Operations
Operate Redis Agent Memory with backups, secret rotation, updates, FIPS posture, and network policy.
Backups
- Back up Metadata Redis. Losing it removes Control Plane store records.
- Back up the Identity Service Metadata Redis, which may be a separate database. Losing it removes agent-key records.
- Back up Store Redis according to the customer's memory-retention policy.
- Back up Job Redis if background job replay or delayed-job preservation is required by the deployment's recovery policy.
- Back up any external secret manager material used to recreate Kubernetes Secrets.
- For Job Redis, use persistent storage where supported and a non-volatile /
noevictionpolicy. OOM can still lose jobs or leave worker state invalid; capacity alerts and compatibility checks should make that caveat visible. - For Metadata Redis and the Identity Service Metadata Redis, use persistent storage and an eviction policy that does not evict store or agent-key records under memory pressure.
Secret rotation
Rotate Redis Agent Memory agent keys through the Identity Service API:
curl -sS -X POST "$IDS_URL/v1/api-keys/<key-id>/rotate?graceSeconds=3600" \
-H "Authorization: Bearer $IDS_CONTROL_TOKEN"
The response contains the new token. Store it immediately; tokens are returned only when a key is minted or rotated.
Rotation returns a new keyId with the new token. Use the new keyId for later
updates, rotations, and revocations. The old key stays valid for graceSeconds,
which defaults to 3600 and has a chart maximum of 604800
(identityService.apiKeys.maxRotateGraceSeconds). The response adds
oldExpiresAt, the time the old key stops working. Revoking the old keyId
ends its grace period early. For the full request and response, see
API examples.
Rotate the Control Plane admin token by updating redis-agent-memory-controlplane-admin-token.
The Control Plane reads the token on use, so changing the token value does not
require a Control Plane redeploy.
kubectl -n <namespace-name> create secret generic redis-agent-memory-controlplane-admin-token \
--from-literal=token='<new-admin-token>' \
--dry-run=client \
-o yaml | kubectl apply -f -
Rotate the Redis Agent Memory license by updating the license Secret and changing
license.existingSecretChecksum so Helm rolls the Data Plane, worker, and
Control Plane pods.
Redis Agent Memory reads and validates the license file during process startup; updating only
the Secret data is not sufficient.
kubectl -n <namespace-name> create secret generic ram-license \
--from-file=license=./license \
--dry-run=client \
-o yaml | kubectl apply -f -
Calculate the new SHA-256 checksum. This value is used by Helm values to roll pods after the license Secret changes; it is not used to validate Secret integrity.
LICENSE_CHECKSUM="$(sha256sum ./license | awk '{print $1}')"
license:
existingSecret: ram-license
existingSecretChecksum: "<new-license-checksum>"
Apply the updated values and verify the workloads rolled:
helm upgrade redis-agent-memory redis-ai/redis-agent-memory \
--version <chart-version> \
--namespace <namespace-name> \
-f ram-values.yaml
kubectl -n <namespace-name> rollout status deploy/redis-agent-memory
kubectl -n <namespace-name> rollout status deploy/redis-agent-memory-worker
kubectl -n <namespace-name> rollout status deploy/redis-agent-memory-controlplane
For immutable license Secrets, create a new Secret name instead, then update
both license.existingSecret and license.existingSecretChecksum.
Config that the chart renders from your values rolls the pods on its own when
you run helm upgrade. If you bring your own config Secrets, rotate the shared
Data Plane config by updating the config Secret and changing
config.existingSecretChecksum, and rotate the Control Plane config by updating
the config Secret and changing controlplane.config.existingSecretChecksum.
If you change an overlay Secret (secrets.*) in place, restart the
deployments, because the chart does not track the Secret contents:
kubectl -n <namespace-name> rollout restart deployment
Updates
For every update:
- Update chart version and image tags.
- Recalculate Secret checksums for changed files.
- Run
helm upgrade. - Verify pod rollout and health endpoints.
Example:
helm upgrade redis-agent-memory redis-ai/redis-agent-memory \
--version <chart-version> \
--namespace <namespace-name> \
-f ram-values.yaml
On small clusters, avoid --atomic unless the timeout and capacity are known to
be sufficient.
