diff --git a/content/operate/kubernetes/active-active/_index.md b/content/operate/kubernetes/active-active/_index.md
index 8507cdd046..6267840534 100644
--- a/content/operate/kubernetes/active-active/_index.md
+++ b/content/operate/kubernetes/active-active/_index.md
@@ -11,7 +11,7 @@ linkTitle: Active-Active databases
weight: 40
---
-Redis Enterprise [Active-Active]({{< relref "/operate/rs/databases/active-active/" >}}) databases on Kubernetes provide read and write access to the same dataset from different Kubernetes clusters. This enables globally distributed applications with local read and write access, automatic conflict resolution, and seamless failover capabilities.
+Redis Enterprise [Active-Active](/content/operate/rs/databases/active-active/_index.md) databases on Kubernetes provide read and write access to the same dataset from different Kubernetes clusters. This enables globally distributed applications with local read and write access, automatic conflict resolution, and seamless failover capabilities.
Active-Active databases use multi-master replication to keep data synchronized across participating clusters, allowing applications to read and write data locally while maintaining global consistency.
@@ -31,9 +31,9 @@ Versions 6.4.2-6 or later fully support the Active-Active controller. Some of th
This setup method includes the following steps:
-1. Gather REC credentials and [prepare participating clusters]({{< relref "/operate/kubernetes/active-active/prepare-clusters" >}}).
-2. Create [`RedisEnterpriseRemoteCluster` (RERC)]({{< relref "/operate/kubernetes/active-active/create-reaadb#create-rerc" >}}) resources.
-3. Create [`RedisEnterpriseActiveActiveDatabase` (REAADB)]({{< relref "/operate/kubernetes/active-active/create-reaadb#create-reaadb" >}}) resource.
+1. Gather REC credentials and [prepare participating clusters](/content/operate/kubernetes/active-active/prepare-clusters.md).
+2. Create [`RedisEnterpriseRemoteCluster` (RERC)](/content/operate/kubernetes/active-active/create-reaadb.md#create-rerc) resources.
+3. Create [`RedisEnterpriseActiveActiveDatabase` (REAADB)](/content/operate/kubernetes/active-active/create-reaadb.md#create-reaadb) resource.
### `crdb-cli` method
@@ -46,33 +46,34 @@ For versions 6.4.2 or earlier, this Active-Active setup method includes the foll
## Redis Enterprise Active-Active controller for Kubernetes
-{{}}These features are supported for general availability in releases 6.4.2-6 and later.{{}}
+> [!NOTE]
+> These features are supported for general availability in releases 6.4.2-6 and later.
-[Active-Active]({{< relref "/operate/rs/databases/active-active/" >}}) databases give you read-and-write access to Redis Enterprise clusters (REC) in different Kubernetes clusters or namespaces. Active-Active deployments managed by the Redis Enterprise operator require two additional custom resources: Redis Enterprise Active-Active database (REAADB) and Redis Enterprise remote cluster (RERC).
+[Active-Active](/content/operate/rs/databases/active-active/_index.md) databases give you read-and-write access to Redis Enterprise clusters (REC) in different Kubernetes clusters or namespaces. Active-Active deployments managed by the Redis Enterprise operator require two additional custom resources: Redis Enterprise Active-Active database (REAADB) and Redis Enterprise remote cluster (RERC).
-To create an Active-Active Redis Enterprise deployment for Kubernetes with these new features, first [prepare participating clusters]({{< relref "/operate/kubernetes/active-active/prepare-clusters" >}}) then [create an Active-Active database]({{< relref "/operate/kubernetes/active-active/create-reaadb" >}}).
+To create an Active-Active Redis Enterprise deployment for Kubernetes with these new features, first [prepare participating clusters](/content/operate/kubernetes/active-active/prepare-clusters.md) then [create an Active-Active database](/content/operate/kubernetes/active-active/create-reaadb.md).
### REAADB custom resource
Redis Enterprise Active-Active database (REAADB) contains a link to the RERC for each participating cluster, and provides configuration and status to the management plane.
-For a full list of fields and options, see the [REAADB API reference]({{}}).
+For a full list of fields and options, see the [REAADB API reference](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md).
-For examples, see the [YAML examples]({{< relref "/operate/kubernetes/reference/yaml/active-active" >}}) section.
+For examples, see the [YAML examples](/content/operate/kubernetes/reference/yaml/active-active.md) section.
### RERC custom resource
Redis Enterprise remote cluster (RERC) custom resource contains configuration details for all the participating clusters.
-For a full list of fields and options, see the [RERC API reference]({{}}).
+For a full list of fields and options, see the [RERC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md).
-For examples, see the [YAML examples]({{< relref "/operate/kubernetes/reference/yaml/active-active" >}}) section.
+For examples, see the [YAML examples](/content/operate/kubernetes/reference/yaml/active-active.md) section.
### Manage certificates
The operator automates Active-Active certificate updates. When you update the proxy or syncer certificate secret on a participating cluster's REC, the operator detects the change and propagates the new certificate to the other participating clusters.
-For details, see [Manage REC certificates]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) and [cert-manager integration]({{< relref "/operate/kubernetes/security/certificates/cert-manager" >}}).
+For details, see [Manage REC certificates](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) and [cert-manager integration](/content/operate/kubernetes/security/certificates/cert-manager.md).
### Limitations
@@ -83,8 +84,8 @@ For details, see [Manage REC certificates]({{< relref "/operate/kubernetes/secur
* Only global database options are supported, no support for specifying configuration per location.
* No support for migration from old (`crdb-cli`) Active-Active database method to new Active-Active controller.
* No support for REAADB with participating clusters co-located within the same Kubernetes cluster, except for a single designated local participating cluster.
-* Active-Active databases cannot be configured as [Redis Flex]({{< relref "/operate/kubernetes/flex" >}}) deployments.
+* Active-Active databases cannot be configured as [Redis Flex](/content/operate/kubernetes/flex/_index.md) deployments.
## More info
-For more general information about Active-Active, see the [Redis Enterprise Software docs]({{< relref "/operate/rs/databases/active-active/" >}}).
+For more general information about Active-Active, see the [Redis Enterprise Software docs](/content/operate/rs/databases/active-active/_index.md).
diff --git a/content/operate/kubernetes/active-active/create-aa-crdb-cli.md b/content/operate/kubernetes/active-active/create-aa-crdb-cli.md
index 32d1cb1379..d48df5ea53 100644
--- a/content/operate/kubernetes/active-active/create-aa-crdb-cli.md
+++ b/content/operate/kubernetes/active-active/create-aa-crdb-cli.md
@@ -10,11 +10,12 @@ description: This section shows how to set up an Active-Active Redis Enterprise
linkTitle: Create Active-Active with crdb-cli
weight: 99
---
-{{}} Versions 6.4.2 and later support the Active-Active database controller. This controller allows you to create Redis Enterprise Active-Active databases (REAADB) and Redis Enterprise remote clusters (RERC) with custom resources. We recommend using the [REAADB method for creating Active-Active databases]({{< relref "/operate/kubernetes/active-active/create-reaadb" >}}).{{}}
+> [!NOTE]
+> Versions 6.4.2 and later support the Active-Active database controller. This controller allows you to create Redis Enterprise Active-Active databases (REAADB) and Redis Enterprise remote clusters (RERC) with custom resources. We recommend using the [REAADB method for creating Active-Active databases](/content/operate/kubernetes/active-active/create-reaadb.md).
-On Kubernetes, Redis Enterprise [Active-Active]({{< relref "/operate/rs/databases/active-active/" >}}) databases provide read-and-write access to the same dataset from different Kubernetes clusters. For more general information about Active-Active, see the [Redis Enterprise Software docs]({{< relref "/operate/rs/databases/active-active/" >}}).
+On Kubernetes, Redis Enterprise [Active-Active](/content/operate/rs/databases/active-active/_index.md) databases provide read-and-write access to the same dataset from different Kubernetes clusters. For more general information about Active-Active, see the [Redis Enterprise Software docs](/content/operate/rs/databases/active-active/_index.md).
-Creating an Active-Active database requires routing [network access]({{< relref "/operate/kubernetes/networking/" >}}) between two Redis Enterprise clusters residing in different Kubernetes clusters. Without the proper access configured for each cluster, syncing between the databases instances will fail.
+Creating an Active-Active database requires routing [network access](/content/operate/kubernetes/networking/_index.md) between two Redis Enterprise clusters residing in different Kubernetes clusters. Without the proper access configured for each cluster, syncing between the databases instances will fail.
This process consists of:
@@ -26,11 +27,12 @@ This process consists of:
Before creating Active-Active databases, you'll need admin access to two or more working Kubernetes clusters that each have:
-- Routing for external access with an [ingress resources]({{< relref "/operate/kubernetes/networking/ingress" >}}) (or [route resources]({{< relref "/operate/kubernetes/networking/routes" >}}) on OpenShift).
-- A working [Redis Enterprise cluster (REC)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) with a unique name.
-- Enough memory resources available for the database (see [hardware requirements]({{< relref "/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements" >}})).
+- Routing for external access with an [ingress resources](/content/operate/kubernetes/networking/ingress.md) (or [route resources](/content/operate/kubernetes/networking/routes.md) on OpenShift).
+- A working [Redis Enterprise cluster (REC)](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) with a unique name.
+- Enough memory resources available for the database (see [hardware requirements](/content/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements.md)).
-{{}} The `activeActive` field and the `ingressOrRouteSpec` field cannot coexist in the same REC. If you configured your ingress via the `ingressOrRouteSpec` field in the REC, create your Active-Active database with the RedisEnterpriseActiveActiveDatabase (REAADB) custom resource.{{}}
+> [!NOTE]
+> The `activeActive` field and the `ingressOrRouteSpec` field cannot coexist in the same REC. If you configured your ingress via the `ingressOrRouteSpec` field in the REC, create your Active-Active database with the RedisEnterpriseActiveActiveDatabase (REAADB) custom resource.
## Document required parameters
@@ -49,9 +51,8 @@ The most common mistake when setting up Active-Active databases is incorrect or
You'll need the following information for each participating Redis Enterprise cluster (REC):
-{{}}
-You'll need to create DNS aliases to resolve your API hostname ``,``, `` to the IP address for the ingress controller’s LoadBalancer (or routes in Openshift) for each database. To avoid entering multiple DNS records, you can use a wildcard in your alias (such as *.ijk.example.com).
-{{}}
+> [!NOTE]
+> You'll need to create DNS aliases to resolve your API hostname ``,``, `` to the IP address for the ingress controller’s LoadBalancer (or routes in Openshift) for each database. To avoid entering multiple DNS records, you can use a wildcard in your alias (such as *.ijk.example.com).
- **REC hostname** ``:
- Description: Hostname used to identify your Redis Enterprise cluster in the `crdb-cli` command. This MUST be different from other participating clusters.
@@ -69,7 +70,7 @@ You'll need to create DNS aliases to resolve your API hostname ``,
- Description: Combined with database name to create the Active-Active database hostname
- Format: string
- Example value: `-cluster.ijk.example.com`
-- [**REC admin credentials**]({{< relref "/operate/kubernetes/security/authentication/manage-rec-credentials" >}}) ` `:
+- [**REC admin credentials**](/content/operate/kubernetes/security/authentication/manage-rec-credentials.md) ` `:
- Description: Admin username and password for the REC stored in a secret
- Format: string
- Example value: username: `user@example.com`, password: `something`
@@ -99,7 +100,7 @@ From inside your K8s cluster, edit your Redis Enterprise cluster (REC) resource
### Using ingress controller
-1. If your cluster uses an [ingress controller]({{< relref "/operate/kubernetes/networking/ingress" >}}), add the following to the `spec` section of your REC resource file.
+1. If your cluster uses an [ingress controller](/content/operate/kubernetes/networking/ingress.md), add the following to the `spec` section of your REC resource file.
Nginx:
@@ -146,11 +147,10 @@ HAproxy:
#### If using Istio Gateway and VirtualService
-No changes are required to the REC spec if you are using [Istio]({{< relref "/operate/kubernetes/networking/istio-ingress" >}}) in place of an ingress controller. The `activeActive` section added above creates ingress resources. The two custom resources used to configure Istio (Gateway and VirtualService) replace the need for ingress resources.
+No changes are required to the REC spec if you are using [Istio](/content/operate/kubernetes/networking/istio-ingress.md) in place of an ingress controller. The `activeActive` section added above creates ingress resources. The two custom resources used to configure Istio (Gateway and VirtualService) replace the need for ingress resources.
-{{}}
-These custom resources are not controlled by the operator and will need to be configured and maintained manually.
-{{}}
+> [!WARNING]
+> These custom resources are not controlled by the operator and will need to be configured and maintained manually.
For each cluster, verify the VirtualService resource has two `- match:` blocks in the `tls` section. The hostname under `sniHosts:` should match your ``.
@@ -173,7 +173,7 @@ For each cluster, verify the VirtualService resource has two `- match:` blocks i
1. Make sure you have DNS aliases for each database that resolve your API hostname ``,``, `` to the route IP address. To avoid entering multiple DNS records, you can use a wildcard in your alias (such as `*.ijk.example.com`).
-1. If your cluster uses [OpenShift routes]({{< relref "/operate/kubernetes/networking/routes" >}}), add the following to the `spec` section of your Redis Enterprise cluster (REC) resource file.
+1. If your cluster uses [OpenShift routes](/content/operate/kubernetes/networking/routes.md), add the following to the `spec` section of your Redis Enterprise cluster (REC) resource file.
```sh
activeActive:
@@ -194,7 +194,7 @@ For each cluster, verify the VirtualService resource has two `- match:` blocks i
## Create an Active-Active database with `crdb-cli`
-The `crdb-cli` command can be run from any Redis Enterprise pod hosted on any participating K8s cluster. You'll need the values for the [required parameters]({{< relref "/operate/kubernetes/active-active/create-aa-crdb-cli#document-required-parameters" >}}) for each Redis Enterprise cluster.
+The `crdb-cli` command can be run from any Redis Enterprise pod hosted on any participating K8s cluster. You'll need the values for the [required parameters](/content/operate/kubernetes/active-active/create-aa-crdb-cli.md#document-required-parameters) for each Redis Enterprise cluster.
```sh
crdb-cli crdb create \
@@ -207,10 +207,10 @@ crdb-cli crdb create \
To create a database that syncs between more than two instances, add additional `--instance` arguments.
-See the [`crdb-cli` reference]({{< relref "/operate/rs/references/cli-utilities/crdb-cli" >}}) for more options.
+See the [`crdb-cli` reference](/content/operate/rs/references/cli-utilities/crdb-cli/_index.md) for more options.
## Test your database
The easiest way to test your Active-Active database is to set a key-value pair in one database and retrieve it from the other.
-You can connect to your databases with the instructions in [Manage databases]({{< relref "/operate/kubernetes/re-databases/db-controller#connect-to-a-database" >}}). Set a test key with `SET foo bar` in the first database. If your Active-Active deployment is working properly, when connected to your second database, `GET foo` should output `bar`.
+You can connect to your databases with the instructions in [Manage databases](/content/operate/kubernetes/re-databases/db-controller.md#connect-to-a-database). Set a test key with `SET foo bar` in the first database. If your Active-Active deployment is working properly, when connected to your second database, `GET foo` should output `bar`.
diff --git a/content/operate/kubernetes/active-active/create-reaadb.md b/content/operate/kubernetes/active-active/create-reaadb.md
index 913f90b5ac..337093aa39 100644
--- a/content/operate/kubernetes/active-active/create-reaadb.md
+++ b/content/operate/kubernetes/active-active/create-reaadb.md
@@ -16,18 +16,19 @@ weight: 30
To create an Active-Active database, make sure you've completed all the following steps and have gathered the information listed below each step.
-1. Configure the [admission controller and ValidatingWebhook]({{< relref "/operate/kubernetes/deployment/quick-start#enable-the-admission-controller/" >}}).
- {{}}These are installed and enabled by default on clusters created via the OpenShift OperatorHub. {{}}
+1. Configure the [admission controller and ValidatingWebhook](/content/operate/kubernetes/deployment/quick-start.md#enable-the-admission-controller/).
+ > [!NOTE]
+ > These are installed and enabled by default on clusters created via the OpenShift OperatorHub.
-2. Create two or more [RedisEnterpriseCluster (REC) custom resources]({{< relref "/operate/kubernetes/deployment/quick-start#create-a-redis-enterprise-cluster-rec" >}}) with enough [memory resources]({{< relref "/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements" >}}).
+2. Create two or more [RedisEnterpriseCluster (REC) custom resources](/content/operate/kubernetes/deployment/quick-start.md#create-a-redis-enterprise-cluster-rec) with enough [memory resources](/content/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements.md).
* Name of each REC (``)
* Namespace for each REC (``)
-3. Configure the REC [`ingressOrRoutes` field]({{< relref "/operate/kubernetes/networking/ingressorroutespec" >}}) and [create DNS records]({{< relref "/operate/kubernetes/networking/ingressorroutespec#configure-dns/" >}}).
+3. Configure the REC [`ingressOrRoutes` field](/content/operate/kubernetes/networking/ingressorroutespec.md) and [create DNS records](/content/operate/kubernetes/networking/ingressorroutespec.md#configure-dns/).
* REC API hostname (`api--.`)
* Database hostname suffix (`.db--.`)
-4. [Prepare participating clusters]({{< relref "/operate/kubernetes/active-active/prepare-clusters" >}})
+4. [Prepare participating clusters](/content/operate/kubernetes/active-active/prepare-clusters.md)
* RERC name (`)
* RERC secret name (`redis-enterprise-`)
@@ -47,7 +48,7 @@ Example RERC (`rerc-raegan`) for the REC named `rec-arlington` in the namespace
{{}}
-For more details on RERC fields, see the [RERC API reference]({{}}).
+For more details on RERC fields, see the [RERC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md).
2. Create a Redis Enterprise remote cluster from each RERC custom resource file.
@@ -89,9 +90,10 @@ Example REAADB named `reaadb-boeing` linked to the REC named `rec-chicago` with
{{}}
-{{}}Sharding is disabled on Active-Active databases created with a `shardCount` of 1. Sharding cannot be enabled after database creation. {{}}
+> [!NOTE]
+> Sharding is disabled on Active-Active databases created with a `shardCount` of 1. Sharding cannot be enabled after database creation.
-For more details on RERC fields, see the [RERC API reference]({{}}).
+For more details on RERC fields, see the [RERC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md).
2. Create a Redis Enterprise Active-Active database from the REAADB custom resource file.
@@ -116,11 +118,11 @@ reaadb-boeing active Valid up
In case of errors, review the REAADB custom resource events and the Redis Enterprise operator logs.
-To add tags to an Active-Active database and expose them as metric labels, see [Enrich database metrics with tags]({{< relref "/operate/kubernetes/re-databases/enrich-metrics-with-tags" >}}).
+To add tags to an Active-Active database and expose them as metric labels, see [Enrich database metrics with tags](/content/operate/kubernetes/re-databases/enrich-metrics-with-tags.md).
## Example values
-This article uses the example values listed below. You can also find them in the [YAML examples]({{< relref "/operate/kubernetes/reference/yaml/active-active" >}}) section.
+This article uses the example values listed below. You can also find them in the [YAML examples](/content/operate/kubernetes/reference/yaml/active-active.md) section.
Example cluster 1:
diff --git a/content/operate/kubernetes/active-active/edit-clusters.md b/content/operate/kubernetes/active-active/edit-clusters.md
index e05dba9fc3..b1a8da9215 100644
--- a/content/operate/kubernetes/active-active/edit-clusters.md
+++ b/content/operate/kubernetes/active-active/edit-clusters.md
@@ -10,7 +10,8 @@ description: Steps to add or remove a participating cluster to an existing Activ
linkTitle: Edit participating clusters
weight: 40
---
-{{}}This feature is supported for general availability in releases 6.4.2-6 and later. Some of these features were available as a preview in 6.4.2-4 and 6.4.2-5. Please upgrade to 6.4.2-6 for the full set of general availability features and bug fixes. and later.{{}}
+> [!NOTE]
+> This feature is supported for general availability in releases 6.4.2-6 and later. Some of these features were available as a preview in 6.4.2-4 and 6.4.2-5. Please upgrade to 6.4.2-6 for the full set of general availability features and bug fixes. and later.
## Add a participating cluster
@@ -18,7 +19,7 @@ Use the following steps to add a participating cluster to an existing Redis Ente
### Prerequisites
-To prepare the Redis Enterprise cluster (REC) to participate in an Active-Active database, perform the following tasks from [Prepare participating clusters]({{< relref "/operate/kubernetes/active-active/prepare-clusters" >}}):
+To prepare the Redis Enterprise cluster (REC) to participate in an Active-Active database, perform the following tasks from [Prepare participating clusters](/content/operate/kubernetes/active-active/prepare-clusters.md):
- Make sure the cluster meets the hardware and naming requirements.
- Enable the Active-Active controllers.
diff --git a/content/operate/kubernetes/active-active/edit-rerc.md b/content/operate/kubernetes/active-active/edit-rerc.md
index 49fe7d7a5f..acfec81d64 100644
--- a/content/operate/kubernetes/active-active/edit-rerc.md
+++ b/content/operate/kubernetes/active-active/edit-rerc.md
@@ -10,17 +10,18 @@ description: Edit the configuration details of an existing RERC with Redis Enter
linkTitle: Edit RERC
weight: 60
---
-{{}}This feature is supported for general availability in releases 6.4.2-6 and later. Some of these features were available as a preview in 6.4.2-4 and 6.4.2-5. Please upgrade to 6.4.2-6 for the full set of general availability features and bug fixes. and later.{{}}
+> [!NOTE]
+> This feature is supported for general availability in releases 6.4.2-6 and later. Some of these features were available as a preview in 6.4.2-4 and 6.4.2-5. Please upgrade to 6.4.2-6 for the full set of general availability features and bug fixes. and later.
