Skip to main content

Azure Managed Redis

Azure Managed Redis is Microsoft's managed in-memory data store built on Redis Enterprise. The Azure Web App Blueprint runs one instance per stage, <prefix>-redis, as the API's cache, reachable only through a private endpoint, only over TLS and only with Microsoft Entra tokens.

What it does​

An instance has a SKU that sets memory and throughput (the Balanced family here) and, optionally, high availability: a replica on a second node in another zone. Its default database sets the client protocol (encrypted or plain), the clustering policy, the eviction policy and optional persistence snapshots. Clients authenticate with access keys or with Microsoft Entra tokens, granted through an access policy assignment. Public access can be disabled in favor of private endpoints.

How BuiltForProd uses it​

The managed-redis unit creates <prefix>-redis with public network access disabled and this default database:

SettingValue
Client protocolEncrypted: TLS only, port 10000
Clustering policyEnterpriseCluster: one endpoint, so the client needs no cluster protocol
Eviction policyVolatileLRU: under memory pressure, keys with an expiry are evicted first
PersistenceOff; rdb_backup_frequency (1h, 6h or 12h) turns on RDB snapshots
AuthenticationMicrosoft Entra only; access keys disabled

No key exists. The application's workload identity id-<prefix>-app holds the default access policy, and the API's Redis client presents an Entra token for https://redis.azure.com from the pod's Workload ID credential. access_keys = true re-enables keys for tools that cannot present tokens and publishes the key to the application vault as redis--password. See managed identities.

Stageredis_sku_name (stack comment)redis_high_availability
devBalanced_B0, ~$40/monthoff
stagingBalanced_B1, ~$80/monthon: two nodes replicated across zones
prodBalanced_B1, ~$80/monthon

Network. The private endpoint pe-<prefix>-redis sits in the stage's snet-endpoints and registers in the central privatelink.redis.azure.net zone; see Private Link. The unit writes redis--host and redis--port to the application vault, which the External Secrets Operator maps into the pod, and the pods' NetworkPolicy allows TCP 10000 to the snet-endpoints prefix only. delete_locks puts a CanNotDelete lock on the instance in prod.

Terms you will see​

TermMeaning
Balanced SKUThe general-purpose size family: B0 in dev, B1 in staging and prod.
Access policy assignmentThe grant that lets an Entra principal use the database.
EnterpriseClusterThe clustering policy that exposes a single endpoint.
Eviction policyWhich keys go first when memory is full.
Access keysShared secrets for the database; disabled here.

Where to read more​