如何在Azure Kubernetes默认VNet中配置Azure Redis Cache?
Hey there! Let's work through your Azure Redis Cache + AKS VNet deployment problem together. First, let's cover the most common errors you might be facing and their fixes, then walk through the full configuration process step by step.
Common Errors & Quick Fixes
Let’s start with the typical issues that pop up when trying to link Redis to your AKS VNet:
Subnet Permission/Service Endpoint Missing
If you’re getting a "failed to associate subnet" error, chances are your subnet doesn’t have theMicrosoft.Cacheservice endpoint enabled. Azure Redis needs this to access the VNet securely.- Fix: Update your subnet to add the service endpoint via CLI:
az network vnet subnet update --resource-group <AKS-Node-RG> --vnet-name <aks-vnet-xxx> --name <target-subnet> --service-endpoints Microsoft.Cache
Or do it via the Azure Portal: Go to your VNet → Subnets → Select your subnet → Enable "Microsoft.Cache" under Service endpoints.
- Fix: Update your subnet to add the service endpoint via CLI:
Insufficient Subnet Size
Azure Redis (Premium SKU) requires a subnet with at least a/24address range (256 IPs) because each cache instance uses multiple private IPs. If your subnet is smaller, you’ll hit a validation error.- Fix: Either resize your existing subnet (if no other resources are using it) or create a new
/24subnet in the same AKS VNet specifically for Redis.
- Fix: Either resize your existing subnet (if no other resources are using it) or create a new
Wrong SKU Selected
Only the Premium SKU of Azure Redis supports VNet integration. If you’re trying to use Basic or Standard, this will fail outright.- Fix: Switch to Premium SKU when creating your Redis Cache.
Region Mismatch
Your Redis Cache must be deployed in the same Azure region as your AKS cluster. Cross-region VNet integration isn’t supported here.- Fix: Delete the existing Redis (if in wrong region) and recreate it in the same region as your AKS cluster.
Insufficient Permissions
The account you’re using to deploy Redis needs theNetwork Contributorrole on the AKS VNet’s resource group. Without this, you can’t associate the cache to the VNet.- Fix: Assign the
Network Contributorrole to your account via the Azure Portal (Access control (IAM) → Add role assignment) or CLI:az role assignment create --assignee <your-email-or-object-id> --role "Network Contributor" --scope <aks-vnet-resource-id>
- Fix: Assign the
Step-by-Step Configuration Guide
Once you’ve fixed any existing errors, here’s how to properly set up Redis in your AKS VNet:
1. Gather AKS VNet Details
First, get the resource group and VNet name for your AKS cluster:
# Get the AKS node resource group (where the VNet lives) AKS_NODE_RG=$(az aks show --resource-group <AKS-Resource-Group> --name <AKS-Cluster-Name> --query "nodeResourceGroup" -o tsv) # List the VNet in that resource group to get its ID and name az network vnet list --resource-group $AKS_NODE_RG --query "[].{name:name, id:id}"
2. Create a Dedicated Subnet for Redis (Optional but Recommended)
It’s best to use a separate subnet for Redis to avoid IP conflicts. Create one with a /24 range:
az network vnet subnet create --resource-group $AKS_NODE_RG --vnet-name <aks-vnet-xxx> --name redis-subnet --address-prefixes 10.240.2.0/24
3. Enable Service Endpoint on the Redis Subnet
As mentioned earlier, enable the Microsoft.Cache service endpoint on your new subnet:
az network vnet subnet update --resource-group $AKS_NODE_RG --vnet-name <aks-vnet-xxx> --name redis-subnet --service-endpoints Microsoft.Cache
4. Deploy Azure Redis Cache to the AKS VNet
Use the Premium SKU and link it to your subnet:
az redis create --resource-group <Your-Resource-Group> --name <Your-Redis-Name> --location <AKS-Region> --sku Premium --vm-size c6 --subnet $(az network vnet subnet show --resource-group $AKS_NODE_RG --vnet-name <aks-vnet-xxx> --name redis-subnet --query id -o tsv)
If using the Azure Portal:
- Go to Create → Azure Cache for Redis
- Select Premium SKU, choose your region (same as AKS)
- Under Networking, select "Virtual Network"
- Pick your AKS VNet and the dedicated Redis subnet you created
5. Configure AKS App to Access Redis
- Store your Redis connection string in a Kubernetes Secret:
kubectl create secret generic redis-connection --from-literal=REDIS_CONN_STRING="<your-redis-connection-string>" - In your app deployment manifest, reference this secret as an environment variable so your app can connect to the Redis cache (since they’re in the same VNet, the private IP or hostname will resolve correctly).
6. Verify the Connection
Test connectivity from an AKS pod to confirm everything works:
# Run a temporary busybox pod kubectl run -it --rm busybox --image=busybox:1.28 --restart=Never # Inside the pod, test SSL connection to Redis (replace with your Redis hostname) telnet <your-redis-hostname>.redis.cache.windows.net 6380
If the connection succeeds, you’ll see a blank prompt (that’s normal for telnet over TLS). Alternatively, use redis-cli if you have it installed in the pod.
内容的提问来源于stack exchange,提问作者user1480180