Before a RedisEnterpriseCluster (REC) can participate in an Active-Active database, it needs an accompanying RedisEnterpriseRemoteCluster (RERC) custom resource. The RERC contains details allowing the REC to link to the RedisEnterpriseActiveActiveDatabase (REAADB). The RERC resource is listed in the REAADB resource to become a participating cluster for the Active-Active database.
The RERC controller periodically connects to the local REC endpoint via its external address, to ensure it’s setup correctly. For this to work, the external load balancer must support [NAT hairpinning](https://en.wikipedia.org/wiki/Network_address_translation#NAT_loopback). In some cloud environments, this may involve disabling IP preservation for the load balancer target groups.
-For more details, see the [RERC API reference]({{}}).
+For more details, see the [RERC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md).
## Edit RERC
-Use the `kubectl patch rerc --type merge --patch` command to patch the local RERC custom resource with your changes. For a full list of available fields, see the [RERC API reference]({{}}).
+Use the `kubectl patch rerc --type merge --patch` command to patch the local RERC custom resource with your changes. For a full list of available fields, see the [RERC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md).
The following example edits the `dbFqdnSuffix` field for the RERC named `rerc-ohare`.
@@ -67,7 +68,7 @@ If the credentials are changed or updated for a REC participating cluster, you n
rerc-ohare Active Valid true
```
- To troubleshoot invalid configurations, view the RERC custom resource events and the [Redis Enterprise operator logs]({{< relref "/operate/kubernetes/logs/" >}}).
+ To troubleshoot invalid configurations, view the RERC custom resource events and the [Redis Enterprise operator logs](/content/operate/kubernetes/logs/_index.md).
1. Verify the status of each REAADB using that RERC is "Active" and the spec status is "Valid."
@@ -81,6 +82,6 @@ If the credentials are changed or updated for a REC participating cluster, you n
reaadb-boeing active Valid up
```
- To troubleshoot invalid configurations, view the RERC custom resource events and the [Redis Enterprise operator logs]({{< relref "/operate/kubernetes/logs/" >}}).
+ To troubleshoot invalid configurations, view the RERC custom resource events and the [Redis Enterprise operator logs](/content/operate/kubernetes/logs/_index.md).
1. Repeat the above steps on all other participating clusters.
\ No newline at end of file
diff --git a/content/operate/kubernetes/active-active/global-config.md b/content/operate/kubernetes/active-active/global-config.md
index c469e5d3c2..09a9c4dafc 100644
--- a/content/operate/kubernetes/active-active/global-config.md
+++ b/content/operate/kubernetes/active-active/global-config.md
@@ -14,7 +14,7 @@ weight: 50
The Redis Enterprise Active-Active database (REAADB) custom resource contains the field `.spec.globalConfigurations`. This field sets configurations for the Active-Active database across all participating clusters, such as memory size, shard count, and the global database secrets.
-The [REAADB API reference]({{}}) contains a full list of available fields.
+The [REAADB API reference](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md) contains a full list of available fields.
## Edit global configurations
@@ -46,7 +46,7 @@ The [REAADB API reference]({{}}).
+This section edits the secrets under the REAADB `.spec.globalConfigurations` section. For more information and all available fields, see the [REAADB API reference](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md).
1. On an existing participating cluster, generate a YAML file containing the database secret with the relevant data.
@@ -108,19 +108,21 @@ This section edits the secrets under the REAADB `.spec.globalConfigurations` sec
You can configure role-based access control (RBAC) permissions for Active-Active databases using the `rolesPermissions` field in the REAADB `.spec.globalConfigurations` section. The role permissions configuration is propagated across all participating clusters, but the underlying roles and Redis ACLs must be created on each cluster.
-You can define those roles and ACLs as Kubernetes resources with the [`RedisEnterpriseRole`]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}) and [`RedisEnterpriseACL`]({{< relref "/operate/kubernetes/security/access-control/manage-acls" >}}) custom resources, or create them directly through the Redis Enterprise admin console or REST API. For an overview of the Kubernetes-native model, see [Access control]({{< relref "/operate/kubernetes/security/access-control" >}}).
+You can define those roles and ACLs as Kubernetes resources with the [`RedisEnterpriseRole`](/content/operate/kubernetes/security/access-control/manage-roles.md) and [`RedisEnterpriseACL`](/content/operate/kubernetes/security/access-control/manage-acls.md) custom resources, or create them directly through the Redis Enterprise admin console or REST API. For an overview of the Kubernetes-native model, see [Access control](/content/operate/kubernetes/security/access-control/_index.md).
-{{}}You must manually create the specified roles and Redis ACLs on all participating clusters before configuring role permissions. The operator only propagates the role permissions configuration—it does not create the underlying roles and ACLs. If roles or ACLs are missing on any cluster, the operator will log errors and dispatch an Event associated with the REAADB object until they are manually created.{{}}
+> [!NOTE]
+> You must manually create the specified roles and Redis ACLs on all participating clusters before configuring role permissions. The operator only propagates the role permissions configuration—it does not create the underlying roles and ACLs. If roles or ACLs are missing on any cluster, the operator will log errors and dispatch an Event associated with the REAADB object until they are manually created.
### Prerequisites
Before configuring role permissions:
-1. Create the required roles and Redis ACLs on all participating clusters, either as [`RedisEnterpriseRole`]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}) and [`RedisEnterpriseACL`]({{< relref "/operate/kubernetes/security/access-control/manage-acls" >}}) resources or through the Redis Enterprise admin console or REST API.
+1. Create the required roles and Redis ACLs on all participating clusters, either as [`RedisEnterpriseRole`](/content/operate/kubernetes/security/access-control/manage-roles.md) and [`RedisEnterpriseACL`](/content/operate/kubernetes/security/access-control/manage-acls.md) resources or through the Redis Enterprise admin console or REST API.
2. Ensure role and ACL names match exactly across all clusters (names are case-sensitive).
3. Verify that roles and ACLs are properly configured on each cluster.
-{{}}The operator does not automatically create or synchronize roles and ACLs across clusters. You are responsible for manually creating identical roles and ACLs on each participating cluster.{{}}
+> [!WARNING]
+> The operator does not automatically create or synchronize roles and ACLs across clusters. You are responsible for manually creating identical roles and ACLs on each participating cluster.
### Add role permissions to REAADB
@@ -162,7 +164,7 @@ Before configuring role permissions:
'{"spec": {"globalConfigurations": {"rolesPermissions": [{"role": "", "acl": "", "type": "redis-enterprise"}]}}}'
```
-3. After the REAADB is active and its replication status is "Up", verify role permissions are applied to the local database using the Redis Enterprise REST API. See [Database requests]({{}}) for details.
+3. After the REAADB is active and its replication status is "Up", verify role permissions are applied to the local database using the Redis Enterprise REST API. See [Database requests](/content/operate/rs/references/rest-api/requests/bdbs/_index.md#get-bdbs) for details.
### Troubleshooting role permissions
@@ -172,4 +174,4 @@ If you encounter issues with role permissions:
- **Permission propagation failures**: Verify that the roles and ACLs are properly configured and accessible on each cluster. Remember that you must manually create identical roles and ACLs on every participating cluster.
- **Case sensitivity issues**: Verify that role and ACL names match exactly, including capitalization, across all clusters.
-For more details on the `rolesPermissions` field structure, see the [REAADB API reference]({{}}).
\ No newline at end of file
+For more details on the `rolesPermissions` field structure, see the [REAADB API reference](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md#specglobalconfigurationsrolespermissions).
\ No newline at end of file
diff --git a/content/operate/kubernetes/active-active/global-db-secret.md b/content/operate/kubernetes/active-active/global-db-secret.md
index 077174e55c..be0b18bc54 100644
--- a/content/operate/kubernetes/active-active/global-db-secret.md
+++ b/content/operate/kubernetes/active-active/global-db-secret.md
@@ -16,7 +16,7 @@ weight: 50
One of the fields available for `globalConfigurations` is `databaseSecretName` which can point to a secret containing the database password. To set the database secret name and sync the data to all participating clusters, follow the steps below.
-To edit other global configruations, see [global configuration]({{< relref "/operate/kubernetes/active-active/global-config" >}})
+To edit other global configruations, see [global configuration](/content/operate/kubernetes/active-active/global-config.md)
1. On an existing participating cluster, generate a YAML file containing the database secret with the database password.
diff --git a/content/operate/kubernetes/active-active/prepare-clusters.md b/content/operate/kubernetes/active-active/prepare-clusters.md
index c53640735f..58ca79c27b 100644
--- a/content/operate/kubernetes/active-active/prepare-clusters.md
+++ b/content/operate/kubernetes/active-active/prepare-clusters.md
@@ -15,13 +15,13 @@ weight: 10
Before you prepare your clusters to participate in an Active-Active database, make sure you've completed all the following steps and have gathered the information listed below each step.
-1. Configure the [admission controller and ValidatingWebhook]({{< relref "/operate/kubernetes/deployment/quick-start#enable-the-admission-controller/" >}}).
+1. Configure the [admission controller and ValidatingWebhook](/content/operate/kubernetes/deployment/quick-start.md#enable-the-admission-controller/).
-2. Create two or more [RedisEnterpriseCluster (REC) custom resources]({{< relref "/operate/kubernetes/deployment/quick-start#create-a-redis-enterprise-cluster-rec" >}}) with enough [memory resources]({{< relref "/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements" >}}).
+2. Create two or more [RedisEnterpriseCluster (REC) custom resources](/content/operate/kubernetes/deployment/quick-start.md#create-a-redis-enterprise-cluster-rec) with enough [memory resources](/content/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements.md).
* Name of each REC (``)
* Namespace for each REC (``)
-3. Configure the REC [`ingressOrRoutes` field]({{< relref "/operate/kubernetes/networking/ingressorroutespec" >}}) and [create DNS records]({{< relref "/operate/kubernetes/networking/ingressorroutespec#configure-dns/" >}}).
+3. Configure the REC [`ingressOrRoutes` field](/content/operate/kubernetes/networking/ingressorroutespec.md) and [create DNS records](/content/operate/kubernetes/networking/ingressorroutespec.md#configure-dns/).
* REC API hostname (`api--.`)
* Database hostname suffix (`.db--.`)
@@ -81,9 +81,8 @@ To communicate with other clusters, all participating clusters will need access
type: Opaque
```
- {{< note >}}
- The `username` and `password` values should be base64 encoded, not plain text.
- {{< /note >}}
+ > [!NOTE]
+ > The `username` and `password` values should be base64 encoded, not plain text.
1. Add the username and password to the new secret for that REC and namespace.
@@ -122,11 +121,11 @@ To communicate with other clusters, all participating clusters will need access
## Next steps
-Now you are ready to [create your Redis Enterprise Active-Active database]({{< relref "/operate/kubernetes/active-active/create-reaadb" >}}).
+Now you are ready to [create your Redis Enterprise Active-Active database](/content/operate/kubernetes/active-active/create-reaadb.md).
## Example values
-This article uses the example values listed below. They can also be found in the [YAML examples]({{< relref "/operate/kubernetes/reference/yaml/active-active" >}}) section.
+This article uses the example values listed below. They can also be found in the [YAML examples](/content/operate/kubernetes/reference/yaml/active-active.md) section.
Example cluster 1:
diff --git a/content/operate/kubernetes/re-clusters/_index.md b/content/operate/kubernetes/re-clusters/_index.md
index e7d75e1cdf..7f410a3acf 100644
--- a/content/operate/kubernetes/re-clusters/_index.md
+++ b/content/operate/kubernetes/re-clusters/_index.md
@@ -19,22 +19,22 @@ REC resources define the cluster configuration, including node specifications, s
Manage your Redis Enterprise cluster lifecycle and configuration:
-- [Connect to admin console]({{< relref "/operate/kubernetes/re-clusters/connect-to-admin-console" >}}) - Access the Redis Enterprise web UI for cluster management
-- [Multi-namespace deployment]({{< relref "/operate/kubernetes/re-clusters/multi-namespace" >}}) - Deploy clusters across multiple Kubernetes namespaces
-- [Delete custom resources]({{< relref "/operate/kubernetes/re-clusters/delete-custom-resources" >}}) - Safely remove REC and related resources
+- [Connect to admin console](/content/operate/kubernetes/re-clusters/connect-to-admin-console.md) - Access the Redis Enterprise web UI for cluster management
+- [Multi-namespace deployment](/content/operate/kubernetes/re-clusters/multi-namespace.md) - Deploy clusters across multiple Kubernetes namespaces
+- [Delete custom resources](/content/operate/kubernetes/re-clusters/delete-custom-resources.md) - Safely remove REC and related resources
## Storage and performance
Optimize storage and performance for your Redis Enterprise cluster:
-- [Redis Flex]({{< relref "/operate/kubernetes/flex" >}}) - Configure automatic data tiering between RAM and flash storage
-- [Expand PVC]({{< relref "/operate/kubernetes/re-clusters/expand-pvc" >}}) - Expand persistent volume claims for additional storage
+- [Redis Flex](/content/operate/kubernetes/flex/_index.md) - Configure automatic data tiering between RAM and flash storage
+- [Expand PVC](/content/operate/kubernetes/re-clusters/expand-pvc.md) - Expand persistent volume claims for additional storage
## Monitoring and observability
Monitor cluster health and performance:
-- [Connect to Prometheus operator]({{< relref "/operate/kubernetes/re-clusters/connect-prometheus-operator" >}}) - Integrate with Prometheus for metrics collection and monitoring
+- [Connect to Prometheus operator](/content/operate/kubernetes/re-clusters/connect-prometheus-operator.md) - Integrate with Prometheus for metrics collection and monitoring
### Call home client
@@ -47,19 +47,18 @@ spec:
disabled: true
```
-{{}}
-The REST API approach used for Redis Software deployments will have no effect on Kubernetes deployments. You must use the REC specification method shown above.
-{{}}
+> [!NOTE]
+> The REST API approach used for Redis Software deployments will have no effect on Kubernetes deployments. You must use the REC specification method shown above.
## Recovery and troubleshooting
Handle cluster recovery and troubleshooting scenarios:
-- [Cluster recovery]({{< relref "/operate/kubernetes/re-clusters/cluster-recovery" >}}) - Recover from cluster failures and restore operations
+- [Cluster recovery](/content/operate/kubernetes/re-clusters/cluster-recovery.md) - Recover from cluster failures and restore operations
## Related topics
-- [Redis Enterprise databases (REDB)]({{< relref "/operate/kubernetes/re-databases" >}}) - Create and manage databases on your cluster
-- [Security]({{< relref "/operate/kubernetes/security" >}}) - Configure security settings for your cluster
-- [Networking]({{< relref "/operate/kubernetes/networking" >}}) - Set up networking and ingress for cluster access
-- [REC API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) - Complete API specification for REC resources
+- [Redis Enterprise databases (REDB)](/content/operate/kubernetes/re-databases/_index.md) - Create and manage databases on your cluster
+- [Security](/content/operate/kubernetes/security/_index.md) - Configure security settings for your cluster
+- [Networking](/content/operate/kubernetes/networking/_index.md) - Set up networking and ingress for cluster access
+- [REC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) - Complete API specification for REC resources
diff --git a/content/operate/kubernetes/re-clusters/cluster-recovery.md b/content/operate/kubernetes/re-clusters/cluster-recovery.md
index de221fc32e..fe13df0fcc 100644
--- a/content/operate/kubernetes/re-clusters/cluster-recovery.md
+++ b/content/operate/kubernetes/re-clusters/cluster-recovery.md
@@ -22,15 +22,15 @@ The Redis Enterprise for Kubernetes automates these recovery steps:
1. Recovers the cluster configuration on the first node in the new cluster
1. Joins the remaining nodes to the new cluster.
-{{}}Redis Enterprise for Kubernetes 7.2.4-2 introduces a new limitation. You cannot recover or upgrade your cluster if there are databases with old module versions or manually uploaded modules. See the [Redis Enterprise Software 7.2.4 known limitations]({{< relref "/operate/rs/release-notes/rs-7-2-4-releases/rs-7-2-4-52#cluster-recovery-with-manually-uploaded-modules" >}}) for more details.{{}}
+> [!WARNING]
+> Redis Enterprise for Kubernetes 7.2.4-2 introduces a new limitation. You cannot recover or upgrade your cluster if there are databases with old module versions or manually uploaded modules. See the [Redis Enterprise Software 7.2.4 known limitations](/content/operate/rs/release-notes/rs-7-2-4-releases/rs-7-2-4-52.md#cluster-recovery-with-manually-uploaded-modules) for more details.
-{{< note >}}
-If your cluster uses user-defined modules, the recovery process doesn't block on module validation errors (such as URL or credential issues). The cluster can recover successfully, and you can resolve any module configuration issues after recovery is complete. See [User-defined modules]({{< relref "/operate/kubernetes/re-databases/modules#user-defined-modules" >}}) for more information.
-{{< /note >}}
+> [!NOTE]
+> If your cluster uses user-defined modules, the recovery process doesn't block on module validation errors (such as URL or credential issues). The cluster can recover successfully, and you can resolve any module configuration issues after recovery is complete. See [User-defined modules](/content/operate/kubernetes/re-databases/modules.md#user-defined-modules) for more information.
## Prerequisites
-- For cluster recovery, the cluster must be [deployed with persistence]({{< relref "/operate/kubernetes/recommendations/persistent-volumes" >}}).
+- For cluster recovery, the cluster must be [deployed with persistence](/content/operate/kubernetes/recommendations/persistent-volumes.md).
## Recover a cluster
@@ -49,4 +49,4 @@ If your cluster uses user-defined modules, the recovery process doesn't block on
watch "kubectl describe rec | grep State"
```
-1. To recover the database, see [Recover a failed database]({{< relref "/operate/rs/databases/recover" >}}).
\ No newline at end of file
+1. To recover the database, see [Recover a failed database](/content/operate/rs/databases/recover.md).
\ No newline at end of file
diff --git a/content/operate/kubernetes/re-clusters/connect-prometheus-operator.md b/content/operate/kubernetes/re-clusters/connect-prometheus-operator.md
index e14d9addd5..221d745d3a 100644
--- a/content/operate/kubernetes/re-clusters/connect-prometheus-operator.md
+++ b/content/operate/kubernetes/re-clusters/connect-prometheus-operator.md
@@ -13,15 +13,15 @@ weight: 92
To collect metrics data from your databases and Redis Enterprise cluster (REC), you can connect your [Prometheus](https://prometheus.io/) server to an endpoint exposed on your REC. Redis Enterprise for Kubernetes creates a dedicated service to expose the `prometheus` port (8070) for data collection. A custom resource called `ServiceMonitor` allows the [Prometheus operator](https://github.com/prometheus-operator/prometheus-operator/tree/main/Documentation) to connect to this port and collect data from Redis Enterprise.
-To expose database tags as metric labels so you can filter and group metrics by attributes such as environment or team, see [Enrich database metrics with tags]({{< relref "/operate/kubernetes/re-databases/enrich-metrics-with-tags" >}}).
+To expose database tags as metric labels so you can filter and group metrics by attributes such as environment or team, see [Enrich database metrics with tags](/content/operate/kubernetes/re-databases/enrich-metrics-with-tags.md).
## Prerequisites
Before connecting Redis Enterprise to Prometheus on your Kubernetes cluster, make sure you've done the following:
-- [Deploy Redis Enterprise for Kubernetes]({{< relref "/operate/kubernetes/deployment/quick-start" >}}) (version 6.2.10-4 or newer)
+- [Deploy Redis Enterprise for Kubernetes](/content/operate/kubernetes/deployment/quick-start.md) (version 6.2.10-4 or newer)
- [Deploy the Prometheus operator](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/getting-started/introduction.md) (version 0.19.0 or newer)
-- [Create a Redis Enterprise cluster]({{< relref "/operate/kubernetes/deployment/quick-start#create-a-redis-enterprise-cluster-rec" >}})
+- [Create a Redis Enterprise cluster](/content/operate/kubernetes/deployment/quick-start.md#create-a-redis-enterprise-cluster-rec)
## Create a `ServiceMonitor` custom resource
@@ -36,7 +36,8 @@ You'll need to configure the following fields to connect Prometheus to Redis Ent
| `spec.selector` | `matchLabels` | REC service label (`app: redis.io/service=prom-metrics`) |
Apply the file in the same namespace as your Redis Enterprise cluster (REC).
- {{}}If Redis Enterprise and Prometheus are deployed in different namespaces, you'll also need to add the [`serviceMonitorNamespaceSelector`](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md) field to your Prometheus resource. See the [Prometheus operator documentation](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/user-guides/running-exporters.md) for more details on cross-namespace `ServiceMonitor` configuration.{{}}
+ > [!NOTE]
+ > If Redis Enterprise and Prometheus are deployed in different namespaces, you'll also need to add the [`serviceMonitorNamespaceSelector`](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md) field to your Prometheus resource. See the [Prometheus operator documentation](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/user-guides/running-exporters.md) for more details on cross-namespace `ServiceMonitor` configuration.
