<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sre on brtkwr.com</title><link>https://brtkwr.com/tags/sre/</link><description>Recent content in Sre on brtkwr.com</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 28 Sep 2026 16:00:00 +0000</lastBuildDate><atom:link href="https://brtkwr.com/tags/sre/index.xml" rel="self" type="application/rss+xml"/><item><title>Zero-downtime Redis password rotation</title><link>https://brtkwr.com/posts/2026-09-28-zero-downtime-redis-password-rotation/</link><pubDate>Mon, 28 Sep 2026 16:00:00 +0000</pubDate><guid>https://brtkwr.com/posts/2026-09-28-zero-downtime-redis-password-rotation/</guid><description>&lt;h2 id="tldr">
 TL;DR
 &lt;a class="heading-link" href="#tldr">
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading">&lt;/i>
 &lt;span class="sr-only">Link to heading&lt;/span>
 &lt;/a>
&lt;/h2>
&lt;p>A Redis ACL user can hold two passwords at once, so a rotation needs no moment where
anyone is locked out. Add the new password to every Redis and Sentinel process, publish
it, restart the clients, then restart the Redis pods one by one. The restarts remove the
old password; you can&amp;rsquo;t do it at runtime on the Bitnami chart, because the health probes
still log in with it. Before restarting, move &lt;code>sentinel-pass&lt;/code> to the new password as
well, or the Sentinels lock each other out.&lt;/p></description></item></channel></rss>