인증 및 권한 부여
Redis 인스턴스에 대한 접근을 제어하도록 Redis 비밀번호, ACL, 사용자 관리를 구성합니다.
인증 및 권한 부여은(는) CoddyKit의 무료 Redis Caching & Messaging (Pub/Sub, Streams) 강의입니다. 이것은 4개 중 1번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Redis Caching & Messaging (Pub/Sub, Streams) 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Redis Caching & Messaging (Pub/Sub, Streams) 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
Why Secure Your Redis?
Redis is super fast and often holds sensitive data. Without proper security, your data could be exposed or modified by unauthorized users. Just like your house, your database needs locks!
This lesson will teach you how to set up basic authentication with passwords and advanced authorization using Access Control Lists (ACLs) to protect your Redis instances.
Basic Password Protection
The simplest way to secure Redis is using the requirepass directive in your redis.conf file. This sets a global password that clients must provide to execute *any* command.
It's like a single master key for everyone.
requirepass your_strong_password_hereLogging In with AUTH
Once requirepass is set, clients connecting to Redis must authenticate using the AUTH command. If the password is wrong, most commands will fail.
Here's how you'd connect via redis-cli and authenticate:
redis-cli
127.0.0.1:6379> AUTH your_strong_password_here
OK
127.0.0.1:6379> SET mykey "hello"
OK
127.0.0.1:6379> GET mykey
"hello"Global Password's Downside
While easy to set up, requirepass has a major limitation: it's a single password for everyone and everything. All authenticated clients have full access to all commands and data.
- No specific user accounts.
- No fine-grained permissions (e.g., read-only for some).
- Hard to manage in complex applications.
This is where Redis Access Control Lists (ACLs) come in handy!
Granular Access with ACLs
Redis ACLs (Access Control Lists) allow you to define multiple users, each with their own password and a specific set of permissions. This provides much finer control over who can do what.
You can control:
- Which commands a user can execute.
- Which keys a user can access.
It's like having different keys for different rooms in your house.
Creating & Setting Users
You manage ACLs directly through Redis commands, either in redis-cli or programmatically. The ACL SETUSER command is central to defining users and their properties.
Let's create a new user named app_user with a password. The > before the password indicates it's a password.
ACL SETUSER app_user ON >some_secret_password
ACL SETUSER another_user ON >another_secret_pass_123
ACL LIST
user default on #... (default user)
user app_user on #... (our new user)Controlling Commands
With ACLs, you can specify exactly which commands a user can run. Permissions are often given in categories (like @all, @read, @write) or specific command names.
+@read: Grants all read-only commands.-@admin: Revokes all administrative commands.+SET: Grants only the SET command.
Here's an example for our app_user, granting read/write but denying admin commands:
ACL SETUSER app_user +@read +@write -@admin
ACL SETUSER metrics_user ON >metrics_pass +INFO +MONITOR
ACL CAT @admin
# ... lists admin commandsKey-Level Access
Beyond commands, ACLs let you restrict access to specific keys or key patterns. This is incredibly powerful for multi-tenant applications or microservices.
~mykey: Access only to the key 'mykey'.~data:*: Access to any key starting with 'data:'.~*: Access to all keys (use with caution!).
Let's refine app_user to only access keys starting with user_data::
ACL SETUSER app_user ON >some_secret_password +@read +@write ~user_data:*
ACL SETUSER readonly_user ON >read_only_pass +@read ~cache:*Secure ACL Habits
To maximize security with ACLs, follow these best practices:
- Principle of Least Privilege: Grant only the necessary permissions. Avoid
+@allif not strictly needed. - Strong Passwords: Use unique, complex passwords for each user. Rotate them regularly.
- Disable Default User: If not used, disable the
defaultuser or give it a strong password and minimal permissions. - Audit Regularly: Periodically review your ACL configurations using
ACL LIST.
Test Your ACL Knowledge
Consider a Redis instance where you want a user named report_viewer to:
- Only read data.
- Only access keys starting with
reports:. - Have the password
ViewerPass!.
Which of the following commands would correctly configure this user?
Recap: Secure Your Redis!
Great job! You've learned how to secure your Redis instances:
requirepass: Provides simple, global password protection.AUTH: The command used by clients to authenticate.- ACLs: Offer advanced, granular control over users, commands, and specific keys.
ACL SETUSER: The primary command to create/modify users and set their permissions.- Best Practices: Always follow the principle of least privilege, use strong passwords, and audit your configurations.
Protecting your data is crucial, and Redis provides powerful tools to do just that!
자주 묻는 질문
“인증 및 권한 부여” 강의는 무료인가요?
네 — “인증 및 권한 부여” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Redis Caching & Messaging (Pub/Sub, Streams) 강의 전체를 잠금 해제할 수 있습니다. Redis Caching & Messaging (Pub/Sub, Streams) 강의에는 총 4개의 강의가 포함되어 있습니다.
“인증 및 권한 부여”에서 뭘 배우나요?
Redis 인스턴스에 대한 접근을 제어하도록 Redis 비밀번호, ACL, 사용자 관리를 구성합니다. 브라우저에서 직접 실행하는 실습 코드로 Redis Caching & Messaging (Pub/Sub, Streams)을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
Redis Caching & Messaging (Pub/Sub, Streams)을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 Redis Caching & Messaging (Pub/Sub, Streams)은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 1번째 강의입니다.
“인증 및 권한 부여” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 Redis Caching & Messaging (Pub/Sub, Streams) 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 Redis Caching & Messaging (Pub/Sub, Streams) 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- 인증 및 권한 부여
- Redis 네트워크 보안
- 운영 모범 사례
- TLS를 사용한 전송 중 암호화