fix: use credential_provider for GCP IAM auth with sync RedisCluster

Fixes #28379. The sync `init_redis_cluster` path passes `redis_connect_func`
to RedisCluster, but RedisCluster's `NodesManager.initialize()` runs
CLUSTER SLOTS before any connection hook fires — so the GCP IAM token
never reaches the bootstrap connection, which fails with
"Authentication required".

The async cluster path already converts `redis_connect_func` to
`credential_provider=GCPIAMCredentialProvider(...)`, which redis-py does
honor on bootstrap. Apply the same swap in the sync path so both paths
behave identically with Google Memorystore for Valkey (cluster-mode IAM).
This commit is contained in:
PRABHU KIRAN VANDRANKI 2026-05-21 19:46:51 -04:00
parent f69b9d6564
commit e66ac1170b

View file

@ -294,6 +294,15 @@ def init_redis_cluster(redis_kwargs) -> redis.RedisCluster:
if arg in args:
cluster_kwargs[arg] = redis_kwargs[arg]
# redis_connect_func is not honored by RedisCluster bootstrap (CLUSTER SLOTS
# runs before the hook fires). Swap it for credential_provider so GCP IAM
# tokens authenticate the bootstrap connection — mirrors the async cluster path.
_rcf = cluster_kwargs.pop("redis_connect_func", None)
if _rcf and hasattr(_rcf, "_gcp_service_account"):
cluster_kwargs["credential_provider"] = GCPIAMCredentialProvider(
_rcf._gcp_service_account
)
new_startup_nodes: List[ClusterNode] = []
for item in redis_kwargs["startup_nodes"]: