{
  "schema_version": 2,
  "id": "operate/iris/agent-memory/self-managed/configuration",
  "title": "Configuration",
  "url": "https://redis.io/docs/latest/operate/iris/agent-memory/self-managed/configuration/",
  "summary": "Configure the Redis Agent Memory Data Plane, Control Plane, and Identity Service from Helm values, or bring your own configuration files.",
  "aliases": [
    "/develop/ai/context-engine/agent-memory/self-managed/data-plane-configuration/",
    "/operate/iris/agent-memory/self-managed/data-plane-configuration/"
  ],
  "tags": [
    "docs",
    "operate",
    "iris"
  ],
  "last_updated": "2026-10-06T00:46:46+03:00",
  "page_type": "content",
  "content_hash": "7e3db4a88e89e695470201e827d78a2dbd7f633743dc0d861a7d28b1ba799905",
  "sections": [
    {
      "id": "overview",
      "title": "Overview",
      "role": "overview",
      "text": "The chart renders the Data Plane, Control Plane, and Identity Service configuration from Helm values\n(`config.render: true`). Credentials stay out of the values, in the overlay Secret. For a complete\nexample, see the values in [step 3 of Deploy](https://redis.io/docs/latest/operate/iris/agent-memory/self-managed/deploy#3-create-ram-valuesyaml).\n\nTo supply complete configuration files in your own Secrets instead, see\n[Bring-your-own (BYO) configuration](#bring-your-own-byo-configuration)."
    },
    {
      "id": "where-each-setting-goes",
      "title": "Where each setting goes",
      "role": "content",
      "text": "| Values | Configures |\n| --- | --- |\n| `shared` | Settings common to the Data Plane and the Control Plane, such as `databases`. The chart merges them under `memory` and `controlplane.configData`. |\n| `memory` | The Data Plane and worker configuration file. |\n| `controlplane.configData` | The Control Plane configuration file. |\n| `identityService.*` | The Identity Service. `identityService.metadata.existingSecret` names the Secret with its Metadata Redis URL. |\n| Overlay Secret (`secrets.secretName`, key `overlay.yaml`) | `metadata.urls`, `metadata.namespace`, `databases.\"1\".urls`, `background_jobs.redis.urls`, and provider `api_key` values. The Data Plane, the workers, and the Control Plane all read it. |"
    },
    {
      "id": "data-plane-settings",
      "title": "Data Plane settings",
      "role": "content",
      "text": "Data Plane settings go under `memory`, or at the top level of a BYO Data Plane configuration file.\n\n| Setting | Purpose |\n| --- | --- |\n| `metadata.urls` | Required. Metadata Redis, which holds store records. `metadata.namespace` sets the key namespace (default `iris:memory`). |\n| `databases` | Required. Store Redis, as `databases.\"1\".urls`. |\n| `embedding.models.default_embedding_model`, `embedding.models.dimensions` | Required. The embedding model and its vector size. The Control Plane's `embedding.dimensions` must match. |\n| `auth` | Data Plane authentication. Defaults to `agent_key`. |\n| `inference_providers` | Required when any `llm` block is set. Each entry holds a provider's `endpoint`. |\n| `server` | Data Plane bind address and port. |\n| `license.license_path` | Path where the license Secret is mounted. |\n| `request_region` | Region used for background work routing. |\n| `background_jobs.redis` | Job Redis connection used by background workers. |\n| `embedders_connection_details` | Embedding provider endpoint and credentials. |\n| `dataplane_client` | Worker callback client configuration. |\n| `promote_session_memory` | Promotion strategy and LLM connection used by workers. |\n\nAn `llm` block names its provider with `llm.provider`, which must match an `inference_providers`\nentry. The endpoint goes in `inference_providers.<name>.endpoint`, not in the `llm` block.\n\nIn the chart-rendered configuration, the chart writes the agent-key introspection settings for you.\nLeave `auth.method` unset to keep the `agent_key` default."
    },
    {
      "id": "bring-your-own-byo-configuration",
      "title": "Bring-your-own (BYO) configuration",
      "role": "content",
      "text": "With BYO configuration, you supply each complete configuration file in your own Secret, and the\nchart injects nothing into it. Add the keys the chart would otherwise write:\n\n- **Data Plane**: the `auth.agent_keys.introspection` block.\n- **Control Plane**: `auth.internal_token.token_file: /etc/controlplane-onprem/internal/token`.\n\nThe Data Plane defaults to `agent_key` whenever no auth method is set. A BYO Data Plane configuration\nwithout `auth` therefore needs the `auth.agent_keys.introspection` block, or `auth.method: none`.\nThe `MEM_AUTH_METHOD` environment variable overrides the method."
