Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions TERMINOLOGY_CANDIDATES.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,17 @@ Repository paths are relative to the sibling checkouts
| **seed** / **seed list** | `ActiveRedisMeshSpec.Seeds` | |
| **pre-flight inspection** | `activeredisinspection_types.go`; `activeredisconnection_webhook.go` | Named after the Web Console `Inspect` action. |

## Sentinel password (added 2026-09-09)

Terms introduced by the documentation of the Web Console's **Set Sentinel
Password** tab (release notes v5.1.0, `functions/10-create-instance.mdx`,
`how_to/access/10-sentinel.mdx`).

| Term as used in docs | Provenance | Note for the reviewer |
|:---|:---|:---|
| **Sentinel password** | `redis-operator/api/databases/v1/redissentinel_types.go:44` — `RedisSentinelSpec.PasswordSecret`, surfaced as `spec.sentinel.passwordSecret`; consumed at `internal/controller/middleware/redis_controller.go:1052` and validated at `internal/webhook/middleware/v1/redis_webhook.go:568` | Used in prose for the credential that authenticates the **Sentinel nodes**, as distinct from the **Redis password** (`spec.passwordSecret`) for the data nodes. The docs previously had no name for it at all. Confirm the pair "Redis password" / "Sentinel password" is the intended customer-facing wording — the Web Console tab labels use exactly this split. |
| **Set Sentinel Password** (Web Console label) | `redis-frontend/src/assets/i18n/en.json:270` — `"set_sentinel_password": "Set Sentinel Password"`; tab defined in `src/app/components/form/template.html:607` | Quoted verbatim as a UI label, so no translation decision is needed. Its sibling label is `set_redis_password` → **Set Redis Password**. |

## Command support and clock synchronization (added 2026-08-11)

Terms introduced by `docs/en/functions/95-disaster-recovery/60-commands.mdx`
Expand Down
29 changes: 27 additions & 2 deletions docs/en/functions/10-create-instance.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,26 @@ Following Redis versions are fully supported: `6.0` and `7.2`; other versions ar

Refer to the [Redis API documentation](../apis/kubernetes_apis/redis/redis.mdx) for field descriptions.

<Directive type="note" title="Sentinel password">
A Sentinel instance has two independent `default` user passwords: `spec.passwordSecret` authenticates the Redis data nodes, and `spec.sentinel.passwordSecret` authenticates the Sentinel nodes. The example above sets neither, which leaves both open. The Web Console enables the Sentinel password by default; when creating an instance from the CLI, set it explicitly.

Each field references a `Secret` in the same namespace that holds the password under the `password` key, and the password must be 8 to 32 characters long.

```bash
$ kubectl -n default create secret generic s6-sentinel-password --from-literal=password='<sentinel-password>'
```

Then reference it from the instance:

```yaml
spec:
sentinel:
passwordSecret: s6-sentinel-password
```

Clients connecting through Sentinel must supply this password separately from the Redis password — refer to [Accessing Instances (Sentinel Mode)](../how_to/access/10-sentinel.mdx).
</Directive>

</Tab>

<Tab label="Cluster CLI">
Expand Down Expand Up @@ -196,9 +216,14 @@ Following Redis versions are fully supported: `6.0` and `7.2`; other versions ar
</tr>

<tr>
<td rowspan="3"><b>Connection Configuration</b></td>
<td rowspan="4"><b>Connection Configuration</b></td>
<td><b>Set Default Password</b></td>
<td>It is recommended to set a password for redis `default` user when startup instance. If no password is set, refer to <a href="../functions/20-user">User Management</a> to reset the password or create extra accounts.</td>
<td>It is recommended to set a password for redis `default` user when startup instance. If no password is set, refer to <a href="../functions/20-user">User Management</a> to reset the password or create extra accounts. <br />For <b>Sentinel architecture</b>, this field lives on the <b>Set Redis Password</b> tab and applies to the Redis data nodes only.</td>
</tr>

<tr>
<td><b>Set Sentinel Password</b></td>
<td>Shown for <b>Sentinel architecture</b> only, on a second tab next to <b>Set Redis Password</b>. The Sentinel nodes have a `default` user of their own, whose password is independent of the Redis data node password, so switch to the <b>Set Sentinel Password</b> tab and set it. <b>Set Password</b> is enabled there by default and both password fields are required while it stays enabled; if you click <b>Create</b> while they are empty, the tab label shows a warning icon and creation is blocked. <br />Clients connecting through Sentinel must supply this password separately from the Redis password — refer to <a href="../how_to/access/10-sentinel">Accessing Instances (Sentinel Mode)</a>.</td>
</tr>

<tr>
Expand Down
32 changes: 29 additions & 3 deletions docs/en/how_to/access/10-sentinel.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,15 @@ Redis Sentinel instances implement the following authentication options:
- **Password Authentication**: When configured with a password, all client connections must provide valid credentials
- **Password-less Access**: If the **Set Password** option is disabled during instance creation, clients can connect without authentication

A Sentinel instance carries **two independent passwords**, set on two separate tabs during instance creation:

| Password | Set on | Authenticates | Client configuration |
| :--- | :--- | :--- | :--- |
| **Redis password** | **Set Redis Password** tab (`spec.passwordSecret`) | The Redis data nodes that serve your commands | The client's ordinary password option |
| **Sentinel password** | **Set Sentinel Password** tab (`spec.sentinel.passwordSecret`) | The Sentinel nodes the client queries for master discovery and failover | A dedicated Sentinel password option, listed per client below |

Since v5.1.0, the **Set Sentinel Password** tab has **Set Password** enabled by default, so instances created from the Web Console normally have a Sentinel password. A client that sends only the Redis password will fail to reach the Sentinel nodes and cannot discover the master. Instances created before v5.1.0 are unchanged and keep whatever Sentinel authentication they were given.

