You are looking at the documentation of a prior release. To read the documentation of the latest release, please
visit here.
New to KubeDB? Please start here.
Reconfiguring TLS of Redis Database
This guide will give an overview on how KubeDB Ops-manager operator reconfigures TLS configuration i.e. add TLS, remove TLS, update issuer/cluster issuer or Certificates and rotate the certificates of a Redis database.
Before You Begin
- You should be familiar with the following
KubeDBconcepts:
How Reconfiguring Redis TLS Configuration Process Works
The following diagram shows how KubeDB Ops-manager operator reconfigures TLS of a Redis database. Open the image in a new tab to see the enlarged version.
The Reconfiguring Redis/RedisSentinel TLS process consists of the following steps:
At first, a user creates a
Redis/RedisSentinelCustom Resource (CR).KubeDBCommunity operator watches theRedisandRedisSentinelCR.When the operator finds a
Redis/RedisSentinelCR, it creates required number ofPetSetsand related necessary stuff like appbinding, services, etc.Then, in order to reconfigure the TLS configuration of the
Redisdatabase the user creates aRedisOpsRequestCR with the desired version.Then, in order to reconfigure the TLS configuration (rotate certificate, update certificate) of the
RedisSentineldatabase the user creates aRedisSentinelOpsRequestCR with the desired version.KubeDBEnterprise operator watches theRedisOpsRequestandRedisSentinelOpsRequestCR.When it finds a
RedisOpsRequestCR, it halts theRedisobject which is referred from theRedisOpsRequest. So, theKubeDBCommunity operator doesn’t perform any operations on theRedisobject during the reconfiguring process.When it finds a
RedisSentinelOpsRequestCR, it halts theRedisSentinelobject which is referred from theRedisSentinelOpsRequest. So, theKubeDBCommunity operator doesn’t perform any operations on theRedisSentinelobject during the reconfiguring process.By looking at the target version from
RedisOpsRequest/RedisSentinelOpsRequestCR,KubeDBEnterprise operator will add, remove, update or rotate TLS configuration based on the Ops Request yaml.After successfully reconfiguring
Redis/RedisSentinelobject, theKubeDBEnterprise operator resumes theRedis/RedisSentinelobject so that theKubeDBCommunity operator can resume its usual operations.
In the next doc, we are going to show a step-by-step guide on updating of a Redis database using update operation.






