```YAML
@@ -68,5 +69,5 @@ For more info about configuring the `ServiceMonitor` resource, see the [`Service
- [Running exporters](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/user-guides/running-exporters.md)
- [Troubleshooting ServiceMonitor changes](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/platform/troubleshooting.md#troubleshooting-servicemonitor-changes)
- redis.io/docs
- - [Metrics in Prometheus]({{< relref "/integrate/prometheus-with-redis-enterprise/prometheus-metrics-definitions" >}})
- - [Monitoring and metrics]({{< relref "/operate/rs/monitoring/" >}})
+ - [Metrics in Prometheus](/content/integrate/prometheus-with-redis-enterprise/prometheus-metrics-definitions.md)
+ - [Monitoring and metrics](/content/operate/rs/monitoring/_index.md)
diff --git a/content/operate/kubernetes/re-clusters/connect-to-admin-console.md b/content/operate/kubernetes/re-clusters/connect-to-admin-console.md
index eff1289312..91e00afd44 100644
--- a/content/operate/kubernetes/re-clusters/connect-to-admin-console.md
+++ b/content/operate/kubernetes/re-clusters/connect-to-admin-console.md
@@ -11,11 +11,10 @@ linkTitle: Connect to the admin console
weight: 10
---
-The username and password for the Redis Enterprise Software [admin console]({{< relref "/operate/rs/" >}}) are stored in a Kubernetes [secret](https://kubernetes.io/docs/concepts/configuration/secret/). After retrieving your credentials, you can use port forwarding to connect to the admin console.
+The username and password for the Redis Enterprise Software [admin console](/content/operate/rs/_index.md) are stored in a Kubernetes [secret](https://kubernetes.io/docs/concepts/configuration/secret/). After retrieving your credentials, you can use port forwarding to connect to the admin console.
-{{}}
-There are several methods for accessing the admin console. Port forwarding is the simplest, but not the most efficient method for long-term use. You could also use a load balancer service or Ingress.
-{{}}
+> [!NOTE]
+> There are several methods for accessing the admin console. Port forwarding is the simplest, but not the most efficient method for long-term use. You could also use a load balancer service or Ingress.
1. Switch to the namespace with your Redis Enterprise cluster (REC).
@@ -44,9 +43,8 @@ There are several methods for accessing the admin console. Port forwarding is th
kubectl get service/-ui -o yaml
```
- {{}}
- The default port is 8443.
- {{}}
+ > [!NOTE]
+ > The default port is 8443.
1. Use `kubectl port-forward` to forward your local port to the service port.
diff --git a/content/operate/kubernetes/re-clusters/delete-custom-resources.md b/content/operate/kubernetes/re-clusters/delete-custom-resources.md
index 3f8d0effd1..b18fdc66b5 100644
--- a/content/operate/kubernetes/re-clusters/delete-custom-resources.md
+++ b/content/operate/kubernetes/re-clusters/delete-custom-resources.md
@@ -51,7 +51,8 @@ To delete the operator from your K8s cluster, you can delete the operator bundle
This will remove the operator and its custom resource definitions (CRDs) from your K8s cluster.
-{{< warning >}} The Redis Enterprise CRDs are non-namespaced resources, meaning they are shared across your entire K8s cluster. Deleting CRDs in one namespace will delete custom resources in every other namespace across the K8s cluster.{{}}
+> [!WARNING]
+> The Redis Enterprise CRDs are non-namespaced resources, meaning they are shared across your entire K8s cluster. Deleting CRDs in one namespace will delete custom resources in every other namespace across the K8s cluster.
### Delete operator from one namespace
@@ -67,7 +68,7 @@ kubectl delete -f admission-service.yaml
kubectl delete -f operator.yaml
```
-You will also need to remove [the `namespaceSelector` section from the validating webhook]({{< relref "/operate/kubernetes/deployment/quick-start#webhook" >}}).
+You will also need to remove [the `namespaceSelector` section from the validating webhook](/content/operate/kubernetes/deployment/quick-start.md#webhook).
## Delete an Active-Active database (REAADB)
@@ -109,7 +110,8 @@ If the operator isn't running, or some other fatal error occurs, the finalizer i
If this happens, you can remove the finalizer manually.
-{{}} If you remove the finalizer manually, there is no guarantee that the underlying REDB has been deleted. This may cause resource issues and require manual intervention. {{}}
+> [!WARNING]
+> If you remove the finalizer manually, there is no guarantee that the underlying REDB has been deleted. This may cause resource issues and require manual intervention.
```sh
kubectl patch redb --type=json -p \
@@ -124,7 +126,8 @@ If the operator isn't running, or some other fatal error occurs, the finalizer i
If this happens, you can remove the finalizer manually.
-{{}} If you remove the finalizer manually, there is no guarantee that the underlying REC has been deleted. This may cause resource issues and require manual intervention. {{}}
+> [!WARNING]
+> If you remove the finalizer manually, there is no guarantee that the underlying REC has been deleted. This may cause resource issues and require manual intervention.
```sh
kubectl patch rec --type=json -p \
diff --git a/content/operate/kubernetes/re-clusters/expand-pvc.md b/content/operate/kubernetes/re-clusters/expand-pvc.md
index 3bd7ac44c0..da23007aab 100644
--- a/content/operate/kubernetes/re-clusters/expand-pvc.md
+++ b/content/operate/kubernetes/re-clusters/expand-pvc.md
@@ -12,28 +12,30 @@ weight: 82
This article outlines steps to increase the size of the persistent volume claim for your Redis Enterprise cluster (REC).
-{{}} This feature is only supported in versions 7.4.2-12 and above. {{}}
+> [!NOTE]
+> This feature is only supported in versions 7.4.2-12 and above.
[PersistentVolumeClaims (PVC)](https://kubernetes.io/docs/concepts/storage/persistent-volumes/#expanding-persistent-volumes-claims) are created by the Redis Enterprise operator and used by the RedisEnterpriseCluster (REC). PVCs are created with a specific size and [can be expanded](https://kubernetes.io/docs/concepts/storage/persistent-volumes/#expanding-persistent-volumes-claims) with the following steps, if the underlying [storage class](https://kubernetes.io/docs/concepts/storage/storage-classes/) supports it.
This process involves deleting and recreating the REC StatefulSet with a larger persistent volume size. The pods owned by the StatefulSet are not restarted or affected by the deletion and recreation process, except when they are left without an owner momentarily.
-{{}}Shrinking (reducing the size) of your PVC is not allowed. This process only allows you to expand (size up) your PVC.{{}}
+> [!NOTE]
+> Shrinking (reducing the size) of your PVC is not allowed. This process only allows you to expand (size up) your PVC.
### Default PVC size
-By default, if you omit [`spec.persistentSpec.volumeSize`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specpersistentspec" >}}), the operator allocates a persistent volume that is five times (5x) the Redis Enterprise node memory request defined in [`spec.redisEnterpriseNodeResources.requests.memory`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specredisenterprisenoderesources" >}}) (per node). This 5x ratio is the recommended minimum capacity.
+By default, if you omit [`spec.persistentSpec.volumeSize`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specpersistentspec), the operator allocates a persistent volume that is five times (5x) the Redis Enterprise node memory request defined in [`spec.redisEnterpriseNodeResources.requests.memory`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specredisenterprisenoderesources) (per node). This 5x ratio is the recommended minimum capacity.
-- If you set [`spec.persistentSpec.volumeSize`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specpersistentspec" >}}) explicitly, that exact size is used and the 5x default does not apply.
+- If you set [`spec.persistentSpec.volumeSize`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specpersistentspec) explicitly, that exact size is used and the 5x default does not apply.
- Changing node memory requests does not automatically resize existing PVCs. Use the procedure below to expand the PVC if you want to maintain the 5x ratio after changing memory.
-- If you omit [`spec.redisEnterpriseNodeResources.requests.memory`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specredisenterprisenoderesources" >}}), the operator uses its default memory request (4Gi). With `volumeSize` omitted, this results in a default PVC size of approximately 20Gi per node (5 × 4Gi). See [sizing on Kubernetes]({{< relref "/operate/kubernetes/recommendations/sizing-on-kubernetes" >}}) for defaults.
+- If you omit [`spec.redisEnterpriseNodeResources.requests.memory`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specredisenterprisenoderesources), the operator uses its default memory request (4Gi). With `volumeSize` omitted, this results in a default PVC size of approximately 20Gi per node (5 × 4Gi). See [sizing on Kubernetes](/content/operate/kubernetes/recommendations/sizing-on-kubernetes.md) for defaults.
-- See the [volume size recommendations]({{< relref "/operate/kubernetes/recommendations/persistent-volumes#volume-size" >}}) and [hardware requirements]({{< relref "/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements" >}}) for guidance.
+- See the [volume size recommendations](/content/operate/kubernetes/recommendations/persistent-volumes.md#volume-size) and [hardware requirements](/content/operate/rs/installing-upgrading/install/plan-deployment/hardware-requirements.md) for guidance.
## Prerequisites
-{{}}Do not change any other REC fields related to the StatefulSet while resizing is in progress.
-{{}}
+> [!WARNING]
+> Do not change any other REC fields related to the StatefulSet while resizing is in progress.
- PVC expansion must be supported and enabled by the StorageClass and underlying storage driver of the REC PVCs.
- The relevant StorageClass is the one associated with the REC PVCs. The StorageClass for existing PVCs cannot be changed.
@@ -41,9 +43,11 @@ By default, if you omit [`spec.persistentSpec.volumeSize`]({{< relref "/operate/
- Your storage driver must support online expansion.
- We highly recommend you backup your databases before beginning this PVC expansion process.
-{{}} OpenShift users should be aware that (`ClusterResourceQuota`) can limit the PVC expansion. Check your quota before resizing using `oc describe clusterresourcequota `.{{}}
+> [!WARNING]
+> OpenShift users should be aware that (`ClusterResourceQuota`) can limit the PVC expansion. Check your quota before resizing using `oc describe clusterresourcequota `.
-{{}} PVC expansion is not supported when using Redis Flex (previously Redis on Flash). Do not enable `enablePersistentVolumeResize` if your REC uses `redisOnFlashSpec` as this will result in conflicts. {{}}
+> [!WARNING]
+> PVC expansion is not supported when using Redis Flex (previously Redis on Flash). Do not enable `enablePersistentVolumeResize` if your REC uses `redisOnFlashSpec` as this will result in conflicts.
## Expand REC PVC
diff --git a/content/operate/kubernetes/re-clusters/multi-namespace.md b/content/operate/kubernetes/re-clusters/multi-namespace.md
index 8a32e1d45b..e07499c6aa 100644
--- a/content/operate/kubernetes/re-clusters/multi-namespace.md
+++ b/content/operate/kubernetes/re-clusters/multi-namespace.md
@@ -14,21 +14,21 @@ weight: 17
Multiple Redis Enterprise database resources (REDBs) can be associated with a single Redis Enterprise cluster resource (REC) even if they reside in different namespaces.
-To learn more about designing a multi-namespace Redis Enterprise cluster, see [flexible deployment options]({{< relref "/operate/kubernetes/architecture/deployment-options" >}}).
+To learn more about designing a multi-namespace Redis Enterprise cluster, see [flexible deployment options](/content/operate/kubernetes/architecture/deployment-options.md).
-{{}}
-Multi-namespace installations now support Active-Active databases (REAADB) with certain configuration requirements. For details, see [Multi-namespace Active-Active databases](#multi-namespace-active-active-databases).
-{{}}
+> [!NOTE]
+> Multi-namespace installations now support Active-Active databases (REAADB) with certain configuration requirements. For details, see [Multi-namespace Active-Active databases](#multi-namespace-active-active-databases).
## Prerequisites
-Before configuring a multi-namespace deployment, you must have a running [Redis Enterprise cluster (REC)]({{< relref "/operate/kubernetes/deployment/quick-start" >}}). See more information in the [deployment]({{< relref "/operate/kubernetes/deployment/" >}}) section.
+Before configuring a multi-namespace deployment, you must have a running [Redis Enterprise cluster (REC)](/content/operate/kubernetes/deployment/quick-start.md). See more information in the [deployment](/content/operate/kubernetes/deployment/_index.md) section.
## Create role and role binding for managed namespaces
Both the operator and the RedisEnterpriseCluster (REC) resource need access to each namespace the REC will manage. For each **managed** namespace, create a `consumer_role.yaml` and `consumer_role_binding.yaml` file within the managed namespace, as shown in the examples below.
-{{}}These will need to be reapplied each time you [upgrade]({{< relref "/operate/kubernetes/upgrade/upgrade-redis-cluster" >}}). {{}}
+> [!NOTE]
+> These will need to be reapplied each time you [upgrade](/content/operate/kubernetes/upgrade/upgrade-redis-cluster.md).
Replace `` with the namespace the REC resides in.
Replace `` with your own value (defaults to the REC name).
@@ -41,14 +41,13 @@ Replace `` with your own value (defaults to the REC name).
{{}}
-{{}}
-**Alternative approach**: Instead of creating individual `Role` objects for each namespace, you can create a single `ClusterRole` and bind it with multiple `RoleBinding` objects. This reduces the number of objects and simplifies role management.
-
-To use this approach:
-1. Change `kind: Role` to `kind: ClusterRole` in the role definition above
-2. Change `roleRef.kind: Role` to `roleRef.kind: ClusterRole` in the role binding definition above
-3. Apply the ClusterRole once globally, then apply a RoleBinding in each managed namespace
-{{}}
+> [!NOTE]
+> **Alternative approach**: Instead of creating individual `Role` objects for each namespace, you can create a single `ClusterRole` and bind it with multiple `RoleBinding` objects. This reduces the number of objects and simplifies role management.
+>
+> To use this approach:
+> 1. Change `kind: Role` to `kind: ClusterRole` in the role definition above
+> 2. Change `roleRef.kind: Role` to `roleRef.kind: ClusterRole` in the role binding definition above
+> 3. Apply the ClusterRole once globally, then apply a RoleBinding in each managed namespace
Apply the files, replacing `` with your own values:
@@ -57,9 +56,8 @@ kubectl apply -f consumer_role.yaml -n
kubectl apply -f consumer_role_binding.yaml -n
```
-{{}}
-If the REC is configured to watch a namespace without setting the role and role binding permissions, or a namespace that is not yet created, the operator will fail and halt normal operations.
-{{}}
+> [!NOTE]
+> If the REC is configured to watch a namespace without setting the role and role binding permissions, or a namespace that is not yet created, the operator will fail and halt normal operations.
## Update Redis Enterprise operator ConfigMap
@@ -70,9 +68,8 @@ There are two methods of updating the operator ConfigMap (`operator-environment-
You can create this ConfigMap manually before deployment, or it will be created automatically after the operator was deployed.
-{{}}
-Only configure the operator to watch a namespace after the namespace is created and configured with the role/role_binding as explained above. If configured to watch a namespace without setting those permissions or a namespace that is not created yet, the operator will fail and not perform normal operations.
-{{}}
+> [!WARNING]
+> Only configure the operator to watch a namespace after the namespace is created and configured with the role/role_binding as explained above. If configured to watch a namespace without setting those permissions or a namespace that is not created yet, the operator will fail and not perform normal operations.
### Method 1: Namespace label (available in versions 6.4.2-4 or later)
@@ -109,9 +106,8 @@ Only configure the operator to watch a namespace after the namespace is created
kubectl label namespace =
```
-{{}}
-The operator restarts when it detects a namespace label was added or removed.
-{{}}
+> [!NOTE]
+> The operator restarts when it detects a namespace label was added or removed.
### Method 2: Explicit namespace list
@@ -131,13 +127,12 @@ You can also deploy `RedisEnterpriseActiveActiveDatabase` (REAADB) objects in co
To do this:
1. Configure each participating cluster’s operator to watch the relevant consumer namespace. See [multi-namespace operator setup](#update-redis-enterprise-operator-configmap).
-2. Ensure all Active-Active prerequisites are met as described in [Configure Active-Active]({{}}).
+2. Ensure all Active-Active prerequisites are met as described in [Configure Active-Active](/content/operate/kubernetes/active-active/create-reaadb.md).
3. In your REAADB custom resource, specify the target consumer namespace using `metadata.namespace`. For each participating cluster, use the `namespace` field under `spec.participatingClusters` to indicate the namespace where the REAADB should be deployed.
-4. If you are using a [global database secret]({{}}), deploy the secret in each consumer namespace.
+4. If you are using a [global database secret](/content/operate/kubernetes/active-active/global-db-secret.md), deploy the secret in each consumer namespace.
-{{}}
-Apply the REAADB object to only one Kubernetes cluster. Based on the specified participating clusters and namespaces, the operator automatically creates the necessary resources in the other clusters.
-{{}}
+> [!NOTE]
+> Apply the REAADB object to only one Kubernetes cluster. Based on the specified participating clusters and namespaces, the operator automatically creates the necessary resources in the other clusters.
For example:
@@ -156,6 +151,5 @@ spec:
```
-{{}}
-Configure the operator to watch a namespace only after the namespace exists and the required `Role` and `RoleBinding` resources have been applied. If the operator is configured to watch a namespace that lacks these permissions or does not exist, it will fail and halt normal operations.
-{{}}
+> [!WARNING]
+> Configure the operator to watch a namespace only after the namespace exists and the required `Role` and `RoleBinding` resources have been applied. If the operator is configured to watch a namespace that lacks these permissions or does not exist, it will fail and halt normal operations.
diff --git a/content/operate/kubernetes/reference/_index.md b/content/operate/kubernetes/reference/_index.md
index 6ffe5a142a..740c6d4a32 100644
--- a/content/operate/kubernetes/reference/_index.md
+++ b/content/operate/kubernetes/reference/_index.md
@@ -65,14 +65,14 @@ kubectl edit redb my-database
Find complete YAML examples for common deployment scenarios:
-- [YAML examples]({{< relref "/operate/kubernetes/reference/yaml" >}}) - Ready-to-use YAML configurations for different deployment types
+- [YAML examples](/content/operate/kubernetes/reference/yaml/_index.md) - Ready-to-use YAML configurations for different deployment types
### Example categories
-- [Basic deployment]({{< relref "/operate/kubernetes/reference/yaml/basic-deployment" >}}) - Essential YAML files for simple Redis Enterprise deployment
-- [Rack awareness]({{< relref "/operate/kubernetes/reference/yaml/rack-awareness" >}}) - YAML examples for rack-aware deployments across availability zones
-- [Active-Active]({{< relref "/operate/kubernetes/reference/yaml/active-active" >}}) - YAML examples for Active-Active databases across multiple clusters
-- [Multi-namespace]({{< relref "/operate/kubernetes/reference/yaml/multi-namespace" >}}) - YAML examples for deploying across multiple namespaces
+- [Basic deployment](/content/operate/kubernetes/reference/yaml/basic-deployment.md) - Essential YAML files for simple Redis Enterprise deployment
+- [Rack awareness](/content/operate/kubernetes/reference/yaml/rack-awareness.md) - YAML examples for rack-aware deployments across availability zones
+- [Active-Active](/content/operate/kubernetes/reference/yaml/active-active.md) - YAML examples for Active-Active databases across multiple clusters
+- [Multi-namespace](/content/operate/kubernetes/reference/yaml/multi-namespace.md) - YAML examples for deploying across multiple namespaces
## API reference
@@ -80,28 +80,28 @@ Review complete API specifications for all Redis Enterprise custom resources:
### Core resources
-- [Redis Enterprise cluster API (REC)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) - Manage Redis Enterprise clusters
-- [Redis Enterprise database API (REDB)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}}) - Manage Redis databases
+- [Redis Enterprise cluster API (REC)](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) - Manage Redis Enterprise clusters
+- [Redis Enterprise database API (REDB)](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md) - Manage Redis databases
### Active-Active resources
-- [Active-Active database API (REAADB)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api" >}}) - Manage Active-Active databases
-- [Remote cluster API (RERC)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api" >}}) - Configure remote cluster connections
+- [Active-Active database API (REAADB)](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md) - Manage Active-Active databases
+- [Remote cluster API (RERC)](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md) - Configure remote cluster connections
### Access control resources
-- [RedisEnterpriseUser API (REUSER)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_user_api" >}}) - Manage users for access control
-- [RedisEnterpriseRole API (REROLE)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_role_api" >}}) - Define roles scoped to selected databases
-- [RedisEnterpriseRoleBinding API (REROLEBINDING)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_role_binding_api" >}}) - Bind users to a scoped role
-- [RedisEnterpriseClusterRole API (RECROLE)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_role_api" >}}) - Define cluster-scoped roles
-- [RedisEnterpriseClusterRoleBinding API (RECROLEBINDING)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_role_binding_api" >}}) - Bind users to a cluster-scoped role
-- [RedisEnterpriseACL API (REACL)]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_acl_api" >}}) - Define access control lists
+- [RedisEnterpriseUser API (REUSER)](/content/operate/kubernetes/reference/api/redis_enterprise_user_api.md) - Manage users for access control
+- [RedisEnterpriseRole API (REROLE)](/content/operate/kubernetes/reference/api/redis_enterprise_role_api.md) - Define roles scoped to selected databases
+- [RedisEnterpriseRoleBinding API (REROLEBINDING)](/content/operate/kubernetes/reference/api/redis_enterprise_role_binding_api.md) - Bind users to a scoped role
+- [RedisEnterpriseClusterRole API (RECROLE)](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_role_api.md) - Define cluster-scoped roles
+- [RedisEnterpriseClusterRoleBinding API (RECROLEBINDING)](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_role_binding_api.md) - Bind users to a cluster-scoped role
+- [RedisEnterpriseACL API (REACL)](/content/operate/kubernetes/reference/api/redis_enterprise_acl_api.md) - Define access control lists
## Compatibility
Check supported Kubernetes distributions and versions:
-- [Supported Kubernetes distributions]({{< relref "/operate/kubernetes/reference/supported_k8s_distributions" >}}) - Compatible Kubernetes platforms and versions
+- [Supported Kubernetes distributions](/content/operate/kubernetes/reference/supported_k8s_distributions.md) - Compatible Kubernetes platforms and versions
## Best practices
diff --git a/content/operate/kubernetes/reference/api/_index.md b/content/operate/kubernetes/reference/api/_index.md
index 1b3037b4ce..552c34a918 100644
--- a/content/operate/kubernetes/reference/api/_index.md
+++ b/content/operate/kubernetes/reference/api/_index.md
@@ -59,4 +59,4 @@ kubectl apply -f my-redis-config.yaml
- Create `RedisEnterpriseDatabase` (REDB) resources within a cluster to provision individual databases
- Use `RedisEnterpriseActiveActiveDatabase` (REAADB) with `RedisEnterpriseRemoteCluster (RERC)` resources to define participating clusters
-For complete YAML configuration examples, see the [YAML examples]({{< relref "/operate/kubernetes/reference/yaml/" >}}) section.
