You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

spring-data-redis与Microsoft Entra ID认证集成的可行方案咨询

Spring Data Redis 集成 Microsoft Entra ID 认证的可行方案

方案1:自定义RedisConnectionFactory实现令牌认证

Spring Data Redis的RedisConnectionFactory本身不直接支持DefaultAzureCredential,但可以基于Lettuce(或Jedis)客户端扩展,手动注入Entra ID令牌作为Redis认证凭证:

  1. 依赖准备
    确保项目引入以下依赖(以Maven为例):
<dependency>
    <groupId>org.springframework.data</groupId>
    <artifactId>spring-data-redis</artifactId>
</dependency>
<dependency>
    <groupId>io.lettuce</groupId>
    <artifactId>lettuce-core</artifactId>
</dependency>
<dependency>
    <groupId>com.azure</groupId>
    <artifactId>azure-identity</artifactId>
</dependency>
  1. 配置自定义连接工厂
    通过DefaultAzureCredential获取Entra ID令牌,配置Lettuce客户端并构建RedisConnectionFactory:
@Configuration
public class AzureRedisConfig {

    @Value("${spring.data.redis.host}")
    private String redisHost;

    @Value("${spring.data.redis.port:6380}")
    private int redisPort;

    @Bean
    public DefaultAzureCredential defaultAzureCredential() {
        return new DefaultAzureCredentialBuilder().build();
    }

    @Bean
    public RedisConnectionFactory redisConnectionFactory(DefaultAzureCredential credential) {
        // 请求Redis服务的Entra ID令牌
        TokenRequestContext tokenContext = new TokenRequestContext()
                .addScopes("https://redis.azure.com/.default");
        AccessToken accessToken = credential.getToken(tokenContext).block();
        if (accessToken == null) {
            throw new IllegalStateException("无法获取用于Redis的Entra ID令牌");
        }

        // 构建带令牌认证的RedisURI
        RedisURI redisUri = RedisURI.builder()
                .host(redisHost)
                .port(redisPort)
                .password(accessToken.getToken())
                .ssl(true) // Azure Redis默认强制SSL
                .build();

        RedisClient redisClient = RedisClient.create(redisUri);
        LettuceConnectionFactory connectionFactory = new LettuceConnectionFactory(redisClient);
        connectionFactory.afterPropertiesSet();
        return connectionFactory;
    }

    @Bean
    public RedisTemplate<String, Object> redisTemplate(RedisConnectionFactory connectionFactory) {
        RedisTemplate<String, Object> template = new RedisTemplate<>();
        template.setConnectionFactory(connectionFactory);
        // 配置序列化器(根据业务需求调整)
        template.setKeySerializer(new StringRedisSerializer());
        template.setValueSerializer(new GenericJackson2JsonRedisSerializer());
        return template;
    }
}
  1. 令牌自动刷新处理
    由于Entra ID令牌存在有效期(通常1小时),需实现令牌自动刷新逻辑:
  • 可以通过定时任务定期刷新令牌,更新RedisURI的密码并重启连接客户端;
  • 利用Lettuce的ConnectionProvider扩展,实现动态获取最新令牌的逻辑。

方案2:使用Azure Redis Spring Boot Starter

微软官方提供的azure-spring-boot-starter-redis已集成Entra ID认证支持,只需简单配置即可:

  1. 引入依赖
<dependency>
    <groupId>com.azure.spring</groupId>
    <artifactId>azure-spring-boot-starter-redis</artifactId>
    <version>3.20.0</version> <!-- 使用最新稳定版 -->
</dependency>
  1. 配置文件设置
# Redis实例信息
spring.data.redis.host=your-redis-resource.redis.cache.windows.net
spring.data.redis.port=6380
spring.data.redis.ssl=true

# 启用Entra ID认证
azure.redis.entra-id-enabled=true

该starter会自动使用DefaultAzureCredential获取令牌完成认证,无需手动处理连接工厂配置,同时内置了令牌刷新机制。

前置条件

  • Azure Redis实例已启用Entra ID认证;
  • 应用所在的服务主体(或托管标识)已被分配Redis的访问角色(如Redis Contributor、Redis Reader);
  • 应用运行环境支持DefaultAzureCredential的身份验证方式(如Azure VM/AKS、本地开发环境配置Azure CLI登录)。

内容的提问来源于stack exchange,提问作者Gekster

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 01:37:03