पाठ 17 / 20
Security Basics: AUTH, ACLs और Network Binding
Passwords, ACL users, localhost binding और TLS से Redis सुरक्षित करें, और उसे कभी सीधे internet पर expose न करें।
Redis को expose न करें
Redis को trusted networks के लिए बनाया गया था। उसे localhost या private interface से bind करें, firewall के पीछे रखें, और port 6379 कभी internet के लिए न खोलें। Exposed instances नियमित रूप से hijack होते हैं।
ACL users
Redis 6+ ACLs एक साझा password के बजाय सीमित commands और key patterns वाले users बनाते हैं।
# redis.conf
bind 127.0.0.1
protected-mode yes
# create an app user that can only use cache:* keys
redis-cli ACL SETUSER app on >strong-password ~cache:* +get +set +del +expire
# connect without putting the password on the command line
REDISCLI_AUTH=strong-password redis-cli --user app PINGजब traffic network पार करे तो TLS चालू करें, और application users के लिए ACLs से FLUSHALL जैसे खतरनाक commands बंद करें।