← RedisCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Redis
Snapshot Sep 30, 2026 · 23:01 UTC · version 1.4.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 217
},
{
"relative_path": "references/acls.md",
"size_in_bytes": 862
},
{
"relative_path": "references/auth.md",
"size_in_bytes": 1650
},
{
"relative_path": "references/network.md",
"size_in_bytes": 902
}
],
"name": "redis-security",
"skill_md_contents": "---\nname: redis-security\ndescription: Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.\nlicense: MIT\n---\n\n# Redis Security\n\nProduction hardening for Redis: authentication, ACL-based access control, and network exposure. Cover all three together — any one of them on its own leaves an exploitable gap.\n\n## When to apply\n\n- Deploying or reviewing a Redis instance destined for production.\n- Setting up application credentials beyond a shared password.\n- Auditing a Redis deployment against a security checklist.\n- Receiving \"Redis exposed to the internet\" findings from a scanner.\n\n## 1. Always authenticate (and use TLS)\n\nNever run a production Redis without a password. Pair authentication with TLS so credentials and data aren't sent in clear text.\n\n```\n# redis.conf\nrequirepass your-strong-password\ntls-port 6380\ntls-cert-file /path/to/redis.crt\ntls-key-file /path/to/redis.key\n```\n\n```python\nr = redis.Redis(\n host=\"localhost\",\n port=6380,\n password=\"your-strong-password\",\n ssl=True,\n ssl_cert_reqs=\"required\",\n)\n```\n\nIf you can use ACL users (next section) instead of the single `requirepass`, do — `requirepass` is effectively the legacy \"default user\" shortcut.\n\nSee [references/auth.md](references/auth.md).\n\n## 2. ACLs for least-privilege access\n\nThe `default` user with a shared password is fine for development. For production, give each application a dedicated ACL user with only the commands and key patterns it actually needs.\n\n```\n# Cache-only reader\nACL SETUSER app_readonly on >password ~cache:* +get +mget +scan\n\n# Writer that can't run dangerous ops\nACL SETUSER app_writer on >password ~* +@all -@dangerous\n\n# Admin (use sparingly, never for application traffic)\nACL SETUSER admin on >strong-password ~* +@all\n```\n\nUseful command categories:\n\n| Category | What it covers |\n|---|---|\n| `@read` | Read commands (`GET`, `MGET`, `HGET`, ...) |\n| `@write` | Write commands (`SET`, `DEL`, `XADD`, ...) |\n| `@dangerous` | `FLUSHALL`, `DEBUG`, `KEYS`, etc. |\n| `@admin` | Administrative commands |\n\nIf app credentials leak, a tight ACL bounds the blast radius — the attacker can't `FLUSHALL` your DB just because they grabbed a cache reader's password.\n\nSee [references/acls.md](references/acls.md).\n\n## 3. Restrict network access\n\nThe most common Redis breach is a public-internet Redis with no auth. Avoid that with three layers:\n\n```\n# redis.conf — bind to specific interfaces, keep protected-mode on\nbind 127.0.0.1 192.168.1.100\nprotected-mode yes\n```\n\n```bash\n# Firewall — allow only application subnets\niptables -A INPUT -p tcp --dport 6379 -s 192.168.1.0/24 -j ACCEPT\niptables -A INPUT -p tcp --dport 6379 -j DROP\n```\n\nAnti-pattern: `bind 0.0.0.0` + `protected-mode no` — exposes Redis to the whole network without protection.\n\nOptional but recommended: rename or disable destructive commands so a compromised client can't trash the DB:\n\n```\nrename-command FLUSHALL \"\"\nrename-command DEBUG \"\"\nrename-command CONFIG \"\"\n```\n\nSee [references/network.md](references/network.md).\n\n## References\n\n- [Redis: Security](https://redis.io/docs/latest/operate/oss_and_stack/management/security/)\n- [Redis: ACL](https://redis.io/docs/latest/operate/oss_and_stack/management/security/acl/)\n"
}SHA-256 of public snapshot: 05416457c75fb8486038412b8a6c34842f75492c2b78dfd0eab593f28f5ac7a4