raji032 opened a new issue, #13926:
URL: https://github.com/apache/apisix/issues/13926

   ### Current Behavior
   
   When policy: "redis" and redis_ssl: true are configured:
   
   1. APISIX connects with TLS but does not set server_name (SNI) in sock_opts.
   2.  Against Redis backends that require SNI (common on port 443), the 
connection returns non-Redis data (often HTTP).
   3.  lua-resty-redis fails parsing the reply with:
   4. failed to limit count: unknown prefix: "72"        (72 = ASCII 'H', i.e. 
an HTTP response like HTTP/1.1 ...)
   5. With allow_degradation: false, the route returns 500.
   
   
   server_name is never set, even though lua-resty-redis connect() supports it.
   
   ### Expected Behavior
   
   When redis_ssl: true and redis_host are set, APISIX should set SNI on the 
TLS handshake, e.g.:
   
   if conf.redis_ssl and conf.redis_host then
       sock_opts.server_name = conf.redis_server_name or conf.redis_host
   end
   
   This should match redis-cli --tls --sni <host> behavior.
   
   Optionally, add redis_server_name to 
[apisix/utils/redis-schema.lua](https://github.com/apache/apisix/blob/release/3.13/apisix/utils/redis-schema.lua)
 when SNI must differ from redis_host.
   
   Lua Resty source: 
https://github.com/openresty/lua-resty-redis/blob/v0.29/lib/resty/redis.lua#L166
   
   ### Error Logs
   
   2026/09/08 18:04:40 [error] 51#51: *385221035 [lua] init.lua:317: 
phase_func(): failed to limit count: unknown prefix: "72", client: 
10.23.131.147, server: _, request: "GET /health/ready HTTP/1.1", host: 
"test-redis.net"
   
   ### Steps to Reproduce
   
   rerequisites
   Redis endpoint that requires TLS + SNI on port 443
   
   redis-cli with TLS for comparison.
   1. Verify Redis works with SNI (baseline)
   redis-cli -h <redis-host> -p 443 --tls \
     --sni <redis-host> \
     --user default \
     -a '<password>' PING
   Expected: PONG
   
   2. Configure limit-count with Redis policy (no SNI in APISIX)
   {
     "limit-count": {
       "count": 60,
       "time_window": 60,
       "policy": "redis",
       "key": "remote_addr",
       "key_type": "var",
       "rejected_code": 429,
       "redis_host": "<redis-host>",
       "redis_port": 443,
       "redis_ssl": true,
       "redis_ssl_verify": false,
       "redis_username": "default",
       "redis_password": "<password>",
       "allow_degradation": false
     }
   }
   
   3. Send traffic to the route
   curl -i https://<apisix-route-url>/
   
   4. Check APISIX error log
   failed to limit count: unknown prefix: "72"
   
   5. Compare without SNI (optional)
   redis-cli -h <redis-host> -p 443 --tls -a '<password>' PING
   
   ### Environment
   
   - APISIX version (run `apisix version`):
   - Operating system (run `uname -a`):
   - OpenResty / Nginx version (run `openresty -V` or `nginx -V`):
   - etcd version, if relevant (run `curl 
http://127.0.0.1:9090/v1/server_info`):
   - APISIX Dashboard version, if relevant:
   - Plugin runner version, for issues related to plugin runners:
   - LuaRocks version, for installation issues (run `luarocks --version`)
   
   
   - APISIX version (run `apisix version`):
     3.18.0
   - Operating system (run `uname -a`):
     Linux <kernel> (Debian-based container / AKS node)
   - OpenResty / Nginx version (run `openresty -V` or `nginx -V`):
     N/A
   - etcd version, if relevant (run `curl 
http://127.0.0.1:9090/v1/server_info`):
     N/A
   - APISIX Dashboard version, if relevant:
     N/A
   - Plugin runner version, for issues related to plugin runners:
     N/A
   - LuaRocks version, for installation issues (run `luarocks --version`):
     N/A (using official APISIX image)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to