Redis (with TLS)
Deploying Redis with TLS encryption using Fly. Read this guide on Fly.Rationale
A key/value database like Redis is useful to have to support caching, session management and, well, anything which needs simple fast storage. That’s why there’s Redis already built into Fly. But there are some things that Redis configuration doesn’t do, like Publish and Subscribe, and that’s when you want to deploy your own Redis on Fly. For this example, we are going to customize a Redis docker image to tune it for running on Fly and deploy it with persistent disk storage for Redis to save its data on.Preparing
There’s a couple of components to this example. We’re going to use the official Redis image,redis:alpine, but we want to change some system settings before Redis starts running. To do that, we’ll use a script, start-redis-server.sh
sysctl calls set up the environment so that Redis doesn’t throw warnings about memory and connections. The script then starts up the Redis server, giving it a password to require and a config file to boot with. The Redis config is simple – it defines IPs to listen on, persistence options:
Dockerfile:
Configuring
First, we need a configuration file - and a slot on Fly - for our new application. We’ll use thefly init command. The parameter is the app name we want - names have to be unique so choose a new unique one or omit the name in the command line and let Fly choose a name for you.
fly.toml takes the internal port and connects it to an HTTP only handler on port 80 and a combined TLS/HTTP handler on port 443. We don’t need that at all, we just need a straight-through connection to the internal port.
Edit your generated fly.toml, removing both [[services.ports]] entries for ports 80 and 443 and replacing them with a single entry:
Keeping a secret
Our script takes a password from an environment variable to secure Redis. We need to set that now using thefly secrets command. This encrypts the value so it can’t leak out; the only time it is decoded is into the Fly application as an environment variable.
Persisting Redis
The last step is to create a disk volume for Redis to save its state on. Then the Redis can be restarted without losing data. For Fly apps, the volume needs to be in the same region as the app. We saw that region when we initialized the app; here it’sord. We’ll give the volume the name redis_server.
Deploy
We’re ready to deploy now. Runfly deploy and the Redis app will be created and launched on the cloud. Once complete you can connect to it using the redis-cli command or any other Redis client. Just remember to use port 10000, not the default port.
Lock it down with TLS
So far, our Redis configuration is good for a demo. But running Redis on an unencrypted public port with password authentication is insecure. Redis has built-in TLS support, we generate certificates and configure the server to require client certificate validation. This is roughly the equivalent security level as running behind a VPN. Generating certs is simple with the excellentmkcert utility. Once you install mkcert, you’ll get a local certificate authority to create your own certificates with.
Here are the commands you’ll need to create certificates for this Redis example:
- Create
certsdirectory for the Docker image:
- Generate server certificates:
- Generate a client certificate:
- Copy the root CA certificate:
redis.conf to configure TLS by adding:
fly.toml:
fly deploy again, and enjoy the relaxation of a locked-down Redis service.
The redis-cli CLI has support for TLS, you can connect with this command:
Discuss
- You can discuss this example on the community.fly.io topic.