spring-data-redis与Microsoft Entra ID认证集成的可行方案咨询
Spring Data Redis 集成 Microsoft Entra ID 认证的可行方案
方案1:自定义RedisConnectionFactory实现令牌认证
Spring Data Redis的RedisConnectionFactory本身不直接支持DefaultAzureCredential,但可以基于Lettuce(或Jedis)客户端扩展,手动注入Entra ID令牌作为Redis认证凭证:
- 依赖准备
确保项目引入以下依赖(以Maven为例):
<dependency> <groupId>org.springframework.data</groupId> <artifactId>spring-data-redis</artifactId> </dependency> <dependency> <groupId>io.lettuce</groupId> <artifactId>lettuce-core</artifactId> </dependency> <dependency> <groupId>com.azure</groupId> <artifactId>azure-identity</artifactId> </dependency>
- 配置自定义连接工厂
通过DefaultAzureCredential获取Entra ID令牌,配置Lettuce客户端并构建RedisConnectionFactory:
@Configuration public class AzureRedisConfig { @Value("${spring.data.redis.host}") private String redisHost; @Value("${spring.data.redis.port:6380}") private int redisPort; @Bean public DefaultAzureCredential defaultAzureCredential() { return new DefaultAzureCredentialBuilder().build(); } @Bean public RedisConnectionFactory redisConnectionFactory(DefaultAzureCredential credential) { // 请求Redis服务的Entra ID令牌 TokenRequestContext tokenContext = new TokenRequestContext() .addScopes("https://redis.azure.com/.default"); AccessToken accessToken = credential.getToken(tokenContext).block(); if (accessToken == null) { throw new IllegalStateException("无法获取用于Redis的Entra ID令牌"); } // 构建带令牌认证的RedisURI RedisURI redisUri = RedisURI.builder() .host(redisHost) .port(redisPort) .password(accessToken.getToken()) .ssl(true) // Azure Redis默认强制SSL .build(); RedisClient redisClient = RedisClient.create(redisUri); LettuceConnectionFactory connectionFactory = new LettuceConnectionFactory(redisClient); connectionFactory.afterPropertiesSet(); return connectionFactory; } @Bean public RedisTemplate<String, Object> redisTemplate(RedisConnectionFactory connectionFactory) { RedisTemplate<String, Object> template = new RedisTemplate<>(); template.setConnectionFactory(connectionFactory); // 配置序列化器(根据业务需求调整) template.setKeySerializer(new StringRedisSerializer()); template.setValueSerializer(new GenericJackson2JsonRedisSerializer()); return template; } }
- 令牌自动刷新处理
由于Entra ID令牌存在有效期(通常1小时),需实现令牌自动刷新逻辑:
- 可以通过定时任务定期刷新令牌,更新
RedisURI的密码并重启连接客户端; - 利用Lettuce的
ConnectionProvider扩展,实现动态获取最新令牌的逻辑。
方案2:使用Azure Redis Spring Boot Starter
微软官方提供的azure-spring-boot-starter-redis已集成Entra ID认证支持,只需简单配置即可:
- 引入依赖
<dependency> <groupId>com.azure.spring</groupId> <artifactId>azure-spring-boot-starter-redis</artifactId> <version>3.20.0</version> <!-- 使用最新稳定版 --> </dependency>
- 配置文件设置
# Redis实例信息 spring.data.redis.host=your-redis-resource.redis.cache.windows.net spring.data.redis.port=6380 spring.data.redis.ssl=true # 启用Entra ID认证 azure.redis.entra-id-enabled=true
该starter会自动使用DefaultAzureCredential获取令牌完成认证,无需手动处理连接工厂配置,同时内置了令牌刷新机制。
前置条件
- Azure Redis实例已启用Entra ID认证;
- 应用所在的服务主体(或托管标识)已被分配Redis的访问角色(如
Redis Contributor、Redis Reader); - 应用运行环境支持
DefaultAzureCredential的身份验证方式(如Azure VM/AKS、本地开发环境配置Azure CLI登录)。
内容的提问来源于stack exchange,提问作者Gekster
相关产品推荐
相关产品推荐

