# Security Basics: AUTH, ACLs & Network Binding — Redis Fundamentals: Caching, Data Structures and Persistence

Source: https://www.geekswithgeeks.com/en/redis/redis-security

> Secure Redis with passwords, ACL users, localhost binding and TLS, and never expose it directly to the internet.

## Do not expose Redis

Redis was designed for trusted networks. Bind it to localhost or a private interface, keep it behind a firewall, and never open port 6379 to the internet. Exposed instances are routinely hijacked.

## ACL users

Redis 6+ ACLs create users with limited commands and key patterns instead of one shared password.

```bash
# redis.conf
bind 127.0.0.1
protected-mode yes

# create an app user that can only use cache:* keys
redis-cli ACL SETUSER app on >strong-password ~cache:* +get +set +del +expire

# connect without putting the password on the command line
REDISCLI_AUTH=strong-password redis-cli --user app PING
```

Enable TLS when traffic crosses a network, and disable dangerous commands such as FLUSHALL for application users via ACLs.