+For complete YAML configuration examples, see the [YAML examples](/content/operate/kubernetes/reference/yaml/_index.md) section.
diff --git a/content/operate/kubernetes/reference/yaml/_index.md b/content/operate/kubernetes/reference/yaml/_index.md
index 0b190315d1..975f20f35f 100644
--- a/content/operate/kubernetes/reference/yaml/_index.md
+++ b/content/operate/kubernetes/reference/yaml/_index.md
@@ -68,11 +68,11 @@ kubectl get events --sort-by=.metadata.creationTimestamp
## Example categories
-- [Basic deployment examples]({{< relref "/operate/kubernetes/reference/yaml/basic-deployment" >}}) - Service account, RBAC, cluster, and database configurations
-- [Rack awareness examples]({{< relref "/operate/kubernetes/reference/yaml/rack-awareness" >}}) - Rack-aware cluster configuration and required RBAC
-- [Active-Active examples]({{< relref "/operate/kubernetes/reference/yaml/active-active" >}}) - Multi-cluster Active-Active database setup
-- [Multi-namespace examples]({{< relref "/operate/kubernetes/reference/yaml/multi-namespace" >}}) - Cross-namespace operator and cluster configurations
-- [Log collector RBAC examples]({{< relref "/operate/kubernetes/reference/yaml/log-collector-rbac" >}}) - RBAC permissions for log collection in restricted and all modes
+- [Basic deployment examples](/content/operate/kubernetes/reference/yaml/basic-deployment.md) - Service account, RBAC, cluster, and database configurations
+- [Rack awareness examples](/content/operate/kubernetes/reference/yaml/rack-awareness.md) - Rack-aware cluster configuration and required RBAC
+- [Active-Active examples](/content/operate/kubernetes/reference/yaml/active-active.md) - Multi-cluster Active-Active database setup
+- [Multi-namespace examples](/content/operate/kubernetes/reference/yaml/multi-namespace.md) - Cross-namespace operator and cluster configurations
+- [Log collector RBAC examples](/content/operate/kubernetes/reference/yaml/log-collector-rbac.md) - RBAC permissions for log collection in restricted and all modes
## Best practices
@@ -82,7 +82,7 @@ kubectl get events --sort-by=.metadata.creationTimestamp
## Related documentation
-- [Reference]({{< relref "/operate/kubernetes/reference" >}}) - Complete API specifications for all custom resources
-- [Deploy Redis Enterprise Software for Kubernetes]({{< relref "/operate/kubernetes/deployment/quick-start" >}}) - Step-by-step deployment instructions
-- [Manage databases in multiple namespaces]({{< relref "/operate/kubernetes/re-clusters/multi-namespace" >}}) - Detailed multi-namespace setup instructions
-- [Active-Active databases]({{< relref "/operate/kubernetes/active-active" >}}) - Active-Active configuration and management
+- [Reference](/content/operate/kubernetes/reference/_index.md) - Complete API specifications for all custom resources
+- [Deploy Redis Enterprise Software for Kubernetes](/content/operate/kubernetes/deployment/quick-start.md) - Step-by-step deployment instructions
+- [Manage databases in multiple namespaces](/content/operate/kubernetes/re-clusters/multi-namespace.md) - Detailed multi-namespace setup instructions
+- [Active-Active databases](/content/operate/kubernetes/active-active/_index.md) - Active-Active configuration and management
diff --git a/content/operate/kubernetes/reference/yaml/active-active.md b/content/operate/kubernetes/reference/yaml/active-active.md
index 488bcccaa4..72e3c0bd25 100644
--- a/content/operate/kubernetes/reference/yaml/active-active.md
+++ b/content/operate/kubernetes/reference/yaml/active-active.md
@@ -12,21 +12,21 @@ weight: 30
This page provides YAML examples for deploying Active-Active Redis Enterprise databases across multiple Kubernetes clusters. Active-Active databases provide multi-master replication with conflict resolution, enabling global distribution and local read/write access.
-For complete deployment instructions, see [Active-Active databases]({{< relref "/operate/kubernetes/active-active" >}}).
+For complete deployment instructions, see [Active-Active databases](/content/operate/kubernetes/active-active/_index.md).
## Applying the configuration
-To deploy Active-Active databases using these YAML files, follow [Create Active-Active database (REAADB)]({{< relref "/operate/kubernetes/active-active/create-reaadb" >}}), which provides detailed instructions for preparing clusters, creating RERC resources, and deploying REAADB configurations.
+To deploy Active-Active databases using these YAML files, follow [Create Active-Active database (REAADB)](/content/operate/kubernetes/active-active/create-reaadb.md), which provides detailed instructions for preparing clusters, creating RERC resources, and deploying REAADB configurations.
## Namespace examples
A namespace is an abstraction used by Kubernetes to support multiple virtual clusters on the same physical cluster.
-`ns-illinois.yaml` is used in [Create Active-Active database]({{< relref "/operate/kubernetes/active-active/create-reaadb#example-values" >}}).
+`ns-illinois.yaml` is used in [Create Active-Active database](/content/operate/kubernetes/active-active/create-reaadb.md#example-values).
{{}}
-`ns-virginia.yaml` is used in [Create Active-Active database]({{< relref "/operate/kubernetes/active-active/create-reaadb#example-values" >}}).
+`ns-virginia.yaml` is used in [Create Active-Active database](/content/operate/kubernetes/active-active/create-reaadb.md#example-values).
{{}}
@@ -34,11 +34,11 @@ A namespace is an abstraction used by Kubernetes to support multiple virtual clu
A Redis Enterprise cluster is a collection of Redis Enterprise nodes that pools system resources across nodes and supports multi-tenant database instances.
-`rec-chicago.yaml` is used in [Create Active-Active database]({{< relref "/operate/kubernetes/active-active/create-reaadb#prerequisites" >}}) and [Create RERC]({{< relref "/operate/kubernetes/active-active/create-reaadb#create-rerc" >}}).
+`rec-chicago.yaml` is used in [Create Active-Active database](/content/operate/kubernetes/active-active/create-reaadb.md#prerequisites) and [Create RERC](/content/operate/kubernetes/active-active/create-reaadb.md#create-rerc).
{{}}
-`rec-arlington.yaml` is used in [Create Active-Active database]({{< relref "/operate/kubernetes/active-active/create-reaadb#prerequisites" >}}) and [Create RERC]({{< relref "/operate/kubernetes/active-active/create-reaadb#create-rerc" >}}).
+`rec-arlington.yaml` is used in [Create Active-Active database](/content/operate/kubernetes/active-active/create-reaadb.md#prerequisites) and [Create RERC](/content/operate/kubernetes/active-active/create-reaadb.md#create-rerc).
{{}}
@@ -46,22 +46,22 @@ A Redis Enterprise cluster is a collection of Redis Enterprise nodes that pools
RedisEnterpriseRemoteCluster represents a remote participating cluster.
-`rerc-ohare.yaml` is used in the [Create RERC]({{< relref "/operate/kubernetes/active-active/create-reaadb#create-rerc" >}}) section.
+`rerc-ohare.yaml` is used in the [Create RERC](/content/operate/kubernetes/active-active/create-reaadb.md#create-rerc) section.
{{}}
-`rerc-raegan.yaml` is used in the [Create RERC]({{< relref "/operate/kubernetes/active-active/create-reaadb#create-rerc" >}}) section.
+`rerc-raegan.yaml` is used in the [Create RERC](/content/operate/kubernetes/active-active/create-reaadb.md#create-rerc) section.
{{}}
### RERC configuration
-- [metadata.name]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api#appredislabscomv1alpha1" >}}): Unique name for this remote cluster reference
-- [spec.recName]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api#spec" >}}): Name of the remote REC
-- [spec.recNamespace]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api#spec" >}}): Namespace of the remote REC
-- [spec.apiFqdnUrl]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api#spec" >}}): API endpoint URL for the remote cluster
-- [spec.dbFqdnSuffix]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api#spec" >}}): Database hostname suffix for the remote cluster
-- [spec.secretName]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api#spec" >}}): Secret containing authentication credentials
+- [metadata.name](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md#appredislabscomv1alpha1): Unique name for this remote cluster reference
+- [spec.recName](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md#spec): Name of the remote REC
+- [spec.recNamespace](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md#spec): Namespace of the remote REC
+- [spec.apiFqdnUrl](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md#spec): API endpoint URL for the remote cluster
+- [spec.dbFqdnSuffix](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md#spec): Database hostname suffix for the remote cluster
+- [spec.secretName](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md#spec): Secret containing authentication credentials
Edit the values in the downloaded YAML file for your specific setup, updating the remote cluster details, API endpoints, and secret names to match your actual environment.
@@ -69,25 +69,25 @@ Edit the values in the downloaded YAML file for your specific setup, updating th
Active-Active databases are geo-distributed databases that span multiple Redis Enterprise clusters and use multi-primary replication and conflict-free replicated data types (CRDTs).
-`reaadb-boeing.yaml` is used in the [Create Active-Active database]({{< relref "/operate/kubernetes/active-active/create-reaadb#create-reaadb" >}}) section.
+`reaadb-boeing.yaml` is used in the [Create Active-Active database](/content/operate/kubernetes/active-active/create-reaadb.md#create-reaadb) section.
{{}}
### REAADB configuration
-- [metadata.name]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api#appredislabscomv1alpha1" >}}): Active-Active database name
-- [spec.participatingClusters]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api#specparticipatingclusters" >}}): List of RERC names that participate in this database
-- [spec.globalConfigurations]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api#specglobalconfigurations" >}}): Database settings applied to all participating clusters
+- [metadata.name](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md#appredislabscomv1alpha1): Active-Active database name
+- [spec.participatingClusters](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md#specparticipatingclusters): List of RERC names that participate in this database
+- [spec.globalConfigurations](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md#specglobalconfigurations): Database settings applied to all participating clusters
Edit the downloaded YAML file to add global database settings such as memory allocation, shard count, replication settings, database secrets, Redis modules, and database-specific Redis configuration.
## Related documentation
-- [Active-Active databases (index)]({{< relref "/operate/kubernetes/active-active" >}})
-- [Prepare participating clusters]({{< relref "/operate/kubernetes/active-active/prepare-clusters" >}})
-- [Create Active-Active database (REAADB)]({{< relref "/operate/kubernetes/active-active/create-reaadb" >}})
-- [Edit global configuration]({{< relref "/operate/kubernetes/active-active/global-config" >}})
-- [Sync global database secret]({{< relref "/operate/kubernetes/active-active/global-db-secret" >}})
-- [RERC API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api" >}})
-- [REAADB API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api" >}})
-- [Networking configuration]({{< relref "/operate/kubernetes/networking" >}})
+- [Active-Active databases (index)](/content/operate/kubernetes/active-active/_index.md)
+- [Prepare participating clusters](/content/operate/kubernetes/active-active/prepare-clusters.md)
+- [Create Active-Active database (REAADB)](/content/operate/kubernetes/active-active/create-reaadb.md)
+- [Edit global configuration](/content/operate/kubernetes/active-active/global-config.md)
+- [Sync global database secret](/content/operate/kubernetes/active-active/global-db-secret.md)
+- [RERC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md)
+- [REAADB API reference](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md)
+- [Networking configuration](/content/operate/kubernetes/networking/_index.md)
diff --git a/content/operate/kubernetes/reference/yaml/basic-deployment.md b/content/operate/kubernetes/reference/yaml/basic-deployment.md
index 251edbf46d..197c562a7d 100644
--- a/content/operate/kubernetes/reference/yaml/basic-deployment.md
+++ b/content/operate/kubernetes/reference/yaml/basic-deployment.md
@@ -12,7 +12,7 @@ weight: 10
This page provides complete YAML examples for a basic Redis Enterprise deployment on Kubernetes. These examples include all the essential components you need to deploy a Redis Enterprise cluster and create a database.
-For complete deployment instructions, see [Deploy on Kubernetes]({{< relref "/operate/kubernetes/deployment/quick-start" >}}).
+For complete deployment instructions, see [Deploy on Kubernetes](/content/operate/kubernetes/deployment/quick-start.md).
## Service account
@@ -83,10 +83,10 @@ Edit the values in the downloaded YAML file based on your requirements, such as
## Apply the configuration
-To deploy these YAML files, follow [Deploy on Kubernetes]({{< relref "/operate/kubernetes/deployment/quick-start" >}}), which provides step-by-step instructions for creating namespaces, deploying the operator, and applying these configuration files.
+To deploy these YAML files, follow [Deploy on Kubernetes](/content/operate/kubernetes/deployment/quick-start.md), which provides step-by-step instructions for creating namespaces, deploying the operator, and applying these configuration files.
## Related documentation
-- [Deploy on Kubernetes]({{< relref "/operate/kubernetes/deployment/quick-start" >}})
-- [REC API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}})
-- [REDB API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}})
+- [Deploy on Kubernetes](/content/operate/kubernetes/deployment/quick-start.md)
+- [REC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md)
+- [REDB API reference](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md)
diff --git a/content/operate/kubernetes/reference/yaml/log-collector-rbac.md b/content/operate/kubernetes/reference/yaml/log-collector-rbac.md
index 83f8a3f08b..4e41b2d37e 100644
--- a/content/operate/kubernetes/reference/yaml/log-collector-rbac.md
+++ b/content/operate/kubernetes/reference/yaml/log-collector-rbac.md
@@ -12,11 +12,11 @@ weight: 50
This page provides YAML examples for configuring RBAC permissions for the Redis Enterprise log collector tool. The log collector requires different permission levels depending on the collection mode you choose.
-For complete log collection instructions, see [Collect logs]({{< relref "/operate/kubernetes/logs/collect-logs" >}}).
+For complete log collection instructions, see [Collect logs](/content/operate/kubernetes/logs/collect-logs.md).
## Prerequisites
-- Install the [Redis Enterprise operator]({{< relref "/operate/kubernetes/deployment" >}})
+- Install the [Redis Enterprise operator](/content/operate/kubernetes/deployment/_index.md)
- Appropriate permissions to create RBAC resources in target namespaces
- Understanding of your deployment model (single namespace, multi-namespace, etc.)
@@ -143,12 +143,12 @@ If your security policies prohibit secrets access, you can remove the secrets pe
## Next steps
-- [Collect logs guide]({{< relref "/operate/kubernetes/logs/collect-logs" >}})
-- [Basic deployment examples]({{< relref "/operate/kubernetes/reference/yaml/basic-deployment" >}})
-- [Multi-namespace deployment]({{< relref "/operate/kubernetes/reference/yaml/multi-namespace" >}})
+- [Collect logs guide](/content/operate/kubernetes/logs/collect-logs.md)
+- [Basic deployment examples](/content/operate/kubernetes/reference/yaml/basic-deployment.md)
+- [Multi-namespace deployment](/content/operate/kubernetes/reference/yaml/multi-namespace.md)
## Related documentation
- [Kubernetes RBAC documentation](https://kubernetes.io/docs/reference/access-authn-authz/rbac/)
-- [Redis Enterprise troubleshooting]({{< relref "/operate/kubernetes/logs" >}})
-- [Operator deployment guide]({{< relref "/operate/kubernetes/deployment" >}})
+- [Redis Enterprise troubleshooting](/content/operate/kubernetes/logs/_index.md)
+- [Operator deployment guide](/content/operate/kubernetes/deployment/_index.md)
diff --git a/content/operate/kubernetes/reference/yaml/multi-namespace.md b/content/operate/kubernetes/reference/yaml/multi-namespace.md
index 63ab090fb5..101ba0a47e 100644
--- a/content/operate/kubernetes/reference/yaml/multi-namespace.md
+++ b/content/operate/kubernetes/reference/yaml/multi-namespace.md
@@ -22,7 +22,7 @@ This example shows:
- Operator namespace: `redis-enterprise-operator` (where the operator and REC run)
- Consumer namespaces: `app-production`, `app-staging` (where REDB resources are created)
-For complete deployment instructions, see [Manage databases in multiple namespaces]({{< relref "/operate/kubernetes/re-clusters/multi-namespace" >}}).
+For complete deployment instructions, see [Manage databases in multiple namespaces](/content/operate/kubernetes/re-clusters/multi-namespace.md).
## Operator service account
@@ -56,12 +56,12 @@ Consumer namespace configuration:
## Next steps
-- [Configure networking across namespaces]({{< relref "/operate/kubernetes/networking" >}})
-- [Set up monitoring for multi-namespace deployment]({{< relref "/operate/kubernetes/re-clusters/connect-prometheus-operator" >}})
-- [Learn about resource management]({{< relref "/operate/kubernetes/recommendations" >}})
+- [Configure networking across namespaces](/content/operate/kubernetes/networking/_index.md)
+- [Set up monitoring for multi-namespace deployment](/content/operate/kubernetes/re-clusters/connect-prometheus-operator.md)
+- [Learn about resource management](/content/operate/kubernetes/recommendations/_index.md)
## Related documentation
-- [Manage databases in multiple namespaces]({{< relref "/operate/kubernetes/re-clusters/multi-namespace" >}})
-- [RBAC configuration]({{< relref "/operate/kubernetes/security" >}})
+- [Manage databases in multiple namespaces](/content/operate/kubernetes/re-clusters/multi-namespace.md)
+- [RBAC configuration](/content/operate/kubernetes/security/_index.md)
- [Kubernetes namespaces](https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/)
diff --git a/content/operate/kubernetes/reference/yaml/rack-awareness.md b/content/operate/kubernetes/reference/yaml/rack-awareness.md
index 4fca72f834..4dba740ab3 100644
--- a/content/operate/kubernetes/reference/yaml/rack-awareness.md
+++ b/content/operate/kubernetes/reference/yaml/rack-awareness.md
@@ -10,20 +10,20 @@ linkTitle: Rack awareness
weight: 20
---
-This page provides YAML examples for deploying Redis Enterprise with [rack awareness]({{< relref "/operate/kubernetes/recommendations/node-selection#using-rack-awareness" >}}). Rack awareness distributes Redis Enterprise nodes and database shards across different availability zones or failure domains to improve high availability and fault tolerance.
+This page provides YAML examples for deploying Redis Enterprise with [rack awareness](/content/operate/kubernetes/recommendations/node-selection.md#using-rack-awareness). Rack awareness distributes Redis Enterprise nodes and database shards across different availability zones or failure domains to improve high availability and fault tolerance.
## Prerequisites
- Label [Kubernetes nodes](https://kubernetes.io/docs/concepts/architecture/nodes/) with zone information
- Typically uses the standard label `topology.kubernetes.io/zone`
- Verify node labels: `kubectl get nodes -o custom-columns="name:metadata.name","rack\\zone:metadata.labels.topology\.kubernetes\.io/zone"`
-- Install the [Redis Enterprise operator]({{< relref "/operate/kubernetes/deployment" >}})
+- Install the [Redis Enterprise operator](/content/operate/kubernetes/deployment/_index.md)
-For complete deployment instructions, see [Deploy on Kubernetes]({{< relref "/operate/kubernetes/deployment" >}}).
+For complete deployment instructions, see [Deploy on Kubernetes](/content/operate/kubernetes/deployment/_index.md).
## Service account
-The service account for rack-aware deployments is the same as [basic deployments]({{< relref "/operate/kubernetes/reference/yaml/basic-deployment#service-account" >}}).
+The service account for rack-aware deployments is the same as [basic deployments](/content/operate/kubernetes/reference/yaml/basic-deployment.md#service-account).
{{}}
@@ -58,7 +58,7 @@ Cluster role binding configuration:
## Rack-aware Redis Enterprise cluster
-The rack-aware [REC configuration]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) includes the `rackAwarenessNodeLabel` field.
+The rack-aware [REC configuration](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) includes the `rackAwarenessNodeLabel` field.
{{}}
@@ -86,7 +86,7 @@ kubectl get nodes -o custom-columns="name:metadata.name","rack\\zone:metadata.la
## Redis Enterprise database
-Database configuration for rack-aware clusters is the same as [basic deployments]({{< relref "/operate/kubernetes/reference/yaml/basic-deployment#redis-enterprise-database" >}}).
+Database configuration for rack-aware clusters is the same as [basic deployments](/content/operate/kubernetes/reference/yaml/basic-deployment.md#redis-enterprise-database).
**Important**: For rack awareness to be effective, ensure your database has replication enabled. Rack awareness distributes primary and replica shards across zones, so databases without replication will not benefit from zone distribution.
