{ }
Resource profile / Redis Data Modeling and Cache Keys
About this skill

Workflow & requirements

BB Skills evidence and version boundaries (2026-10-04)

This package includes the original official Redis skill and all of its relative references. Original instruction bytes are retained under upstream-original; BB Skills scope notes are identified here. No upstream script is executed automatically on download or installation.

Our disposable Redis 7.4.11 / Python 3.13.16 experiment recorded 44 named observations across the core and security resources together. The source, runner, exact environment and command results are under examples. This is an independent native command fixture, not an AI client's execution of this complete skill; runtime_tested remains false. There are no live-site, TLS, Redis Cluster, persistence, replication, JSON, Vector Set, Java or redis-py checks. Field-level expiry and newer data types require their own server-version and module review.

Use an authorized target and review commands before acting. Core writes can replace values and expiry policies; ACL changes can affect other clients. A plain SET removed existing key expiry in our fixture, while KEEPTTL and hash-field changes retained a positive TTL. WATCH detected one controlled conflicting write. Key naming conventions alone do not enforce tenant isolation.

The source's read-only ACL example includes SCAN: in our fixture it revealed a synthetic key name outside the allowed cache prefix even though GET and mixed-prefix MGET were denied. ACL SETUSER updates are additive; explicitly reset the intended key and command grants when tightening an existing role and verify the response. User off prevented new authentication but an existing connection continued reading until an authorized CLIENT KILL USER. These are observed command semantics, not a claim of a Redis vulnerability or complete production hardening.

The upstream production TLS and network references remain guidance to review separately. The runner uses an internal Docker network with no published ports or production mounts and generated in-memory passwords; its container bind is not a recommended production deployment. No paid service, model call or external account was used. MIT covers included skill sources and identified BB Skills additions; runtime server licenses are separate and no server binary is bundled.

Redis Core

Foundational guidance for modeling data in Redis. Covers data-type selection and key-name conventions — the two decisions that most directly drive memory, performance, and maintainability.

When to apply

  • Caching objects, sessions, or per-user state.
  • Counters, leaderboards, recent-items lists, unique-membership sets.
  • Reviewing or refactoring Redis key names.
  • Deciding between a Redis Hash and a JSON document for an entity.

1. Choose the right data structure

Pick the type that matches the access pattern, not just the shape of the data.

Use case Recommended type Why
Simple values, counters String Atomic INCR/DECR, SET/GET
Object with independently updated fields Hash Per-field reads/writes, no whole-object rewrite
Queue, recent-N items List O(1) push/pop at ends
Unique items, membership checks Set O(1) SADD/SISMEMBER/SCARD
Rankings, score-based ranges Sorted Set Score-ordered; ZADD/ZRANGE/ZRANK
Nested / hierarchical data JSON Path-level updates, nested arrays, RQE indexing
Event log, fan-out messaging Stream Persistent, consumer groups
Vector similarity Vector Set Native vector storage with HNSW

Common anti-pattern: stuffing a flat object into a serialized string. Updating one field means fetch + parse + mutate + rewrite. Use a Hash instead.

See references/choose-data-structure.md for full rationale and Python/Java examples.

2. Use consistent key names

Use colon-separated segments with a stable hierarchy:

{entity}:{id}:{attribute}
user:1001:profile
user:1001:settings
order:2024:items
session:abc123
article:987:likes
game:space-invaders:leaderboard

Rules of thumb:

  • Lowercase, colon-separated. No spaces, no mixed casing (User_1001_Profile is bad).
  • Keep keys short but readable — keys live in memory and appear in every command.
  • Don't use full URLs or long strings as keys. Extract a short identifier, or use a hash digest of the URL.
  • Prefix for multi-tenancy (tenant:42:user:7:cart) so scans and ACLs can target a tenant cleanly.
  • Be consistent. Pick one convention per service and apply it across all keys.

See references/key-naming.md for cleanup examples and edge cases.

References

PACKAGE TRANSPARENCY

Inspect before installing

Source: Redis, Inc. · MIT · SHA-256 shown alongside the download.

13 files19720 ZIP bytes2 script/code files

License file included. A license and checksum are not a security certification. Review package instructions and scripts before running them.

View files and uncompressed sizes
Machine-readable installation guide →
CATALOG REVIEW NOTES

Know what you need before installing

Source and packaging checks recorded on 2026-10-04. These notes are not safety certification or measured task performance.

Requirements

Review target Redis version, required data types/modules, TLS and application credentials. Source package requires no account. Included fixture needs Python 3, Docker and separately reviewed runtime images; it uses RESP2 with synthetic data. See examples/README.md for reproducing outside the original lab image.

Costs, access & practical limits

Free MIT source package and free synthetic command experiment; no paid API or cloud account used. Not a full AI skill, TLS, production, load/performance, Redis Cluster or persistence evaluation. Scope notes explain ACL names, additive updates and existing connections. Runtime binaries/licenses are separate.

