feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: add Redis TLS support - #1011

Merged
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls
Mar 17, 2026
Merged

feat: add Redis TLS support#1011
brendan-kellam merged 4 commits into
mainfrom
bkellam/redis_tls

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Extracts Redis client into packages/backend/src/redis.ts with TLS support
  • Adds env vars for Redis TLS configuration (REDIS_TLS_ENABLED, certs, SNI, cipher options, etc.)
  • Adds Infrastructure docs section with a Redis TLS configuration page

Fixes#1006

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added Redis TLS support configurable via environment variables to enable and customize secure Redis connections.
  • Documentation

    • Added an Infrastructure section with Architecture and Redis pages.
    • Expanded Redis docs with TLS configuration and enablement guidance.
    • Consolidated environment variables documentation into the Configuration section and clarified REDIS_URL/TLS notes.

Extracts Redis client into its own module with configurable TLS options.
Adds env vars for TLS, and documents them in a new Infrastructure section.
Fixes#1006
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6f093900-6bd1-4d3b-9a16-05b04f7abe00

📥 Commits

Reviewing files that changed from the base of the PR and between 11cdf04 and be6020e.

📒 Files selected for processing (1)
  • packages/backend/src/redis.ts

Walkthrough

Adds Redis TLS support: a new backend Redis module builds TLS options from environment variables, shared env schema exposes REDIS_TLS_* keys, backend imports the shared Redis client, and docs/manifest updated with infrastructure and Redis TLS documentation.

Changes

Cohort / File(s)Summary
Documentation structure & pages
docs/docs.json, docs/docs/configuration/environment-variables.mdx, docs/docs/deployment/infrastructure/architecture.mdx, docs/docs/deployment/infrastructure/redis.mdx
Added an Infrastructure group and Redis TLS doc; consolidated placement of the environment variables page and added a TLS-enable note for REDIS_URL.
Backend Redis client
packages/backend/src/redis.ts, packages/backend/src/index.ts
Added redis.ts exporting a shared redis client that conditionally builds TLS options from REDIS_TLS_* env vars; replaced local Redis instantiation in index.ts with import of the shared instance.
Shared environment schema
packages/shared/src/env.server.ts
Added server-scoped REDIS_TLS_* environment declarations (enable flag, CA/cert/key paths, servername, validation flags, protocol, ciphers, honor order, key passphrase).
Changelog
CHANGELOG.md
Documented Redis-over-TLS support and listed related env vars in Unreleased.

Sequence Diagram(s)

sequenceDiagram
participant Env as "Environment (REDIS_URL + REDIS_TLS_*)"
participant RedisModule as "packages/backend/src/redis.ts"
participant Backend as "packages/backend/src/index.ts"
participant RedisServer as "Redis (remote)"
Env->>RedisModule: provide `REDIS_URL` and `REDIS_TLS_*` vars
RedisModule->>RedisModule: buildTlsOptions() (read flags, load files)
RedisModule->>RedisModule: instantiate shared `redis` with TLS options
Backend->>RedisModule: import shared `redis`
Backend->>RedisServer: connect via `redis` (TLS if enabled)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe PR title accurately summarizes the main change: adding Redis TLS support is the primary objective implemented across multiple files.
Linked Issues check✅ PassedThe PR fully addresses issue #1006 by enabling TLS configuration for Redis via environment variables (REDIS_TLS_ENABLED and related vars), extracting Redis initialization to support TLS options, and providing comprehensive documentation.
Out of Scope Changes check✅ PassedAll changes directly support Redis TLS functionality: environment variables, Redis client extraction with TLS handling, documentation, and changelog entry are all in-scope.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch bkellam/redis_tls
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
docs/docs/deployment/infrastructure/redis.mdx (1)

6-6: Use second-person voice in the opening sentence.

Please rephrase Line 6 to second person (for example, “You use Redis…”), to match docs style consistency.

As per coding guidelines, docs/**/*.mdx: "Write in second person ('you') and present tense."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@docs/docs/deployment/infrastructure/redis.mdx` at line 6, Replace the
sentence "Sourcebot uses Redis as a job queue for background indexing work."
with a second-person, present-tense variant (e.g., "You use Redis as a job queue
for background indexing work.") to match docs style; update the text in the
redis.mdx content where that exact sentence appears so the opening sentence uses
"you" and present tense.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/redis.ts`:
- Around line 5-8: buildTlsOptions currently only enables TLS when
REDIS_TLS_ENABLED="true", ignoring when REDIS_URL uses rediss://; change it so
TLS options are built when either env.REDIS_TLS_ENABLED==="true" OR
env.REDIS_URL startsWith("rediss://"). Populate and return a proper tls options
object using env-driven values (e.g. REDIS_TLS_SERVERNAME -> servername,
REDIS_TLS_CA/REDIS_TLS_CERT/REDIS_TLS_KEY -> ca/cert/key,
REDIS_TLS_REJECT_UNAUTHORIZED -> rejectUnauthorized, REDIS_TLS_CIPHERS ->
ciphers, etc.) so ioredis receives detailed TLS config; otherwise return {}.
Ensure this logic lives in buildTlsOptions so callers of that function get the
correct tls config.
---
Nitpick comments:
In `@docs/docs/deployment/infrastructure/redis.mdx`:
- Line 6: Replace the sentence "Sourcebot uses Redis as a job queue for
background indexing work." with a second-person, present-tense variant (e.g.,
"You use Redis as a job queue for background indexing work.") to match docs
style; update the text in the redis.mdx content where that exact sentence
appears so the opening sentence uses "you" and present tense.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2e10554d-339f-4016-bd50-ff8f6d5f1978

📥 Commits

Reviewing files that changed from the base of the PR and between ca63bf2 and 585a675.

📒 Files selected for processing (7)
  • docs/docs.json
  • docs/docs/configuration/environment-variables.mdx
  • docs/docs/deployment/infrastructure/architecture.mdx
  • docs/docs/deployment/infrastructure/redis.mdx
  • packages/backend/src/index.ts
  • packages/backend/src/redis.ts
  • packages/shared/src/env.server.ts

Comment threadpackages/backend/src/redis.ts
@brendan-kellam
brendan-kellam merged commit 2a22dd1 into mainMar 17, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the bkellam/redis_tls branch March 17, 2026 19:28
@github-actionsgithub-actionsBot mentioned this pull request Mar 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow to specify tls options for Redis

1 participant

@brendan-kellam