如何获取IBM Cloud Kubernetes中Redis的URI以通过IBM Functions访问
Let's break down how to get the correct Redis URI and connect successfully, since you're running Redis on IBM Cloud Kubernetes Service without a password by default.
Step 1: Expose Redis to be accessible from outside the Kubernetes cluster
By default, Kubernetes services use ClusterIP which only allows internal cluster access. Since IBM Functions runs outside your K8s cluster, you need to expose Redis via a LoadBalancer service (IBM Cloud will provision a public IP for this) or use VPC peering for a more secure internal connection.
Option 1: Use LoadBalancer (quick for testing)
- Check your existing Redis service with:
kubectl get svc - If your Redis service is
ClusterIP, update its configuration toLoadBalancer:
Create or edit aredis-service.yamlfile:apiVersion: v1 kind: Service metadata: name: redis-service # Match your existing service name spec: type: LoadBalancer selector: app: redis # Match your Redis deployment's label ports: - port: 6379 targetPort: 6379 # Match Redis container port - Apply the change:
kubectl apply -f redis-service.yaml
Step 2: Get the Redis URI
After updating the service, wait a minute for IBM Cloud to assign an external IP. Run this command again:
kubectl get svc redis-service
Look for the EXTERNAL-IP column — this is your public access IP.
Your Redis URI will be:
redis://<EXTERNAL-IP>:6379
Since there's no password, we don't include any auth credentials in the URI.
Step 3: Use the URI in your IBM Functions JavaScript function
Here's a working example function that connects to Redis, sets a key, retrieves it, and returns the value:
const redis = require('redis'); async function main(params) { // Replace <EXTERNAL-IP> with your Redis service's external IP const redisUri = 'redis://<EXTERNAL-IP>:6379'; const client = redis.createClient({ url: redisUri }); // Handle connection errors client.on('error', (err) => console.error('Redis connection error:', err)); try { await client.connect(); await client.set('ibm-functions-test', 'Hello from IBM Functions!'); const storedValue = await client.get('ibm-functions-test'); await client.disconnect(); return { result: `Success! Retrieved value: ${storedValue}` }; } catch (err) { return { error: `Failed to interact with Redis: ${err.message}` }; } } exports.main = main;
Security Note (Critical for Production)
Since Redis is exposed publicly without a password, it's extremely vulnerable to unauthorized access. For production environments:
- Set a Redis password by adding an environment variable to your Redis deployment:
env: - name: REDIS_PASSWORD value: "your-strong-password-here" - Update your URI to include the password:
redis://:<your-strong-password-here>@<EXTERNAL-IP>:6379 - Consider using VPC peering instead of a public LoadBalancer to keep traffic within IBM Cloud's private network (this requires configuring VPC peering between your K8s cluster's VPC and the IBM Functions runtime VPC, then using the Redis service's
ClusterIPin your URI).
内容的提问来源于stack exchange,提问作者Thomas Suedbroecker

