminal window kubectl rollout restart deploy/redis-operator -n ot-operators
Finished?
Use the below navigation to proceed