Coordination bus (Redis)
Applies to: SimpleTwo 0.9.x (agent 0.5.127 or newer) · Checked: 07.10.2026
1. What it is for and what it holds
The bus is one Redis instance that these coordinate over:
| Consumer | What it keeps on the bus |
|---|---|
| SFU pool (LiveKit) | which room is on which node, the node registry, signalling messages |
| MCU cluster | node load, meeting-room device registrations, forwarded dial-outs |
| Recorder (egress) | the recording job queue |
| PSTN gateway | RPC between the gateway and the SFU |
All of it is ephemeral: every consumer republishes its keys within seconds of reconnecting, so the bus is tuned as a message bus, not as a database. A single SFU node works without a bus; a second SFU node, a second MCU node and the PSTN gateway are not deployed without one.
The bus is either the redis role (installed by the agent, listening on the private network,
6379 open only to the consumers' addresses) or an external Redis your organisation runs.
2. Where to look
Service → Coordination bus (Redis) (permission gateways:read):
- which bus is in use — the role or an external one — and its address;
- the bus host's report: version, uptime, memory and ceiling, eviction policy, keys, expired and evicted keys, clients, operations per second, persistence status, master/replica role;
- who is connected: every SFU, MCU, recorder and PSTN host with its connection count — and "unknown" rows for connections from addresses that are not hosts of this install;
- which addresses the firewall admits on 6379.
The report is read by the agent on the bus host (INFO and CLIENT LIST) and sent on its heartbeat: the coordinator never connects to the bus. An external Redis has no agent beside it — the card shows its settings, and the connection check is under Settings → External stores.
A vendor support token reads this card with client names and commands pseudonymised.
3. Tuning
Permission gateways:write; every change is in the audit trail.
| Setting | Default | Why |
|---|---|---|
| Memory ceiling | not set | 0 — no ceiling, 25% — share of the host's RAM, 512mb — in MiB |
| When the ceiling is reached | noeviction | an evicted key is a room that silently vanishes from routing, or a device registration a node stops forwarding; at the ceiling a write that fails loudly is the better failure |
| Persistence | off | nothing on the bus outlives its consumers; a snapshot restored after a restart would bring back rooms and registrations that no longer exist |
RDB snapshots and AOF (fsync every second) are available if something else lives on the bus or the recording queue must survive a bus restart.
Changes are applied to the running server (CONFIG SET): the bus is not restarted and keeps its data. Only a change of the bus host's address restarts it.
If the "evicted" counter grows, consumers have been losing state. Raise the ceiling or return to
noeviction.
4. Changing the password without downtime
Rotate the password (permission gateways:write):
- the bus starts accepting both passwords — the old and the new;
- consumers get the new password one at a time. They read the password only at start, so each restarts once, and the next waits until the previous one is back;
- the bus drops the old password.
The bus never refuses a consumer, but calls on an SFU or MCU node reconnect when that node restarts — rotate at a quiet hour. If a step waits more than 10 minutes (a host is off), the card offers Skip this node; the host picks the new password up when it returns. Abort before the last step moves the consumers already moved back to the old password.
Rotation is not available:
- on Redis 5 — it holds one password, so a change would lock everyone out until restarted;
- for an external Redis — change the password on that server, then enter it in the settings;
- until the bus host has reported.
5. External Redis
Settings → External stores → Redis: address, password and the TLS checkbox. With TLS the server's certificate is verified against the host name in the address — by every consumer and by the check button. The check button sends the saved password only to the saved address.
MCU nodes reach the bus over TLS from MCU 0.9.0.
6. High availability
Replica and Sentinel are not supported yet: with the bus down, calls in progress continue, new calls are not routed across SFU nodes, and MCU nodes run standalone. systemd restarts the bus in seconds. The plan is in ADR-0055 §7.