Files
redis-cluster/argocd/README.md
Corrado Mulas a407903a8d First Commit
2026-07-23 12:09:41 +02:00

2.3 KiB

Argo CD examples

This directory is excluded from the packaged Helm chart. Its files are examples for managing the chart from Argo CD.

Application

application.yaml deploys:

  • three Redis shards;
  • one replica per shard;
  • authenticated Redis with a chart-generated initial password;
  • persistent volumes using the cluster's default StorageClass;
  • internal-only Redis Services;
  • RedisInsight connected automatically to the balanced bootstrap endpoint.

Apply it once:

kubectl apply -f argocd/application.yaml

Edit the destination namespace, target revision, and inline valuesObject as needed. Because this file is not a Helm template, changing it in the Redis Application's own repository does not change the live Application spec during a normal sync. Reapply it, or manage it from an app-of-apps/ApplicationSet.

Password Secret

For production GitOps, use an externally managed Secret and set:

auth:
  enabled: true
  existingSecret: redis-auth
  existingSecretKey: redis-password

redis-auth-secret.example.yaml documents the required Secret shape. Do not commit an actual cleartext password.

If the chart generates the password, retain RespectIgnoreDifferences=true and the Secret ignore rule from application.yaml; Argo's Helm renderer cannot use lookup to read the live Secret while comparing desired state.

Enabling external access

Add this to valuesObject:

externalAccess:
  enabled: true
  loadBalancerClass: ""
  loadBalancerSourceRanges:
    - 203.0.113.0/24

This creates one balanced bootstrap LoadBalancer and one LoadBalancer per Redis member. Every advertised member address must be routable from external clients.

Exposing RedisInsight with Istio

Add:

redisInsight:
  enabled: true
  ingress:
    enabled: true
    host: redisinsight.example.com
    tls:
      enabled: true
      credentialName: redisinsight-tls
      certificate:
        create: true
        issuerName: letsencrypt-production
        issuerKind: ClusterIssuer
        secretNamespace: istio-system

Replace the hostname, issuer, gateway selector, and Secret namespace with values from your environment. RedisInsight has no built-in ingress authentication; add an identity-aware proxy or Istio authorization policy before exposing it.