Both ports open during a migration
Unmigrated clients keep using plaintext, silently
- tls-port
- 6379
- allow-plaintext
- yes
Generate the TLS block for redis.conf. The trap is that TLS is a separate port: setting tls-port does not close the plaintext one, so an instance can look migrated while still accepting unencrypted connections on 6379.
Worked setups you can load into the form above. Each one is a decision the generator makes differently, and the reason it makes it.
Unmigrated clients keep using plaintext, silently
Encrypted, but the client is still not identified
These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.
The plaintext port stays open until port is set to 0, and a client using it looks exactly like one that is not.
Instead:Set port 0 once every client has moved.
The replication link stays unencrypted, so the whole dataset crosses the network in the clear on every full resync.
Instead:Set tls-replication yes and tls-cluster yes.
That would trust any certificate signed by any public CA, which is every certificate on the internet.
Instead:Point it at the CA that signed your client certificates.
Expiry is a cluster-wide authentication outage that arrives without warning.
Instead:Automate renewal and alert well before the date.
A Redis node makes more than one kind of connection, and enabling TLS for clients does not enable it for the others.
Setting tls-port adds a TLS listener. It does not remove the plaintext one. Until port is set to 0, the instance still accepts unencrypted connections, and nothing in a successful client connection reveals which listener it used.
A replica connecting to its primary does not use TLS just because client TLS is on. tls-replication yes is what encrypts it, and without it the entire dataset crosses the network in the clear on every full resync.
Nodes gossip over the bus port, and tls-cluster controls that independently. Leaving it off means cluster state and the node ids travel unencrypted while client traffic is protected.
TLS without client certificates gives confidentiality only: anyone who can reach the port still connects and authenticates with a password. tls-auth-clients yes requires a certificate signed by your CA, and that certificate can then serve as the identity an ACL is written against.
Certificates expire on a date that is rarely diarised, and the failure is total authentication loss across the cluster. Redis reloads certificates on CONFIG SET, so renewal does not require a restart, which makes automating it straightforward.