@@ -94,7 +94,7 @@ Database configuration for rack-aware clusters is the same as [basic deployments
## Apply the configuration
-To deploy rack-aware Redis Enterprise clusters, follow [Deploy on Kubernetes]({{< relref "/operate/kubernetes/deployment" >}}) and ensure your Kubernetes nodes have proper zone labels. For detailed rack awareness configuration, see the [node selection recommendations]({{< relref "/operate/kubernetes/recommendations/node-selection" >}}).
+To deploy rack-aware Redis Enterprise clusters, follow [Deploy on Kubernetes](/content/operate/kubernetes/deployment/_index.md) and ensure your Kubernetes nodes have proper zone labels. For detailed rack awareness configuration, see the [node selection recommendations](/content/operate/kubernetes/recommendations/node-selection.md).
## Troubleshooting
@@ -118,14 +118,14 @@ To deploy rack-aware Redis Enterprise clusters, follow [Deploy on Kubernetes]({{
## Next steps
-- [Configure Active-Active databases]({{< relref "/operate/kubernetes/reference/yaml/active-active" >}})
-- [Set up multi-namespace deployment]({{< relref "/operate/kubernetes/reference/yaml/multi-namespace" >}})
-- [Learn about database replication]({{< relref "/operate/kubernetes/re-databases/replica-redb" >}})
+- [Configure Active-Active databases](/content/operate/kubernetes/reference/yaml/active-active.md)
+- [Set up multi-namespace deployment](/content/operate/kubernetes/reference/yaml/multi-namespace.md)
+- [Learn about database replication](/content/operate/kubernetes/re-databases/replica-redb.md)
## Related documentation
-- [Node selection recommendations]({{< relref "/operate/kubernetes/recommendations/node-selection" >}})
-- [REC API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}})
-- [REDB API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}})
+- [Node selection recommendations](/content/operate/kubernetes/recommendations/node-selection.md)
+- [REC API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md)
+- [REDB API reference](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md)
- [Kubernetes node affinity](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/)
-- [Redis Enterprise cluster architecture]({{< relref "/operate/kubernetes/architecture" >}})
+- [Redis Enterprise cluster architecture](/content/operate/kubernetes/architecture/_index.md)
diff --git a/content/operate/kubernetes/security/_index.md b/content/operate/kubernetes/security/_index.md
index fe894fa02b..e7969c465c 100644
--- a/content/operate/kubernetes/security/_index.md
+++ b/content/operate/kubernetes/security/_index.md
@@ -15,24 +15,24 @@ Configure security settings for Redis for Kubernetes. Security covers access con
## Access control
-- [Access control]({{< relref "/operate/kubernetes/security/access-control" >}}) — manage Redis Software users, roles, ACLs, and role bindings as Kubernetes custom resources.
+- [Access control](/content/operate/kubernetes/security/access-control/_index.md) — manage Redis Software users, roles, ACLs, and role bindings as Kubernetes custom resources.
## Authentication
-- [Authentication]({{< relref "/operate/kubernetes/security/authentication" >}}) — manage cluster credentials, LDAP, SAML SSO, and configuration secrets.
+- [Authentication](/content/operate/kubernetes/security/authentication/_index.md) — manage cluster credentials, LDAP, SAML SSO, and configuration secrets.
## Certificates and encryption
-- [Certificates and encryption]({{< relref "/operate/kubernetes/security/certificates" >}}) — provision TLS certificates, integrate cert-manager, add client certificates, and enable internode encryption.
+- [Certificates and encryption](/content/operate/kubernetes/security/certificates/_index.md) — provision TLS certificates, integrate cert-manager, add client certificates, and enable internode encryption.
## Secret management
-- [HashiCorp Vault integration]({{< relref "/operate/kubernetes/security/vault" >}}) — use HashiCorp Vault as the centralized secret store for Redis for Kubernetes.
+- [HashiCorp Vault integration](/content/operate/kubernetes/security/vault.md) — use HashiCorp Vault as the centralized secret store for Redis for Kubernetes.
## Resource management
-- [Allow resource adjustment]({{< relref "/operate/kubernetes/security/allow-resource-adjustment" >}}) — enable automatic adjustment of system resources for security compliance.
+- [Allow resource adjustment](/content/operate/kubernetes/security/allow-resource-adjustment.md) — enable automatic adjustment of system resources for security compliance.
## Compliance
-- [FIPS compliance]({{< relref "/operate/kubernetes/security/fips" >}}) — run your cluster in FIPS 140-3 compliance mode.
+- [FIPS compliance](/content/operate/kubernetes/security/fips.md) — run your cluster in FIPS 140-3 compliance mode.
diff --git a/content/operate/kubernetes/security/access-control/_index.md b/content/operate/kubernetes/security/access-control/_index.md
index 079ea7ece4..0f1e619cff 100644
--- a/content/operate/kubernetes/security/access-control/_index.md
+++ b/content/operate/kubernetes/security/access-control/_index.md
@@ -116,13 +116,13 @@ After applying this and a Secret named `alice-password` with a `password` key, A
The underlying Redis Software behavior is unchanged. For concepts and reference details, see the existing Redis Software docs:
-- [Cluster-scoped role definitions]({{< relref "/operate/rs/security/access-control/create-cluster-roles" >}}) — what `Admin`, `ClusterMember`, `ClusterViewer`, and `UserManager` grant.
-- [Database-scoped role definitions]({{< relref "/operate/rs/security/access-control/create-db-roles" >}}) — what `DBMember` and `DBViewer` grant.
-- [Combined cluster and database roles]({{< relref "/operate/rs/security/access-control/create-combined-roles" >}}) — when a role grants both planes.
-- [Redis ACL syntax]({{< relref "/operate/rs/security/access-control/redis-acl-overview" >}}) — rule format for `RedisEnterpriseACL` resources.
-- [Login lockout and unlock]({{< relref "/operate/rs/security/access-control/manage-users/login-lockout" >}}) — how locked users are recovered.
-- [Password complexity rules]({{< relref "/operate/rs/security/access-control/manage-passwords/password-complexity-rules" >}}) and [password expiration]({{< relref "/operate/rs/security/access-control/manage-passwords/password-expiration" >}}) — applied by Redis Software regardless of how the password is delivered.
-- [Default user]({{< relref "/operate/rs/security/access-control/manage-users/default-user" >}}) — the built-in cluster admin account.
+- [Cluster-scoped role definitions](/content/operate/rs/security/access-control/create-cluster-roles.md) — what `Admin`, `ClusterMember`, `ClusterViewer`, and `UserManager` grant.
+- [Database-scoped role definitions](/content/operate/rs/security/access-control/create-db-roles.md) — what `DBMember` and `DBViewer` grant.
+- [Combined cluster and database roles](/content/operate/rs/security/access-control/create-combined-roles.md) — when a role grants both planes.
+- [Redis ACL syntax](/content/operate/rs/security/access-control/redis-acl-overview.md) — rule format for `RedisEnterpriseACL` resources.
+- [Login lockout and unlock](/content/operate/rs/security/access-control/manage-users/login-lockout.md) — how locked users are recovered.
+- [Password complexity rules](/content/operate/rs/security/access-control/manage-passwords/password-complexity-rules.md) and [password expiration](/content/operate/rs/security/access-control/manage-passwords/password-expiration.md) — applied by Redis Software regardless of how the password is delivered.
+- [Default user](/content/operate/rs/security/access-control/manage-users/default-user.md) — the built-in cluster admin account.
## What's different on Kubernetes
@@ -137,13 +137,13 @@ Access control resources are reconciled only in the operator namespace. Password
## In this section
-- [Manage users]({{< relref "/operate/kubernetes/security/access-control/manage-users" >}}) — create `RedisEnterpriseUser` resources, rotate passwords, recover from lockouts.
-- [Manage roles]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}) — create database and cluster roles with the right scope and management permissions.
-- [Manage ACLs]({{< relref "/operate/kubernetes/security/access-control/manage-acls" >}}) — create and update `RedisEnterpriseACL` resources used by roles.
-- [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}) — assign roles to users with `RedisEnterpriseRoleBinding` and `RedisEnterpriseClusterRoleBinding`.
-- [Migrate from REDB rolesPermissions]({{< relref "/operate/kubernetes/security/access-control/migrate-rolespermissions" >}}) — move from the deprecated `RedisEnterpriseDatabase.spec.rolesPermissions` field to the new CRD model.
+- [Manage users](/content/operate/kubernetes/security/access-control/manage-users.md) — create `RedisEnterpriseUser` resources, rotate passwords, recover from lockouts.
+- [Manage roles](/content/operate/kubernetes/security/access-control/manage-roles.md) — create database and cluster roles with the right scope and management permissions.
+- [Manage ACLs](/content/operate/kubernetes/security/access-control/manage-acls.md) — create and update `RedisEnterpriseACL` resources used by roles.
+- [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md) — assign roles to users with `RedisEnterpriseRoleBinding` and `RedisEnterpriseClusterRoleBinding`.
+- [Migrate from REDB rolesPermissions](/content/operate/kubernetes/security/access-control/migrate-rolespermissions.md) — move from the deprecated `RedisEnterpriseDatabase.spec.rolesPermissions` field to the new CRD model.
## Related topics
-- [Redis Software for Kubernetes operator API reference]({{< relref "/operate/kubernetes/reference/api" >}}) — field-by-field specification for every CRD in the `app.redislabs.com/v1alpha1` group.
-- [Redis databases (REDB)]({{< relref "/operate/kubernetes/re-databases" >}}) — the resources that role scopes resolve against.
+- [Redis Software for Kubernetes operator API reference](/content/operate/kubernetes/reference/api/_index.md) — field-by-field specification for every CRD in the `app.redislabs.com/v1alpha1` group.
+- [Redis databases (REDB)](/content/operate/kubernetes/re-databases/_index.md) — the resources that role scopes resolve against.
diff --git a/content/operate/kubernetes/security/access-control/manage-acls.md b/content/operate/kubernetes/security/access-control/manage-acls.md
index f9b80b147d..37f7489477 100644
--- a/content/operate/kubernetes/security/access-control/manage-acls.md
+++ b/content/operate/kubernetes/security/access-control/manage-acls.md
@@ -14,13 +14,13 @@ A `RedisEnterpriseACL` resource holds a Redis ACL rule that controls which comma
ACLs are reusable: one `RedisEnterpriseACL` can be attached to any number of `RedisEnterpriseRole` or `RedisEnterpriseClusterRole` resources. The role decides which databases the ACL applies to; the ACL itself just defines the rule.
-To grant a user the permissions in an ACL, reference the ACL from a role and bind the role to the user. See [Manage roles]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}) and [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}).
+To grant a user the permissions in an ACL, reference the ACL from a role and bind the role to the user. See [Manage roles](/content/operate/kubernetes/security/access-control/manage-roles.md) and [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md).
## Before you start
- Requires Redis Software for Kubernetes operator 8.2.0-12 or later.
- The `RedisEnterpriseACL` resource must live in the operator namespace.
-- The rule string uses Redis ACL syntax — key patterns, command categories, and explicit commands. See [Redis ACL overview]({{< relref "/operate/rs/security/access-control/redis-acl-overview" >}}) for the full syntax.
+- The rule string uses Redis ACL syntax — key patterns, command categories, and explicit commands. See [Redis ACL overview](/content/operate/rs/security/access-control/redis-acl-overview.md) for the full syntax.
## Create an ACL
@@ -54,7 +54,7 @@ kubectl get redisenterpriseacl read-only -o yaml
| A specific command set | `+get +set +del ~app:*` |
| Block dangerous commands | `+@all -@dangerous ~*` |
-For category names (`@read`, `@write`, `@admin`, `@dangerous`, etc.) and the full operator precedence rules, see [Redis ACL overview]({{< relref "/operate/rs/security/access-control/redis-acl-overview" >}}).
+For category names (`@read`, `@write`, `@admin`, `@dangerous`, etc.) and the full operator precedence rules, see [Redis ACL overview](/content/operate/rs/security/access-control/redis-acl-overview.md).
## Update an ACL
@@ -108,13 +108,13 @@ Watch reconciliation events with `kubectl describe redisenterpriseacl `. C
Other things to check:
- **`status.uid` is empty** — The operator hasn't reconciled the ACL yet, or Redis Software rejected the rule. Check the events for an `RSOperationFailed` with the syntax message.
-- **Rule parses but grants nothing** — A common cause is an explicit `-@all` later in the rule overriding earlier `+` clauses. Redis ACL evaluation is order-sensitive; see the [Redis ACL overview]({{< relref "/operate/rs/security/access-control/redis-acl-overview" >}}).
+- **Rule parses but grants nothing** — A common cause is an explicit `-@all` later in the rule overriding earlier `+` clauses. Redis ACL evaluation is order-sensitive; see the [Redis ACL overview](/content/operate/rs/security/access-control/redis-acl-overview.md).
- **Delete is blocked** — A `RedisEnterpriseRole` or `RedisEnterpriseClusterRole` still references the ACL in `spec.acl`. Remove the reference or delete the role first.
-For full field details, see the [`RedisEnterpriseACL`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_acl_api" >}}) API reference.
+For full field details, see the [`RedisEnterpriseACL`](/content/operate/kubernetes/reference/api/redis_enterprise_acl_api.md) API reference.
## Related topics
-- [Redis ACL overview]({{< relref "/operate/rs/security/access-control/redis-acl-overview" >}}) — rule syntax, categories, and evaluation order.
-- [Manage roles]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}) — attach ACLs to `RedisEnterpriseRole` and `RedisEnterpriseClusterRole` resources.
-- [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}) — grant the role to a user.
+- [Redis ACL overview](/content/operate/rs/security/access-control/redis-acl-overview.md) — rule syntax, categories, and evaluation order.
+- [Manage roles](/content/operate/kubernetes/security/access-control/manage-roles.md) — attach ACLs to `RedisEnterpriseRole` and `RedisEnterpriseClusterRole` resources.
+- [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md) — grant the role to a user.
diff --git a/content/operate/kubernetes/security/access-control/manage-bindings.md b/content/operate/kubernetes/security/access-control/manage-bindings.md
index b8cfc6f4c0..bd159f005f 100644
--- a/content/operate/kubernetes/security/access-control/manage-bindings.md
+++ b/content/operate/kubernetes/security/access-control/manage-bindings.md
@@ -17,7 +17,7 @@ A role binding assigns a role to one or more users. Redis Software for Kubernete
Both have the same two spec fields: `roleRef` points at a single role, and `subjects` lists the users who receive it. A user holds the permissions defined by every role bound to it across all bindings.
-For the conceptual model and a complete end-to-end example, see [Roles and bindings]({{< relref "/operate/kubernetes/security/access-control/_index#roles-and-bindings" >}}).
+For the conceptual model and a complete end-to-end example, see [Roles and bindings](/content/operate/kubernetes/security/access-control/_index.md#roles-and-bindings).
## Common patterns
@@ -164,10 +164,10 @@ Watch reconciliation events with `kubectl describe redisenterpriserolebinding }}) and [`RedisEnterpriseClusterRoleBinding`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_role_binding_api" >}}) API reference.
+For full field details, see the [`RedisEnterpriseRoleBinding`](/content/operate/kubernetes/reference/api/redis_enterprise_role_binding_api.md) and [`RedisEnterpriseClusterRoleBinding`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_role_binding_api.md) API reference.
## Related topics
-- [Roles and bindings]({{< relref "/operate/kubernetes/security/access-control/_index#roles-and-bindings" >}}) — the conceptual model and an end-to-end example.
-- [Manage roles]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}) — create the roles that a binding references.
-- [Manage users]({{< relref "/operate/kubernetes/security/access-control/manage-users" >}}) — create the users that a binding lists as subjects.
+- [Roles and bindings](/content/operate/kubernetes/security/access-control/_index.md#roles-and-bindings) — the conceptual model and an end-to-end example.
+- [Manage roles](/content/operate/kubernetes/security/access-control/manage-roles.md) — create the roles that a binding references.
+- [Manage users](/content/operate/kubernetes/security/access-control/manage-users.md) — create the users that a binding lists as subjects.
diff --git a/content/operate/kubernetes/security/access-control/manage-roles.md b/content/operate/kubernetes/security/access-control/manage-roles.md
index 1a3e1ba738..40c593b8b7 100644
--- a/content/operate/kubernetes/security/access-control/manage-roles.md
+++ b/content/operate/kubernetes/security/access-control/manage-roles.md
@@ -15,14 +15,14 @@ A role defines a reusable set of Redis Software permissions — Cluster Manager
- `RedisEnterpriseRole` — applies to one or more REDBs selected by `spec.scopes`. Use when you want to grant access to a specific database or set of databases.
- `RedisEnterpriseClusterRole` — applies cluster-wide, across every REDB. Use for administrative access or for permissions you want everywhere.
-For details on how roles and bindings work together, see [Roles and bindings]({{< relref "/operate/kubernetes/security/access-control/_index#roles-and-bindings" >}}). To assign a role to a user, see [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}).
+For details on how roles and bindings work together, see [Roles and bindings](/content/operate/kubernetes/security/access-control/_index.md#roles-and-bindings). To assign a role to a user, see [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md).
## Before you start
- Requires Redis Software for Kubernetes operator 8.2.0-12 or later.
- The role resource must live in the operator namespace. Database scopes resolve to REDBs in that namespace.
- Decide whether you need [management permissions](#choose-a-management-role), [data-path permissions](#attach-an-acl), or both.
-- If the role references one or more `RedisEnterpriseACL` resources, create those first. See [Manage ACLs]({{< relref "/operate/kubernetes/security/access-control/manage-acls" >}}).
+- If the role references one or more `RedisEnterpriseACL` resources, create those first. See [Manage ACLs](/content/operate/kubernetes/security/access-control/manage-acls.md).
## Choose a management role
@@ -33,7 +33,7 @@ For details on how roles and bindings work together, see [Roles and bindings]({{
| `RedisEnterpriseRole` | `DBMember`, `DBViewer`, `None` |
| `RedisEnterpriseClusterRole` | `Admin`, `ClusterMember`, `ClusterViewer`, `DBMember`, `DBViewer`, `UserManager`, `None` |
-`None` grants no management permissions and is the default when `managementRole` is omitted. For what each Redis Software role grants, see [Cluster-scoped role definitions]({{< relref "/operate/rs/security/access-control/create-cluster-roles" >}}) and [Database-scoped role definitions]({{< relref "/operate/rs/security/access-control/create-db-roles" >}}).
+`None` grants no management permissions and is the default when `managementRole` is omitted. For what each Redis Software role grants, see [Cluster-scoped role definitions](/content/operate/rs/security/access-control/create-cluster-roles.md) and [Database-scoped role definitions](/content/operate/rs/security/access-control/create-db-roles.md).
## Create a database role
@@ -170,7 +170,7 @@ For cluster roles, replace `redisenterpriserolebinding` with `redisenterpriseclu
## Delete a role
-Delete any bindings that reference the role first, then delete the role. Find the bindings with the recipes in [Find bindings that reference a role or user]({{< relref "/operate/kubernetes/security/access-control/manage-bindings#find-bindings-that-reference-a-role-or-user" >}}), delete each by name, then delete the role:
+Delete any bindings that reference the role first, then delete the role. Find the bindings with the recipes in [Find bindings that reference a role or user](/content/operate/kubernetes/security/access-control/manage-bindings.md#find-bindings-that-reference-a-role-or-user), delete each by name, then delete the role:
```sh
kubectl delete redisenterpriserolebinding alice-orders-viewer
@@ -188,12 +188,12 @@ Watch reconciliation events with `kubectl describe redisenterpriserole ` (
- **Permissions don't reach the database** — Check `status.uid` on the role, the matching REDB's `status.rolesPermissions`, and confirm a binding assigns the role to the user.
- **`RoleDeletionBlocked`** — A binding still references the role in Redis Software. Delete the binding first.
-For full field details, see the [`RedisEnterpriseRole`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_role_api" >}}) and [`RedisEnterpriseClusterRole`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_role_api" >}}) API reference.
+For full field details, see the [`RedisEnterpriseRole`](/content/operate/kubernetes/reference/api/redis_enterprise_role_api.md) and [`RedisEnterpriseClusterRole`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_role_api.md) API reference.
## Related topics
-- [Roles and bindings]({{< relref "/operate/kubernetes/security/access-control/_index#roles-and-bindings" >}}) — the conceptual model.
-- [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}) — assign a role to a user.
-- [Manage ACLs]({{< relref "/operate/kubernetes/security/access-control/manage-acls" >}}) — define the data-path permissions a role references.
-- [Manage users]({{< relref "/operate/kubernetes/security/access-control/manage-users" >}}) — create the users that bindings target.
-- [Migrate from REDB rolesPermissions]({{< relref "/operate/kubernetes/security/access-control/migrate-rolespermissions" >}}) — move from the deprecated `RedisEnterpriseDatabase.spec.rolesPermissions` field to the new CRD model.
+- [Roles and bindings](/content/operate/kubernetes/security/access-control/_index.md#roles-and-bindings) — the conceptual model.
+- [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md) — assign a role to a user.
+- [Manage ACLs](/content/operate/kubernetes/security/access-control/manage-acls.md) — define the data-path permissions a role references.
+- [Manage users](/content/operate/kubernetes/security/access-control/manage-users.md) — create the users that bindings target.
