Zum Hauptinhalt springen
IT Security NachrichtenShutdown-Sabotage: KI-Agenten verhindern eigenmächtig ihre Abschaltung(03.10.2026 um 06:05 Uhr)
•
Sichere ProgrammierungTFTP Uses UDP 69—but the File Transfer Uses More Ports(03.10.2026 um 07:12 Uhr)
•
Sichere ProgrammierungMy best-looking resume template scored 0 of 7 in the text layer(03.10.2026 um 07:12 Uhr)
•
Sichere ProgrammierungDHCP Ports Explained: UDP 67/68 for IPv4 and 546/547 for IPv6(03.10.2026 um 07:12 Uhr)
•
Sichere ProgrammierungCaddy or Nginx Proxy Manager? Choose the Workflow You’ll Maintain(03.10.2026 um 07:13 Uhr)
•
Sichere ProgrammierungDNS Port 53: When to Use UDP, TCP, DoT, or DoH(03.10.2026 um 07:13 Uhr)
•
Sichere ProgrammierungCosmoDex: Making Coding Practice Feel Like a Game 🚀(03.10.2026 um 07:14 Uhr)
•
Sichere ProgrammierungListing DNF Repositories: Enabled, Disabled, and DNF4 vs DNF5(03.10.2026 um 07:14 Uhr)
•
Sichere ProgrammierungPort 25 Explained: How SMTP Email Delivery Works(03.10.2026 um 07:14 Uhr)
••
IT Security NachrichtenShutdown-Sabotage: KI-Agenten verhindern eigenmächtig ihre Abschaltung(03.10.2026 um 06:05 Uhr)
•
Sichere ProgrammierungTFTP Uses UDP 69—but the File Transfer Uses More Ports(03.10.2026 um 07:12 Uhr)
•
Sichere ProgrammierungMy best-looking resume template scored 0 of 7 in the text layer(03.10.2026 um 07:12 Uhr)
•
Sichere ProgrammierungDHCP Ports Explained: UDP 67/68 for IPv4 and 546/547 for IPv6(03.10.2026 um 07:12 Uhr)
•
Sichere ProgrammierungCaddy or Nginx Proxy Manager? Choose the Workflow You’ll Maintain(03.10.2026 um 07:13 Uhr)
•
Sichere ProgrammierungDNS Port 53: When to Use UDP, TCP, DoT, or DoH(03.10.2026 um 07:13 Uhr)
•
Sichere ProgrammierungCosmoDex: Making Coding Practice Feel Like a Game 🚀(03.10.2026 um 07:14 Uhr)
•
Sichere ProgrammierungListing DNF Repositories: Enabled, Disabled, and DNF4 vs DNF5(03.10.2026 um 07:14 Uhr)
•
Sichere ProgrammierungPort 25 Explained: How SMTP Email Delivery Works(03.10.2026 um 07:14 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Locking It Down with Redis ACLs: A Dev's Guide to Secure Access

Hi there! I'm Maneshwar. Right now, I’m building LiveAPI, a first-of-its-kind tool that helps you automatically index API endpoints across all your r…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Hi there! I'm Maneshwar. Right now, I’m building LiveAPI, a first-of-its-kind tool that helps you automatically index API endpoints across all your repositories. LiveAPI makes it easier to discover, understand, and interact with APIs in large infrastructures.






Redis has long been the go-to for fast in-memory data, whether it's caching, job queues, pub/sub, or real-time analytics.



But with great power comes the need for great control.



If you've ever worried about giving too much access to too many Redis clients, it's time you got familiar with Redis ACLs (Access Control Lists).



Whether you're a backend dev, a DevOps engineer, or just someone who’s tired of redis-cli users running KEYS * in production — this blog is for you.






Why Redis ACLs?



Prior to Redis 6, Redis had only one global password. Anyone with access to Redis could do anything — flush databases, delete keys, rewrite config, and more.



That’s not ideal when you're scaling up with multiple services, teams, or environments.



Enter ACLs: user-based access control introduced in Redis 6.



With Redis ACLs, you can:



Create named users

Assign specific permissions (read-only, streams-only, pub/sub, etc.)

