Lesson 17 / 20
Security Basics: AUTH, ACLs & Network Binding
Secure Redis with passwords, ACL users, localhost binding and TLS, and never expose it directly to the internet.
Do not expose Redis
Redis was designed for trusted networks. Bind it to localhost or a private interface, keep it behind a firewall, and never open port 6379 to the internet. Exposed instances are routinely hijacked.
ACL users
Redis 6+ ACLs create users with limited commands and key patterns instead of one shared password.
# redis.conf
bind 127.0.0.1
protected-mode yes
# create an app user that can only use cache:* keys
redis-cli ACL SETUSER app on >strong-password ~cache:* +get +set +del +expire
# connect without putting the password on the command line
REDISCLI_AUTH=strong-password redis-cli --user app PINGEnable TLS when traffic crosses a network, and disable dangerous commands such as FLUSHALL for application users via ACLs.