← Files RedisARCHIVED FILE

skills/redis-security/references/acls.md

862 Bytes · Oct 2, 2026 · 00:19 UTC

↓ Download file

# Use ACLs for Fine-Grained Access Control

Create users with only the permissions they need (principle of least privilege).

**Correct:** Create specific users with limited permissions.

```
# Read-only user for cache access
ACL SETUSER app_readonly on >password ~cache:* +get +mget +scan

# Writer that can't run dangerous commands
ACL SETUSER app_writer on >password ~* +@all -@dangerous

# Admin user (use sparingly)
ACL SETUSER admin on >strong-password ~* +@all
```

**Incorrect:** Using the default user for everything.

```
# Bad: Single password for all access
requirepass shared-password
```

**ACL categories:**
- `@read` - Read commands
- `@write` - Write commands
- `@dangerous` - Commands like FLUSHALL, DEBUG
- `@admin` - Administrative commands

Reference: [Redis ACL](https://redis.io/docs/latest/operate/oss_and_stack/management/security/acl/)

SHA-256: 103a0d4e3b613207752a5d445faf5e80b3931fb43db211c5036ce85fc676f368