← Back to plugin index

Single Mode Redis State Repository

Description

State repository that stores all values in a single Redis instance.

Type name
SingleModeRedisStateRepository
Class
com.airlock.iam.common.application.configuration.state.SingleModeRedisStateRepositoryConfig
May be used by
Properties
Redis URI (redisUri)
Description
The URI to connect to Redis.
  • For TLS, use rediss://host:port (double 's' in 'rediss:', recommended)
  • For an unencrypted connection, use redis://host:port (not recommended for production setups)
Attributes
String
Mandatory
Example
rediss://redis:6379
Example
redis://localhost:6379
Username (username)
Description
The username to login on Redis.
Attributes
String
Optional
Password (password)
Description
The password to login on Redis.
Attributes
String
Optional
Sensitive
Minimum Idle Connections (minimumIdleConnections)
Description
The minimum amount of idle Redis connections.
Attributes
Integer
Optional
Default value
24
Maximum Pool Size (maximumPoolSize)
Description
The maximum Redis connection pool size.
Attributes
Integer
Optional
Default value
64
Idle Timeout [ms] (idleTimeoutInMs)
Description
The maximum time in milliseconds a connection is allowed to be idle before it is closed and removed from the pool. The connection is closed and removed from the pool only if the current number of connections exceeds the minimum idle connections pool size.
Attributes
Integer
Optional
Default value
10000
Connection Timeout [ms] (connectionTimeoutInMs)
Description
The maximum time in milliseconds to wait to acquire a live connection to the Redis server.
Attributes
Integer
Optional
Default value
10000
Response Timeout [ms] (responseTimeoutInMs)
Description
The Redis server response timeout. The timer starts as soon as the Redis command is sent successfully.
Attributes
Integer
Optional
Default value
10000
Ping Connection Interval [ms] (pingConnectionIntervalInMs)
Description
The time interval with which "PING" commands (https://redis.io/commands/ping/) are sent to Redis for each connection. To disable the pinging set the value to 0.
Attributes
Integer
Optional
Default value
30000
Trust Store Path (trustStorePath)
Description
Keystore file name containing trusted certificate issuers and trusted certificates.
Attributes
File/Path
Optional
Trust Store Password (trustStorePassword)
Description
The password used to check the integrity of the trust store, or to unlock the trust store.

The password must be provided if a trust store is configured.

Attributes
String
Optional
Sensitive
Verify Server Hostname (verifyServerHostname)
Description

Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.

Attributes
Boolean
Optional
Default value
true
Key Store Path (keyStorePath)
Description
The keystore containing a client certificate (including a private key) for Airlock IAM. The client certificate is used to establish a mutual SSL connection with Redis.
Attributes
File/Path
Optional
Key Store Password (keyStorePassword)
Description
The password used to check the integrity of the keystore, or to unlock the keystore.

The password must be provided if a keystore is configured.

Attributes
String
Optional
Sensitive
Encryption (encryption)
Description

Encryption settings defining whether and how state information in Redis is encrypted. IAM state contains sensitive information. State encryption prevents other systems from reading and modifying IAM state information.

To enable state encryption with non-encrypted state already present, use the "Migrating State Encryption" plugin.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Namespace (namespace)
Description

A string that will be used as a namespace for the keys in Redis.

This is useful if, for example, multiple IAM instances share the same Redis instance and one must ensure that their Redis keys don't interfere with each other

When changing this setting after state has already been stored in Redis, that state will be lost and the corresponding sessions will be terminated.

Attributes
String
Optional
Validation RegEx: ^[A-Za-z0-9]+$
Default value
default
YAML Template (with default values)

type: SingleModeRedisStateRepository
id: SingleModeRedisStateRepository-xxxxxx
displayName: 
comment: 
properties:
  connectionTimeoutInMs: 10000
  encryption:
  idleTimeoutInMs: 10000
  keyStorePassword:
  keyStorePath:
  maximumPoolSize: 64
  minimumIdleConnections: 24
  namespace: default
  password:
  pingConnectionIntervalInMs: 30000
  redisUri:
  responseTimeoutInMs: 10000
  trustStorePassword:
  trustStorePath:
  username:
  verifyServerHostname: true