Skip to content

Add TLS to Redis session storage - #6731

Open
Sanskarzz wants to merge 2 commits into
stacklok:mainfrom
Sanskarzz:feat/tls-redis-session
Open

Sanskarzz wants to merge 2 commits into
stacklok:mainfrom
Sanskarzz:feat/tls-redis-session

Conversation

@Sanskarzz

@Sanskarzz Sanskarzz commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Redis session storage configuration currently cannot enable TLS, even though the shared redisconn library supports it. This prevents standalone vMCP and proxy runtimes from connecting to Redis endpoints that require TLS. Redis-backed rate limiting creates a separate client and needs the same settings.

  • Add a shared runtime TLS configuration used by vMCP sessions, proxy sessions, and their Redis rate limiters.
  • Preserve plaintext when tls is omitted; tls: {} enables certificate and hostname verification using system roots.
  • Support private CAs through a PEM file, and return errors for missing, empty, or malformed configured CA bundles without falling back to plaintext or system roots.
  • Reuse redisconn.NewClient for the rate limiter and share CA loading with the embedded auth server while preserving its existing snake_case configuration.
  • Update runtime documentation, deep-copy code, generated schemas, and the Go SDK contract.

Partially addresses #6730. This is the runtime prerequisite; the Kubernetes API fields, CA Secret projection, and rollout handling will follow in PR B. Keep the issue open until that integration is merged.

TLS support for the operator-wide defaultRedis fallback is outside the scope of both PR A and PR B and will be tracked in a separate follow-up issue.

Type of change

  • Bug fix
  • New feature
  • Refactoring (no behavior change)
  • Dependency update
  • Documentation
  • Other (describe):

Test plan

  • Focused unit tests through a temporary Taskfile using the repository's race detector, linker flags, and gotestfmt configuration; verify PR A independently of the operator changes.
  • SDK tests (task sdk-test).
  • Linting (task lint-fix, previously run on the complete implementation).
  • Regenerate manifests and API reference documentation (task operator-manifests, task crdref-gen --force) against PR A alone and compare with the staged artifacts.
  • E2E tests (task test-e2e).

Coverage includes:

  • Nil TLS versus an explicitly empty TLS object, JSON/YAML round trips, and rejection of TLS with non-Redis vMCP session storage.
  • CA loading failures for missing, empty, and malformed bundles.
  • Real TLS handshakes against a TLS-only miniredis endpoint, successful session create/load operations, password authentication, and rate-limit decisions.
  • Certificate rejection without the required private CA and errors for missing configured CA files.
  • Propagation from proxy session settings into middleware parameters and from vMCP settings into the rate-limit factory.
  • Existing proxy command and operator controller/converter tests against the runtime-only patch.

The full repository unit run previously hit a failure in TestPush/key_push_forwards_signing_capability in the plugin client package; that package passed on an isolated rerun. The full repository suite is not claimed as green here. Runner coverage does not execute the full Runner.Run lifecycle against TLS Redis, and no live Kubernetes workload connection is included in this PR.

API Compatibility

  • This PR does not break the v1beta1 API.

The optional nested VirtualMCPServer.spec.config.sessionStorage.tls schema additions are generated from the embedded runtime configuration, in both served versions. They keep generated artifacts aligned with the runtime type; top-level spec.sessionStorage.tls and Secret references belong to PR B. Existing omitted TLS settings preserve plaintext behavior.

Changes

File or area Change
pkg/redisconfig/tls.go Shared serializable TLS configuration and CA loading/validation.
pkg/authserver/runner/embeddedauthserver.go Convert the existing auth-server TLS configuration through the shared loader, retaining its public field names.
pkg/vmcp/config/config.go, validator.go Optional session TLS field and provider validation.
pkg/vmcp/server/server.go Load TLS settings before constructing Redis session data storage.
pkg/runner/config.go, runner.go, middleware.go Preserve TLS through proxy run configuration, session storage, and middleware parameters.
pkg/ratelimit/middleware.go Use the shared Redis client builder and pass TLS into the independent limiter client.
pkg/vmcp/ratelimit/factory/limiter.go Forward vMCP session TLS settings to the limiter factory.
Runtime tests and test/helpers/redistls/redistls.go TLS endpoint fixture, failure cases, storage/limiter behavior, and config propagation.
cmd/vmcp/README.md Standalone YAML configuration and trust behavior.
Generated deep-copy, VirtualMCPServer CRDs, and API reference Preserve the new pointer and document the runtime schema.
docs/server/*, sdk/go/openapi.*, sdk/go/client/oas_*_gen.go, sdk/go/client/client_test.go Publish the optional runtime TLS schema and update its deliberate contract count.

Does this introduce a user-facing change?

Yes. Standalone thv vmcp serve --config ... and vmcp serve --config ... accept:

sessionStorage:
  provider: redis
  address: redis.example.com:6379
  tls: {}

For a private CA, set tls.caCertFile to a readable PEM bundle in the runtime filesystem. Proxy run configurations receive the same optional TLS object under their existing session Redis settings. No new CLI flag is introduced.

Implementation plan

Implementation plan
  1. Introduce a neutral runtime TLS type with nil/empty semantics and shared CA loading.
  2. Wire it into both session storage runtimes and their independent Redis rate limiters.
  3. Preserve the embedded auth server's existing serialized format while reusing loading logic.
  4. Verify TLS handshakes, config propagation, provider validation, and plaintext compatibility through existing tests.
  5. Regenerate affected schemas, documentation, deep-copy code, and SDK artifacts.
  6. Deliver Kubernetes Secret references, projection, and rollout handling in PR B after this prerequisite.

Special notes for reviewers

  • A custom CA bundle replaces system roots for this Redis connection.
  • CA material is loaded at client startup; there is no certificate reload. Restart clients after changing CA file contents.
  • Explicitly configuring an empty CA file now also fails for the embedded auth server. Previously empty bytes could select system roots; public auth-server configuration field names are unchanged.
  • insecureSkipVerify is an explicit opt-in that disables certificate and hostname verification.
  • Sessions and rate limiting share settings and client construction, but retain separate clients and existing cleanup ownership.
  • Kubernetes top-level TLS fields and CA Secret mounts are deferred to PR B. TLS for the operator-wide defaultRedis fallback is a separate follow-up.
  • The production change is 10 source files and 133 changed lines; tests, docs, and generated artifacts account for the larger total diff.

Signed-off-by: Sanskarzz <sanskar.gur@gmail.com>
@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 93.84615% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 79.28%. Comparing base (47dbcab) to head (5bda236).

Files with missing lines Patch % Lines
pkg/runner/runner.go 0.00% 4 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff           @@
##             main    #6731   +/-   ##
=======================================
  Coverage   79.28%   79.28%           
=======================================
  Files         802      804    +2     
  Lines       81218    81271   +53     
=======================================
+ Hits        64395    64439   +44     
- Misses      16818    16827    +9     
  Partials        5        5           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant