READ-ONLY PACKAGE PREVIEW

redis-security/references/acls.md

Version a84871d065f3.bb1 · MIT. This preview displays packaged text and does not execute code. Treat the contents as untrusted instructions.

← Return to resource and package checksum

Use ACLs for Fine-Grained Access Control

Create users with only the permissions they need (principle of least privilege).

Correct: Create specific users with limited permissions.

# Read-only user for cache access
ACL SETUSER app_readonly on >password ~cache:* +get +mget +scan

# Writer that can't run dangerous commands
ACL SETUSER app_writer on >password ~* +@all -@dangerous

# Admin user (use sparingly)
ACL SETUSER admin on >strong-password ~* +@all

Incorrect: Using the default user for everything.

# Bad: Single password for all access
requirepass shared-password

ACL categories: - @read - Read commands - @write - Write commands - @dangerous - Commands like FLUSHALL, DEBUG - @admin - Administrative commands

Reference: Redis ACL