ElastiCache Redis
A Redis OSS replication group with encryption at rest and TLS required in transit.
GovCloudCMKView source
- Module
- redis
- Layer
- Data
- Interface
- 23 inputs, 6 outputs
- Used by
- No apps yet
Why it matters
Apps use Redis for sessions, caches, and job queues, where answers have to come back in milliseconds. This module builds a primary and a replica in two availability zones, encrypts data on disk, and rejects any connection that is not TLS.
Use it when
- The app needs a session store, cache, rate limiter, or job queue backend.
Reach for something else when
- The data must survive as the system of record. Use rds-postgres.
What it creates
aws_elasticache_subnet_group(private subnets)aws_security_group(port 6379 from allowed_security_group_ids and allowed_cidr_blocks only)aws_elasticache_parameter_group(redis7)aws_cloudwatch_log_group(slow log and engine log, each optional)aws_elasticache_replication_group(Redis 7.1, 2 nodes, automatic failover)
Secure by default
- Data at rest is encrypted (at_rest_encryption_enabled = true, not configurable).
- Plaintext connections are rejected (transit_encryption_mode = "required").
- Two nodes with automatic failover across availability zones (num_cache_clusters = 2, multi_az = true).
- Snapshots are kept for 7 days.
Commercial and GovCloud
module "redis" {
source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//redis?ref=v1.7.0"
app_name = local.app_name
vpc_id = module.networking.vpc_id
private_subnet_ids = module.networking.private_subnet_ids
allowed_security_group_ids = [module.ecs_service.security_group_id]
node_type = "cache.t4g.small"
auth_token = data.aws_ssm_parameter.redis_auth_token.value
tags = local.tags
}| Setting | Commercial default | Federal setting | Note |
|---|---|---|---|
kms_key_id | null (AWS managed ElastiCache key) | customer managed KMS key ARN | FedRAMP SC-13. |
log_kms_key_arn | null (AWS managed) | the same key as kms_key_id | |
enable_slow_log, enable_engine_log | false | true | |
log_retention_days | 30 | 90 | FedRAMP AU-11, as set in examples/federal. |
auth_token | null (security group and TLS only) | a token read from an SSM SecureString |
How it connects
- From networking: vpc_id, private_subnet_ids
- From ecs-service: security_group_id (as allowed_security_group_ids)
- To ecs-service: endpoint_address and port, in an SSM REDIS_URL
Inputs
| Name | Type | Default | Required | Description |
|---|---|---|---|---|
app_name | string | yes | Application name used in resource naming | |
node_type | string | yes | ElastiCache node type (e.g. cache.t4g.micro, cache.t4g.small) | |
private_subnet_ids | list(string) | yes | Private subnet IDs for the ElastiCache subnet group | |
vpc_id | string | yes | VPC ID | |
allowed_cidr_blocks | list(string) | [] | no | CIDR blocks allowed to connect on port 6379. Use when security group creates a circular dependency. |
allowed_security_group_ids | list(string) | [] | no | Security group IDs allowed to connect on port 6379 (use module.ecs_service.security_group_id) |
auth_token | string | null | no | Optional Redis AUTH token - pass this from an SSM data source, never hardcode. Null falls back to SG + TLS isolation only. Sensitive. |
enable_engine_log | bool | false | no | Stream the Redis engine log to CloudWatch. Off by default to avoid log group churn for v1 callers; federal posture should enable. |
enable_slow_log | bool | false | no | Stream the Redis SLOWLOG to CloudWatch. Off by default to avoid log group churn for v1 callers; federal posture should enable. |
engine_version | string | "7.1" | no | Redis engine version |
environment | string | "" | no | Environment suffix (dev, prod, staging). Leave empty if the account has no env concept. |
kms_key_id | string | null | no | Customer-managed KMS key ARN for at-rest encryption. Null falls back to the AWS-managed ElastiCache key. Required for federal posture (FedRAMP SC-13). |
log_kms_key_arn | string | null | no | KMS key ARN for the slow-log and engine-log CloudWatch log groups. Null falls back to the AWS-managed key. Federal posture should set this to the same key as kms_key_id. |
log_retention_days | number | 30 | no | CloudWatch log retention for slow-log and engine-log groups. |
maintenance_window | string | null | no | Weekly maintenance window in UTC, e.g. "sun:05:00-sun:07:00". Null lets AWS choose. |
multi_az | bool | true | no | Enable Multi-AZ. Coerced to false when num_cache_clusters = 1. |
num_cache_clusters | number | 2 | no | Number of cache clusters in the replication group (1 primary + N-1 replicas). Set to 1 for non-HA dev. |
parameter_group_family | string | "redis7" | no | Parameter group family. Must match engine_version (e.g. redis7 for engine 7.x). |
security_group_description | string | null | no | Override the Redis SG description. Set when adopting an existing SG (description is immutable in AWS). |
snapshot_retention_limit | number | 7 | no | Days to retain automatic snapshots. 0 disables snapshots. |
snapshot_window | string | null | no | Daily snapshot window in UTC, e.g. "03:00-05:00". Null lets AWS choose. |
tags | map(string) | {} | no | Tags to apply to all resources |
transit_encryption_mode | string | "required" | no | TLS enforcement: "required" rejects plaintext, "preferred" allows both during in-place migration. Federal posture requires "required". |
Outputs
| Name | Description |
|---|---|
endpoint_address | Value: aws_elasticache_replication_group.this.primary_endpoint_address |
port | Value: aws_elasticache_replication_group.this.port |
reader_endpoint_address | Value: aws_elasticache_replication_group.this.reader_endpoint_address |
replication_group_arn | Value: aws_elasticache_replication_group.this.arn |
replication_group_id | Value: aws_elasticache_replication_group.this.id |
security_group_id | Value: aws_security_group.redis.id |
Used by
No Kaizen app uses this module yet.