From e66ac1170b3d16166784d3ebf1a55e9ee889a8e6 Mon Sep 17 00:00:00 2001 From: PRABHU KIRAN VANDRANKI <72809214+VANDRANKI@users.noreply.github.com> Date: Thu, 21 May 2026 19:46:51 -0400 Subject: [PATCH] fix: use credential_provider for GCP IAM auth with sync RedisCluster MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fixes #28379. The sync `init_redis_cluster` path passes `redis_connect_func` to RedisCluster, but RedisCluster's `NodesManager.initialize()` runs CLUSTER SLOTS before any connection hook fires — so the GCP IAM token never reaches the bootstrap connection, which fails with "Authentication required". The async cluster path already converts `redis_connect_func` to `credential_provider=GCPIAMCredentialProvider(...)`, which redis-py does honor on bootstrap. Apply the same swap in the sync path so both paths behave identically with Google Memorystore for Valkey (cluster-mode IAM). --- litellm/_redis.py | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/litellm/_redis.py b/litellm/_redis.py index f12afbac297..3a50d957d75 100644 --- a/litellm/_redis.py +++ b/litellm/_redis.py @@ -294,6 +294,15 @@ def init_redis_cluster(redis_kwargs) -> redis.RedisCluster: if arg in args: cluster_kwargs[arg] = redis_kwargs[arg] + # redis_connect_func is not honored by RedisCluster bootstrap (CLUSTER SLOTS + # runs before the hook fires). Swap it for credential_provider so GCP IAM + # tokens authenticate the bootstrap connection — mirrors the async cluster path. + _rcf = cluster_kwargs.pop("redis_connect_func", None) + if _rcf and hasattr(_rcf, "_gcp_service_account"): + cluster_kwargs["credential_provider"] = GCPIAMCredentialProvider( + _rcf._gcp_service_account + ) + new_startup_nodes: List[ClusterNode] = [] for item in redis_kwargs["startup_nodes"]: