Connect to Valkey
Tested with: Valkey 8.1.3 on Databasezy · drivers listed per tab · zb CLI 0.1
- Copy the host and port from Connect. Valkey on Databasezy uses ACL users, so you connect with a username and a
password, never with
requirepassalone. - Download the CA bundle (
zb api GET /v1/orgs/{org}/ca.pem > databasezy-ca.pem) if your client does not read the OS trust store. - Add your egress IPs under Network → Allow-list.
- Use
rediss://(two s) or the driver’s TLS option with hostname verification, as in every snippet below.
Valkey listens on port 6379 (RESP (Redis protocol)). Versions: 9.1, 8.1, 8.0. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.
rediss://default:<password>@valkey-7f3k.us-east.databasezy.com:6379/0import { readFileSync } from "node:fs";import Redis from "ioredis";
const host = "valkey-7f3k.us-east.databasezy.com";export const redis = new Redis({ host, port: 6379, username: "app", password: process.env.ZB_PASSWORD, tls: { ca: readFileSync("databasezy-ca.pem", "utf8"), servername: host, // hostname verification rejectUnauthorized: true, }, maxRetriesPerRequest: 3,});
await redis.set("hello", "world", "EX", 60);console.log(await redis.get("hello"));Tested with: Valkey 9.1 · ioredis 5.4
import osimport valkey # or: import redis as valkey
r = valkey.Valkey( host="valkey-7f3k.us-east.databasezy.com", port=6379, username="app", password=os.environ["ZB_PASSWORD"], ssl=True, ssl_cert_reqs="required", ssl_ca_certs="databasezy-ca.pem", ssl_check_hostname=True, decode_responses=True,)r.set("hello", "world", ex=60)print(r.get("hello"))Tested with: Valkey 9.1 · valkey-py 6.0 (redis-py 5.x compatible)
package main
import ( "context" "crypto/tls" "crypto/x509" "fmt" "os"
"github.com/valkey-io/valkey-go")
func main() { pem, _ := os.ReadFile("databasezy-ca.pem") roots := x509.NewCertPool() roots.AppendCertsFromPEM(pem)
client, err := valkey.NewClient(valkey.ClientOption{ InitAddress: []string{"valkey-7f3k.us-east.databasezy.com:6379"}, Username: "app", Password: os.Getenv("ZB_PASSWORD"), TLSConfig: &tls.Config{RootCAs: roots, ServerName: "valkey-7f3k.us-east.databasezy.com", MinVersion: tls.VersionTLS12}, }) if err != nil { panic(err) } defer client.Close()
ctx := context.Background() client.Do(ctx, client.B().Set().Key("hello").Value("world").Ex(60*1e9).Build()) v, _ := client.Do(ctx, client.B().Get().Key("hello").Build()).ToString() fmt.Println(v)}Tested with: Valkey 9.1 · valkey-go 1.0 (go-redis v9 works the same)
use redis::{AsyncCommands, Client, TlsCertificates};
#[tokio::main]async fn main() -> redis::RedisResult<()> { let pw = std::env::var("ZB_PASSWORD").expect("ZB_PASSWORD"); let url = format!("rediss://app:{pw}@valkey-7f3k.us-east.databasezy.com:6379/0"); let certs = TlsCertificates { client_tls: None, root_cert: Some(std::fs::read("databasezy-ca.pem").expect("read CA")), }; let client = Client::build_with_tls(url, certs)?; let mut conn = client.get_multiplexed_async_connection().await?; conn.set_ex::<_, _, ()>("hello", "world", 60).await?; let v: String = conn.get("hello").await?; println!("{v}"); Ok(())}Tested with: Valkey 9.1 · redis 0.27 (tokio-rustls-comp)
// One-time: keytool -importcert -noprompt -alias databasezy -file databasezy-ca.pem \// -keystore databasezy-truststore.p12 -storetype PKCS12 -storepass changeitimport io.lettuce.core.RedisClient;import io.lettuce.core.RedisURI;import io.lettuce.core.SslOptions;import io.lettuce.core.ClientOptions;import java.io.File;
public final class Cache { public static void main(String[] args) { var uri = RedisURI.Builder.redis("valkey-7f3k.us-east.databasezy.com", 6379) .withSsl(true) .withVerifyPeer(true) // chain + hostname .withAuthentication("app", System.getenv("ZB_PASSWORD").toCharArray()) .build(); var client = RedisClient.create(uri); client.setOptions(ClientOptions.builder() .sslOptions(SslOptions.builder() .truststore(new File("databasezy-truststore.p12"), "changeit").build()) .build()); try (var conn = client.connect()) { conn.sync().setex("hello", 60, "world"); System.out.println(conn.sync().get("hello")); } client.shutdown(); }}Tested with: Valkey 9.1 · Lettuce 6.5
using StackExchange.Redis;
var options = new ConfigurationOptions{ EndPoints = { { "valkey-7f3k.us-east.databasezy.com", 6379 } }, User = "app", Password = Environment.GetEnvironmentVariable("ZB_PASSWORD"), Ssl = true, SslHost = "valkey-7f3k.us-east.databasezy.com", // hostname verification};// If the CA is not in the OS store, trust it explicitly:options.TrustIssuer("databasezy-ca.pem");
var mux = await ConnectionMultiplexer.ConnectAsync(options);var db = mux.GetDatabase();await db.StringSetAsync("hello", "world", TimeSpan.FromSeconds(60));Console.WriteLine(await db.StringGetAsync("hello"));Tested with: Valkey 9.1 · StackExchange.Redis 2.8
<?php$client = new Predis\Client([ "scheme" => "tls", "host" => "valkey-7f3k.us-east.databasezy.com", "port" => 6379, "username" => "app", "password" => getenv("ZB_PASSWORD"), "ssl" => ["cafile" => "databasezy-ca.pem", "verify_peer" => true, "verify_peer_name" => true],]);$client->setex("hello", 60, "world");echo $client->get("hello");Tested with: Valkey 9.1 · predis 2.3
require "redis"
redis = Redis.new( url: "rediss://app:#{ENV.fetch('ZB_PASSWORD')}@valkey-7f3k.us-east.databasezy.com:6379/0", ssl_params: { ca_file: "databasezy-ca.pem", verify_mode: OpenSSL::SSL::VERIFY_PEER })redis.set("hello", "world", ex: 60)puts redis.get("hello")Tested with: Valkey 9.1 · redis-rb 5.3
valkey-cli --tls --cacert databasezy-ca.pem -h valkey-7f3k.us-east.databasezy.com -p 6379 --user app --askpass
# orzb connect valkey-7f3kTested with: Valkey 9.1 · valkey-cli 9.1
The RESP endpoint is TLS-only. Clients that try plaintext get a RESP error explaining that TLS is required. Any Redis client from the 7.x era works; the Redis and Valkey client libraries are interchangeable on the wire.
Connections and pooling
Section titled “Connections and pooling”- Valkey handles thousands of connections cheaply, but the size’s
max_connectionsstill applies. Use a single multiplexed client per process (ioredis, StackExchange.Redis and valkey-go do this by default) rather than a pool. - Pub/Sub and blocking commands (
BLPOP,XREAD BLOCK) hold a connection each; count them. - Free instances sleep after 15 idle minutes; a client with reconnect-on-error handles the wake transparently.
Persistence and backups
Section titled “Persistence and backups”RDB snapshots plus AOF are shipped to object storage. There is no point-in-time recovery for key-value engines;
restores land on the last snapshot boundary. FLUSHALL and DEBUG are restricted to the app ACL user’s own
keyspace and audited.