Control what commands and keys each user can access

Use hashed passwords and role-based restrictions





Redis ACL Essentials



Redis ACLs work by defining users in either the redis.conf or a dedicated ACL file.



Let’s break down a typical ACL entry:




user runner-8 on >mySecretPass +xadd +xread ~logs_stream






This means:




  • runner-8 is the username

  • on → user is enabled

  • > mySecretPass → password (in plaintext)

  • +xadd +xread → only allowed to run XADD and XREAD (Redis Streams)

  • ~logs_stream → can only access key logs_stream



You can also hash passwords with SHA256:




user runner-8 on sanitize-payload #<sha256-hash> +xadd ~logs_stream









Creating ACL Users: Manual & Automated






Option 1: Manually via redis-cli



Connect to your Redis server and run:




ACL SETUSER runner-8 on >mySecretPass +xadd +xread ~logs_stream






To verify:




ACL LIST






To see current user:




ACL WHOAMI






To delete a user:




ACL DELUSER runner-8






But this won't persist across restarts unless saved to an ACL file.









Option 2: Define ACLs in users.acl file



Create (or edit) your ACL file:




sudo nano /etc/redis/users.acl






Add:




user default on >supersecret +@all ~*
user runner-8 on >mySecretPass +xadd +xread ~logs_stream






Then make sure your redis.conf has this line:




aclfile /etc/redis/users.acl






Restart Redis:




sudo systemctl restart redis









Example: Isolating Access for Asynq Workers



Let’s say you have a Go service using Asynq for background jobs. You don’t want it touching anything except:




  • A stream named logs_stream

  • Heartbeat keys like runners:heartbeat

  • Pub/Sub channels used by Asynq



You’d write:




user runner-8 on >Masd2dnnsd +xadd +xread +xrange +xrevrange +subscribe +psubscribe +publish +unsubscribe ~logs_stream ~runners:heartbeat ~__asynq* ~asynq*






In ACL terms:




  • +xadd/xread/... → Redis Stream commands

  • +subscribe/... → Pub/Sub permissions

  • ~key → key patterns the user can access



And then use in code:




asynq.RedisClientOpt{
Addr: "localhost:6379",
Username: "runner-8",
Password: "Masd2dnnsd",
}









Testing Access



Try running:




redis-cli -u redis://runner-8:Masd2dnnsd@localhost:6379






Inside:




SET foo bar
# → (error) NOPERM this user has no permissions to run the 'SET' command

XADD logs_stream * message "hello"
# → OK









Bonus: Use Ansible to Manage Redis ACLs



An example Ansible task:




- name: Configure Redis ACL file
copy:
dest: /etc/redis/users.acl
content: |
user default on >supersecret +@all ~*
user runner-8 on >Masd2dnnsd +xadd +xread +xrange +xrevrange +subscribe +psubscribe +publish +unsubscribe ~logs_stream ~runners:heartbeat ~__asynq* ~asynq*
owner: redis
group: redis
mode: "0644"

- name: Ensure Redis uses ACL file
lineinfile:
path: /etc/redis/redis.conf
regexp: '^aclfile '
line: 'aclfile /etc/redis/users.acl'

- name: Restart Redis
systemd:
name: redis-server
state: restarted









Summary



Redis ACLs give you powerful, fine-grained access control. Whether you're running job queues, microservices, or multi-tenant systems, ACLs help you enforce the principle of least privilege.



No more all-or-nothing access. Just clean, secure, permission-scoped access — Redis style.



Got Redis ACL horror stories or wins? Drop them in the comments. Or let me know if you want a prebuilt ACL policy template for your app or worker.






LiveAPI helps you get all your backend APIs documented in a few minutes.



With LiveAPI, you can generate interactive API docs that allow users to search and execute endpoints directly from the browser.



LiveAPI Demo



If you're tired of updating Swagger manually or syncing Postman collections, give it a shot.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Locking It Down with Redis ACLs: A Dev's Guide to Secure Access

Thematisch verwandte Begriffe: Locking, Down, with, Redis · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
Nächster Beitrag