Skip to content

Redis

Redis is a high-performance in-memory key-value database widely used for caching, session management, message queues, and more. This article covers Redis installation, core configuration, service management, command-line tool usage, persistence strategies, and security hardening.

Live version data by pkgseek.com

The EL 9 AppStream repository includes Redis:

Install Redis (EL 9)
sudo dnf install redis -y

Using the Remi Repository (for Latest Version)

Section titled “Using the Remi Repository (for Latest Version)”

To install the latest stable version of Redis:

Install Remi repository
sudo dnf install epel-release -y
sudo dnf install https://rpms.remirepo.net/enterprise/remi-release-$(rpm -E %{rhel}).rpm -y
Enable Redis module from Remi repository (EL 9)
sudo dnf module reset redis -y
sudo dnf module enable redis:remi-7.2 -y
sudo dnf install redis -y
Start and enable Redis
sudo systemctl start redis
sudo systemctl enable redis
sudo systemctl status redis

Verify that Redis is running properly:

Test Redis connection
redis-cli ping

If it returns PONG, Redis is running correctly.

The main Redis configuration file is located at /etc/redis/redis.conf (on some systems, /etc/redis.conf).

Confirm configuration file location
redis-cli CONFIG GET dir
find /etc -name "redis.conf" 2>/dev/null

Back up the configuration before making changes:

Back up configuration file
sudo cp /etc/redis/redis.conf /etc/redis/redis.conf.bak

By default, Redis only listens on 127.0.0.1, which is the most secure setting.

View current bind address
grep "^bind" /etc/redis/redis.conf

If you need Redis to accept connections from a specific network:

Modify bind address
sudo sed -i 's/^bind 127.0.0.1.*/bind 127.0.0.1 192.168.1.10/' /etc/redis/redis.conf

Note: Never bind Redis directly to 0.0.0.0 and expose it to the public internet. Redis is not designed to be directly internet-facing.

A password must be set in production environments:

Set Redis password
sudo sed -i 's/^# requirepass foobared/requirepass YourStrongRedisPassword!/' /etc/redis/redis.conf

Or add it directly to the configuration file:

Append password configuration
echo 'requirepass YourStrongRedisPassword!' | sudo tee -a /etc/redis/redis.conf

Connecting with a password:

Connect to Redis with a password
redis-cli -a YourStrongRedisPassword!
# Or connect first then authenticate
redis-cli
# Once connected, run: AUTH YourStrongRedisPassword!
Change Redis port
sudo sed -i 's/^port 6379/port 6380/' /etc/redis/redis.conf

Limit the maximum memory Redis can use and the eviction policy when memory is full:

Configure maximum memory and eviction policy
sudo tee -a /etc/redis/redis.conf << 'EOF'
# Maximum memory limit
maxmemory 256mb
# Memory eviction policy
# allkeys-lru: Evict the least recently used key from all keys
# volatile-lru: Evict only from keys with an expiration set
# noeviction: Do not evict; return errors on writes when memory is full
maxmemory-policy allkeys-lru
EOF
Restart Redis to apply changes
sudo systemctl restart redis
Redis service management commands
# Start Redis
sudo systemctl start redis
# Stop Redis
sudo systemctl stop redis
# Restart Redis
sudo systemctl restart redis
# Check status
sudo systemctl status redis
# Enable at boot
sudo systemctl enable redis
# Disable at boot
sudo systemctl disable redis
# View Redis logs
sudo journalctl -u redis -f
View full Redis information
redis-cli INFO
# View specific sections
redis-cli INFO server
redis-cli INFO memory
redis-cli INFO clients
redis-cli INFO stats

redis-cli is the Redis command-line client tool.

String operations
redis-cli
# Set key-value pairs
SET name "CentOS Fan"
SET counter 100
# Get values
GET name
GET counter
# Set with expiration (seconds)
SET session:abc123 "user_data" EX 3600
# Check remaining TTL
TTL session:abc123
# Increment/Decrement
INCR counter
DECR counter
INCRBY counter 10
Hash operations
# Set hash fields
HSET user:1 name "Zhang San" email "[email protected]" age 30
# Get a single field
HGET user:1 name
# Get all fields and values
HGETALL user:1
# Delete a field
HDEL user:1 age
List operations
# Push from the left
LPUSH queue "task1" "task2" "task3"
# Pop from the right
RPOP queue
# View list contents
LRANGE queue 0 -1
# List length
LLEN queue
Set operations
# Add members
SADD tags "linux" "centos" "redis"
# View all members
SMEMBERS tags
# Check if a member exists
SISMEMBER tags "linux"
# Set size
SCARD tags
Key management operations
# View all keys (use with caution in production)
KEYS *
# Use SCAN for safe iteration (recommended)
SCAN 0 MATCH "user:*" COUNT 10
# Check if a key exists
EXISTS name
# Delete a key
DEL name
# Set expiration time
EXPIRE counter 300
# Check data type of a key
TYPE counter
# View total number of keys in the database
DBSIZE
# Flush current database (dangerous)
# FLUSHDB
# Flush all databases (extremely dangerous)
# FLUSHALL

Redis provides two persistence methods that can be used individually or together.

RDB writes in-memory data snapshots to disk at specified intervals. The files are compact and fast to restore, but data after the last snapshot may be lost.

View current RDB configuration
grep -n "^save\|^dbfilename\|^dir" /etc/redis/redis.conf

Default RDB rules in the configuration file:

RDB snapshot trigger rules
# At least 1 key modified within 900 seconds
save 900 1
# At least 10 keys modified within 300 seconds
save 300 10
# At least 10000 keys modified within 60 seconds
save 60 10000
# RDB file name
dbfilename dump.rdb
# RDB file storage directory
dir /var/lib/redis

Manually trigger an RDB snapshot:

Manually generate RDB snapshot
# Blocking method (not recommended for production)
redis-cli SAVE
# Background async method (recommended)
redis-cli BGSAVE
# Check last snapshot time
redis-cli LASTSAVE

AOF (Append Only File) records every write command, providing higher data safety but larger file sizes.

Enable AOF
sudo sed -i 's/^appendonly no/appendonly yes/' /etc/redis/redis.conf

AOF sync policy configuration:

AOF sync policy options
# always - Sync on every write command, safest but slowest
# everysec - Sync once per second (recommended, balances performance and safety)
# no - Let the OS decide when to sync
appendfsync everysec

AOF rewrite (compaction) configuration:

AOF rewrite configuration
# Trigger rewrite when AOF file grows 100% beyond the size after last rewrite
auto-aof-rewrite-percentage 100
# Minimum 64MB AOF file size to trigger rewrite
auto-aof-rewrite-min-size 64mb

Manually trigger AOF rewrite:

Manually trigger AOF rewrite
redis-cli BGREWRITEAOF
Enable both RDB and AOF
sudo tee -a /etc/redis/redis.conf << 'EOF'
# Enable AOF
appendonly yes
appendfsync everysec
# Keep default RDB configuration
# Redis prioritizes AOF for data recovery on restart (as AOF data is more complete)
EOF
Restart Redis to apply persistence configuration
sudo systemctl restart redis
Create a Redis data backup script
sudo tee /usr/local/bin/redis-backup.sh << 'SCRIPT'
#!/bin/bash
BACKUP_DIR="/backup/redis"
DATE=$(date +%Y%m%d_%H%M%S)
REDIS_DATA="/var/lib/redis"
RETENTION_DAYS=7
mkdir -p "$BACKUP_DIR"
# Trigger RDB snapshot
redis-cli BGSAVE
sleep 5
# Copy the RDB file
cp "${REDIS_DATA}/dump.rdb" "${BACKUP_DIR}/dump_${DATE}.rdb"
# If AOF is enabled, also back up the AOF file
if [ -f "${REDIS_DATA}/appendonly.aof" ]; then
cp "${REDIS_DATA}/appendonly.aof" "${BACKUP_DIR}/appendonly_${DATE}.aof"
fi
# Clean up old backups
find "$BACKUP_DIR" -name "*.rdb" -mtime +${RETENTION_DAYS} -delete
find "$BACKUP_DIR" -name "*.aof" -mtime +${RETENTION_DAYS} -delete
echo "Redis backup completed: ${BACKUP_DIR}"
SCRIPT
sudo chmod +x /usr/local/bin/redis-backup.sh

This was covered in the “Set a Password” section above. The importance is worth emphasizing again: Redis executes commands extremely fast, making weak passwords very easy to brute-force.

Verify password is set
redis-cli CONFIG GET requirepass

Some commands pose significant risks in production and can be disabled by renaming them to an empty string:

Disable dangerous commands
sudo tee -a /etc/redis/redis.conf << 'EOF'
# Disable dangerous commands
rename-command FLUSHDB ""
rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG "REDIS_CONFIG_b4f2e8a1"
EOF

Note: After disabling the CONFIG command, you must use the renamed version to execute it. Use this configuration with caution in Sentinel and Cluster modes.

Limit maximum client connections
sudo sed -i 's/^# maxclients 10000/maxclients 5000/' /etc/redis/redis.conf

Redis has protected-mode enabled by default, which rejects external connections when no password is set and the bind address is not 127.0.0.1. Always keep this option enabled:

Confirm protected-mode is enabled
grep "^protected-mode" /etc/redis/redis.conf

If Redis needs to accept remote connections, access sources must be restricted through the firewall:

Restrict Redis port access by source
# Allow only a specific IP
sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.100" port port="6379" protocol="tcp" accept'
sudo firewall-cmd --reload

Do not open the Redis port to all sources:

Bad example (do not do this)
# Not recommended! Do not open the Redis port to everyone
# sudo firewall-cmd --permanent --add-port=6379/tcp

By default, Redis already runs as the redis user. You can confirm this:

Confirm Redis running user
ps aux | grep redis-server

Use the following commands to quickly check Redis security status:

Redis security status check
echo "=== Bind Address ==="
redis-cli CONFIG GET bind
echo "=== Password Setting ==="
redis-cli CONFIG GET requirepass
echo "=== Protected Mode ==="
redis-cli CONFIG GET protected-mode
echo "=== Listening Port ==="
redis-cli CONFIG GET port
echo "=== Maximum Memory ==="
redis-cli CONFIG GET maxmemory
echo "=== Connected Clients ==="
redis-cli INFO clients | grep connected_clients
Redis daily operations commands
# Start / Stop / Restart
sudo systemctl start redis
sudo systemctl stop redis
sudo systemctl restart redis
# Connect to Redis
redis-cli
redis-cli -a password
redis-cli -h host -p port -a password
# View Redis version
redis-server --version
# Monitor all commands in real time (for debugging, use with caution in production)
redis-cli MONITOR
# View slow query log
redis-cli SLOWLOG GET 10
# View memory usage
redis-cli INFO memory
# View memory usage of a specific key
redis-cli MEMORY USAGE keyname
# Modify configuration at runtime (no restart needed)
redis-cli CONFIG SET maxmemory 512mb
redis-cli CONFIG SET maxmemory-policy allkeys-lru
# Write runtime configuration to the configuration file
redis-cli CONFIG REWRITE