Before submitting, make sure you've checked the following:
Target branch: Verify that the pull request targets the dev branch. Not targeting the dev branch will lead to immediate closure of the PR.
Description: Provide a concise description of the changes made in this pull request down below.
Changelog: Ensure a changelog entry following the format of Keep a Changelog is added at the bottom of the PR description.
Documentation: If necessary, update relevant documentation Open WebUI Docs like environment variables, the tutorials, or other documentation sources.
Dependencies: Are there any new dependencies? Have you updated the dependency versions in the documentation?
Testing: Perform manual tests to verify the implemented fix/feature works as intended AND does not break any other functionality. Take this as an opportunity to make screenshots of the feature/fix and include it in the PR description.
Agentic AI Code: Confirm this Pull Request is not written by any AI Agent or has at least gone through additional human review AND manual testing. If any AI Agent is the co-author of this PR, it may lead to immediate closure of the PR.
Code review: Have you performed a self-review of your code, addressing any coding standard issues and ensuring adherence to the project's coding standards?
Title Prefix: To clearly categorize this pull request, prefix the pull request title
Changelog Entry
Description
This pull request adds comprehensive SSL/TLS support for Redis Sentinel connections, enabling secure communication with Redis Sentinel instances. The implementation allows users to configure secure connections using the rediss:// scheme and pass custom SSL parameters (such as certificate paths and verification settings) via query parameters in the connection URL. This is particularly useful for production environments requiring encrypted connections or self-signed certificates.
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
Note
Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.
## 📋 Pull Request Information
**Original PR:** https://github.com/open-webui/open-webui/pull/21329
**Author:** [@NargiT](https://github.com/NargiT)
**Created:** 2/12/2026
**Status:** 🔄 Open
**Base:** `dev` ← **Head:** `redis-ssl`
---
### 📝 Commits (6)
- [`dca8832`](https://github.com/open-webui/open-webui/commit/dca88326927a2a2dc0d9de6b05dc849fe31345b8) enable ssl option for sentinel
- [`202e39f`](https://github.com/open-webui/open-webui/commit/202e39f26c4bf6beab2223c7d67ddf24be9998af) add test for redis parameters
- [`2c955c1`](https://github.com/open-webui/open-webui/commit/2c955c1a680c560ad41f813901c451552ce361e9) fix ssl
- [`4207b2c`](https://github.com/open-webui/open-webui/commit/4207b2ce550a3da43b4370d1fc63f34d9441a3dc) avoid overiding username/password, just for clarity, no impact
- [`99cf0ea`](https://github.com/open-webui/open-webui/commit/99cf0ea2f8137d5180460aaade986eb44458af2f) improve args routing
- [`5ee7c46`](https://github.com/open-webui/open-webui/commit/5ee7c467796331778ba8faf88c6e3e978d6259eb) formating
### 📊 Changes
**2 files changed** (+54 additions, -14 deletions)
<details>
<summary>View changed files</summary>
📝 `backend/open_webui/test/util/test_redis.py` (+17 -0)
📝 `backend/open_webui/utils/redis.py` (+37 -14)
</details>
### 📄 Description
# Pull Request Checklist
**Before submitting, make sure you've checked the following:**
- [x] **Target branch:** Verify that the pull request targets the `dev` branch. **Not targeting the `dev` branch will lead to immediate closure of the PR.**
- [x] **Description:** Provide a concise description of the changes made in this pull request down below.
- [x] **Changelog:** Ensure a changelog entry following the format of [Keep a Changelog](https://keepachangelog.com/) is added at the bottom of the PR description.
- [x] **Documentation:** If necessary, update relevant documentation [Open WebUI Docs](https://github.com/open-webui/docs) like environment variables, the tutorials, or other documentation sources.
- [x] **Dependencies:** Are there any new dependencies? Have you updated the dependency versions in the documentation?