+- [Migrate from REDB rolesPermissions](/content/operate/kubernetes/security/access-control/migrate-rolespermissions.md) — move from the deprecated `RedisEnterpriseDatabase.spec.rolesPermissions` field to the new CRD model.
diff --git a/content/operate/kubernetes/security/access-control/manage-users.md b/content/operate/kubernetes/security/access-control/manage-users.md
index 856383c77f..d1455f8f27 100644
--- a/content/operate/kubernetes/security/access-control/manage-users.md
+++ b/content/operate/kubernetes/security/access-control/manage-users.md
@@ -12,13 +12,13 @@ weight: 10
A `RedisEnterpriseUser` resource defines a Redis Software user. The operator creates the user in Redis Software and keeps it in sync with the resource. Passwords live in Kubernetes Secrets that the resource references by name.
-This page covers creating users, changing passwords, and recovering locked accounts. To grant a user permissions, see [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}).
+This page covers creating users, changing passwords, and recovering locked accounts. To grant a user permissions, see [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md).
## Before you start
- Requires Redis Software for Kubernetes operator 8.2.0-12 or later.
- The `RedisEnterpriseUser` resource and every referenced password Secret must live in the operator namespace.
-- Passwords must satisfy the cluster's [password complexity rules]({{< relref "/operate/rs/security/access-control/manage-passwords/password-complexity-rules" >}}).
+- Passwords must satisfy the cluster's [password complexity rules](/content/operate/rs/security/access-control/manage-passwords/password-complexity-rules.md).
## Create a user
@@ -62,9 +62,9 @@ The new user has no permissions until you create a role binding. The operator as
| `spec.username` | No | Defaults to a generated value. ASCII only, excluding `&`, `<`, `>`, `"`. The effective value appears in `status.username`. |
| `spec.passwordSecrets` | Yes | At least one Secret. Each Secret must have a `password` key. |
| `spec.passwordMode` | No | `Single` (default) or `Rotatable`. See [Choose a password mode](#choose-a-password-mode). |
-| `spec.alerts` | No | Email alert settings. Effective only when [cluster alerts]({{< relref "/operate/rs/clusters/configure/cluster-settings#alert-settings" >}}) are configured. |
+| `spec.alerts` | No | Email alert settings. Effective only when [cluster alerts](/content/operate/rs/clusters/configure/cluster-settings.md#alert-settings) are configured. |
-For the full schema, see [`RedisEnterpriseUser`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_user_api" >}}).
+For the full schema, see [`RedisEnterpriseUser`](/content/operate/kubernetes/reference/api/redis_enterprise_user_api.md).
### Use a generated username
@@ -152,13 +152,13 @@ The `status` block reports observed state from Redis Software:
`status.signinStatus: Locked` means the user failed too many sign-in attempts. The operator skips password changes while the user is locked, so you must update the resource before unlocking — otherwise the operator can later reconcile the old desired password back onto the user.
1. Update the password in the `RedisEnterpriseUser` source of truth: change the referenced Secret value (Single mode) or add a new Secret reference (Rotatable mode).
-2. Follow the [Redis Software unlock procedure]({{< relref "/operate/rs/security/access-control/manage-users/login-lockout#unlock-locked-user-accounts" >}}) to reset and unlock the account in the cluster.
+2. Follow the [Redis Software unlock procedure](/content/operate/rs/security/access-control/manage-users/login-lockout.md#unlock-locked-user-accounts) to reset and unlock the account in the cluster.
`status.signinStatus: PasswordExpired` clears once you set a new password through the resource.
## Delete a user
-Delete every binding that references the user before deleting the user itself. Use the recipes in [Find bindings that reference a role or user]({{< relref "/operate/kubernetes/security/access-control/manage-bindings#find-bindings-that-reference-a-role-or-user" >}}) to list them, delete each by name, then delete the user:
+Delete every binding that references the user before deleting the user itself. Use the recipes in [Find bindings that reference a role or user](/content/operate/kubernetes/security/access-control/manage-bindings.md#find-bindings-that-reference-a-role-or-user) to list them, delete each by name, then delete the user:
```sh
kubectl delete redisenterpriserolebinding alice-orders-viewer
@@ -192,7 +192,7 @@ Other things to check:
## Related topics
-- [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}) — assign roles to this user.
-- [Default user]({{< relref "/operate/rs/security/access-control/manage-users/default-user" >}}) — the built-in cluster admin account, managed outside the CRD model.
-- [Password complexity rules]({{< relref "/operate/rs/security/access-control/manage-passwords/password-complexity-rules" >}}) and [password expiration]({{< relref "/operate/rs/security/access-control/manage-passwords/password-expiration" >}}).
-- [`RedisEnterpriseUser` API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_user_api" >}}).
+- [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md) — assign roles to this user.
+- [Default user](/content/operate/rs/security/access-control/manage-users/default-user.md) — the built-in cluster admin account, managed outside the CRD model.
+- [Password complexity rules](/content/operate/rs/security/access-control/manage-passwords/password-complexity-rules.md) and [password expiration](/content/operate/rs/security/access-control/manage-passwords/password-expiration.md).
+- [`RedisEnterpriseUser` API reference](/content/operate/kubernetes/reference/api/redis_enterprise_user_api.md).
diff --git a/content/operate/kubernetes/security/access-control/migrate-rolespermissions.md b/content/operate/kubernetes/security/access-control/migrate-rolespermissions.md
index 6b950963cd..f5929f8878 100644
--- a/content/operate/kubernetes/security/access-control/migrate-rolespermissions.md
+++ b/content/operate/kubernetes/security/access-control/migrate-rolespermissions.md
@@ -17,8 +17,8 @@ This page covers moving an existing database from `rolesPermissions` to the CRD
## Before you start
- Requires Redis Software for Kubernetes operator 8.2.0-12 or later.
-- Every user who currently holds access through `rolesPermissions` must exist as a `RedisEnterpriseUser` resource before you can bind a CRD role to them. If you created users through the Redis Software REST API or Cluster Manager UI, migrate them first. See [Manage users]({{< relref "/operate/kubernetes/security/access-control/manage-users" >}}).
-- List which Redis Software users hold each role. The CRD inventory only captures the database side of the assignment; the user-to-role mapping lives in Redis Software. Pull it from the Cluster Manager UI or the [Redis Software users REST API]({{< relref "/operate/rs/references/rest-api/objects/user" >}}).
+- Every user who currently holds access through `rolesPermissions` must exist as a `RedisEnterpriseUser` resource before you can bind a CRD role to them. If you created users through the Redis Software REST API or Cluster Manager UI, migrate them first. See [Manage users](/content/operate/kubernetes/security/access-control/manage-users.md).
+- List which Redis Software users hold each role. The CRD inventory only captures the database side of the assignment; the user-to-role mapping lives in Redis Software. Pull it from the Cluster Manager UI or the [Redis Software users REST API](/content/operate/rs/references/rest-api/objects/user.md).
## How the two sources interact
@@ -63,7 +63,7 @@ Each entry has a `role` (Redis Software role name) and an `acl` (Redis Software
### 2. Create RedisEnterpriseACL resources
-For every distinct ACL name in the inventory, create a `RedisEnterpriseACL` resource that holds the same rule string. See [Manage ACLs]({{< relref "/operate/kubernetes/security/access-control/manage-acls" >}}).
+For every distinct ACL name in the inventory, create a `RedisEnterpriseACL` resource that holds the same rule string. See [Manage ACLs](/content/operate/kubernetes/security/access-control/manage-acls.md).
```yaml
apiVersion: app.redislabs.com/v1alpha1
@@ -78,7 +78,7 @@ The resource `metadata.name` doesn't have to match the original Redis Software A
### 3. Create RedisEnterpriseRole resources
-For each role-ACL-REDB combination in the inventory, create a `RedisEnterpriseRole` scoped to the target REDB. See [Manage roles]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}).
+For each role-ACL-REDB combination in the inventory, create a `RedisEnterpriseRole` scoped to the target REDB. See [Manage roles](/content/operate/kubernetes/security/access-control/manage-roles.md).
```yaml
apiVersion: app.redislabs.com/v1alpha1
@@ -110,7 +110,7 @@ spec:
### 4. Create bindings for affected users
-For each user that previously gained access through `rolesPermissions`, create a `RedisEnterpriseRoleBinding` that references the new role. See [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}).
+For each user that previously gained access through `rolesPermissions`, create a `RedisEnterpriseRoleBinding` that references the new role. See [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md).
```yaml
apiVersion: app.redislabs.com/v1alpha1
@@ -186,8 +186,8 @@ To revert to the deprecated field, set `allowREDBRolesPermissions: true` (or omi
## Related topics
-- [Manage roles]({{< relref "/operate/kubernetes/security/access-control/manage-roles" >}}) — full details on `RedisEnterpriseRole` and `RedisEnterpriseClusterRole`.
-- [Manage ACLs]({{< relref "/operate/kubernetes/security/access-control/manage-acls" >}}) — define the data-path permissions roles reference.
-- [Manage role bindings]({{< relref "/operate/kubernetes/security/access-control/manage-bindings" >}}) — assign the new roles to users.
-- [`RedisEnterpriseDatabase` API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}}) — the source schema, including the deprecated `rolesPermissions` field.
-- [`RedisEnterpriseCluster` API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) — the `accessControl.policy.allowREDBRolesPermissions` flag.
+- [Manage roles](/content/operate/kubernetes/security/access-control/manage-roles.md) — full details on `RedisEnterpriseRole` and `RedisEnterpriseClusterRole`.
+- [Manage ACLs](/content/operate/kubernetes/security/access-control/manage-acls.md) — define the data-path permissions roles reference.
+- [Manage role bindings](/content/operate/kubernetes/security/access-control/manage-bindings.md) — assign the new roles to users.
+- [`RedisEnterpriseDatabase` API reference](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md) — the source schema, including the deprecated `rolesPermissions` field.
+- [`RedisEnterpriseCluster` API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) — the `accessControl.policy.allowREDBRolesPermissions` flag.
diff --git a/content/operate/kubernetes/security/allow-resource-adjustment.md b/content/operate/kubernetes/security/allow-resource-adjustment.md
index 472c746b76..5fcc6b355c 100644
--- a/content/operate/kubernetes/security/allow-resource-adjustment.md
+++ b/content/operate/kubernetes/security/allow-resource-adjustment.md
@@ -68,7 +68,7 @@ oc delete scc/redis-enterprise-scc-v2
oc adm policy remove-scc-from-user redis-enterprise-scc-v2 -z
```
-If running with automatic resource adjustment enabled, manually reapply the [security context constraints (SCC)](https://docs.openshift.com/container-platform/4.8/authentication/managing-security-context-constraints.html) file ([`scc.yaml`]({{< relref "/operate/kubernetes/deployment/openshift/openshift-cli#deploy-the-operator" >}})).
+If running with automatic resource adjustment enabled, manually reapply the [security context constraints (SCC)](https://docs.openshift.com/container-platform/4.8/authentication/managing-security-context-constraints.html) file ([`scc.yaml`](/content/operate/kubernetes/deployment/openshift/openshift-cli.md#deploy-the-operator)).
```sh
oc apply -f openshift/scc.yaml
@@ -87,9 +87,8 @@ To enable automatic resource adjustment after installation, apply and grant perm
1. Apply the `scc.yaml` file.
- {{}}
-Do not edit this file.
- {{}}
+ > [!WARNING]
+ > Do not edit this file.
```sh
oc apply -f openshift/scc.yaml
diff --git a/content/operate/kubernetes/security/authentication/_index.md b/content/operate/kubernetes/security/authentication/_index.md
index 5a1322d86e..cc4b03d3eb 100644
--- a/content/operate/kubernetes/security/authentication/_index.md
+++ b/content/operate/kubernetes/security/authentication/_index.md
@@ -24,23 +24,23 @@ Authentication covers cluster credentials, external identity providers (LDAP and
The underlying Redis Software behavior is unchanged. For concepts and reference details, see the existing Redis Software docs:
-- [LDAP authentication overview]({{< relref "/operate/rs/security/access-control/ldap" >}}) — server requirements, supported attributes, and the LDAP model.
-- [Enable role-based LDAP]({{< relref "/operate/rs/security/access-control/ldap/enable-role-based-ldap" >}}) — concepts behind role-based LDAP.
-- [Map LDAP groups to roles]({{< relref "/operate/rs/security/access-control/ldap/map-ldap-groups-to-roles" >}}) — group-to-role mapping rules.
-- [SAML single sign-on]({{< relref "/operate/rs/security/access-control/saml-sso" >}}) — identity provider requirements and SAML attribute mappings.
-- [Default user]({{< relref "/operate/rs/security/access-control/manage-users/default-user" >}}) — what the bootstrap admin account is for.
+- [LDAP authentication overview](/content/operate/rs/security/access-control/ldap/_index.md) — server requirements, supported attributes, and the LDAP model.
+- [Enable role-based LDAP](/content/operate/rs/security/access-control/ldap/enable-role-based-ldap.md) — concepts behind role-based LDAP.
+- [Map LDAP groups to roles](/content/operate/rs/security/access-control/ldap/map-ldap-groups-to-roles.md) — group-to-role mapping rules.
+- [SAML single sign-on](/content/operate/rs/security/access-control/saml-sso.md) — identity provider requirements and SAML attribute mappings.
+- [Default user](/content/operate/rs/security/access-control/manage-users/default-user.md) — what the bootstrap admin account is for.
## What's different on Kubernetes
- **Initial credentials are auto-generated by default.** If you don't provide them, the operator generates them and stores them in the credentials Secret, which you retrieve after the REC is up. You can instead supply your own Secret name and credentials at cluster creation time.
-- **Change the cluster admin credentials in Redis Software, then mirror them to the Secret.** Update the credentials directly in Redis Software and reflect the new values in the credentials Secret — see [Manage REC credentials]({{< relref "/operate/kubernetes/security/authentication/manage-rec-credentials" >}}). Credentials for other users are managed through their `RedisEnterpriseUser` resources and Secrets.
+- **Change the cluster admin credentials in Redis Software, then mirror them to the Secret.** Update the credentials directly in Redis Software and reflect the new values in the credentials Secret — see [Manage REC credentials](/content/operate/kubernetes/security/authentication/manage-rec-credentials.md). Credentials for other users are managed through their `RedisEnterpriseUser` resources and Secrets.
- **LDAP and SSO configuration is part of the REC spec.** The operator applies it through the Redis Software REST API, so the configuration is source-controlled.
- **Sensitive values live in Kubernetes Secrets** (or HashiCorp Vault) instead of in Redis Software configuration files.
## In this section
-- [Manage REC credentials]({{< relref "/operate/kubernetes/security/authentication/manage-rec-credentials" >}}) — retrieve and update the cluster admin credentials Secret.
-- [Manage REDB passwords]({{< relref "/operate/kubernetes/security/authentication/manage-redb-credentials" >}}) — retrieve and rotate database passwords through the database Secret.
-- [Configuration secrets]({{< relref "/operate/kubernetes/security/authentication/configuration-secrets" >}}) — store config items in Kubernetes Secrets and reconcile updates automatically.
-- [LDAP authentication]({{< relref "/operate/kubernetes/security/authentication/ldap" >}}) — configure LDAP for Cluster Manager and database access.
-- [SSO authentication]({{< relref "/operate/kubernetes/security/authentication/sso" >}}) — configure SAML single sign-on for the Cluster Manager UI.
+- [Manage REC credentials](/content/operate/kubernetes/security/authentication/manage-rec-credentials.md) — retrieve and update the cluster admin credentials Secret.
+- [Manage REDB passwords](/content/operate/kubernetes/security/authentication/manage-redb-credentials.md) — retrieve and rotate database passwords through the database Secret.
+- [Configuration secrets](/content/operate/kubernetes/security/authentication/configuration-secrets.md) — store config items in Kubernetes Secrets and reconcile updates automatically.
+- [LDAP authentication](/content/operate/kubernetes/security/authentication/ldap.md) — configure LDAP for Cluster Manager and database access.
+- [SSO authentication](/content/operate/kubernetes/security/authentication/sso.md) — configure SAML single sign-on for the Cluster Manager UI.
diff --git a/content/operate/kubernetes/security/authentication/configuration-secrets.md b/content/operate/kubernetes/security/authentication/configuration-secrets.md
index 6efa72a6e5..c0e995aae3 100644
--- a/content/operate/kubernetes/security/authentication/configuration-secrets.md
+++ b/content/operate/kubernetes/security/authentication/configuration-secrets.md
@@ -51,9 +51,8 @@ spec:
----- LICENSE END -----
```
-{{}}
-You must include the pipe symbol (`|`) after `license:` and maintain proper indentation.
-{{}}
+> [!NOTE]
+> You must include the pipe symbol (`|`) after `license:` and maintain proper indentation.
## Cluster credential configuration
@@ -67,11 +66,10 @@ By default, the operator automatically creates a secret with a random username a
You can customize the credential secret name during cluster creation using the `clusterCredentialSecretName` field in your REC specification. The secret must contain `username` and `password` fields.
-{{}}
-The `clusterCredentialSecretName` field cannot be changed after cluster creation.
-{{}}
+> [!NOTE]
+> The `clusterCredentialSecretName` field cannot be changed after cluster creation.
-For detailed instructions, see [Customize the credential secret name]({{< relref "/operate/kubernetes/security/authentication/manage-rec-credentials#customize-the-credential-secret-name" >}}).
+For detailed instructions, see [Customize the credential secret name](/content/operate/kubernetes/security/authentication/manage-rec-credentials.md#customize-the-credential-secret-name).
## TLS certificate configuration
@@ -85,7 +83,7 @@ You can store TLS certificates in Kubernetes Secrets to secure communication bet
kubectl -n create secret generic client-cert-secret --from-file=cert=
```
-2. Add the secret to your REDB using the `clientAuthenticationCertificates` property. See [Add client certificates]({{< relref "/operate/kubernetes/security/certificates/add-client-certificates" >}}) for details.
+2. Add the secret to your REDB using the `clientAuthenticationCertificates` property. See [Add client certificates](/content/operate/kubernetes/security/certificates/add-client-certificates.md) for details.
### Service certificates
@@ -116,7 +114,7 @@ kubectl create secret generic dp-internode-cert \
--from-literal=name=dp_internode_encryption
```
-Reference these secrets in your REC specification under `spec.certificates`. See [Internode encryption]({{< relref "/operate/kubernetes/security/certificates/internode-encryption" >}}) for complete configuration details.
+Reference these secrets in your REC specification under `spec.certificates`. See [Internode encryption](/content/operate/kubernetes/security/certificates/internode-encryption.md) for complete configuration details.
## Secrets and PEM files in Redis Enterprise pods
@@ -151,7 +149,7 @@ Field names vary by deployment.
## See also
-- [Manage REC credentials]({{< relref "/operate/kubernetes/security/authentication/manage-rec-credentials" >}})
-- [Manage REC certificates]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}})
-- [Add client certificates]({{< relref "/operate/kubernetes/security/certificates/add-client-certificates" >}})
-- [Redis Enterprise Cluster API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}})
+- [Manage REC credentials](/content/operate/kubernetes/security/authentication/manage-rec-credentials.md)
+- [Manage REC certificates](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md)
+- [Add client certificates](/content/operate/kubernetes/security/certificates/add-client-certificates.md)
+- [Redis Enterprise Cluster API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md)
diff --git a/content/operate/kubernetes/security/authentication/ldap.md b/content/operate/kubernetes/security/authentication/ldap.md
index 314ab51b20..d8e8b14a55 100644
--- a/content/operate/kubernetes/security/authentication/ldap.md
+++ b/content/operate/kubernetes/security/authentication/ldap.md
@@ -13,11 +13,11 @@ weight: 30
## LDAP support for Redis Enterprise Software
-Redis Enterprise Software supports LDAP authentication and authorization through [role-based access controls]({{< relref "/operate/rs/security/access-control/" >}}) (RBAC). You can map LDAP groups to [Redis Enterprise roles]({{< relref "/operate/rs/security/access-control" >}}) to control access to your database and the Cluster Manager UI. For more details on how LDAP works with Redis Enterprise, see [LDAP authentication]({{< relref "/operate/rs/security/access-control/ldap/" >}}).
+Redis Enterprise Software supports LDAP authentication and authorization through [role-based access controls](/content/operate/rs/security/access-control/_index.md) (RBAC). You can map LDAP groups to [Redis Enterprise roles](/content/operate/rs/security/access-control/_index.md) to control access to your database and the Cluster Manager UI. For more details on how LDAP works with Redis Enterprise, see [LDAP authentication](/content/operate/rs/security/access-control/ldap/_index.md).
Redis Enterprise for Kubernetes supports enabling and configuring LDAP authentication using the `RedisEnterpriseCluster` (REC) custom resource. Currently, the Redis Enterprise cluster (REC) only supports configuration related to the LDAP server, such as server addresses, connection details, credentials, and query configuration.
-To [map LDAP groups to Redis Enterprise access control roles]({{< relref "/operate/rs/security/access-control/ldap/enable-role-based-ldap.md" >}}), you'll need to use the Redis Enterprise [API]({{< relref "/operate/rs/references/rest-api/requests/ldap_mappings/" >}}) or [admin console]({{< relref "/operate/rs/security/access-control/ldap/enable-role-based-ldap.md" >}}).
+To [map LDAP groups to Redis Enterprise access control roles](/content/operate/rs/security/access-control/ldap/enable-role-based-ldap.md), you'll need to use the Redis Enterprise [API](/content/operate/rs/references/rest-api/requests/ldap_mappings/_index.md) or [admin console](/content/operate/rs/security/access-control/ldap/enable-role-based-ldap.md).
## Enable LDAP
@@ -47,7 +47,7 @@ spec:
attribute: memberOf
```
-Refer to the `RedisEnterpriseCluster` [API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specldap" >}}) for full details on the available fields.
+Refer to the `RedisEnterpriseCluster` [API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specldap) for full details on the available fields.
