redis-security

bởi redis

Hướng dẫn bảo mật Redis bao gồm xác thực (requirepass và người dùng ACL), TLS, kiểm soát truy cập dựa trên nguyên tắc đặc quyền tối thiểu qua ACL, hạn chế phơi nhiễm mạng qua…

npx skills add https://github.com/redis/agent-skills --skill redis-security

Redis Security

Production hardening for Redis: authentication, ACL-based access control, and network exposure. Cover all three together — any one of them on its own leaves an exploitable gap.

When to apply

  • Deploying or reviewing a Redis instance destined for production.
  • Setting up application credentials beyond a shared password.
  • Auditing a Redis deployment against a security checklist.
  • Receiving "Redis exposed to the internet" findings from a scanner.

1. Always authenticate (and use TLS)

Never run a production Redis without a password. Pair authentication with TLS so credentials and data aren't sent in clear text.

# redis.conf
requirepass your-strong-password
tls-port 6380
tls-cert-file /path/to/redis.crt
tls-key-file  /path/to/redis.key
r = redis.Redis(
    host="localhost",
    port=6380,
    password="your-strong-password",
    ssl=True,
    ssl_cert_reqs="required",
)

If you can use ACL users (next section) instead of the single requirepass, do — requirepass is effectively the legacy "default user" shortcut.

See references/auth.md.

2. ACLs for least-privilege access

The default user with a shared password is fine for development. For production, give each application a dedicated ACL user with only the commands and key patterns it actually needs.

# Cache-only reader
ACL SETUSER app_readonly on >password ~cache:* +get +mget +scan

# Writer that can't run dangerous ops
ACL SETUSER app_writer   on >password ~*        +@all -@dangerous

# Admin (use sparingly, never for application traffic)
ACL SETUSER admin        on >strong-password ~* +@all

Useful command categories:

CategoryWhat it covers
@readRead commands (GET, MGET, HGET, ...)
@writeWrite commands (SET, DEL, XADD, ...)
@dangerousFLUSHALL, DEBUG, KEYS, etc.
@adminAdministrative commands

If app credentials leak, a tight ACL bounds the blast radius — the attacker can't FLUSHALL your DB just because they grabbed a cache reader's password.

See references/acls.md.

3. Restrict network access

The most common Redis breach is a public-internet Redis with no auth. Avoid that with three layers:

# redis.conf — bind to specific interfaces, keep protected-mode on
bind 127.0.0.1 192.168.1.100
protected-mode yes
# Firewall — allow only application subnets
iptables -A INPUT -p tcp --dport 6379 -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 6379 -j DROP

Anti-pattern: bind 0.0.0.0 + protected-mode no — exposes Redis to the whole network without protection.

Optional but recommended: rename or disable destructive commands so a compromised client can't trash the DB:

rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG ""

See references/network.md.

References

Thêm skills từ redis

docs-sync
redis
Phân tích triển khai và cấu hình của nhánh master để tìm tài liệu bị thiếu, sai hoặc lỗi thời trong docs/, README.md và các README theo từng gói. Sử dụng…
redis-query-engine
redis
Hướng dẫn về Redis Query Engine (RQE) bao gồm thiết kế schema FT.CREATE, lựa chọn kiểu trường (TEXT, TAG, NUMERIC, GEO, GEOSHAPE, VECTOR), cú pháp truy vấn DIALECT 2,…
redis-search
redis
Hướng dẫn Redis Search bao gồm thiết kế schema FT.CREATE, lựa chọn loại trường (TEXT, TAG, NUMERIC, GEO, GEOSHAPE, VECTOR, đường dẫn JSON), cú pháp truy vấn DIALECT 2,…
redis-semantic-cache
redis
Hướng dẫn Redis LangCache về bộ nhớ đệm ngữ nghĩa cho phản hồi LLM trên Redis Cloud — gọi search/set qua SDK hoặc REST API, điều chỉnh ngưỡng tương đồng,…
redis-vector-search
redis
Hướng dẫn tìm kiếm vector Redis bao gồm lựa chọn thuật toán HNSW so với FLAT, cấu hình chỉ mục vector (số chiều, độ đo khoảng cách, kiểu dữ liệu), tìm kiếm kết hợp có bộ lọc…
bump-test-image
redis
Cập nhật image docker test Redis mặc định (redislabs/client-libs-test) trong DEFAULT_DOCKER_CONFIG dùng chung và ma trận CI, sau đó force-push…
i18n
redis
Quy ước quốc tế hóa cho giao diện RedisInsight (i18next). Sử dụng khi thêm hoặc thay đổi chuỗi hướng đến người dùng trong redisinsight/ui/**, chỉnh sửa…
dead-dependencies
redis
Tìm và an toàn loại bỏ các dependency npm không dùng ("chết") trong RedisInsight bằng công thức grep + leaf-check + build-gate. Sử dụng khi dọn dẹp dependencies,…