Accept a redis-py credential provider in place of URL credentials - #484
uesleilima wants to merge 8 commits into
Conversation
Docket, StrikeList, and RedisConnection take an optional credential_provider and hand it to every pool and client Docket opens, so rotating credentials such as Azure Entra ID tokens from redis-entraid work. The clients that wrap a pool get it too, since redis-py only re-authenticates pooled connections for a streaming provider when the client is given it. Closes chrisguidry#483 Co-Authored-By: Claude Opus 5.5 <[email protected]>
The ruff format hook in prek failed on two assertions in these tests that ran past the line limit. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Y2QtufEUxxm9XgTqCWySHG
❌ 1 Tests Failed:
View the top 2 failed test(s) by shortest run time
To view more test analytics, go to the Test Analytics Dashboard |
|
I checked the CI failures from the previous run (30c6b1c) against the current head (2bf7d00, after merging main) and couldn't reproduce either timeout locally:
Neither timing-out test sets a credential provider, and without one this change passes nothing new to redis-py, so these look like intermittent timeouts rather than something this PR introduced. CI hasn't run on 2bf7d00 yet (it's waiting for workflow approval). |
Keep credential_provider on the standalone pub/sub client and take main's coverage pragma for that branch. Co-authored-by: Cursor <[email protected]>
Resolve monorepo move conflicts: keep the credential-provider _redis.py line budget under python/, and relocate the new tests with the rest of the suite. Co-authored-by: Cursor <[email protected]>
Those methods are only exercised by the ACL/standalone Redis legs, so the memory core suite failed the 100% coverage gate after the monorepo move kept measuring this test module. Co-authored-by: Cursor <[email protected]>
|
@chrisguidry we are currently implementing FastMCP Docket integration pinned to this commit, currently working in prod for azure entraid credential provider, your review would be really appreciated so we could rely on an officially released version with this capability, thanks! |
Hi @uesleilima, I'll take a look today to cut a patch release with these changes. Thanks for the PR! |
Closes #483
Adds an optional
credential_provider(a redis-pyCredentialProvider) toDocket,StrikeListandRedisConnection. It replaces URL credentials for rotating tokens such as Azure Entra ID viaredis-entraid.RedisConnectionpasses it to every pool it builds: standalone, pub/sub, Sentinel data nodes,RedisCluster, and the cluster pub/sub node pool.Redis(connection_pool=...)client that wraps those pools, including the result store's. redis-py only registers re-authentication of pooled connections for aStreamingCredentialProviderwhen the client is given the provider, and without that Docket's long-lived blocking-read and pub/sub connections would be dropped when a token expires.Dockethands it to itsStrikeList.docs/production.md.loq.toml:_redis.pybaseline goes up by 19 lines.Tests (
tests/test_credential_provider.py):Workerauthenticated only by the provider, and a provider with wrong credentials is refused. In the ACL legs this only passes if the provider's credentials are actually used.Ran locally:
prek run --all-files, and the full suite with--cov-fail-under=100on memory, Redis 8.6, and Redis 8.6 with ACL. The new tests also pass with redis-py 5.3. On Redis 8.6 cluster I ran a focused subset (results, pub/sub, strikes, credential tests), because the full cluster run hit local Docker container-start failures. CI's cluster leg is the real check there.🤖 Generated with Claude Code