Install and Secure Redis on Linux (bind, AUTH, firewall, TLS basics)

redis install secure linux - custom-redis-featured.png

Redis is fast, simple, and everywhere — which also means it is a frequent target when left on 0.0.0.0 with no password.
A default package install is fine for learning on a laptop; on a server you should assume port 6379 will be scanned.

This guide installs Redis from distribution packages, locks network access, enables authentication, and trims the commands that have no business on a production cache.
Pair it with your UFW baseline and application secrets stored outside the repo (see
Ansible Vault).

What You Are Protecting

Redis holds session data, job queues, rate-limit counters, and sometimes business-critical state. It is not a document database with rich ACLs by default — network exposure plus no AUTH equals full read/write for anyone who connects.

architectureredis-access.txt
  app servers (private net) --> TCP 6379 --> redis (bind + AUTH)
  internet scanners ------------X (blocked by bind + firewall)
Redis exposure risk
Open port 6379 is a common finding

Install and Start Redis

Use the distribution package so you get a maintained unit file and config path. Enable the service before you tune it.

bashDebian / Ubuntu
sudo apt install -y redis-server
sudo systemctl enable --now redis-server
bashAlmaLinux / Rocky (EPEL/Remi or module)
sudo dnf install -y redis
sudo systemctl enable --now redis
bashsmoke test
redis-cli ping
Package install
redis-server unit

Bind to a Safe Address

Set bind to 127.0.0.1 if only local apps connect, or to a private NIC address if other hosts in the same VLAN need access. Avoid 0.0.0.0 unless you have a firewall that strictly limits source IPs.

ini/etc/redis/redis.conf (or redis6.conf)
bind 127.0.0.1 ::1
# or: bind 10.0.0.12
protected-mode yes
bashapply
sudo systemctl restart redis
ss -lntp | grep 6379
bind-address
Localhost vs private IP

Enable Authentication

Redis 6+ supports ACL users; older setups use requirepass. Pick one model and rotate credentials like any database password.

inirequirepass (simple)
requirepass YOUR_LONG_RANDOM_SECRET
iniACL user (Redis 6+)
user app on >APP_SECRET ~* +@all -@dangerous
bashtest
redis-cli -a YOUR_LONG_RANDOM_SECRET ping
WarningNever commit Redis passwords to git. Load them from env, a secrets manager, or Ansible Vault.
AUTH and ACLs
Password or ACL user

Firewall Port 6379

Even with bind and AUTH, allow only application subnets to reach Redis. Default-deny incoming on the host firewall.

bashUFW example
sudo ufw allow from 10.0.0.0/24 to any port 6379 proto tcp
sudo ufw status numbered
bashfirewalld example
sudo firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=10.0.0.0/24 port port=6379 protocol=tcp accept'
sudo firewall-cmd --reload
Restrict 6379
Source subnet only

Disable or Rename Dangerous Commands

Commands such as FLUSHALL and CONFIG have caused outages when mistyped or abused. Rename them to long random names or disable them for application users via ACL.

inirename example
rename-command FLUSHALL ""
rename-command CONFIG b840fc02d524045429941cc15f59e41cb7be6c52
TipWith ACLs, grant +@read +@write but not +@dangerous for app users.
Dangerous commands
rename-command or ACL deny

Persistence and Backups (Brief)

RDB snapshots and AOF logs trade durability for disk I/O. For cache-only use cases you may disable persistence; for queues and sessions keep AOF with a sane appendfsync and monitor disk.

iniAOF (common for durability)
appendonly yes
appendfsync everysec
bashbackup RDB while running
redis-cli -a SECRET --rdb /backup/redis-$(date +%F).rdb
RDB vs AOF
Match durability to the data

Verify From an App Host

From a machine that should have access, confirm connectivity and AUTH. From the internet (or a wrong subnet), confirm the port is closed.

bashfrom app server
redis-cli -h 10.0.0.12 -a SECRET ping
bashfrom elsewhere (should fail)
nc -zv public-ip 6379
Verification
Allowed vs blocked

Quick Reference

  • Bind to localhost or a private IP; protected-mode yes
  • AUTH via ACL or requirepass; firewall 6379 by source subnet
  • Rename/disable dangerous commands for app users

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.