redis-security

द्वारा redis

Redis सुरक्षा मार्गदर्शन जिसमें प्रमाणीकरण (requirepass और ACL उपयोगकर्ता), TLS, ACL-आधारित न्यूनतम-विशेषाधिकार पहुँच नियंत्रण, नेटवर्क एक्सपोज़र को प्रतिबंधित करना शामिल है…

npx skills add https://github.com/redis/agent-skills --skill redis-security

Redis Security

Production hardening for Redis: authentication, ACL-based access control, and network exposure. Cover all three together — any one of them on its own leaves an exploitable gap.

When to apply

  • Deploying or reviewing a Redis instance destined for production.
  • Setting up application credentials beyond a shared password.
  • Auditing a Redis deployment against a security checklist.
  • Receiving "Redis exposed to the internet" findings from a scanner.

1. Always authenticate (and use TLS)

Never run a production Redis without a password. Pair authentication with TLS so credentials and data aren't sent in clear text.

# redis.conf
requirepass your-strong-password
tls-port 6380
tls-cert-file /path/to/redis.crt
tls-key-file  /path/to/redis.key
r = redis.Redis(
    host="localhost",
    port=6380,
    password="your-strong-password",
    ssl=True,
    ssl_cert_reqs="required",
)

If you can use ACL users (next section) instead of the single requirepass, do — requirepass is effectively the legacy "default user" shortcut.

See references/auth.md.

2. ACLs for least-privilege access

The default user with a shared password is fine for development. For production, give each application a dedicated ACL user with only the commands and key patterns it actually needs.

# Cache-only reader
ACL SETUSER app_readonly on >password ~cache:* +get +mget +scan

# Writer that can't run dangerous ops
ACL SETUSER app_writer   on >password ~*        +@all -@dangerous

# Admin (use sparingly, never for application traffic)
ACL SETUSER admin        on >strong-password ~* +@all

Useful command categories:

CategoryWhat it covers
@readRead commands (GET, MGET, HGET, ...)
@writeWrite commands (SET, DEL, XADD, ...)
@dangerousFLUSHALL, DEBUG, KEYS, etc.
@adminAdministrative commands

If app credentials leak, a tight ACL bounds the blast radius — the attacker can't FLUSHALL your DB just because they grabbed a cache reader's password.

See references/acls.md.

3. Restrict network access

The most common Redis breach is a public-internet Redis with no auth. Avoid that with three layers:

# redis.conf — bind to specific interfaces, keep protected-mode on
bind 127.0.0.1 192.168.1.100
protected-mode yes
# Firewall — allow only application subnets
iptables -A INPUT -p tcp --dport 6379 -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 6379 -j DROP

Anti-pattern: bind 0.0.0.0 + protected-mode no — exposes Redis to the whole network without protection.

Optional but recommended: rename or disable destructive commands so a compromised client can't trash the DB:

rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG ""

See references/network.md.

References

redis की और Skills

docs-sync
redis
मास्टर ब्रांच के कार्यान्वयन और कॉन्फ़िगरेशन का विश्लेषण करें ताकि docs/, README.md, और प्रति-पैकेज README में गायब, गलत, या पुराने दस्तावेज़ का पता लगाया जा सके। उपयोग करें…
official
implement-command
redis
Add a new Redis command (or command variant) to node-redis end-to-end — the `<NAME>.ts` Command file, its registration with JSDoc in the package…
official
maintainer-review
redis
GitHub issue या pull request URL की समीक्षा node-redis अनुरक्षक के रूप में करें, जिसमें यह चरणबद्ध मूल्यांकन हो कि दावा वास्तविक है, व्यावहारिक रूप से महत्वपूर्ण है, पहले से...
official
pr-draft-summary
redis
node-redis के लिए आवश्यक PR-तैयार सारांश ब्लॉक, शाखा सुझाव, शीर्षक और ड्राफ्ट विवरण बनाएं। इसका उपयोग अंतिम प्रतिक्रिया से पहले किया जाना चाहिए जब भी...
official
runtime-behavior-probe
redis
रनटाइम व्यवहार जांच की योजना बनाएं और अस्थायी TypeScript प्रोब स्क्रिप्ट, सत्यापन मैट्रिक्स, स्थिति नियंत्रण और निष्कर्ष-प्रथम रिपोर्ट के साथ उन्हें क्रियान्वित करें। उपयोग करें…
official
backend
redis
NestJS बैकएंड विकास पैटर्न RedisInsight API के लिए: मॉड्यूल संरचना, सेवाएँ, नियंत्रक, DTO, निर्भरता इंजेक्शन, और त्रुटि प्रबंधन। उपयोग करें जब...
official
branches
redis
लोअरकेस केबब-केस का उपयोग करें, जिसमें टाइप प्रीफिक्स और इश्यू/टिकट आइडेंटिफायर हो। ब्रांच नाम GitHub Actions वर्कफ़्लो नियमों से मेल खाने चाहिए (.github/workflows/enforce-branch-name-rules.yml देखें)।
official
code-quality
redis
Code-quality standards for RedisInsight: TypeScript strictness, naming conventions (camelCase, PascalCase, UPPER_SNAKE_CASE), linting rules, no `any` without…
official