### Bind credentials
@@ -163,6 +163,6 @@ Redis Enterprise Software can't resolve DNS names with a `.local` suffix.
## Next steps
-To [map LDAP groups to Redis Enterprise access control roles]({{< relref "/operate/rs/security/access-control/ldap/enable-role-based-ldap.md" >}}), you'll need to use the Redis Enterprise [API]({{< relref "/operate/rs/references/rest-api/requests/ldap_mappings/" >}}) or [admin console]({{< relref "/operate/rs/security/access-control/ldap/enable-role-based-ldap.md" >}}).
+To [map LDAP groups to Redis Enterprise access control roles](/content/operate/rs/security/access-control/ldap/enable-role-based-ldap.md), you'll need to use the Redis Enterprise [API](/content/operate/rs/references/rest-api/requests/ldap_mappings/_index.md) or [admin console](/content/operate/rs/security/access-control/ldap/enable-role-based-ldap.md).
-For more details on how LDAP works with Redis Enterprise, see [LDAP authentication]({{< relref "/operate/rs/security/access-control/ldap/" >}}).
+For more details on how LDAP works with Redis Enterprise, see [LDAP authentication](/content/operate/rs/security/access-control/ldap/_index.md).
diff --git a/content/operate/kubernetes/security/authentication/manage-rec-credentials.md b/content/operate/kubernetes/security/authentication/manage-rec-credentials.md
index 3408fda7fa..0ce9acadf3 100644
--- a/content/operate/kubernetes/security/authentication/manage-rec-credentials.md
+++ b/content/operate/kubernetes/security/authentication/manage-rec-credentials.md
@@ -9,7 +9,7 @@ aliases: [/operate/kubernetes/security/manage-rec-credentials/]
linkTitle: Manage REC credentials
weight: 10
---
-Redis Enterprise for Kubernetes uses a custom resource called [`RedisEnterpriseCluster`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) to create a Redis Enterprise cluster (REC). During creation, it generates random credentials for the operator to use. The credentials are saved in a Kubernetes (K8s) [secret](https://kubernetes.io/docs/concepts/configuration/secret/). The secret name defaults to the cluster name and is specified by the `clusterCredentialSecretName` field in the REC specification.
+Redis Enterprise for Kubernetes uses a custom resource called [`RedisEnterpriseCluster`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) to create a Redis Enterprise cluster (REC). During creation, it generates random credentials for the operator to use. The credentials are saved in a Kubernetes (K8s) [secret](https://kubernetes.io/docs/concepts/configuration/secret/). The secret name defaults to the cluster name and is specified by the `clusterCredentialSecretName` field in the REC specification.
## Retrieve the current username and password
@@ -92,15 +92,14 @@ The credentials can be used to access the Redis Enterprise admin console or the
\"old_password\":\"\"}"
```
-{{}}
-The username for the K8s secret is the email displayed on the Redis Enterprise admin console.
-{{}}
+> [!NOTE]
+> The username for the K8s secret is the email displayed on the Redis Enterprise admin console.
### Change both the REC username and password
-1. [Connect to the admin console]({{< relref "/operate/kubernetes/re-clusters/connect-to-admin-console.md" >}}).
+1. [Connect to the admin console](/content/operate/kubernetes/re-clusters/connect-to-admin-console.md).
-1. [Add another admin user]({{< relref "/operate/rs/security/access-control/create-users" >}}) and choose a new password.
+1. [Add another admin user](/content/operate/rs/security/access-control/create-users.md) and choose a new password.
1. Specify the new username in the `username` field of your REC custom resource spec.
@@ -120,9 +119,8 @@ The username for the K8s secret is the email displayed on the Redis Enterprise a
1. Delete the previous admin user from the cluster.
-{{}}
-The operator may log errors in the time between updating the username in the REC spec and the secret update.
-{{}}
+> [!NOTE]
+> The operator may log errors in the time between updating the username in the REC spec and the secret update.
### Update the credentials secret in Vault
diff --git a/content/operate/kubernetes/security/authentication/manage-redb-credentials.md b/content/operate/kubernetes/security/authentication/manage-redb-credentials.md
index a98005372a..fc3e233a6c 100644
--- a/content/operate/kubernetes/security/authentication/manage-redb-credentials.md
+++ b/content/operate/kubernetes/security/authentication/manage-redb-credentials.md
@@ -10,7 +10,7 @@ linkTitle: Manage REDB passwords
weight: 15
---
-Each [`RedisEnterpriseDatabase`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}}) resource has a password stored under the `password` key of the secret named by `spec.databaseSecretName`. If you don't set `databaseSecretName`, the operator creates a secret named `redb-` with a random password and updates the REDB spec to reference it.
+Each [`RedisEnterpriseDatabase`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md) resource has a password stored under the `password` key of the secret named by `spec.databaseSecretName`. If you don't set `databaseSecretName`, the operator creates a secret named `redb-` with a random password and updates the REDB spec to reference it.
The operator reads the `password` key on every reconciliation and applies it to the database, so you rotate the password by updating the secret.
@@ -30,9 +30,8 @@ The operator reads the `password` key on every reconciliation and applies it to
## Change the REDB password
-{{}}
-If the REDB spec sets `defaultUser: false`, the operator does not create or update the database secret. Rotating the secret has no effect in that mode — manage credentials through [access control]({{< relref "/operate/kubernetes/security/access-control" >}}) instead, using [`RedisEnterpriseUser`]({{< relref "/operate/kubernetes/security/access-control/manage-users" >}}) resources.
-{{}}
+> [!NOTE]
+> If the REDB spec sets `defaultUser: false`, the operator does not create or update the database secret. Rotating the secret has no effect in that mode — manage credentials through [access control](/content/operate/kubernetes/security/access-control/_index.md) instead, using [`RedisEnterpriseUser`](/content/operate/kubernetes/security/access-control/manage-users.md) resources.
1. Base64-encode the new password. Use `echo -n` to avoid encoding a trailing newline:
@@ -66,6 +65,5 @@ To disable authentication for the default user, set the `password` value to an e
Existing client connections authenticated with the old password remain open — Redis Enterprise does not drop sessions when the password changes. New connections, and any `AUTH` commands issued on existing connections, must use the new password. Coordinate the secret update with your client configuration to avoid authentication errors.
-{{}}
-For Active-Active databases, the database secret is not created automatically. See [Create a global database secret]({{< relref "/operate/kubernetes/active-active/global-db-secret" >}}).
-{{}}
+> [!NOTE]
+> For Active-Active databases, the database secret is not created automatically. See [Create a global database secret](/content/operate/kubernetes/active-active/global-db-secret.md).
diff --git a/content/operate/kubernetes/security/authentication/sso.md b/content/operate/kubernetes/security/authentication/sso.md
index a1fe322758..5a092fddaf 100644
--- a/content/operate/kubernetes/security/authentication/sso.md
+++ b/content/operate/kubernetes/security/authentication/sso.md
@@ -35,7 +35,7 @@ Before enabling SSO, ensure you have:
1. An existing Redis Enterprise cluster (REC) deployed in Kubernetes
-2. **External access to the Cluster Manager UI** - The Cluster Manager UI must be accessible externally via a LoadBalancer service or Ingress so users can access it from their browser and the identity provider can redirect back after authentication. See [Connect to the admin console]({{< relref "/operate/kubernetes/re-clusters/connect-to-admin-console.md" >}}) for configuration options.
+2. **External access to the Cluster Manager UI** - The Cluster Manager UI must be accessible externally via a LoadBalancer service or Ingress so users can access it from their browser and the identity provider can redirect back after authentication. See [Connect to the admin console](/content/operate/kubernetes/re-clusters/connect-to-admin-console.md) for configuration options.
3. A SAML 2.0-compatible identity provider (such as Okta, Azure AD, or similar)
@@ -43,9 +43,8 @@ Before enabling SSO, ensure you have:
5. A TLS certificate and private key for the service provider (SP)
-{{}}
-SSO requires external access to the Cluster Manager UI. Port forwarding is not sufficient for SSO authentication because the identity provider needs to redirect users back to the UI after authentication. You must configure either a LoadBalancer service (via `spec.uiServiceType: LoadBalancer`) or an Ingress controller.
-{{}}
+> [!WARNING]
+> SSO requires external access to the Cluster Manager UI. Port forwarding is not sufficient for SSO authentication because the identity provider needs to redirect users back to the UI after authentication. You must configure either a LoadBalancer service (via `spec.uiServiceType: LoadBalancer`) or an Ingress controller.
### Step 1: Upload Service Provider certificate and private key
@@ -120,9 +119,8 @@ Examples:
- `"redis-ui.example.com:443"` (defaults to https://)
- `"http://redis-ui.example.com:9443"` (NOT recommended for production)
-{{}}
-Using `http://` is NOT recommended for production environments as it transmits sensitive SAML assertions in plaintext. Only use `http://` for testing or development purposes.
-{{}}
+> [!WARNING]
+> Using `http://` is NOT recommended for production environments as it transmits sensitive SAML assertions in plaintext. Only use `http://` for testing or development purposes.
**Usage guidelines:**
- **For LoadBalancer services:** Leave this field blank to use the default REC UI service, or set it explicitly to the LoadBalancer address for custom services.
@@ -140,9 +138,8 @@ If you configured `spMetadataSecretName` in Step 1, the operator creates a secre
kubectl -n get secret sp-metadata -o jsonpath='{.data.sp_metadata}' | base64 -d > sp-metadata.xml
```
-{{}}
-This secret is only created when the cluster is configured to use Kubernetes secrets (`spec.clusterCredentialSecretType` is unset or set to `"kubernetes"`). When using Vault secrets, use Option B instead.
-{{}}
+> [!NOTE]
+> This secret is only created when the cluster is configured to use Kubernetes secrets (`spec.clusterCredentialSecretType` is unset or set to `"kubernetes"`). When using Vault secrets, use Option B instead.
#### Option B: Retrieve from the API
@@ -209,9 +206,8 @@ Now configure the identity provider details in your Redis Enterprise cluster.
Replace `` with the path to your IdP certificate file.
- {{}}
-While IdP metadata XML may contain the certificate, Redis Enterprise Server does not use it from there, so the certificate must be provided separately via this secret.
- {{}}
+ > [!NOTE]
+ > While IdP metadata XML may contain the certificate, Redis Enterprise Server does not use it from there, so the certificate must be provided separately via this secret.
2. Configure the IdP using one of the following options:
@@ -292,9 +288,8 @@ If IdP metadata XML is unavailable, you can manually configure the issuer settin
kubectl apply -f .yaml
```
-{{}}
-If both `idpMetadataSecretName` and `issuer` are provided, `idpMetadataSecretName` takes precedence and `issuer` is ignored.
-{{}}
+> [!NOTE]
+> If both `idpMetadataSecretName` and `issuer` are provided, `idpMetadataSecretName` takes precedence and `issuer` is ignored.
### Step 6: Assign SAML app to users
@@ -361,7 +356,7 @@ spec:
baseAddress: "https://redis-ui.example.com:443"
```
-Refer to the `RedisEnterpriseCluster` [API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specsso" >}}) for full details on the available fields.
+Refer to the `RedisEnterpriseCluster` [API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specsso) for full details on the available fields.
## Next steps
@@ -371,4 +366,4 @@ After enabling SSO:
2. Set up the `redisRoleMapping` attribute in your identity provider to assign appropriate roles for new users
3. Test both IdP-initiated and SP-initiated SSO flows
-For more information about Redis Enterprise Software security, see [Access control]({{< relref "/operate/rs/security/access-control/" >}}).
+For more information about Redis Enterprise Software security, see [Access control](/content/operate/rs/security/access-control/_index.md).
diff --git a/content/operate/kubernetes/security/certificates/_index.md b/content/operate/kubernetes/security/certificates/_index.md
index 192b4c2e40..7fe41b77e5 100644
--- a/content/operate/kubernetes/security/certificates/_index.md
+++ b/content/operate/kubernetes/security/certificates/_index.md
@@ -24,15 +24,15 @@ Certificates and encryption use Kubernetes Secrets and cert-manager integration
The underlying certificate roles, requirements, and TLS behavior are unchanged. For concepts and reference details, see the existing Redis Software docs:
-- [Certificate roles and types]({{< relref "/operate/rs/security/certificates" >}}) — which certificate is used for what.
-- [Create certificates]({{< relref "/operate/rs/security/certificates/create-certificates" >}}) — certificate requirements (SAN, CN, validity).
-- [Update certificates]({{< relref "/operate/rs/security/certificates/updating-certificates" >}}) — rotation considerations on Redis Software.
-- [Monitor certificates]({{< relref "/operate/rs/security/certificates/monitor-certificates" >}}) — certificate expiration alerts.
-- [Client certificate authentication]({{< relref "/operate/rs/security/certificates/certificate-based-authentication" >}}) — how the cluster validates client certificates.
-- [TLS protocols]({{< relref "/operate/rs/security/encryption/tls/tls-protocols" >}}) and [ciphers]({{< relref "/operate/rs/security/encryption/tls/ciphers" >}}) — protocol and cipher selection.
-- [Enable TLS]({{< relref "/operate/rs/security/encryption/tls/enable-tls" >}}) — TLS for management, replication, and client connections.
-- [Internode encryption]({{< relref "/operate/rs/security/encryption/internode-encryption" >}}) — purpose and scope.
-- [PEM encryption]({{< relref "/operate/rs/security/encryption/pem-encryption" >}}) — encrypted private keys.
+- [Certificate roles and types](/content/operate/rs/security/certificates/_index.md) — which certificate is used for what.
+- [Create certificates](/content/operate/rs/security/certificates/create-certificates.md) — certificate requirements (SAN, CN, validity).
+- [Update certificates](/content/operate/rs/security/certificates/updating-certificates.md) — rotation considerations on Redis Software.
+- [Monitor certificates](/content/operate/rs/security/certificates/monitor-certificates.md) — certificate expiration alerts.
+- [Client certificate authentication](/content/operate/rs/security/certificates/certificate-based-authentication.md) — how the cluster validates client certificates.
+- [TLS protocols](/content/operate/rs/security/encryption/tls/tls-protocols.md) and [ciphers](/content/operate/rs/security/encryption/tls/ciphers.md) — protocol and cipher selection.
+- [Enable TLS](/content/operate/rs/security/encryption/tls/enable-tls.md) — TLS for management, replication, and client connections.
+- [Internode encryption](/content/operate/rs/security/encryption/internode-encryption.md) — purpose and scope.
+- [PEM encryption](/content/operate/rs/security/encryption/pem-encryption.md) — encrypted private keys.
## What's different on Kubernetes
@@ -41,7 +41,7 @@ The underlying certificate roles, requirements, and TLS behavior are unchanged.
## In this section
-- [Manage REC certificates]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) — configure cluster TLS certificates.
-- [cert-manager integration]({{< relref "/operate/kubernetes/security/certificates/cert-manager" >}}) — automate certificate issuance and rotation with cert-manager.
-- [Add client certificates]({{< relref "/operate/kubernetes/security/certificates/add-client-certificates" >}}) — enable client certificate authentication for databases.
-- [Internode encryption]({{< relref "/operate/kubernetes/security/certificates/internode-encryption" >}}) — enable encryption between cluster nodes.
+- [Manage REC certificates](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) — configure cluster TLS certificates.
+- [cert-manager integration](/content/operate/kubernetes/security/certificates/cert-manager.md) — automate certificate issuance and rotation with cert-manager.
+- [Add client certificates](/content/operate/kubernetes/security/certificates/add-client-certificates.md) — enable client certificate authentication for databases.
+- [Internode encryption](/content/operate/kubernetes/security/certificates/internode-encryption.md) — enable encryption between cluster nodes.
diff --git a/content/operate/kubernetes/security/certificates/cert-manager.md b/content/operate/kubernetes/security/certificates/cert-manager.md
index 21f9f8daad..063e9ebb57 100644
--- a/content/operate/kubernetes/security/certificates/cert-manager.md
+++ b/content/operate/kubernetes/security/certificates/cert-manager.md
@@ -25,7 +25,8 @@ Benefits of using cert-manager include:
- **Multiple certificate authorities**: Support for Let's Encrypt, private CAs, Vault, and more.
- **Automatic propagation**: For Active-Active databases, certificate changes automatically sync across all participating clusters.
-{{}}The cert-manager integration uses Kubernetes secrets. It is not compatible with Vault-based secret management (when `clusterCredentialSecretType: vault`). See [HashiCorp Vault integration]({{< relref "/operate/kubernetes/security/vault" >}}) for details.{{}}
+> [!WARNING]
+> The cert-manager integration uses Kubernetes secrets. It is not compatible with Vault-based secret management (when `clusterCredentialSecretType: vault`). See [HashiCorp Vault integration](/content/operate/kubernetes/security/vault.md) for details.
## Prerequisites
@@ -44,7 +45,8 @@ cert-manager creates standard Kubernetes TLS secrets with the following fields:
The Redis Enterprise operator automatically recognizes these secrets and can use them interchangeably with manually created secrets.
-{{}}If you currently use opaque secrets for your certificates, you can switch to cert-manager's TLS secrets without any additional configuration changes to your Redis resources.{{}}
+> [!NOTE]
+> If you currently use opaque secrets for your certificates, you can switch to cert-manager's TLS secrets without any additional configuration changes to your Redis resources.
### Supported secret formats
@@ -56,9 +58,11 @@ The operator supports multiple field names for backward compatibility:
| Private key | `tls.key`, `key` |
| CA certificate | `ca.crt` |
-{{}}Support for the `tls.crt` and `tls.key` field names requires Redis Software for Kubernetes 8.0.18 or later. For secret requirements on earlier versions, see [Manage REC certificates]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}).{{}}
+> [!NOTE]
+> Support for the `tls.crt` and `tls.key` field names requires Redis Software for Kubernetes 8.0.18 or later. For secret requirements on earlier versions, see [Manage REC certificates](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md).
-{{}}The `ca.crt` field is automatically appended to the certificate chain when present. cert-manager typically populates this field when it has access to the root certificate.{{}}
+> [!NOTE]
+> The `ca.crt` field is automatically appended to the certificate chain when present. cert-manager typically populates this field when it has access to the root certificate.
## Quick start
@@ -114,7 +118,7 @@ spec:
metricsExporterCertificateSecretName: metrics-tls
```
-Each secret name corresponds to a `Certificate` resource managed by cert-manager. For details on these fields, see the [RedisEnterpriseCluster API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}).
+Each secret name corresponds to a `Certificate` resource managed by cert-manager. For details on these fields, see the [RedisEnterpriseCluster API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md).
## Database replication with TLS
@@ -176,7 +180,7 @@ spec:
port: 636
```
-For more details on LDAP configuration, see [Enable LDAP authentication]({{< relref "/operate/kubernetes/security/authentication/ldap" >}}).
+For more details on LDAP configuration, see [Enable LDAP authentication](/content/operate/kubernetes/security/authentication/ldap.md).
## Active-Active databases with automatic certificate sync
@@ -215,7 +219,8 @@ Redis Software needs the full chain, including the root CA, to trust the certifi
1. Create a Kubernetes secret that contains the full chain.
1. Reference that secret in your Redis custom resource instead of the secret that cert-manager generates.
-{{}}This applies to any issuer that doesn't populate `ca.crt` with the root certificate, not only Let's Encrypt.{{}}
+> [!NOTE]
+> This applies to any issuer that doesn't populate `ca.crt` with the root certificate, not only Let's Encrypt.
For production environments where the issuer supplies the full chain automatically, such as a private CA or HashiCorp Vault, no extra steps are required.
@@ -351,7 +356,7 @@ If you encounter certificate chain validation errors:
## See also
- [cert-manager documentation](https://cert-manager.io/docs/)
-- [Manage REC certificates]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}})
-- [RedisEnterpriseCluster API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}})
-- [RedisEnterpriseDatabase API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}})
-- [HashiCorp Vault integration]({{< relref "/operate/kubernetes/security/vault" >}})
+- [Manage REC certificates](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md)
+- [RedisEnterpriseCluster API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md)
+- [RedisEnterpriseDatabase API reference](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md)
+- [HashiCorp Vault integration](/content/operate/kubernetes/security/vault.md)
diff --git a/content/operate/kubernetes/security/certificates/internode-encryption.md b/content/operate/kubernetes/security/certificates/internode-encryption.md
index a72dfb07bc..7390746085 100644
--- a/content/operate/kubernetes/security/certificates/internode-encryption.md
+++ b/content/operate/kubernetes/security/certificates/internode-encryption.md
@@ -30,7 +30,7 @@ spec:
dataInternodeEncryption: false
```
-To learn more about internode encryption, see [Internode encryption for Redis Enterprise Software]({{< relref "/operate/rs/security/encryption/internode-encryption.md" >}}).
+To learn more about internode encryption, see [Internode encryption for Redis Enterprise Software](/content/operate/rs/security/encryption/internode-encryption.md).
