Kaizen

ElastiCache Redis

A Redis OSS replication group with encryption at rest and TLS required in transit.

GovCloudCMKView source
Module
redis
Layer
Data
Interface
23 inputs, 6 outputs
Used by
No apps yet

Why it matters

Apps use Redis for sessions, caches, and job queues, where answers have to come back in milliseconds. This module builds a primary and a replica in two availability zones, encrypts data on disk, and rejects any connection that is not TLS.

Use it when

  • The app needs a session store, cache, rate limiter, or job queue backend.

Reach for something else when

  • The data must survive as the system of record. Use rds-postgres.

What it creates

  • aws_elasticache_subnet_group (private subnets)
  • aws_security_group (port 6379 from allowed_security_group_ids and allowed_cidr_blocks only)
  • aws_elasticache_parameter_group (redis7)
  • aws_cloudwatch_log_group (slow log and engine log, each optional)
  • aws_elasticache_replication_group (Redis 7.1, 2 nodes, automatic failover)

Secure by default

  • Data at rest is encrypted (at_rest_encryption_enabled = true, not configurable).
  • Plaintext connections are rejected (transit_encryption_mode = "required").
  • Two nodes with automatic failover across availability zones (num_cache_clusters = 2, multi_az = true).
  • Snapshots are kept for 7 days.

Commercial and GovCloud

main.tf
module "redis" {
  source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//redis?ref=v1.7.0"

  app_name           = local.app_name
  vpc_id             = module.networking.vpc_id
  private_subnet_ids = module.networking.private_subnet_ids

  allowed_security_group_ids = [module.ecs_service.security_group_id]

  node_type  = "cache.t4g.small"
  auth_token = data.aws_ssm_parameter.redis_auth_token.value

  tags = local.tags
}
SettingCommercial defaultFederal settingNote
kms_key_idnull (AWS managed ElastiCache key)customer managed KMS key ARNFedRAMP SC-13.
log_kms_key_arnnull (AWS managed)the same key as kms_key_id
enable_slow_log, enable_engine_logfalsetrue
log_retention_days3090FedRAMP AU-11, as set in examples/federal.
auth_tokennull (security group and TLS only)a token read from an SSM SecureString

How it connects

  • From networking: vpc_id, private_subnet_ids
  • From ecs-service: security_group_id (as allowed_security_group_ids)
  • To ecs-service: endpoint_address and port, in an SSM REDIS_URL

Inputs

NameTypeDefaultRequiredDescription
app_namestringyesApplication name used in resource naming
node_typestringyesElastiCache node type (e.g. cache.t4g.micro, cache.t4g.small)
private_subnet_idslist(string)yesPrivate subnet IDs for the ElastiCache subnet group
vpc_idstringyesVPC ID
allowed_cidr_blockslist(string)[]noCIDR blocks allowed to connect on port 6379. Use when security group creates a circular dependency.
allowed_security_group_idslist(string)[]noSecurity group IDs allowed to connect on port 6379 (use module.ecs_service.security_group_id)
auth_tokenstringnullnoOptional Redis AUTH token - pass this from an SSM data source, never hardcode. Null falls back to SG + TLS isolation only. Sensitive.
enable_engine_logboolfalsenoStream the Redis engine log to CloudWatch. Off by default to avoid log group churn for v1 callers; federal posture should enable.
enable_slow_logboolfalsenoStream the Redis SLOWLOG to CloudWatch. Off by default to avoid log group churn for v1 callers; federal posture should enable.
engine_versionstring"7.1"noRedis engine version
environmentstring""noEnvironment suffix (dev, prod, staging). Leave empty if the account has no env concept.
kms_key_idstringnullnoCustomer-managed KMS key ARN for at-rest encryption. Null falls back to the AWS-managed ElastiCache key. Required for federal posture (FedRAMP SC-13).
log_kms_key_arnstringnullnoKMS key ARN for the slow-log and engine-log CloudWatch log groups. Null falls back to the AWS-managed key. Federal posture should set this to the same key as kms_key_id.
log_retention_daysnumber30noCloudWatch log retention for slow-log and engine-log groups.
maintenance_windowstringnullnoWeekly maintenance window in UTC, e.g. "sun:05:00-sun:07:00". Null lets AWS choose.
multi_azbooltruenoEnable Multi-AZ. Coerced to false when num_cache_clusters = 1.
num_cache_clustersnumber2noNumber of cache clusters in the replication group (1 primary + N-1 replicas). Set to 1 for non-HA dev.
parameter_group_familystring"redis7"noParameter group family. Must match engine_version (e.g. redis7 for engine 7.x).
security_group_descriptionstringnullnoOverride the Redis SG description. Set when adopting an existing SG (description is immutable in AWS).
snapshot_retention_limitnumber7noDays to retain automatic snapshots. 0 disables snapshots.
snapshot_windowstringnullnoDaily snapshot window in UTC, e.g. "03:00-05:00". Null lets AWS choose.
tagsmap(string){}noTags to apply to all resources
transit_encryption_modestring"required"noTLS enforcement: "required" rejects plaintext, "preferred" allows both during in-place migration. Federal posture requires "required".

Outputs

NameDescription
endpoint_addressValue: aws_elasticache_replication_group.this.primary_endpoint_address
portValue: aws_elasticache_replication_group.this.port
reader_endpoint_addressValue: aws_elasticache_replication_group.this.reader_endpoint_address
replication_group_arnValue: aws_elasticache_replication_group.this.arn
replication_group_idValue: aws_elasticache_replication_group.this.id
security_group_idValue: aws_security_group.redis.id

Used by

No Kaizen app uses this module yet.

On this page