redis-security

작성자: redis

Redis 보안 가이드로 인증(requirepass 및 ACL 사용자), TLS, ACL 기반 최소 권한 접근 제어, 네트워크 노출 제한 등을 다룹니다.

npx skills add https://github.com/redis/agent-skills --skill redis-security

Redis Security

Production hardening for Redis: authentication, ACL-based access control, and network exposure. Cover all three together — any one of them on its own leaves an exploitable gap.

When to apply

  • Deploying or reviewing a Redis instance destined for production.
  • Setting up application credentials beyond a shared password.
  • Auditing a Redis deployment against a security checklist.
  • Receiving "Redis exposed to the internet" findings from a scanner.

1. Always authenticate (and use TLS)

Never run a production Redis without a password. Pair authentication with TLS so credentials and data aren't sent in clear text.

# redis.conf
requirepass your-strong-password
tls-port 6380
tls-cert-file /path/to/redis.crt
tls-key-file  /path/to/redis.key
r = redis.Redis(
    host="localhost",
    port=6380,
    password="your-strong-password",
    ssl=True,
    ssl_cert_reqs="required",
)

If you can use ACL users (next section) instead of the single requirepass, do — requirepass is effectively the legacy "default user" shortcut.

See references/auth.md.

2. ACLs for least-privilege access

The default user with a shared password is fine for development. For production, give each application a dedicated ACL user with only the commands and key patterns it actually needs.

# Cache-only reader
ACL SETUSER app_readonly on >password ~cache:* +get +mget +scan

# Writer that can't run dangerous ops
ACL SETUSER app_writer   on >password ~*        +@all -@dangerous

# Admin (use sparingly, never for application traffic)
ACL SETUSER admin        on >strong-password ~* +@all

Useful command categories:

CategoryWhat it covers
@readRead commands (GET, MGET, HGET, ...)
@writeWrite commands (SET, DEL, XADD, ...)
@dangerousFLUSHALL, DEBUG, KEYS, etc.
@adminAdministrative commands

If app credentials leak, a tight ACL bounds the blast radius — the attacker can't FLUSHALL your DB just because they grabbed a cache reader's password.

See references/acls.md.

3. Restrict network access

The most common Redis breach is a public-internet Redis with no auth. Avoid that with three layers:

# redis.conf — bind to specific interfaces, keep protected-mode on
bind 127.0.0.1 192.168.1.100
protected-mode yes
# Firewall — allow only application subnets
iptables -A INPUT -p tcp --dport 6379 -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 6379 -j DROP

Anti-pattern: bind 0.0.0.0 + protected-mode no — exposes Redis to the whole network without protection.

Optional but recommended: rename or disable destructive commands so a compromised client can't trash the DB:

rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG ""

See references/network.md.

References

redis의 다른 스킬

docs-sync
redis
마스터 브랜치의 구현 및 구성을 분석하여 docs/, README.md, 패키지별 README에서 누락되거나, 부정확하거나, 오래된 문서를 찾습니다.
redis-query-engine
redis
Redis Query Engine (RQE) 가이드: FT.CREATE 스키마 설계, 필드 유형 선택(TEXT, TAG, NUMERIC, GEO, GEOSHAPE, VECTOR), DIALECT 2 쿼리 구문,…
redis-search
redis
Redis Search 가이드: FT.CREATE 스키마 설계, 필드 유형 선택(TEXT, TAG, NUMERIC, GEO, GEOSHAPE, VECTOR, JSON 경로), DIALECT 2 쿼리 구문,…
redis-semantic-cache
redis
Redis LangCache를 사용하여 Redis Cloud에서 LLM 응답의 시맨틱 캐싱을 수행하는 방법 — SDK 또는 REST API를 통한 검색/설정 호출, 유사도 임계값 조정,…
redis-vector-search
redis
Redis 벡터 검색 가이드: HNSW vs FLAT 알고리즘 선택, 벡터 인덱스 구성(차원, 거리 메트릭, 데이터 타입), 필터링된 하이브리드 검색…
bump-test-image
redis
공유 DEFAULT_DOCKER_CONFIG 및 CI 매트릭스에서 기본 Redis docker 테스트 이미지(redislabs/client-libs-test)를 범프한 다음 강제 푸시합니다…
i18n
redis
RedisInsight UI(i18next)의 국제화 규칙입니다. redisinsight/ui/** 아래의 사용자 표시 문자열을 추가하거나 변경할 때, ...를 편집할 때 사용합니다.
dead-dependencies
redis
RedisInsight에서 grep + leaf-check + build-gate 레시피를 사용하여 사용되지 않는("dead") npm 종속성을 찾아 안전하게 제거합니다. 종속성을 정리할 때 사용하세요,…