All skills
redis avatar

/redis-security

@17faa8d official
by redisredis/agent-skills163 stars
30

Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.

Use this Skill: https://skilld.dev/gh/redis/agent-skills/redis-security

This session only. Nothing lands on disk.

referencesnetwork.md

≈226 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Secure Network Access

Restrict network access to Redis to only trusted sources.

Correct: Bind to specific interfaces.

# redis.conf
bind 127.0.0.1 192.168.1.100
protected-mode yes

Correct: Use firewall rules.

# Allow only application servers
iptables -A INPUT -p tcp --dport 6379 -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 6379 -j DROP

Incorrect: Exposing Redis to the internet.

# Bad: Binds to all interfaces
bind 0.0.0.0
protected-mode no

Security checklist:

  • Use TLS for connections
  • Bind to specific interfaces, not 0.0.0.0
  • Use firewall rules to restrict access
  • Disable dangerous commands in production
# Disable dangerous commands
rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG ""

Reference: Redis Security

Source: SKILL.md on GitHub

1 warning1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides standard security hardening guidance for Redis deployments, including instructions for authentication, TLS configuration, ACL management, and network security. No malicious patterns were detected.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 17faa8d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
metadata
{
  "author": "Redis, Inc.",
  "version": "0.1.0"
}
  • redis
  • authentication
  • acl
  • tls
  • network-security
  • firewall
  • access-control
  • production
  • hardening

README badge

README badge for redis/agent-skills/redis-security

Configures Redis authentication via requirepass and ACL users, enables TLS encryption, restricts network exposure with bind and protected-mode, and disables dangerous commands. Apply this skill when deploying Redis to production, setting up per-application credentials, or auditing an instance against security hardening requirements.

Generated from the current SKILL.md.

Does this skill cover both authentication and network isolation?
Yes. The skill covers authentication (requirepass and ACL users), TLS encryption, network binding, protected-mode, firewall rules, and command disabling. All three layers are recommended together to avoid exploitable gaps.
Can I use this skill to set up ACL users for different applications?
Yes. The skill includes examples of creating dedicated ACL users with least-privilege access — e.g., read-only cache users, writers without dangerous commands, and admin users. Each user can be restricted to specific command categories and key patterns.
Does this cover TLS/SSL configuration?
Yes. The skill includes redis.conf settings for tls-port, tls-cert-file, and tls-key-file, plus a Python client example using SSL connections.
What commands can be disabled or renamed?
The skill covers disabling or renaming dangerous commands like FLUSHALL, DEBUG, KEYS, and CONFIG using the rename-command directive in redis.conf.
Is this skill for development or production only?
Primarily production. The skill notes that a single shared password with the default user is acceptable for development, but recommends ACL users and full hardening for production deployments.

Generated from the current SKILL.md. These answers refresh after source changes.