    },
    {
      "id": "data-plane-configuration-file",
      "title": "Data Plane configuration file",
      "role": "content",
      "text": "Create `memory-dataplane.config.yaml`:\n\n[code example]\n\nThe `auth.worker_identity` and `dataplane_client.auth` settings let workers call the Data Plane\nunder agent-key authentication. They need `workerAuth.enabled: true` in the values, and the platform\nsetup in [worker identity](https://redis.io/docs/latest/operate/iris/agent-memory/self-managed/deploy#prepare-worker-identity-for-your-platform).\n\nCreate the Data Plane config Secret with the key `memory-dataplane.config.yaml`:\n\n[code example]"
    },
    {
      "id": "control-plane-configuration-file",
      "title": "Control Plane configuration file",
      "role": "content",
      "text": "Create `controlplane-onprem.config.yaml`:\n\n[code example]\n\nThe Control Plane only needs `embedding.dimensions`, to create each store's vector index. Configure\nthe embedding provider, model, and credentials in the Data Plane configuration.\n\nCreate the Control Plane config Secret:\n\n[code example]"
    },
    {
      "id": "helm-values",
      "title": "Helm values",
      "role": "content",
      "text": "In `ram-values.yaml`, replace `config.render`, `shared`, `memory`, `controlplane.config.render`, and\n`controlplane.configData` with the two Secrets. The chart fails at install time if both\n`config.existingSecret` and `config.render` are set.\n\n[code example]"
    }
  ],
  "examples": [
    {
      "id": "data-plane-configuration-file-ex0",
      "language": "yaml",
      "code": "server:\n  host: 0.0.0.0\n  port: 9000\n\nlicense:\n  license_path: /etc/redis-agent-memory/license\ndefault_extraction_strategy: instruct\n\nrequest_region:\n  default: eu1\n\nbackground_jobs:\n  redis:\n    enabled: true\n    queue_prefix: ram\n    urls:\n      - redis://<job-redis-host>:6379\n    worker_regions:\n      - eu1\n\nmetadata:\n  urls:\n    - redis://<metadata-redis-host>:6379\n  namespace: iris:memory\n\ndatabases:\n  \"1\":\n    urls:\n      - redis://<store-redis-host>:6379\n\nauth:\n  agent_keys:\n    introspection:\n      base_url: http://redis-agent-memory-identity-service:9200\n      allow_insecure_transport: true\n      product: memory\n      credential:\n        token_file: /etc/identity-service/runtime/memory-dp/token\n  worker_identity:\n    enabled: true\n    issuer: <service-account-issuer>\n    jwks_uri: https://kubernetes.default.svc/openid/v1/jwks\n    audience:\n      - redis-agent-memory\n    subjects:\n      - subject: \"system:serviceaccount:<namespace-name>:redis-agent-memory-worker\"\n        user_id: redis-agent-memory-worker\n        roles:\n          - operator\n        resources:\n          \"mem-store:*\":\n            permissions:\n              - write\n\nembedding:\n  provider: openai\n  models:\n    default_embedding_model: text-embedding-3-large\n    dimensions: 3072\n\nembedders_connection_details:\n  openai:\n    base_url: https://api.openai.com\n    credentials:\n      type: static\n      api_key: \"<embedding-api-key>\"\n\ninference_providers:\n  openai:\n    endpoint:\n      base_url: https://api.openai.com/v1\n      timeout: 30s\n      auth_format: bearer\n\ndataplane_client:\n  base_url: http://redis-agent-memory:9000\n  auth:\n    disabled: false\n    type: service_account_token\n    token_file: /var/run/secrets/redis-agent-memory-worker/token\n\npromote_session_memory:\n  strategies:\n    instruct:\n      llm:\n        provider: openai\n        credentials:\n          type: static\n          api_key: \"<promotion-llm-api-key>\"\n        models:\n          default_chat_model: gpt-4o",
      "section_id": "data-plane-configuration-file"
    },
    {
      "id": "data-plane-configuration-file-ex1",
      "language": "bash",
      "code": "kubectl -n <namespace-name> create secret generic ram-config \\\n  --from-file=memory-dataplane.config.yaml=./memory-dataplane.config.yaml",
      "section_id": "data-plane-configuration-file"
    },
    {
      "id": "control-plane-configuration-file-ex0",
      "language": "yaml",
      "code": "profile: prod\n\nauth:\n  type: admin-token\n  admin_token:\n    token_file: /etc/controlplane-onprem/admin/token\n  internal_token:\n    token_file: /etc/controlplane-onprem/internal/token\n\nlicense:\n  license_path: /etc/redis-agent-memory/license\n\nmetadata:\n  urls:\n    - redis://<metadata-redis-host>:6379\n  namespace: iris:memory\n\ndatabases:\n  \"1\":\n    urls:\n      - redis://<store-redis-host>:6379\n\nembedding:\n  dimensions: 3072",
      "section_id": "control-plane-configuration-file"
    },
    {
      "id": "control-plane-configuration-file-ex1",
      "language": "bash",
      "code": "kubectl -n <namespace-name> create secret generic ram-controlplane-config \\\n  --from-file=controlplane-onprem.config.yaml=./controlplane-onprem.config.yaml",
      "section_id": "control-plane-configuration-file"
    },
    {
      "id": "helm-values-ex0",
      "language": "yaml",
      "code": "config:\n  existingSecret: ram-config\ncontrolplane:\n  config:\n    existingSecret: ram-controlplane-config",
      "section_id": "helm-values"
    }
  ]
}
