Hi CAS community,

I'd like to confirm whether the following Redis behavior is expected or 
potentially a CAS configuration/auto-configuration issue.

We encountered this in a production CAS 7.2.3 deployment with multiple CAS 
instances, using both:

- CAS Redis Ticket Registry
- Spring Session backed by Redis
- Lettuce connection pooling

We configured the two Redis usages with different pool settings.

For example:

cas.ticket.registry.redis.pool.max-active = 50

and:

spring.data.redis.lettuce.pool.max-active = 300

However, during a production incident, Spring Session operations appeared 
to be using CAS's `redisTicketConnectionFactory` and therefore the Ticket 
Registry's Lettuce pool.

When the pool was exhausted, the Spring Session call path failed with 
errors similar to:

org.springframework.data.redis.connection.PoolException:
Could not get a resource from the pool

Caused by:
java.util.NoSuchElementException:
Timeout waiting for idle object

The call path was roughly:

SessionRepositoryFilter
 -> RedisSessionRepository.findById
 -> LettucePoolingConnectionProvider.getConnection
 -> GenericObjectPool.borrowObject
 -> timeout

An important observation was that changing:

spring.data.redis.lettuce.pool.max-active

did not affect the actual pool used by Spring Session, while changing:

cas.ticket.registry.redis.pool.max-active

did.

>From our investigation, it seems possible that CAS registers a 
`RedisConnectionFactory` for the Ticket Registry, and Spring Boot's Redis 
auto-configuration then backs off because a `RedisConnectionFactory` bean 
already exists. Spring Session may consequently resolve CAS's Ticket 
Registry connection factory instead of an independently configured Spring 
Data Redis connection factory.

So I would like to confirm:

1. Is Spring Session sharing `redisTicketConnectionFactory` with the CAS 
Redis Ticket Registry an expected configuration in CAS?

2. If `cas.ticket.registry.redis.*` and `spring.data.redis.*` are both 
configured, should users expect two independent Redis connection 
factories/pools, or must the Spring Session connection factory be 
explicitly defined?

3. In CAS 7.3.x, with the newer container/HTTP-session-backed approach for 
delegated authentication session state, is explicitly separating the Spring 
Session Redis connection factory from the Ticket Registry Redis connection 
factory still recommended?

I can provide the detailed production stack trace, Redis pool 
configuration, and a minimal reproduction if needed.

Thanks.

-- 
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/28be8a3a-411a-43c2-925a-eb7432841145n%40apereo.org.

Reply via email to