Skip to main content

Store ASP.NET session state in Zaris

Clustron Zaris can hold your web application's session state, so any instance behind a load balancer serves a user's next request and sessions survive an app restart or pod recycle. There are two packages, one for each ASP.NET world:

  • Clustron.Zaris.AspNetCore.Session — the modern ASP.NET Core ISession store (net8.0).
  • Clustron.Zaris.SessionState — the classic ASP.NET (System.Web) SessionStateStoreProvider for Web Forms / classic MVC on .NET Framework 4.7.2 / 4.8.

Both store each session under a normal Zaris key with a TTL equal to the session timeout, re-armed on every access (sliding expiration).

ASP.NET Core​

Install the package and wire it with a single call:

dotnet add package Clustron.Zaris.AspNetCore.Session
using Clustron.Zaris.AspNetCore.Session;

builder.Services.AddZarisSession(options =>
{
options.StoreName = "sessions";
options.ConnectionString = "zaris://zaris-1:7861,zaris-2:7861/sessions"; // or zaris://inproc/sessions
options.KeyPrefix = "zaris:session:";
options.IdleTimeout = TimeSpan.FromMinutes(30); // sliding, enforced by Zaris TTL
options.CookieName = ".Zaris.Session";
options.CookieIsEssential = true;
});

var app = builder.Build();
app.UseSession();

Then use HttpContext.Session exactly as always:

app.MapGet("/", (HttpContext ctx) =>
{
var count = (ctx.Session.GetInt32("count") ?? 0) + 1;
ctx.Session.SetInt32("count", count);
return Results.Text($"count={count}");
});

Options​

OptionDefaultMeaning
StoreNamesessionsThe Zaris store that holds session entries.
ConnectionString—Zaris connection string. Use zaris://inproc/<store> for an embedded store in dev, or zaris://host:7861,.../<store> (TLS: zariss://…) for a cluster.
KeyPrefixzaris:session:Prefix for every session key written to Zaris.
IdleTimeout20 minSliding session lifetime, enforced by Zaris TTL and re-armed on each access.
CookieName.Zaris.SessionThe session cookie name.
CookieIsEssentialfalseMarks the cookie essential for consent scenarios.

A runnable sample (counter + self-test, embedded or networked) is in the Session sample.

Classic ASP.NET (System.Web)​

For Web Forms / classic MVC on .NET Framework, it's a configuration-only, drop-in provider:

dotnet add package Clustron.Zaris.SessionState
<configuration>
<connectionStrings>
<add name="ZarisSessions"
connectionString="zaris://zaris-1:7861,zaris-2:7861/sessions" />
</connectionStrings>
<system.web>
<!-- timeout = sliding session timeout, in minutes -->
<sessionState mode="Custom" customProvider="Zaris" timeout="20">
<providers>
<add name="Zaris"
type="Clustron.Zaris.SessionState.ZarisSessionStateStoreProvider, Clustron.Zaris.SessionState"
connectionStringName="ZarisSessions"
keyPrefix="zaris:session:"
lockTimeoutSeconds="90" />
</providers>
</sessionState>
</system.web>
</configuration>

Your code is unchanged — Session["user"] = "alice"; now reads and writes Zaris. The provider implements correct exclusive-lock semantics (lock id / age / timeout), sliding expiration, and cookieless support.

AttributeRequiredDefaultMeaning
connectionStringone of these—Zaris connection string.
connectionStringNameone of these—Name of a <connectionStrings> entry holding it.
keyPrefixnozaris:session:Prefix for every Zaris key the provider writes.
lockTimeoutSecondsno90Safety-net TTL on the lock key so a crashed request can't wedge a session. Set ≥ your longest request.

See also​