# Redis / Valkey cache

Source: https://docs.quake.ai/resources/iac-templates/redis-cache
Markdown: https://docs.quake.ai/resources/iac-templates/redis-cache.md

---

# Redis / Valkey cache

This pattern composes Compute, Network, and Block Storage into a private cache.

## What this template does

Provisions a single instance running Valkey (or Redis OSS) in Docker on a private network, for use as a cache, session store, or queue backend:

- Compute instance running the engine container, with the cache bound to the private IP only (not `0.0.0.0`)
- Private network, subnet, router, and security group; the cache port is reachable only from `private_cidr`
- No floating IP, so the cache is not exposed to the public internet. SSH is the only rule open to the internet.
- `requirepass` authentication set from `redis_password`, read from a config file mounted read-only
- Optional append-only persistence on a block volume mounted at `/data`. Turn it off for an in-memory-only cache.

Valkey is the default engine. Valkey is the BSD-3-Clause licensed fork of Redis, created after Redis OSS moved to the RSALv2 and SSPLv1 source-available license in 2024. To run Redis OSS instead, set `redis_image` to `redis:7-alpine` and `server_command` to `redis-server`.

Set `redis_password` to a strong value when you apply; the template ships no default password.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `redis_password` | Cache password (`requirepass`), required, no default | _none_ |
| `redis_image` | Engine image | `valkey/valkey:8-alpine` |
| `server_command` | Server binary the image runs | `valkey-server` |
| `flavor_name` | Instance size | `s1a.small` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix and container name | `redis-cache` |
| `redis_port` | Port the cache listens on | `6379` |
| `persistence_enabled` | Attach a volume and enable append-only persistence | `true` |
| `volume_size` | Persistence volume size in GiB | `10` |
| `external_network` | External network for the router gateway | `PublicStatic` |
| `private_cidr` | Private subnet CIDR; the only range allowed to reach the cache port | `10.20.0.0/24` |

## When to use this pattern

Run a cache, session store, or queue backend on a single private instance, reached by an app on the same private network. For a relational datastore, use [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres). For the app tier that consumes this cache, see the [Next.js app template](/resources/iac-templates/nextjs-app) or [Containerized app template](/resources/iac-templates/containerized-app).

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "redis-cache", required: true },
  ]}
/>

## Template source

<TemplateSource slug="redis-cache" />

<TemplateResourceMap template="redis-cache" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [self-managed PostgreSQL template](/resources/iac-templates/self-managed-postgres)
- [Next.js app template](/resources/iac-templates/nextjs-app)