View the recorded checks
  • Included upstream originals match pinned Git blob and SHA-256
  • Every relative reference resolves within the package
  • MIT notices and exact modification attribution retained
  • Synthetic native command observations bound to exact fixture sources and image identities
  • No AI-client execution, TLS, production hardening or performance certification claimed

Upstream commit: a84871d065f398fed55e1633f66b66f731eb4e2b

Runtime status: not tested by this catalog. Configure your client and test the skill in your own environment.

LICENSE & ATTRIBUTION

Different files carry different terms

This bundle preserves more than one upstream license. The labels do not mean that every file is offered under either license at your choice. Read the original notices before adapting or redistributing it.

MIT ↗

Redis official skill instructions, complete references and source context

Attribution: Copyright (c) 2026 Redis, Inc.

Changes: Primary instruction preface added; unchanged original retained and references unmodified

Included notice: redis-core/LICENSE.upstream.txt

Declared source ↗

MIT ↗

BB Skills fixture, scope preface and evidence

Attribution: Copyright (c) 2026 BB Skills

Changes: Independent synthetic command fixture and explicit bounded observations added

Included notice: redis-core/LICENSE.bb-skills.txt

Declared source ↗

For the CC BY-SA material, retain attribution and license links, indicate changes, and apply the required ShareAlike terms to adaptations. These notices do not imply endorsement by the original creators.

SCENARIOS

Inputs, criteria and recorded outcomes

Records are supplied by the site administrator and bound to a specific package. They are not third-party safety certification. This page does not execute skills.

Native Redis types, expiry and controlled WATCH conflict

Reported passed · va84871d065f3.bb1

View input and acceptance criteria

Input

Synthetic String/Hash/Set/Sorted Set, key-level expiry changes and one two-connection transaction conflict. Shared fixture has 44 observations; this record covers the data/expiry/transaction subset only.

Acceptance criteria

Recorded native responses agree with the named synthetic command contracts. Explicit denied operations, aborted transaction and connection termination are expected results. These are documented command boundaries rather than a security certification or full skill evaluation.

Recorded outcome

Synthetic String/Hash/Set/Sorted Set, key-level expiry changes and one two-connection transaction conflict. Shared fixture has 44 observations; this record covers the data/expiry/transaction subset only.

