Memorystore for Valkey
Memorystore for Valkey is Google Cloud's managed Valkey, the open-source, Redis-compatible in-memory store. The GCP Web App Blueprint runs one instance per stage as the application's cache, with TLS on every connection and no static password.
What it does
A Memorystore instance has a node type (its size and price per node-hour), a number of shards and replicas per shard. In cluster-disabled mode it behaves like a single Valkey server, which is what most Redis clients expect. Multi-zone distribution places replicas in other zones with automatic failover. In-transit encryption with server authentication makes clients verify the instance's own certificate authority. IAM authentication replaces the static password with a short-lived access token. Clients reach the instance through Private Service Connect endpoints in a VPC.
How BuiltForProd uses it
resource "google_memorystore_instance" "this" {
project = var.project_id
instance_id = "${var.name_prefix}-valkey"
location = var.gcp_region
engine_version = var.engine_version
node_type = var.node_type # SHARED_CORE_NANO (dev) | STANDARD_SMALL (staging, prod)
mode = "CLUSTER_DISABLED"
shard_count = 1
replica_count = var.replicas
zone_distribution_config {
mode = var.replicas > 0 ? "MULTI_ZONE" : "SINGLE_ZONE"
}
transit_encryption_mode = "SERVER_AUTHENTICATION"
authorization_mode = var.iam_auth ? "IAM_AUTH" : "AUTH_DISABLED"
deletion_protection_enabled = var.delete_protection
persistence_config {
mode = var.persistence ? "RDB" : "DISABLED"
}
maintenance_policy {
weekly_maintenance_window {
day = var.maintenance_day
start_time {
hours = var.maintenance_hour
minutes = 0
seconds = 0
nanos = 0
}
}
}
labels = var.labels
}
The valkey unit creates <prefix>-valkey (for example acme-usw1-prd-valkey), Valkey 8.0, one shard in cluster-disabled mode, persistence off, with a weekly maintenance window on Sunday at 03:00 UTC. Per stage:
| Stage | valkey_node_type | valkey_replicas | valkey_delete_protection |
|---|---|---|---|
| dev | SHARED_CORE_NANO | 0 (single zone) | off |
| staging | STANDARD_SMALL | 1 (multi-zone, failover) | off |
| prod | STANDARD_SMALL | 1 (multi-zone, failover) | on |
Billing is per node-hour, and a replica doubles the node count.
Authentication. The application's Kubernetes service account, bound as an IAM principal through Workload Identity Federation for GKE, holds roles/memorystore.dbConnectionUser with a condition that matches this instance only. The application sends its access token as the AUTH password of the user default.
Network. The unit creates two Private Service Connect consumer endpoints itself, internal addresses in the stage's data subnet of the Shared VPC with a forwarding rule each, and registers them on the instance. It does not use a service connection policy, because such a policy is unique per VPC and region and the stages of one isolation domain share a VPC. The chart's NetworkPolicy allows TCP 6379 only to the stage's data subnet.
Connection values. The unit writes redis--host (the primary endpoint's address), redis--port (6379) and redis--ca (the instance's server CA bundle) to Secret Manager; the External Secrets Operator maps them to REDIS_HOST, REDIS_PORT and REDIS_CA_PEM. No credential is published.
Terms you will see
| Term | Meaning |
|---|---|
| Node type | The size of each node, such as SHARED_CORE_NANO or STANDARD_SMALL. |
| Cluster-disabled mode | One shard that clients address like a single Valkey server. |
| IAM authentication | An access token as the password, checked against IAM. |
| PSC endpoint | An internal address in a VPC that forwards to the instance. |
redis--ca | The secret holding the CA the client verifies the server against. |
Where to read more
- GCP Web App Blueprint overview for the data stores.
- Firestore with MongoDB compatibility for the database beside it.
- Private Service Access for how the platform reaches managed services privately.