redis-security

tarafından redis

Redis güvenlik rehberi; kimlik doğrulama (requirepass ve ACL kullanıcıları), TLS, ACL tabanlı en az ayrıcalık erişim kontrolü, ağ maruziyetini sınırlama yoluyla…

npx skills add https://github.com/redis/agent-skills --skill redis-security

Redis Security

Production hardening for Redis: authentication, ACL-based access control, and network exposure. Cover all three together — any one of them on its own leaves an exploitable gap.

When to apply

  • Deploying or reviewing a Redis instance destined for production.
  • Setting up application credentials beyond a shared password.
  • Auditing a Redis deployment against a security checklist.
  • Receiving "Redis exposed to the internet" findings from a scanner.

1. Always authenticate (and use TLS)

Never run a production Redis without a password. Pair authentication with TLS so credentials and data aren't sent in clear text.

# redis.conf
requirepass your-strong-password
tls-port 6380
tls-cert-file /path/to/redis.crt
tls-key-file  /path/to/redis.key
r = redis.Redis(
    host="localhost",
    port=6380,
    password="your-strong-password",
    ssl=True,
    ssl_cert_reqs="required",
)

If you can use ACL users (next section) instead of the single requirepass, do — requirepass is effectively the legacy "default user" shortcut.

See references/auth.md.

2. ACLs for least-privilege access

The default user with a shared password is fine for development. For production, give each application a dedicated ACL user with only the commands and key patterns it actually needs.

# Cache-only reader
ACL SETUSER app_readonly on >password ~cache:* +get +mget +scan

# Writer that can't run dangerous ops
ACL SETUSER app_writer   on >password ~*        +@all -@dangerous

# Admin (use sparingly, never for application traffic)
ACL SETUSER admin        on >strong-password ~* +@all

Useful command categories:

CategoryWhat it covers
@readRead commands (GET, MGET, HGET, ...)
@writeWrite commands (SET, DEL, XADD, ...)
@dangerousFLUSHALL, DEBUG, KEYS, etc.
@adminAdministrative commands

If app credentials leak, a tight ACL bounds the blast radius — the attacker can't FLUSHALL your DB just because they grabbed a cache reader's password.

See references/acls.md.

3. Restrict network access

The most common Redis breach is a public-internet Redis with no auth. Avoid that with three layers:

# redis.conf — bind to specific interfaces, keep protected-mode on
bind 127.0.0.1 192.168.1.100
protected-mode yes
# Firewall — allow only application subnets
iptables -A INPUT -p tcp --dport 6379 -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 6379 -j DROP

Anti-pattern: bind 0.0.0.0 + protected-mode no — exposes Redis to the whole network without protection.

Optional but recommended: rename or disable destructive commands so a compromised client can't trash the DB:

rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG ""

See references/network.md.

References

redis tarafından daha fazla skill

docs-sync
redis
Ana dal uygulamasını ve yapılandırmasını analiz ederek docs/, README.md ve paket bazlı README'lerde eksik, hatalı veya güncelliğini yitirmiş dokümantasyonu bul. Kullan…
official
implement-command
redis
Add a new Redis command (or command variant) to node-redis end-to-end — the `<NAME>.ts` Command file, its registration with JSDoc in the package…
official
maintainer-review
redis
Bir GitHub sorununu veya çekme isteği URL'sini node-redis bakımcısı olarak inceleyin; iddianın gerçek, pratik olarak önemli, zaten… olup olmadığına dair aşamalı bir değerlendirme yapın.
official
pr-draft-summary
redis
Gerekli PR hazır özet bloğunu, dal önerisini, başlığı ve node-redis için taslak açıklamayı oluşturur. Her ne zaman… son yanıttan önce kullanılmalıdır.
official
runtime-behavior-probe
redis
Geçici TypeScript prob betikleri, doğrulama matrisleri, durum kontrolleri ve bulguları öncelikli raporlarla runtime davranış araştırmalarını planlayın ve yürütün. Kullan…
official
backend
redis
NestJS backend geliştirme desenleri, RedisInsight API için: modül yapısı, servisler, kontrolcüler, DTO'lar, bağımlılık enjeksiyonu ve hata yönetimi. Şu durumlarda kullan…
official
branches
redis
Küçük harf kebab-case kullanın ve tür öneki ile sorun/bilet tanımlayıcısı ekleyin. Dal adları GitHub Actions iş akışı kurallarına uymalıdır (bkz. .github/workflows/enforce-branch-name-rules.yml).
official
code-quality
redis
Code-quality standards for RedisInsight: TypeScript strictness, naming conventions (camelCase, PascalCase, UPPER_SNAKE_CASE), linting rules, no `any` without…
official