Skip to main content

Managed Valkey (Spotahome Sentinel)

Okustera Managed Valkey delivers enterprise-grade, high-performance in-memory caching and key-value storage powered by Valkey 7.2 (valkey/valkey:7.2.7) and orchestrated by the Spotahome Operator.

Valkey is a community-driven, truly open-source high-performance key-value store maintaining 100% wire-protocol compatibility with the standard RESP specification.

Designed for sub-millisecond latency ($< 1$ ms), it provides automated 3-node Sentinel quorum election, automatic master failover in under 10 seconds, dynamic Ceph NVMe persistence, and automated credential escrow with OpenStack Barbican KMS.


Architectural Highlights​

  • Automated Sentinel Failover: Sentinels continuously monitor the master pod. If unresponsive for $> 5$ seconds, a replacement master is automatically promoted with zero manual intervention.
  • Ceph NVMe Persistence: Data safety is guaranteed through Append-Only File (AOF) and Point-in-Time RDB snapshots mounted on Ceph NVMe PersistentVolumes (ceph-rbd StorageClass).
  • Wire Compatibility: Fully compatible with standard client SDKs (valkey-py, iovalkey, go-valkey).
  • Barbican KMS Key Escrow: Cluster authentication passwords are encrypted and vaulted in OpenStack Barbican, syncing to Kubernetes Secrets (valkey-<name>-auth) automatically.

Provisioning with Terraform​

Declare Valkey clusters using the official Okustera Terraform provider:

resource "okustera_database_valkey" "session_cache" {
name = "production-session-cache"
namespace = "tenant-app"
replicas = 3
sentinel_replicas = 3
memory_limit = "4Gi"
storage_size = "10Gi"
storage_class = "ceph-rbd"
}

output "valkey_master_endpoint" {
value = okustera_database_valkey.session_cache.master_endpoint
}

output "valkey_sentinel_endpoint" {
value = okustera_database_valkey.session_cache.sentinel_endpoint
}

Refer to the Terraform Resource Reference for complete schema documentation.


Connecting from Python (valkey-py)​

Because Valkey 7.2 is fully RESP protocol compatible, standard clients connect seamlessly:

import valkey
from valkey.sentinel import Sentinel

# Initialize Sentinel discovery client
sentinel = Sentinel([
('rfr-production-session-cache.tenant-app.svc.cluster.local', 26379)
], socket_timeout=0.5)

# Discover current Valkey master
master = sentinel.master_for('mymaster', socket_timeout=0.5, password='<PASSWORD>')

# Discover read replicas
slave = sentinel.slave_for('mymaster', socket_timeout=0.5, password='<PASSWORD>')

# Execute in-memory cache operations
master.set('session:token:9012', 'authenticated', ex=3600)
session_state = slave.get('session:token:9012')
print("Session State:", session_state)