Spring Session replaces container-local HttpSession storage with Redis-backed state so a browser request can reach any application replica.
Spring Session Redis across replicas: shared login state has a Redis failure boundary
Move the state, not the cookie
A parcel operator signs in through replica A, then a load balancer sends the next request to replica B. With a container-local session, B knows only the cookie ID and cannot load its state. Spring Session's Redis repository lets both replicas resolve the same ID. The browser still sends a cookie; the server stores the session contents in Redis. OAuth2 login may store authorization state in that session, so an unavailable Redis tier can make login or subsequent authenticated requests fail.
Set a failure policy
Choose a session timeout, Redis namespace and connection budget for this application. Keep the stored attributes small and serialization-compatible across rolling releases; placing a large mutable domain graph in a session amplifies every read or write. Redis eviction can remove an active session before its intended idle timeout, so reserve capacity and set an eviction policy compatible with login state. This configuration sketch does not provide Redis failover or guarantee session availability.
Test the route change
Authenticate, pin the first request to one replica, send the next request with the same cookie to another, then disconnect Redis. Record whether the application returns an authentication failure or a service error; make that behavior explicit in the client flow. A single-node login test cannot prove cross-replica session continuity.
Implementation sketch
server:
servlet:
session:
timeout: 23m
spring:
session:
redis:
namespace: parcel-console:session
data:
redis:
host: redis.internalCost and verification
Each session lookup adds Redis I/O and serialized state. Size the pool for peak authenticated traffic and measure Redis latency separately from controller latency.
Common Mistakes
- Do not assume a shared cookie makes container-local sessions shared.
- Do not put large entity graphs or nonportable serialized classes in session attributes.
- Do not treat Redis as optional when session lookup is on every authenticated path.
Read next
Spring Security CSRF: protect cookie-authenticated writes, Spring Security OAuth2 login: callback, identity and browser session, Spring Boot graceful shutdown: finish accepted requests within a deadline, Spring Session cookie policy: SameSite, Secure and the reverse proxy.