Chart tests
The chart can render optional helm test resources when tests.enabled=true.
Enable and run the basic chart test:
helm upgrade --install redis-agent-memory redis-ai/redis-agent-memory \
--version <chart-version> \
--namespace <namespace-name> \
-f ram-values.yaml \
--set tests.enabled=true
helm test redis-agent-memory --namespace <namespace-name>
To run the API smoke test, also provide a configured store ID:
helm upgrade --install redis-agent-memory redis-ai/redis-agent-memory \
--version <chart-version> \
--namespace <namespace-name> \
-f ram-values.yaml \
--set tests.enabled=true \
--set tests.smoke.enabled=true \
--set tests.smoke.storeId=<store-id>
helm test redis-agent-memory --namespace <namespace-name> --logs
Use the smoke test only for auth-disabled Data Plane deployments or for environments where the in-cluster test path is allowed.
FIPS-oriented posture
The chart supports an opt-in FIPS-oriented posture for regulated environments:
security:
profile: fips
You can also apply the bundled FIPS values overlay with the normal values file.
Download the chart to get values-fips.yaml from the chart root:
helm pull redis-ai/redis-agent-memory --version 0.7.0 --untar
helm upgrade --install redis-agent-memory redis-ai/redis-agent-memory \
--version <chart-version> \
--namespace <namespace-name> \
-f ram-values.yaml \
-f redis-agent-memory/values-fips.yaml
When enabled, the chart sets GODEBUG=fips140=on on the Data Plane, worker,
Control Plane, and Identity Service pods and enables FIPS-oriented runtime
checks. The Identity Service also gets IDS_SECURITY_PROFILE.
This is not a formal FIPS 140 compliance or validation claim. Treat it as a deployment posture and guardrail that must still be reviewed against the customer's compliance boundary.
When the posture is active, the Data Plane and worker reject config that:
- enables
skip_verifyon outbound HTTP clients; or - uses non-
rediss://URLs for Redis connections covered by the posture.
The Control Plane runs under the same posture and rejects non-rediss://
metadata.urls or databases."1".urls.
The Redis Agent Memory API listener itself speaks HTTP inside the cluster. Edge TLS termination is owned by the hosting environment, such as ingress, service mesh, or external load balancer. Outbound TLS to Redis, embedding providers, LLM providers, and worker callback endpoints is configured through Redis Agent Memory config and is covered by the posture checks.
Verify the runtime posture with:
kubectl -n <namespace-name> get deploy redis-agent-memory \
-o jsonpath='{.spec.template.spec.containers[0].env[?(@.name=="GODEBUG")].value}'
kubectl -n <namespace-name> logs deploy/redis-agent-memory | grep -i 'FIPS security profile'
Use the chart-generated Deployment to enable the FIPS-oriented posture. Do not override the container command to configure it.
Network policy
For auth-disabled Data Plane deployments, restrict access to trusted callers. For agent-key deployments behind a gateway, prevent direct bypass paths unless the direct caller also has a valid Redis Agent Memory credential.
The chart includes networkpolicy.reference.yaml at the chart root as a
reference manifest. Get it with
helm pull redis-ai/redis-agent-memory --version 0.7.0 --untar. It is not templated because allowed callers are
environment-specific.
Customize the placeholders before applying it:
<namespace>: namespace where Redis Agent Memory is installed.<release-name>: Helm release name. This guide usesredis-agent-memory. The release name also prefixes release-derived service and deployment names.nameOverrideandfullnameOverridechange rendered resource names, but theapp.kubernetes.io/instanceselector remains the Helm release name.<caller-namespace>and caller pod labels: ingress controller, service mesh gateway, application pod, or approved internal caller allowed to call Redis Agent Memory.
The reference policy default-denies ingress to Redis Agent Memory chart pods, then allows TCP
traffic to server pods on port 9000 from approved callers and the worker
Deployment. It also includes a Control Plane stanza for port 9100, which
always applies.
The reference policy has no Identity Service stanza. Under default-deny, add rules that allow:
- Data Plane to Identity Service on port
9200, for agent-key checks. - Identity Service to Control Plane on port
9100.
Review the manifest against the customer's CNI, ingress path, and service mesh behavior before production use.