Distributed locks for 1C:Enterprise in a Yandex Managed Service for Valkey™ cluster
You can use a Yandex Managed Service for Valkey™ cluster as a distributed lock storage for 1C:Enterprise, e.g., to prevent multiple users from editing the same catalog item at the same time.
Integration is implemented via an intermediate HTTP server running on a Yandex Compute Cloud virtual machine. The server provides an HTTP API for managing locks and uses a Valkey™ cluster as its backend. A 1C:Enterprise module accesses the API through an external connection.
Note
The module requires 1C:Enterprise 8.3 or later.
To set up locks:
- Set up your infrastructure.
- Deploy your HTTP lock server.
- Configure the 1C:Enterprise module.
- Test the locks.
- Delete the resources you created.
Getting started
Sign up for Yandex Cloud and create a billing account:
- Navigate to the management console
and log in to Yandex Cloud or create a new account. - On the Yandex Cloud Billing
page, make sure you have a billing account linked and it has theACTIVEorTRIAL_ACTIVEstatus. If you do not have a billing account, create one and link a cloud to it.
If you have an active billing account, you can create or select a folder for your infrastructure on the cloud page
Learn more about clouds and folders here.
Required paid resources
- Yandex Managed Service for Valkey™ cluster: the host's computing resources and storage size (see Yandex Managed Service for Valkey™ pricing).
- VM instance: use of computing resources, storage, public IP address, and OS (see Compute Cloud pricing).
Set up your infrastructure
-
Create a Yandex Managed Service for Valkey™ cluster with the following specifications:
-
Valkey version:
9.1. -
Name:
1c-locks. -
Use FQDN instead of IP addresses: Enabled.
-
Data persistence mode: On replicas.
Warning
Locks have a limited TTL. To prevent data loss, use a high-availability cluster configuration.
-
Enable WebSQL access.
-
-
Create a VM for the HTTP lock server in the same network as the cluster.
-
Configure security groups to allow:
- The HTTP server to connect to the cluster.
- The 1C:Enterprise server to access the HTTP server on the selected port.
-
If you do not have Terraform yet, install it.
-
Get the authentication credentials. You can add them to environment variables or specify them later in the provider configuration file.
-
Configure and initialize a provider. Instead of manually creating the provider configuration file, you can download it
. -
Place the configuration file in a separate working directory and specify the parameter values. If you have not added the authentication credentials to environment variables, specify them in the configuration file.
-
Download the valkey-1c-http.tf
configuration file to your current working directory.This file describes:
- Network.
- Subnet.
- Security groups.
- Yandex Managed Service for Valkey™ cluster.
- Virtual machine with public internet access and a pre-installed HTTP server with all required dependencies.
-
In
valkey-1c-http.tf, specify the following:- Password to access the Yandex Managed Service for Valkey™ cluster.
- HTTP lock server access port.
- Lock key prefix in Valkey™.
-
Validate your Terraform configuration using this command:
terraform validateTerraform will display any configuration errors detected in your files.
-
Create the required infrastructure:
-
Run this command to view the intended changes:
terraform planIf you described the configuration correctly, the terminal will display a list of the resources to update and their parameters. This is a verification step that does not apply changes to your resources.
-
If everything looks correct, apply the changes:
-
Run this command:
terraform apply -
Confirm updating the resources.
-
Wait for the operation to complete.
-
All the required resources will be created in the specified folder. You can check resource availability and their settings in the management console
. -
After creating the resources, the terminal will display the following HTTP lock server settings:
vm_public_ip: Server public IP address.http_url: Server connection endpoint.
Deploy your HTTP lock server
An HTTP lock server is a thin layer between a 1C:Enterprise server and a Yandex Managed Service for Valkey™ cluster. It exposes endpoints with the lock prefix:
| Endpoint | Method | Purpose |
|---|---|---|
lock/acquire |
POST | Acquire a lock |
lock/release |
POST | Release a lock |
lock/renew |
POST | Extend a lock |
lock/status |
POST | Get the status of a lock |
lock/list |
GET | Get a list of locks |
How to work with your cluster:
-
To acquire a lock (
lock/acquire), use theSETcommand with theNXargument and specify the key TTL (PX). TheNXargument ensures the lock is only acquired when no such key exists, while the TTL prevents the lock from lasting indefinitely:SET <key> <token> NX PX <ttl_in_milliseconds> -
To release (
lock/release) or renew (lock/renew) a lock, use theEVALcommand to call Lua scripts. These scripts perform the following operations in Valkey™ sequentially:- Get lock data by key.
- Compare the lock token with the request token.
- Delete the key or renew the lock.
Calling a script ensures transaction atomicity, meaning that either all operations complete successfully or none of them do. Below is an example of a script for releasing a lock:
-- release: Delete the key only if the token matches. local value = server.call('GET', KEYS[1]) if not value then return 0 end local ok, lock = pcall(cjson.decode, value) if not ok or lock['token'] ~= ARGV[1] then return 0 end return server.call('DEL', KEYS[1]) -
The server returns HTTP status codes and error messages showing whether it successfully acquired, released, or renewed the lock.