## Use custom certificates for internode encryption
@@ -131,6 +131,6 @@ When you remove a certificate secret reference from the REC specification, the o
## More info
-- [Manage REC certificates]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) - General certificate management for Redis Enterprise clusters
-- [Configuration secrets]({{< relref "/operate/kubernetes/security/authentication/configuration-secrets" >}}) - Best practices for storing configuration in Kubernetes secrets
-- [Internode encryption for Redis Enterprise Software]({{< relref "/operate/rs/security/encryption/internode-encryption.md" >}}) - Detailed information about how internode encryption works
+- [Manage REC certificates](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) - General certificate management for Redis Enterprise clusters
+- [Configuration secrets](/content/operate/kubernetes/security/authentication/configuration-secrets.md) - Best practices for storing configuration in Kubernetes secrets
+- [Internode encryption for Redis Enterprise Software](/content/operate/rs/security/encryption/internode-encryption.md) - Detailed information about how internode encryption works
diff --git a/content/operate/kubernetes/security/certificates/manage-rec-certificates.md b/content/operate/kubernetes/security/certificates/manage-rec-certificates.md
index c6a5fbd2e1..1aef90765c 100644
--- a/content/operate/kubernetes/security/certificates/manage-rec-certificates.md
+++ b/content/operate/kubernetes/security/certificates/manage-rec-certificates.md
@@ -18,11 +18,11 @@ You can manage REC certificates in two ways:
- **[Method 1: Manage certificates with the REC custom resource](#method-1-manage-certificates-with-the-rec-custom-resource)** (recommended). Store each certificate in a Kubernetes secret and reference the secret from the REC custom resource. The operator applies the certificate and keeps the cluster in sync with the secret. Use this method whenever the certificate type is exposed in `spec.certificates`.
- **[Method 2: Manage certificates with the Redis Software REST API](#method-2-manage-certificates-with-the-redis-software-rest-api)**. Call the cluster's REST API directly, bypassing the operator. Use this method only when you need to follow the Redis Software procedure for a cluster that does not define the certificate in `spec.certificates`. The operator overwrites changes made this way if the same certificate is also defined in the REC custom resource.
-For the list of certificates and what each one encrypts, see the [certificates table]({{< relref "/operate/rs/security/certificates" >}}).
+For the list of certificates and what each one encrypts, see the [certificates table](/content/operate/rs/security/certificates/_index.md).
## Method 1: Manage certificates with the REC custom resource
-This is the Kubernetes-native method. The operator detects changes to a referenced secret and rotates the certificate without manual intervention. You can create the secret manually, or have [cert-manager]({{< relref "/operate/kubernetes/security/certificates/cert-manager" >}}) issue and renew it automatically.
+This is the Kubernetes-native method. The operator detects changes to a referenced secret and rotates the certificate without manual intervention. You can create the secret manually, or have [cert-manager](/content/operate/kubernetes/security/certificates/cert-manager.md) issue and renew it automatically.
### Supported certificates
@@ -64,9 +64,10 @@ The operator accepts several key names for the certificate and private key, so y
| Certificate | `cert`, `certificate`, or `tls.crt` |
| Private key | `key` or `tls.key` |
-{{}}On Redis Software for Kubernetes versions older than 8.0.18, also include `--from-literal=name=` in the `kubectl create secret` command, where `` is the value from the **Certificate name in Redis Software** column in the [supported certificates](#supported-certificates) table.{{}}
+> [!NOTE]
+> On Redis Software for Kubernetes versions older than 8.0.18, also include `--from-literal=name=` in the `kubectl create secret` command, where `` is the value from the **Certificate name in Redis Software** column in the [supported certificates](#supported-certificates) table.
-For internode encryption certificates, see [Internode encryption]({{< relref "/operate/kubernetes/security/certificates/internode-encryption" >}}) for the full setup, which covers enabling internode encryption alongside the certificate configuration.
+For internode encryption certificates, see [Internode encryption](/content/operate/kubernetes/security/certificates/internode-encryption.md) for the full setup, which covers enabling internode encryption alongside the certificate configuration.
### Step 2: Reference the secret in the REC custom resource
@@ -107,21 +108,22 @@ GET /v1/cluster/certificates
Use the Redis Software REST API or `rladmin` directly against the cluster, bypassing the operator.
-{{}}If `spec.certificates` in the REC custom resource defines the same certificate, the operator overwrites your API change. Before you update a certificate through the REST API, remove the corresponding field from `spec.certificates`, or apply the same change in both places.{{}}
+> [!WARNING]
+> If `spec.certificates` in the REC custom resource defines the same certificate, the operator overwrites your API change. Before you update a certificate through the REST API, remove the corresponding field from `spec.certificates`, or apply the same change in both places.
-For the procedure, including the `rladmin` and REST API examples, see [Update certificates]({{< relref "/operate/rs/security/certificates/updating-certificates" >}}).
+For the procedure, including the `rladmin` and REST API examples, see [Update certificates](/content/operate/rs/security/certificates/updating-certificates.md).
After the update, verify the rotation as described in [Step 3](#step-3-verify-the-rotation-optional).
## Active-Active database certificate updates
-The operator automates certificate updates for [Active-Active]({{< relref "/operate/kubernetes/active-active" >}}) databases. When you update the proxy or syncer certificate secret referenced by the REC, the operator detects the change and propagates the new certificate to all participating clusters.
+The operator automates certificate updates for [Active-Active](/content/operate/kubernetes/active-active/_index.md) databases. When you update the proxy or syncer certificate secret referenced by the REC, the operator detects the change and propagates the new certificate to all participating clusters.
-This automation applies whether you manage the secret directly or with [cert-manager]({{< relref "/operate/kubernetes/security/certificates/cert-manager#active-active-databases-with-automatic-certificate-sync" >}}).
+This automation applies whether you manage the secret directly or with [cert-manager](/content/operate/kubernetes/security/certificates/cert-manager.md#active-active-databases-with-automatic-certificate-sync).
## More info
-- [Update certificates]({{< relref "/operate/rs/security/certificates/updating-certificates" >}})
-- [Install your own certificates]({{< relref "/operate/rs/security/certificates/create-certificates" >}})
-- [Certificates table]({{< relref "/operate/rs/security/certificates" >}})
-- [Glossary/Transport Layer Security (TLS)]({{< relref "/glossary#letter-t" >}})
+- [Update certificates](/content/operate/rs/security/certificates/updating-certificates.md)
+- [Install your own certificates](/content/operate/rs/security/certificates/create-certificates.md)
+- [Certificates table](/content/operate/rs/security/certificates/_index.md)
+- [Glossary/Transport Layer Security (TLS)](/content/glossary/_index.md#letter-t)
diff --git a/content/operate/kubernetes/security/vault.md b/content/operate/kubernetes/security/vault.md
index aff1199cb8..a7238ef954 100644
--- a/content/operate/kubernetes/security/vault.md
+++ b/content/operate/kubernetes/security/vault.md
@@ -20,41 +20,40 @@ When Vault integration is enabled, all secrets referenced in Redis Enterprise cu
| **Category** | **Secret Type** | **API Field** | **Description** |
|---|---|---|---|
| **Cluster secrets** | | | |
-| | [Cluster credentials]({{< relref "/operate/kubernetes/deployment/quick-start" >}}) | [`clusterCredentialSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#spec" >}}) | Authentication credentials for cluster access |
-| | [License]({{< relref "/operate/kubernetes/deployment/quick-start#install-the-license" >}}) | [`licenseSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#spec" >}}) | Redis Enterprise license key |
-| | [API certificate]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) | [`apiCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for API server |
-| | [Cluster manager certificate]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) | [`cmCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for cluster manager |
-| | [Metrics exporter certificate]({{< relref "/operate/kubernetes/re-clusters/connect-prometheus-operator" >}}) | [`metricsExporterCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for metrics exporter |
-| | [Proxy certificate]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) | [`proxyCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for proxy |
-| | [Syncer certificate]({{< relref "/operate/kubernetes/active-active" >}}) | [`syncerCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for Active-Active syncer |
-| | [LDAP client certificate]({{< relref "/operate/kubernetes/security/authentication/ldap" >}}) | [`ldapClientCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for LDAP client authentication |
-| | [LDAP bind credentials]({{< relref "/operate/kubernetes/security/authentication/ldap" >}}) | [`bindCredentialsSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specldap" >}}) | Credentials for authenticating to the LDAP server |
-| | [CPINE certificate]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) | [`cpInternodeEncryptionCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for Control Plane Internode Encryption (CPINE) |
-| | [DPINE certificate]({{< relref "/operate/kubernetes/security/certificates/manage-rec-certificates" >}}) | [`dpInternodeEncryptionCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | TLS certificate for Data Plane Internode Encryption (DPINE) |
-| | [SSO service certificate]({{< relref "/operate/kubernetes/security/authentication/sso" >}}) | [`ssoServiceCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | Service Provider (SP) certificate for SAML SSO |
-| | [SSO issuer certificate]({{< relref "/operate/kubernetes/security/authentication/sso" >}}) | [`ssoIssuerCertificateSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#speccertificates" >}}) | Identity Provider (IdP) public certificate for SAML SSO |
-| | [SSO IdP metadata]({{< relref "/operate/kubernetes/security/authentication/sso" >}}) | [`idpMetadataSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specssosaml" >}}) | SAML Identity Provider metadata XML |
-| | [User-defined module credentials]({{< relref "/operate/kubernetes/re-databases/modules" >}}) | [`credentialsSecret`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api#specuserdefinedmodulessourcehttps" >}}) | Credentials for downloading user-defined modules from authenticated repositories |
+| | [Cluster credentials](/content/operate/kubernetes/deployment/quick-start.md) | [`clusterCredentialSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#spec) | Authentication credentials for cluster access |
+| | [License](/content/operate/kubernetes/deployment/quick-start.md#install-the-license) | [`licenseSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#spec) | Redis Enterprise license key |
+| | [API certificate](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) | [`apiCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for API server |
+| | [Cluster manager certificate](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) | [`cmCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for cluster manager |
+| | [Metrics exporter certificate](/content/operate/kubernetes/re-clusters/connect-prometheus-operator.md) | [`metricsExporterCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for metrics exporter |
+| | [Proxy certificate](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) | [`proxyCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for proxy |
+| | [Syncer certificate](/content/operate/kubernetes/active-active/_index.md) | [`syncerCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for Active-Active syncer |
+| | [LDAP client certificate](/content/operate/kubernetes/security/authentication/ldap.md) | [`ldapClientCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for LDAP client authentication |
+| | [LDAP bind credentials](/content/operate/kubernetes/security/authentication/ldap.md) | [`bindCredentialsSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specldap) | Credentials for authenticating to the LDAP server |
+| | [CPINE certificate](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) | [`cpInternodeEncryptionCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for Control Plane Internode Encryption (CPINE) |
+| | [DPINE certificate](/content/operate/kubernetes/security/certificates/manage-rec-certificates.md) | [`dpInternodeEncryptionCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | TLS certificate for Data Plane Internode Encryption (DPINE) |
+| | [SSO service certificate](/content/operate/kubernetes/security/authentication/sso.md) | [`ssoServiceCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | Service Provider (SP) certificate for SAML SSO |
+| | [SSO issuer certificate](/content/operate/kubernetes/security/authentication/sso.md) | [`ssoIssuerCertificateSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#speccertificates) | Identity Provider (IdP) public certificate for SAML SSO |
+| | [SSO IdP metadata](/content/operate/kubernetes/security/authentication/sso.md) | [`idpMetadataSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specssosaml) | SAML Identity Provider metadata XML |
+| | [User-defined module credentials](/content/operate/kubernetes/re-databases/modules.md) | [`credentialsSecret`](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md#specuserdefinedmodulessourcehttps) | Credentials for downloading user-defined modules from authenticated repositories |
| **Database secrets** | | | |
-| | [Database passwords]({{< relref "/operate/kubernetes/networking/database-connectivity/#credentials-and-secrets-management" >}}) | Various | Passwords for Redis databases |
-| | [Replica source client TLS key]({{< relref "/operate/kubernetes/re-databases/replica-redb" >}}) | [`clientKeySecret`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api#specreplicasources" >}}) | Client TLS key for cross-cluster replication |
-| | [Replica source server certificate]({{< relref "/operate/kubernetes/re-databases/replica-redb" >}}) | [`serverCertSecret`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api#specreplicasources" >}}) | Server certificate for cross-cluster replication |
-| | [S3 backup credentials]({{< relref "/operate/kubernetes/re-databases" >}}) | [`awsSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api#specbackups3" >}}) | AWS S3 storage credentials for database backups |
-| | [SFTP backup credentials]({{< relref "/operate/kubernetes/re-databases" >}}) | [`sftpSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api#specbackupsftp" >}}) | SFTP storage credentials for database backups |
-| | [Swift backup credentials]({{< relref "/operate/kubernetes/re-databases" >}}) | [`swiftSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api#specbackupswift" >}}) | Swift storage credentials for database backups |
-| | [Azure Blob backup credentials]({{< relref "/operate/kubernetes/re-databases" >}}) | [`absSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api#specbackupabs" >}}) | Azure Blob storage credentials for database backups |
-| | [Google Cloud backup credentials]({{< relref "/operate/kubernetes/re-databases" >}}) | [`gcsSecretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api#specbackupgcs" >}}) | Google Cloud storage credentials for database backups |
-| | [Client authentication certificates]({{< relref "/operate/kubernetes/security/certificates/add-client-certificates" >}}) | Various | TLS client certificates for authentication |
+| | [Database passwords](/content/operate/kubernetes/networking/database-connectivity.md#credentials-and-secrets-management) | Various | Passwords for Redis databases |
+| | [Replica source client TLS key](/content/operate/kubernetes/re-databases/replica-redb.md) | [`clientKeySecret`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md#specreplicasources) | Client TLS key for cross-cluster replication |
+| | [Replica source server certificate](/content/operate/kubernetes/re-databases/replica-redb.md) | [`serverCertSecret`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md#specreplicasources) | Server certificate for cross-cluster replication |
+| | [S3 backup credentials](/content/operate/kubernetes/re-databases/_index.md) | [`awsSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md#specbackups3) | AWS S3 storage credentials for database backups |
+| | [SFTP backup credentials](/content/operate/kubernetes/re-databases/_index.md) | [`sftpSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md#specbackupsftp) | SFTP storage credentials for database backups |
+| | [Swift backup credentials](/content/operate/kubernetes/re-databases/_index.md) | [`swiftSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md#specbackupswift) | Swift storage credentials for database backups |
+| | [Azure Blob backup credentials](/content/operate/kubernetes/re-databases/_index.md) | [`absSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md#specbackupabs) | Azure Blob storage credentials for database backups |
+| | [Google Cloud backup credentials](/content/operate/kubernetes/re-databases/_index.md) | [`gcsSecretName`](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md#specbackupgcs) | Google Cloud storage credentials for database backups |
+| | [Client authentication certificates](/content/operate/kubernetes/security/certificates/add-client-certificates.md) | Various | TLS client certificates for authentication |
| **Other secrets** | | | |
-| | [Remote cluster secrets]({{< relref "/operate/kubernetes/active-active" >}}) | [`secretName`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api#spec" >}}) | Credentials for Redis Enterprise Remote Cluster (RERC) configurations |
-| | [Active-Active database secrets]({{< relref "/operate/kubernetes/active-active" >}}) | [`globalConfigurations`]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api#specglobalconfigurations" >}}) | All secret names specified in REAADB global configurations |
+| | [Remote cluster secrets](/content/operate/kubernetes/active-active/_index.md) | [`secretName`](/content/operate/kubernetes/reference/api/redis_enterprise_remote_cluster_api.md#spec) | Credentials for Redis Enterprise Remote Cluster (RERC) configurations |
+| | [Active-Active database secrets](/content/operate/kubernetes/active-active/_index.md) | [`globalConfigurations`](/content/operate/kubernetes/reference/api/redis_enterprise_active_active_database_api.md#specglobalconfigurations) | All secret names specified in REAADB global configurations |
{{}}
-{{}}
-The SSO Service Provider (SP) metadata secret (`spMetadataSecretName`) is **not** managed by Vault. This secret is operator-generated and is not written to Vault. To retrieve SP metadata when using Vault, fetch it directly from the Redis Enterprise Server API (`GET /v1/cluster/sso/saml/metadata/sp`).
-{{}}
+> [!NOTE]
+> The SSO Service Provider (SP) metadata secret (`spMetadataSecretName`) is **not** managed by Vault. This secret is operator-generated and is not written to Vault. To retrieve SP metadata when using Vault, fetch it directly from the Redis Enterprise Server API (`GET /v1/cluster/sso/saml/metadata/sp`).
-For complete details on supported secrets, see the [`RedisEnterpriseCluster` API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) and [`RedisEnterpriseDatabase` API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}}).
+For complete details on supported secrets, see the [`RedisEnterpriseCluster` API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) and [`RedisEnterpriseDatabase` API reference](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md).
### Secret path structure
@@ -70,9 +69,8 @@ secret/data/redisenterprise-redis-ns/my-database-password
secret/data/redisenterprise-redis-ns/tls-certificates
```
-{{}}
-When using OpenShift, replace `kubectl` commands with `oc` throughout this guide.
-{{}}
+> [!NOTE]
+> When using OpenShift, replace `kubectl` commands with `oc` throughout this guide.
## Prerequisites
@@ -120,9 +118,8 @@ This guide covers the most common deployment scenario with the following assumpt
- Namespace isolation using Kubernetes namespace suffixes for Vault configurations
- Production security with proper RBAC and network policies
-{{}}
-Multi-cluster considerations: When deploying across multiple Kubernetes clusters with identical namespace names, additional prefixing may be required to avoid Vault path conflicts.
-{{}}
+> [!NOTE]
+> Multi-cluster considerations: When deploying across multiple Kubernetes clusters with identical namespace names, additional prefixing may be required to avoid Vault path conflicts.
## Configure the operator
@@ -209,11 +206,10 @@ Multi-cluster considerations: When deploying across multiple Kubernetes clusters
3. Deploy the operator
- Deploy the Redis Enterprise operator following the [standard installation guide]({{< relref "/operate/kubernetes/deployment" >}}).
+ Deploy the Redis Enterprise operator following the [standard installation guide](/content/operate/kubernetes/deployment/_index.md).
- {{}}
- The operator pod will not be ready until the admission controller secret is stored in Vault (covered in the next step).
- {{}}
+ > [!WARNING]
+ > The operator pod will not be ready until the admission controller secret is stored in Vault (covered in the next step).
@@ -238,9 +234,8 @@ Multi-cluster considerations: When deploying across multiple Kubernetes clusters
vault kv put -namespace= /redisenterprise-/admission-tls @output.json
```
- {{}}
- Once the operator is running with Vault integration, proceed to create Redis Enterprise clusters. Do not create clusters before completing this setup.
- {{}}
+ > [!NOTE]
+ > Once the operator is running with Vault integration, proceed to create Redis Enterprise clusters. Do not create clusters before completing this setup.
@@ -254,9 +249,8 @@ Multi-cluster considerations: When deploying across multiple Kubernetes clusters
--from-file=vault.ca=
```
- {{}}
- The Vault server certificate must be signed by the Certificate Authority provided in this secret.
- {{}}
+ > [!WARNING]
+ > The Vault server certificate must be signed by the Certificate Authority provided in this secret.
## Create Redis Enterprise clusters
@@ -278,11 +272,10 @@ Multi-cluster considerations: When deploying across multiple Kubernetes clusters
password=
```
- {{< alert title="Important notes" >}}
- - The username field in the REC spec is ignored when using Vault
- - The username from the Vault secret takes precedence
- - Use strong, unique passwords for each cluster
- {{}}
+ > [!NOTE] Important notes
+ > - The username field in the REC spec is ignored when using Vault
+ > - The username from the Vault secret takes precedence
+ > - Use strong, unique passwords for each cluster
@@ -355,18 +348,17 @@ To create a Redis Enterprise database (REDB) with Vault integration:
2. Create the REDB custom resource:
- Follow the standard [database creation process]({{< relref "/operate/kubernetes/re-databases" >}}). The REC configuration automatically enables Vault integration for all databases.
+ Follow the standard [database creation process](/content/operate/kubernetes/re-databases/_index.md). The REC configuration automatically enables Vault integration for all databases.
3. Configure additional secrets (optional):
- Store additional REDB secrets in the path `redisenterprise-/`. Secrets must comply with the [REDB secrets schema]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}}).
+ Store additional REDB secrets in the path `redisenterprise-/`. Secrets must comply with the [REDB secrets schema](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md).
-{{}}
-When using the Redis Enterprise Vault plugin, set `defaultUser: false` and associate users through ACL bindings to the REDB.
-{{}}
+> [!NOTE]
+> When using the Redis Enterprise Vault plugin, set `defaultUser: false` and associate users through ACL bindings to the REDB.
-For complete field documentation, see the [Redis Enterprise database API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}}).
+For complete field documentation, see the [Redis Enterprise database API reference](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md).
### Redis Enterprise Remote Cluster secrets
@@ -378,9 +370,8 @@ REAADB resources include REDB specifications in the `globalConfigurations` field
## Manage secrets
-{{}}
-Complete field documentation is available in the [`RedisEnterpriseCluster` API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_cluster_api" >}}) and [`RedisEnterpriseDatabase` API reference]({{< relref "/operate/kubernetes/reference/api/redis_enterprise_database_api" >}}).
-{{}}
+> [!NOTE]
+> Complete field documentation is available in the [`RedisEnterpriseCluster` API reference](/content/operate/kubernetes/reference/api/redis_enterprise_cluster_api.md) and [`RedisEnterpriseDatabase` API reference](/content/operate/kubernetes/reference/api/redis_enterprise_database_api.md).
### Redis Enterprise cluster secrets
@@ -470,7 +461,7 @@ vault kv put -namespace= \
password=
```
-Reference this secret in your REC specification's `userDefinedModules` section. See [Configure modules]({{< relref "/operate/kubernetes/re-databases/modules" >}}) for details.
+Reference this secret in your REC specification's `userDefinedModules` section. See [Configure modules](/content/operate/kubernetes/re-databases/modules.md) for details.
## Troubleshooting