Dragonfly Instance Authentication
This guide provides step-by-step instructions for setting up Dragonfly with authentication. It covers two authentication configurations managed through Kubernetes secrets:
- Password-based authentication through a secret
- TLS-based authentication through a secret
Prerequisites
- A Kubernetes cluster with Dragonfly installed
Password-based authentication
Password-based authentication is the simplest way to secure your Dragonfly instance. In this method, you can set a password for your Dragonfly instance through a secret. The password is then used to authenticate the clients.
Create a secret
kubectl create secret generic dragonfly-auth --from-literal=password=dragonfly
Deploy Dragonfly with authentication
kubectl apply -f - <<EOF
apiVersion: dragonflydb.io/v1alpha1
kind: Dragonfly
metadata:
name: dragonfly-auth
spec:
authentication:
passwordFromSecret:
name: dragonfly-auth
key: password
replicas: 2
EOF
Check the status of the Dragonfly instance
kubectl describe dragonflies.dragonflydb.io dragonfly-auth
Connecting to Dragonfly
kubectl run -it --rm --restart=Never redis-cli --image=redis:7.0.10 -- redis-cli -h dragonfly-auth.default
if you don't see a command prompt, try pressing enter.
dragonfly-auth.default:6379> GET 1
(error) NOAUTH Authentication required.
dragonfly-auth.default:6379> AUTH dragonfly
OK
dragonfly-auth.default:6379> GET 1
(nil)
dragonfly-auth.default:6379> SET 1 2
OK
dragonfly-auth.default:6379> GET 1
"2"
dragonfly-auth.default:6379> exit
TLS-based authentication
TLS-based authentication is a more secure way to secure your Dragonfly instance. First, you need TLS configured on your Dragonfly instance. Then, you can specify a list of CA certificates that are trusted by the Dragonfly instance. The clients must present a certificate signed by one of the trusted CAs to connect to the Dragonfly instance.
Create a TLS secret for Dragonfly through cert-manager
Install cert-manager
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.13.0/cert-manager.yaml
Create a self-signed certificate
kubectl apply -f - <<EOF
apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
name: ca-issuer
spec:
selfSigned: {}
EOF
Request a TLS certificate
kubectl apply -f - <<EOF
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: dragonfly-sample
spec:
secretName: dragonfly-sample
duration: 2160h # 90d
renewBefore: 360h # 15d
subject:
organizations:
- dragonfly-sample
privateKey:
algorithm: RSA
encoding: PKCS1
size: 2048
dnsNames:
- dragonfly-sample.com
- www.dragonfly-sample.com
issuerRef:
name: ca-issuer
kind: Issuer
group: cert-manager.io
EOF