<Directive type="warning" title="Security Best Practice">
For production environments, implementing password authentication is strongly recommended to protect your data. Refer to [User Management](../../functions/20-user) for detailed instructions on configuring and maintaining secure credentials.
</Directive>
Expand Down Expand Up @@ -79,7 +88,10 @@ The following examples demonstrate best practices for connecting to Redis Sentin
client := redis.NewFailoverClient(&redis.FailoverOptions{
SentinelAddrs: []string{"<address>"},
MasterName: "mymaster",
Password: "<password>",
// Password of the Redis data nodes.
Password: "<password>",
// Password of the Sentinel nodes, set on the "Set Sentinel Password" tab.
SentinelPassword: "<sentinel-password>",
OnConnect: func(ctx context.Context, conn *redis.Conn) error {
ctx, cancel := context.WithTimeout(ctx, 500*time.Millisecond)
defer cancel()
Expand Down Expand Up @@ -171,12 +183,17 @@ The following examples demonstrate best practices for connecting to Redis Sentin
.connectionTimeoutMillis(2000)
// Command timeout
.timeoutMillis(10000)
// Password of the Redis data nodes.
.password("<password>")
.build();

// A separate client config is used for the Sentinel nodes, so that they
// can be given their own password.
DefaultJedisClientConfig sentinelConfig = DefaultJedisClientConfig.builder()
.connectionTimeoutMillis(2000)
.timeoutMillis(10000)
// Password of the Sentinel nodes, set on the "Set Sentinel Password" tab.
.password("<sentinel-password>")
.build();

Set<HostAndPort> nodes = new HashSet<>();
Expand Down Expand Up @@ -217,8 +234,12 @@ The following examples demonstrate best practices for connecting to Redis Sentin
public class Main {
public static void main(String[] args) {
RedisURI.Builder redisUriBuilder = RedisURI.builder();
redisUriBuilder.withSentinel(RedisURI.create("<ip1>", <port1>));
redisUriBuilder.withSentinel(RedisURI.create("<ip2>", <port2>));
// The third argument is the password of the Sentinel nodes, set on the
// "Set Sentinel Password" tab. In Lettuce the password carried by the URI
// itself applies to the data nodes only, so each Sentinel is given its own.
redisUriBuilder.withSentinel("<ip1>", <port1>, "<sentinel-password>");
redisUriBuilder.withSentinel("<ip2>", <port2>, "<sentinel-password>");
// Password of the Redis data nodes.
redisUriBuilder.withPassword("<password>");

// Client name for debugging and tracking connection source.
Expand Down Expand Up @@ -311,7 +332,12 @@ The following examples demonstrate best practices for connecting to Redis Sentin
config.setNettyThreads(64)
.useSentinelServers()
.addSentinelAddress(nodes.toArray(new String[0]))
// Password of the Redis data nodes.
.setPassword("<password>")
// Password of the Sentinel nodes, set on the "Set Sentinel Password" tab.
// If unset, Redisson reuses the Redis password for the Sentinel nodes;
// set it whenever the two differ.
.setSentinelPassword("<sentinel-password>")
.setMasterName("mymaster")
// Enable discovery for sentinel nodes.
.setSentinelsDiscovery(true)
Expand Down
8 changes: 8 additions & 0 deletions docs/en/release_notes.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,14 @@ Existing backups on `ReadWriteMany` volumes stay restorable and take the same ne

Selecting a node-local `StorageClass` in the Web Console additionally requires Alauda Container Platform Data Services Essentials `v4.4.1` or later. See [Backup & Restore Instance](./functions/70-backup-restore.mdx).

#### Sentinel Password Enabled by Default in the Web Console

When a Sentinel instance is created — or restored from a backup — in the Web Console, the **Connection Configuration** section now offers two tabs: **Set Redis Password** and **Set Sentinel Password**. On the **Set Sentinel Password** tab, **Set Password** is enabled by default and the password fields are required while it stays enabled, so a new Sentinel instance receives a Sentinel credential of its own unless the toggle is deliberately turned off. If you click **Create** while those fields are empty, the tab label shows a warning icon and creation is blocked.

The Sentinel credential is separate from the Redis credential: it is stored in `spec.sentinel.passwordSecret` and authenticates the Sentinel nodes, while `spec.passwordSecret` authenticates the Redis data nodes. Clients must therefore supply the two passwords separately — see [Accessing Instances (Sentinel Mode)](./how_to/access/10-sentinel.mdx).

Existing instances are not affected. The tabs are only rendered while an instance is being created or restored; updating an instance leaves its Sentinel authentication unchanged.

#### New APIs

The `ActiveRedis`, `ActiveRedisMesh`, and `ActiveRedisInspection` resources are documented under [Redis APIs](./apis/kubernetes_apis/redis/index.mdx).
Expand Down