- [x] **Testing:** Perform manual tests to **verify the implemented fix/feature works as intended AND does not break any other functionality**. Take this as an opportunity to **make screenshots of the feature/fix and include it in the PR description**.
- [x] **Agentic AI Code:** Confirm this Pull Request is **not written by any AI Agent** or has at least **gone through additional human review AND manual testing**. If any AI Agent is the co-author of this PR, it may lead to immediate closure of the PR.
- [x] **Code review:** Have you performed a self-review of your code, addressing any coding standard issues and ensuring adherence to the project's coding standards?
- [x] **Title Prefix:** To clearly categorize this pull request, prefix the pull request title
# Changelog Entry
### Description
This pull request adds comprehensive SSL/TLS support for Redis Sentinel connections, enabling secure communication with Redis Sentinel instances. The implementation allows users to configure secure connections using the `rediss://` scheme and pass custom SSL parameters (such as certificate paths and verification settings) via query parameters in the connection URL. This is particularly useful for production environments requiring encrypted connections or self-signed certificates.
Related discussion: #21274
### Added
- SSL/TLS support for Redis Sentinel connections via `rediss://` URL scheme
- Query parameter parsing for Redis Sentinel URLs to support custom SSL configuration options (e.g., `ssl_cert_reqs`, `ssl_ca_certs`, `ssl_certfile`, `ssl_keyfile`)
- Proper separation of `sentinel_kwargs` and `connection_kwargs` to correctly apply SSL settings to both sentinel discovery and master/replica connections
### Changed
- Refactored `parse_redis_service_url()` function to extract and return query parameters from Redis Sentinel URLs
### Deprecated
- None
### Removed
- None
### Fixed
- Fixed issue where SSL configuration was ignored when using Redis Sentinel
### Security
- Added support for encrypted Redis Sentinel connections using SSL/TLS
### Breaking Changes
- None
---
### Additional Information
This enhancement allows users to configure secure Redis Sentinel connections in production environments. Example connection strings:
```bash
rediss://mymaster:6380/0?ssl_cert_reqs=required&ssl_ca_certs=/etc/ssl-custom/certs/bundle.pem
```
### Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the [Contributor License Agreement (CLA)](https://github.com/open-webui/open-webui/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT), and I am providing my contributions under its terms.
> [!NOTE]
> Deleting the CLA section will lead to immediate closure of your PR and it will not be merged in.
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/21329
Author: @NargiT
Created: 2/12/2026
Status: 🔄 Open
Base:
dev← Head:redis-ssl📝 Commits (6)
dca8832enable ssl option for sentinel202e39fadd test for redis parameters2c955c1fix ssl4207b2cavoid overiding username/password, just for clarity, no impact99cf0eaimprove args routing5ee7c46formating📊 Changes
2 files changed (+54 additions, -14 deletions)
View changed files
📝
backend/open_webui/test/util/test_redis.py(+17 -0)📝
backend/open_webui/utils/redis.py(+37 -14)📄 Description
Pull Request Checklist
Before submitting, make sure you've checked the following:
devbranch. Not targeting thedevbranch will lead to immediate closure of the PR.Changelog Entry
Description
This pull request adds comprehensive SSL/TLS support for Redis Sentinel connections, enabling secure communication with Redis Sentinel instances. The implementation allows users to configure secure connections using the
rediss://scheme and pass custom SSL parameters (such as certificate paths and verification settings) via query parameters in the connection URL. This is particularly useful for production environments requiring encrypted connections or self-signed certificates.Related discussion: #21274
Added
rediss://URL schemessl_cert_reqs,ssl_ca_certs,ssl_certfile,ssl_keyfile)sentinel_kwargsandconnection_kwargsto correctly apply SSL settings to both sentinel discovery and master/replica connectionsChanged
parse_redis_service_url()function to extract and return query parameters from Redis Sentinel URLsDeprecated
Removed
Fixed
Security
Breaking Changes
Additional Information
This enhancement allows users to configure secure Redis Sentinel connections in production environments. Example connection strings:
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.