Skip to content

Ansible Role linuxfabrik.lfops.redis

This role installs and configures Redis, per default listening on TCP port 6379 on the loopback interfaces. Note that this role configures Systemd with unit file overrides for Redis.

This role is compatible with Redis v6+.

RHEL 10 does not ship Redis, so this role does not support it. Use the linuxfabrik.lfops.valkey role there.

You can pre-enable Remi's repo with the linuxfabrik.lfops.repo_remi role to get an up-to-date Redis version. If you use the Redis Playbook, this is automatically done for you.

This role is compatible with the following Redis versions:

  • 7.0
  • 7.2
  • 7.4 (note: not available in the Remi Repo as of 2025-03-05)
  • 8.0
  • 8.2
  • 8.8

Available since LFOps 2.0.0.

How the Role Behaves

  • The daemonize and supervised settings of redis.conf are not exposed as role variables, because no value an administrator could pick would change the running service. A Redis that is supervised by systemd never daemonizes, whatever daemonize says, and every packaged unit either passes --supervised systemd on its ExecStart line or, in the case of the packages.redis.io unit used on Debian and Ubuntu, relies on the supervised auto this role deploys. The only other value that unit would accept is systemd, which is what auto resolves to there anyway; no stops Redis from reporting readiness and leaves the unit failed. The role therefore deploys daemonize no and supervised auto on every platform.

Tags

redis

  • Installs and configures Redis.
  • Triggers: redis.service restart.

redis:state

  • Manages the state of the Redis service.
  • Triggers: none.

Optional Role Variables

redis__service_enabled

  • Enables or disables the redis service, analogous to systemctl enable/disable.
  • Type: Bool.
  • Default: true

redis__service_limit_nofile

  • Systemd: Resource limit directive for the number of file descriptors.
  • Type: Number.
  • Default: 10240

redis__service_state

  • Changes the state of the redis service, analogous to systemctl start/stop/restart/reload.
  • Type: String. One of reloaded, restarted, started, stopped.
  • Default: 'started' if redis__service_enabled is true, else 'stopped'

redis__service_timeout_start_sec

  • Systemd: Configures the time to wait for start-up. If Redis does not signal start-up completion within the configured time, the service will be considered failed and will be shut down again.
  • Type: String.
  • Default: '90s'

redis__service_timeout_stop_sec

  • Systemd: First, it configures the time to wait for the ExecStop= command. Second, it configures the time to wait for the Redis itself to stop. If Redis doesn't terminate in the specified time, it will be forcibly terminated by SIGKILL.
  • Type: String.
  • Default: '90s'

Example:

# optional
redis__service_enabled: true
redis__service_limit_nofile: 10240
redis__service_state: 'started'
redis__service_timeout_start_sec: 5
redis__service_timeout_stop_sec: 5

Optional Role Variables - redis__conf_* Config Directives

Variables for redis.conf directives and their default values, defined and supported by this role.

redis__conf_appendonly

redis__conf_auto_aof_rewrite_min_size

redis__conf_bind

  • redis.conf
  • Type: String.
  • Default: '127.0.0.1 -::1'
  • A - in front of an address makes it optional: Redis logs a warning and keeps running where that address does not exist, rather than aborting with Failed listening on port 6379 (tcp), aborting.. Without the prefix, ::1 takes down the service on a host with no IPv6 loopback, such as a RHEL minimal installation.

redis__conf_databases

redis__conf_loglevel

redis__conf_maxmemory

redis__conf_maxmemory_policy

redis__conf_port

  • If port 0 is specified Redis will not listen on a TCP socket. redis.conf
  • Type: Number.
  • Default: 6379

redis__conf_protected_mode

redis__conf_replica_serve_stale_data

redis__conf_requirepass

redis__conf_save

  • redis.conf
  • Type: List.
  • Default: ['3600 1', '300 100', '60 10000']

redis__conf_tls_auth_clients

redis__conf_tls_ca_cert_file

redis__conf_tls_cert_file

redis__conf_tls_key_file

redis__conf_tls_port

  • TLS Port. Set redis__conf_port: 0 to only listen with TLS. redis.conf
  • Type: Number.
  • Default: unset

Example:

redis__conf_appendonly: 'yes'
redis__conf_auto_aof_rewrite_min_size: '64mb'
redis__conf_bind: '127.0.0.1'
redis__conf_databases: 16
redis__conf_loglevel: 'notice'
redis__conf_maxmemory: '50M'
redis__conf_maxmemory_policy: 'noeviction'
redis__conf_port: 6379  # If port 0 is specified Redis will not listen on a TCP socket.
redis__conf_protected_mode: 'yes'
redis__conf_replica_serve_stale_data: 'yes'
redis__conf_requirepass: 'password'
redis__conf_save:
  - '3600 1'
  - '300 100'
  - '60 10000'
redis__conf_tls_auth_clients: 'no'
redis__conf_tls_ca_cert_file: '/etc/redis/ca.pem'
redis__conf_tls_cert_file: '/etc/redis/redis.pem'
redis__conf_tls_key_file: '/etc/redis/redis.key'
redis__conf_tls_port: 6379

Troubleshooting

WARNING supervised by systemd - you MUST set appropriate values for TimeoutStartSec and TimeoutStopSec in your service unit in /var/log/redis/redis.log

The run aborts with Redis X.Y is not supported by this role

  • The enabled repositories offer a Redis version this role has no configuration template for. Either pin the host to a supported version, or add the matching roles/redis/templates/etc/redis/<version>-redis.conf.j2 template and list the version in roles/redis/vars/main.yml.

License

The Unlicense

Author Information

Linuxfabrik GmbH, Zurich