Azure Managed Redis
Azure Managed Redis is Microsoft's managed in-memory data store built on Redis Enterprise. The Azure Web App Blueprint runs one instance per stage, <prefix>-redis, as the API's cache, reachable only through a private endpoint, only over TLS and only with Microsoft Entra tokens.
What it does
An instance has a SKU that sets memory and throughput (the Balanced family here) and, optionally, high availability: a replica on a second node in another zone. Its default database sets the client protocol (encrypted or plain), the clustering policy, the eviction policy and optional persistence snapshots. Clients authenticate with access keys or with Microsoft Entra tokens, granted through an access policy assignment. Public access can be disabled in favor of private endpoints.
How BuiltForProd uses it
The managed-redis unit creates <prefix>-redis with public network access disabled and this default database:
| Setting | Value |
|---|---|
| Client protocol | Encrypted: TLS only, port 10000 |
| Clustering policy | EnterpriseCluster: one endpoint, so the client needs no cluster protocol |
| Eviction policy | VolatileLRU: under memory pressure, keys with an expiry are evicted first |
| Persistence | Off; rdb_backup_frequency (1h, 6h or 12h) turns on RDB snapshots |
| Authentication | Microsoft Entra only; access keys disabled |
No key exists. The application's workload identity id-<prefix>-app holds the default access policy, and the API's Redis client presents an Entra token for https://redis.azure.com from the pod's Workload ID credential. access_keys = true re-enables keys for tools that cannot present tokens and publishes the key to the application vault as redis--password. See managed identities.
| Stage | redis_sku_name (stack comment) | redis_high_availability |
|---|---|---|
| dev | Balanced_B0, ~$40/month | off |
| staging | Balanced_B1, ~$80/month | on: two nodes replicated across zones |
| prod | Balanced_B1, ~$80/month | on |
Network. The private endpoint pe-<prefix>-redis sits in the stage's snet-endpoints and registers in the central privatelink.redis.azure.net zone; see Private Link. The unit writes redis--host and redis--port to the application vault, which the External Secrets Operator maps into the pod, and the pods' NetworkPolicy allows TCP 10000 to the snet-endpoints prefix only. delete_locks puts a CanNotDelete lock on the instance in prod.
Terms you will see
| Term | Meaning |
|---|---|
| Balanced SKU | The general-purpose size family: B0 in dev, B1 in staging and prod. |
| Access policy assignment | The grant that lets an Entra principal use the database. |
EnterpriseCluster | The clustering policy that exposes a single endpoint. |
| Eviction policy | Which keys go first when memory is full. |
| Access keys | Shared secrets for the database; disabled here. |
Where to read more
- Azure Web App Blueprint overview for the data path of the API.
- Azure Cosmos DB for MongoDB vCore for the database beside it.
- Private Link for the private endpoints.