{
  "format": 1,
  "executed_at": "2026-10-04T11:30:47.481468+00:00",
  "redis_version": "7.4.11",
  "python": "3.13.16",
  "observations": 44,
  "cases": [
    {
      "name": "initial-default-authentication",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "initial-isolated-default-ping",
      "observed": "PONG",
      "expected": "PONG",
      "status": "passed"
    },
    {
      "name": "string-counter-increments",
      "observed": 1,
      "expected": 1,
      "status": "passed"
    },
    {
      "name": "string-counter-second-increment",
      "observed": 2,
      "expected": 2,
      "status": "passed"
    },
    {
      "name": "hash-add-two-fields",
      "observed": 2,
      "expected": 2,
      "status": "passed"
    },
    {
      "name": "hash-update-existing-field",
      "observed": 0,
      "expected": 0,
      "status": "passed"
    },
    {
      "name": "hash-other-field-preserved",
      "observed": "Sample",
      "expected": "Sample",
      "status": "passed"
    },
    {
      "name": "set-deduplicates",
      "observed": 2,
      "expected": 2,
      "status": "passed"
    },
    {
      "name": "set-membership",
      "observed": 1,
      "expected": 1,
      "status": "passed"
    },
    {
      "name": "sorted-set-score-order",
      "observed": 2,
      "expected": 2,
      "status": "passed"
    },
    {
      "name": "sorted-set-reversed-ranking",
      "observed": [
        "b",
        "a"
      ],
      "expected": [
        "b",
        "a"
      ],
      "status": "passed"
    },
    {
      "name": "ttl-created-with-set-ex",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "ttl-in-positive-window",
      "observed": true,
      "expected": true,
      "status": "passed"
    },
    {
      "name": "plain-set-replaces-value",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "plain-set-removes-existing-ttl",
      "observed": -1,
      "expected": -1,
      "status": "passed"
    },
    {
      "name": "set-keepttl-update",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "keepttl-retains-positive-window",
      "observed": true,
      "expected": true,
      "status": "passed"
    },
    {
      "name": "hash-field-write-retains-key-ttl",
      "observed": true,
      "expected": true,
      "status": "passed"
    },
    {
      "name": "missing-key-ttl",
      "observed": -2,
      "expected": -2,
      "status": "passed"
    },
    {
      "name": "watch-registers",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "watch-exec-aborts-after-intervening-write",
      "observed": null,
      "expected": null,
      "status": "passed"
    },
    {
      "name": "aborted-transaction-did-not-write",
      "observed": "1",
      "expected": "1",
      "status": "passed"
    },
    {
      "name": "multi-exec-success",
      "observed": [
        2,
        "2"
      ],
      "expected": [
        2,
        "2"
      ],
      "status": "passed"
    },
    {
      "name": "dedicated-admin-authentication",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "anonymous-command-after-default-disabled",
      "observed": {
        "error": "NOAUTH"
      },
      "expected": {
        "error": "NOAUTH"
      },
      "status": "passed"
    },
    {
      "name": "reader-authentication",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "reader-get-allowed-prefix",
      "observed": "synthetic-cache",
      "expected": "synthetic-cache",
      "status": "passed"
    },
    {
      "name": "reader-get-denied-other-prefix",
      "observed": {
        "error": "NOPERM"
      },
      "expected": {
        "error": "NOPERM"
      },
      "status": "passed"
    },
    {
      "name": "reader-write-denied",
      "observed": {
        "error": "NOPERM"
      },
      "expected": {
        "error": "NOPERM"
      },
      "status": "passed"
    },
    {
      "name": "reader-flushall-denied",
      "observed": {
        "error": "NOPERM"
      },
      "expected": {
        "error": "NOPERM"
      },
      "status": "passed"
    },
    {
      "name": "reader-mixed-prefix-mget-denied",
      "observed": {
        "error": "NOPERM"
      },
      "expected": {
        "error": "NOPERM"
      },
      "status": "passed"
    },
    {
      "name": "denied-write-left-value-unchanged",
      "observed": "synthetic-cache",
      "expected": "synthetic-cache",
      "status": "passed"
    },
    {
      "name": "scan-can-reveal-key-name-outside-acl-prefix",
      "observed": true,
      "expected": true,
      "status": "passed"
    },
    {
      "name": "additive-acl-update-retains-private-prefix",
      "observed": "synthetic-private",
      "expected": "synthetic-private",
      "status": "passed"
    },
    {
      "name": "additive-acl-update-retains-write-command",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "acl-tighten-key-and-command-rules",
      "observed": "OK",
      "expected": "OK",
      "status": "passed"
    },
    {
      "name": "resetkeys-removes-private-prefix",
      "observed": {
        "error": "NOPERM"
      },
      "expected": {
        "error": "NOPERM"
      },
      "status": "passed"
    },
    {
      "name": "command-reset-removes-write",
      "observed": {
        "error": "NOPERM"
      },
      "expected": {
        "error": "NOPERM"
      },
      "status": "passed"
    },
    {
      "name": "command-reset-removes-scan",
      "observed": {
        "error": "NOPERM"
      },
      "expected": {
        "error": "NOPERM"
      },
      "status": "passed"
    },
    {
      "name": "off-prevents-new-user-authentication",
      "observed": {
        "error": "WRONGPASS"
      },
      "expected": {
        "error": "WRONGPASS"
      },
      "status": "passed"
    },
    {
      "name": "off-existing-authenticated-connection-still-reads",
      "observed": "changed",
      "expected": "changed",
      "status": "passed"
    },
    {
      "name": "kill-user-closes-one-existing-connection",
      "observed": 1,
      "expected": 1,
      "status": "passed"
    },
    {
      "name": "killed-user-connection-closed",
      "observed": true,
      "expected": true,
      "status": "passed"
    },
    {
      "name": "private-data-remains-after-denied-destructive-command",
      "observed": "synthetic-private",
      "expected": "synthetic-private",
      "status": "passed"
    }
  ],
  "runtime_tested": false,
  "native_command_fixture_tested": true,
  "tls_tested": false,
  "production_tested": false,
  "ai_client_executed": false,
  "synthetic_credentials_retained": false,
  "source_hashes": {
    "probe-redis.py": "661f1ba5cc70b97bc01b7a0c93112feb25b404ac57356d7423a48f9438dcfe08",
    "run-redis-fixture.py": "0da5619bea2435069f92d6a0df36211e79e113de68adf487571462be1c1b814e"
  },
  "images": {
    "redis:7-alpine": {
      "id": "sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499",
      "digests": [
        "redis@sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499"
      ]
    },
    "bb-skills:20261004-v41": {
      "id": "sha256:58a204606eb5975702ea621384c6f92a5697aa4cd9252bc3fa22db800f6cab78",
      "digests": [
        "bb-skills@sha256:58a204606eb5975702ea621384c6f92a5697aa4cd9252bc3fa22db800f6cab78"
      ]
    }
  },
  "fixture": {
    "internal_network": true,
    "published_ports": false,
    "production_mounts": false,
    "persistent_data": false,
    "synthetic_only": true,
    "network_bind_note": "Container-only 0.0.0.0 within a dedicated internal Docker network; not a production network configuration."
  }
}

Environment

Disposable internal Docker network, no published ports or production mounts, tmpfs data. Redis 7.4.11; Python 3.13.16. Synthetic credentials and values only. No AI client, TLS, production, persistence, replication or Redis Cluster.

Package SHA-256: 0f0e6d360117403858a429ed6760565e870d89202f6f08e6162ed07c0574307b

Outcome recorded: 2026-10-04 11:30 UTC

Community reviews

★ New

Be the first to share your experience.

Sign in to leave a review →

Guides using this resource

All guides →
Practical guide

Test Redis cache expiry and ACL boundaries before shipping

Test Redis cache expiry and ACL boundaries before shipping. Our disposable Redis fixture checked data types, TTL updates, conflicting writes, key-name visibility and connection…

By BB Skills · Read guide →

More to explore

View all ↗