Skip to content

Managed Valkey

Use 1ctl valkey to run Valkey. This is a private, in-cluster service: the hostname returned by 1ctl is reachable from workloads in the cluster, not from the public internet.

Terminal window
1ctl auth status
1ctl org current

The active organization owns the service and its Kubernetes namespace.

Terminal window
1ctl valkey create sessions \
--persistence \
--append-only \
--append-fsync everysec \
--storage-size 8Gi \
--cpu-request 250m \
--cpu 500m \
--memory-request 256Mi \
--memory 512Mi

--persistence is required when data must survive a workload restart. Add --metrics if you want the managed Prometheus exporter. Omit --machine-id for automatic placement, or supply an eligible machine explicitly:

Terminal window
1ctl valkey create sessions \
--persistence \
--machine-id <machine-id>
Terminal window
1ctl valkey status sessions
1ctl -o json valkey get sessions

Wait for Status: healthy and Instances: 1/1 ready. The JSON response shows the selected machine_id, namespace, private hostname, and persistence settings. These values are useful when checking placement with your cluster administrator.

Terminal window
1ctl valkey credentials sessions

This prints a private valkey:// connection URI and password. Treat both as secrets: place them in your application’s secret configuration, never commit them, and do not put them in satusky.toml.

Use a Valkey-compatible client library and the returned valkey:// URI. Redis-compatible clients and commands also work; keep the private valkey:// endpoint unchanged rather than inventing a public Redis URL.

Terminal window
1ctl valkey update sessions \
--cpu-request 500m \
--cpu 1 \
--memory-request 512Mi \
--memory 1Gi \
--maxmemory-policy allkeys-lfu \
--maxmemory-percent 75

You can also enable AOF or metrics on an existing service:

Terminal window
1ctl valkey update sessions \
--append-only \
--append-fsync everysec \
--metrics
Terminal window
1ctl valkey users create sessions cache-api \
--preset read_write \
--key-pattern 'cache:*'

The generated password is shown once. Rotate a custom user’s password when needed:

Terminal window
1ctl valkey users rotate-password sessions cache-api --yes

Rotate the protected default user’s password separately:

Terminal window
1ctl valkey rotate-credentials sessions --yes
Terminal window
1ctl valkey metrics sessions
1ctl valkey logs sessions --tail 200
1ctl valkey redeploy sessions
1ctl valkey restart sessions

redeploy reconciles the saved configuration. restart rolls the managed workload; for persistent services, check 1ctl valkey status sessions after the restart before resuming dependent work.

Terminal window
1ctl valkey delete sessions --yes

Deletion destroys the service and its managed data. Export anything you need first, then confirm that no applications still use its connection URI.