पाठ 17 / 20

Security Basics: AUTH, ACLs और Network Binding

Passwords, ACL users, localhost binding और TLS से Redis सुरक्षित करें, और उसे कभी सीधे internet पर expose न करें।

Redis को expose न करें

Redis को trusted networks के लिए बनाया गया था। उसे localhost या private interface से bind करें, firewall के पीछे रखें, और port 6379 कभी internet के लिए न खोलें। Exposed instances नियमित रूप से hijack होते हैं।

ACL users

Redis 6+ ACLs एक साझा password के बजाय सीमित commands और key patterns वाले users बनाते हैं।

# redis.conf
bind 127.0.0.1
protected-mode yes

# create an app user that can only use cache:* keys
redis-cli ACL SETUSER app on >strong-password ~cache:* +get +set +del +expire

# connect without putting the password on the command line
REDISCLI_AUTH=strong-password redis-cli --user app PING

जब traffic network पार करे तो TLS चालू करें, और application users के लिए ACLs से FLUSHALL जैसे खतरनाक commands बंद करें।