Base solution for your next web application
Open Closed

Need help enabling distributed sessions across multiple servers #12561


User avatar
0
[email protected] created

Hello ASPNETZERO Team,

I’m currently working on a distributed deployment of an aspnetzero application based on MVC version (13.4)), and I need to ensure that user sessions persist OR stateless across multiple servers without enabling load balancer affinity.

Here’s my current setup:

Framework: 13.4

Frontend: MVC

Load Balancer: ~Nginx / IIS ARR (without sticky sessions)

Cache & Key Store: Redis (StackExchange)

Session Goal: Persist authenticated user sessions across servers via Redis OR distributed session store

In my current setup:

Even though Redis caching, user login sessions do not appear to be shared across servers.

For example:

Logging in on Server A does not carry over to Server B when accessed via the load balancer.

No user session data appears in Redis (ProjectKey:Session:* keys).

Only manually written test sessions (via HttpContext.Session.SetString) appear.

This suggests that login/session management might not be using ASP.NET Core’s ISession.

Questions:

Is user session model (IAbpSession, ICurrentUser) designed to work with the standard ASP.NET Core ISession middleware?

If not, what is the recommended way to persist authenticated sessions across multiple servers?

Is there an module or extension point that would allow us to use Redis (or another distributed store) for user session tracking, rather than relying solely on cookies?

If aspnetzero relies only on authentication cookies and Data Protection keys, can you confirm that’s the intended multi-server approach?

Goal:

We want to make our application stateless and load-balanced, so that authenticated users remain logged in regardless of which server handles their requests — without sticky sessions.

Thanks in advance for your guidance.

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

5 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    The issue is Data Protection Keys. When a user logs in:

    ASP.NET Core Identity creates an authentication cookie This cookie is encrypted using Data Protection keys By default, these keys are stored locally on each server (in filesystem or machine key) Server A encrypts with Key A, Server B can't decrypt it (uses Key B)

    Result: User logs in on Server A → Load balancer sends next request to Server B → Server B can't decrypt the cookie → User appears logged out.

    You need to configure ASP.NET Core Data Protection to store keys in Redis. Add this to your Startup.cs:

    // In ConfigureServices method, add this BEFORE IdentityRegistrar.Register:
    
    // Configure Data Protection for distributed deployment
    services.AddDataProtection()
        .SetApplicationName("AbpZeroTemplate")
        .PersistKeysToStackExchangeRedis(
            ConnectionMultiplexer.Connect(_appConfiguration["Abp:RedisCache:ConnectionString"]),
            "DataProtection-Keys" // Redis key prefix
        );
    

    Required NuGet Packages:

    <PackageReference Include="Microsoft.AspNetCore.DataProtection.StackExchangeRedis" Version="9.0.10" />
    <PackageReference Include="StackExchange.Redis" Version="2.9.32" />
    

    Additional Configuration for SignalR (if using)

    Looking at your code, you're using SignalR:

    Startup.cs

        services.AddSignalR();
    

    For SignalR to work across servers, also add:

    services.AddSignalR()
        .AddStackExchangeRedis(_appConfiguration["Abp:RedisCache:ConnectionString"], options => {
            options.Configuration.ChannelPrefix = "AbpZeroTemplate";
        });
    

    Redis Configuration Check

    Your current Redis configuration:

      "Abp": {
        "RedisCache": {
          "ConnectionString": "localhost",
          "DatabaseId": -1
        }
      },
    

    Update for production:

    "Abp": {
      "RedisCache": {
        "ConnectionString": "your-redis-server:6379,abortConnect=false,connectTimeout=5000,syncTimeout=5000",
        "DatabaseId": -1
      }
    }
    

    Could you try these changes and see if your issue is resolved? If the issue persists, please don't hesitate to get in touch.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    [email protected] created

    Hello ASP.NET Zero Support Team,

    Thank you for your guidance.

    We have implemented the suggested configuration for Data Protection and SignalR with Redis, but unfortunately, the issue still persists. Here’s what we have done so far:

    Added the following packages to the Web.Mvc project:

    Microsoft.AspNetCore.DataProtection.StackExchangeRedis (v8.0.21) StackExchange.Redis (v2.9.32)

    Enabled Redis in EnterpriseBaseWebCoreModule and then added the following code in Startup.cs

    However:

    We do not see any DataProtection-Keys entries in Redis Insight — it seems the keys are not being created or stored.

    When configuring SignalR with Redis, we’re getting an error (screenshots attached below for reference).

    Could you please help us identify what might be missing or misconfigured? Any specific module or initialization order that could affect this setup?

    Thank you for your continued support.

    Best regards,

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @mnihal

    Thanks for the update.

    If the DataProtection-Keys are not appearing in Redis, it usually means the Data Protection service is initialized too late or the Redis connection isn’t working at startup.

    Please make sure that in your Startup.cs, the Data Protection setup is added before Identity configuration:

    var redis = ConnectionMultiplexer.Connect(_appConfiguration["Abp:RedisCache:ConnectionString"]);
    
    services.AddDataProtection()
        .SetApplicationName("AbpZeroTemplate")
        .PersistKeysToStackExchangeRedis(redis, "DataProtection-Keys");
    

    For SignalR my earlier note was slightly incomplete. The AddStackExchangeRedis extension is provided by a separate package:

    <PackageReference Include="Microsoft.AspNetCore.SignalR.StackExchangeRedis" Version="9.0.10" />
    

    Could you please install this package and try again?

    After adjusting these, restart all app instances and check again if Redis now shows the DataProtection-Keys. Please give it a try and let me know if you can now see the keys in Redis and SignalR connects properly.

    Thank you

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    [email protected] created

    Hi,

    I’ve added the following package in the Web.Mvc project:

    <PackageReference Include="Microsoft.AspNetCore.DataProtection.StackExchangeRedis" Version="8.0.8" />

    Also, I updated the Startup.cs file in the same project to include the Data Protection configuration before the IdentityRegistrar.Register(services); line, as suggested.

    For now, I haven’t tried the SignalR configuration yet.

    However, I noticed that no DataProtection-Keys are being created in Redis. I also tried persisting the keys to the database using Microsoft.AspNetCore.DataProtection.EntityFrameworkCore, but that didn’t work either.

    Please let me know if there are any additional configurations or steps I should check.

    Thanks,

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @mnihal

    Sorry for the late reply. You can review the following documentation that includes the setup steps required to configure Data Protection and SignalR in a distributed or clustered environment.

    Deploying to a Clustered Environment ASP.NET Core SignalR hosting and scaling

    These guides cover how to configure Redis for Data Protection key storage and SignalR backplane support across multiple application instances.

    Once you’ve reviewed these documents and confirmed that all configurations are set up correctly, please check whether the issue is resolved. If it still persists after completing the setup, let us know so we can assist you further with troubleshooting.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)