Skip to main content
Direct clients connect to the Resource gateway over TLS on TCP 6379. Use the Resource access name as the ACL username and a short-lived Forge token as the password.
With automatic routing, keep the destination hostname and ordinary client command.

Policy fields and actions

Forge supports RESP2 and RESP3 ordinary commands and buffered pipelines. It can match the selected logical database, destination ACL user, and uppercase top-level command. Connections and commands can be allowed, flagged, approved, or blocked. Keys, arguments, values, and replies are not retained or available as policy fields. Redis response transformation is not supported.

Destination authentication

The gateway uses the Redis ACL username and password assigned to the caller. The caller’s Forge credential is never forwarded to Redis. Destination TLS and hostname verification are always required.

Current limits

Transactions, Pub/Sub, MONITOR, Cluster or Sentinel routing, inline or streamed RESP, key/value inspection, and response transformation are not supported. Unsupported modes fail explicitly. See Credentials and identity and Resource Policies.