To deploy your server:
-
Install Go 1.26.2
or higher. -
Clone the repository:
git clone https://git@git.sourcecraft.dev/valkey/webinar-260624-1c-example.git && \ cd webinar-260624-1c-example/http-lock-valkey -
Create environment variables with the server configuration:
export HTTP_ADDR=:<server_port_exposed_for_requests> export VALKEY_ADDR=<Valkey™_host_FQDN>:6379 export VALKEY_USER=default export VALKEY_PASSWORD=<Valkey™_password> export DEFAULT_LOCK_TTL=<lock_renewal_interval_in_seconds> export LOCK_KEY_PREFIX=<lock_key_prefix> -
Start the HTTP server with this command:
go run .
The Terraform configuration file contains all commands required to deploy the HTTP server. Once the infrastructure is created, the server is ready to use.
-
Update the server settings in the configuration file as needed:
- The lock renewal interval in the
DEFAULT_LOCK_TTLsetting of thecloud_initlocal variable. - The lock key prefix in the
lock_key_prefixlocal variable. - The server port for Valkey™ cluster requests in the
http_portlocal variable.
- The lock renewal interval in the
-
Make sure the settings are correct.
-
In the command line, navigate to the directory that contains the current Terraform configuration files defining the infrastructure.
-
Run this command:
terraform validateTerraform will show any errors found in your configuration files.
-
-
Confirm resource changes.
-
Run this command to view the intended changes:
terraform planIf you described the configuration correctly, the terminal will display a list of the resources to update and their parameters. This is a verification step that does not apply changes to your resources.
-
If everything looks correct, apply the changes:
-
Run this command:
terraform apply -
Confirm updating the resources.
-
Wait for the operation to complete.
-
-
After updating the resources, the terminal will display the updated HTTP lock server settings:
vm_public_ip: Server public IP address.http_url: Server connection endpoint.
Configure the 1C:Enterprise module
1C:Enterprise uses the Catalog lock module, which accesses the HTTP server through an external connection. The ready-to-use module code is in the container hosting the 1C:Enterprise test database in the valkey/webinar-260624-1c-example
The module performs the following functions:
- Sends HTTP requests to the server endpoints (
lock/acquire,lock/release,lock/status,lock/renew,lock/list) depending on the action. - Generates a lock key from the full catalog path (collection metadata) and the item ID. This ensures a unique lock for each catalog item.
- In the module form, you can configure event handlers for catalogs:
- On opening: Attempt to acquire the lock.
- On modification and closing: Renew or release the lock.
- To prevent the lock from expiring while the user is working with the form, configure periodic lock renewal.
- For clarity, the form displays lock information: its status (acquired or available), the remaining TTL, and the token used to verify lock ownership.
To configure the module:
-
Connect the database from the
1CExamplerepository directory and copy theCatalogLockscommon module to your 1C:Enterprise configuration. -
If methods are called from server form code, make sure server calls are enabled for the module.
-
In the
HTTPRequest()function, specify the HTTP lock server address:Connection = New HTTPConnection("<new_VM_public_IP_address>", <port_from_HTTP_ADDR_variable>); -
Add the lock to the appropriate form. Follow these steps:
- Add form attributes for the token and status.
- When opening the form, call
LockCatalog(). - When closing the form, call
UnlockCatalog(). - Enable periodic
renewsending.
-
Connect the form event handlers to the appropriate catalogs. Here is a minimum functionality example:
OnCreatingOnServer: acquire OnOpening: renew OnClosing: release -
Set up a lock key. By default, the key is generated as follows:
"Catalog." + Reference.Metadata().Name + ":" + Reference.UniqueID()For documents, you can use the same approach:
Document.CustomerOrder:UniqueID()If you need to use one module for different object types, generalize the
LockKey()function.
Warning
The module connection settings may vary depending on the 1C:Enterprise implementation.
Test the locks
-
Open 1C:Enterprise and go to a catalog, such as
Customers. -
Open an item, such as
Roman, for editing. The form will display the lock status as acquired, along with the lock TTL and token. -
Monitor the TTL for a while: it should decrease over time, e.g., from
41to31seconds. When the renewal interval expires (30 seconds by default), 1C:Enterprise automatically renews the lock. -
Make sure the lock appears in the cluster:
Management consoleSQL- Open Yandex WebSQL Connections
. - Add a database connection for the Valkey™ server you created earlier. Specify
0as the database name. - Connect to the
0database and find the the lock key row.
Note
Due to encoding limitations, WebSQL may display the key name incorrectly. To verify lock ownership, check whether the key exists and look at its value (token), rather than checking whether the key name is readable.
Connect to the Yandex Managed Service for Valkey™ cluster and run this command:
KEYS <lock_key_prefix>:*Valkey™ will return the lock key as a string.
- Open Yandex WebSQL Connections
Delete the resources you created
To reduce resource usage, delete the resources you no longer need:
-
In the terminal window, go to the directory containing the infrastructure plan.
Warning
Make sure the directory has no Terraform manifests with the resources you want to keep. Terraform deletes all resources that were created using the manifests in the current directory.
-
Delete resources:
-
Run this command:
terraform destroy -
Confirm deleting the resources and wait for the operation to complete.
All the resources described in the Terraform manifests will be deleted.
-