Redis ACL Generator

Describe what an application needs and get an ACL SETUSER rule. Rules apply strictly left to right, so the order matters more than the contents: the same words in the other order produce a superuser.

The user

No password is written into the rule. The output carries a placeholder for the SHA-256, because an ACL file with a real hash in it is a credential in your repository.

What it may touch

users.acl

updates as you type

    Examples

    Worked setups you can load into the form above. Each one is a decision the generator makes differently, and the reason it makes it.

    A read-only reporting user

    Grants come before revocations, which is what makes it restrictive

    username
    reporting
    key-pattern
    metrics:*
    access
    read

    An admin that is not a superuser

    +@all then -@dangerous, in that order and not the other

    username
    ops
    key-pattern
    *
    access
    admin

    Common mistakes

    These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

    1. Writing -@dangerous before +@all

      Rules apply left to right, so the revocation happens to a user with no permissions and the grant then hands back everything. The result is a superuser that reads like a restricted account.

      Instead:Grant first, revoke second.

    2. Using the > form with a clear-text password

      The password ends up in the config file, in shell history and in any log that captured the command.

      Instead:Use the # form with a SHA-256 hash.

    3. Granting a key pattern but no commands

      The user authenticates and then fails every call, which looks like a network or client fault rather than a permissions one.

      Instead:Grant both, and test with the real application.

    4. Assuming ~pattern covers pub/sub channels

      Channels use &pattern and are tracked separately. From Redis 7 the default is no channels at all.

      Instead:Add &pattern explicitly if the user subscribes.

    Why the order of an ACL rule decides what it means

    ACL rules are not a set of permissions. They are a sequence of instructions applied left to right, and that is the source of nearly every ACL that does not do what its author intended.

    +@all -@dangerous and -@dangerous +@all are opposites

    The first grants everything then takes the dangerous commands back. The second removes dangerous commands from a user who has none, then grants everything, including the ones just removed. Nothing warns about the second, and ACL GETUSER shows the resulting permissions rather than the mistake.

    The password is stored as a hash, and should be supplied as one

    The > form takes clear text, which then lives in the config file, in shell history and in any log that captured the command. The # form takes a SHA-256 hash and never exposes the original. ACL GETUSER shows existing hashes, so an existing user can be moved without knowing the password.

    A user with no key pattern can read nothing

    The default is no access at all rather than full access, which is the right way round. It also means a rule that grants commands but forgets ~pattern produces a user that authenticates successfully and then fails every command, which reads like a broken connection.

    Channels are separate from keys

    Pub/sub permissions use &pattern and are not covered by ~pattern. Before Redis 7 the default was all channels; from Redis 7 it is none. A rule written against the old default silently loses pub/sub access on upgrade.

    What this cannot check

    It cannot see your keyspace, so it cannot tell you whether the pattern matches the keys the application actually uses. Test the rule with the real application before it reaches production, because an ACL failure looks like an application bug.

    More redis tools

    Redis Hash Slot Calculator Which of the 16,384 slots does this key land in? Redis Hash Tag Tester Will these keys survive a multi-key command? Redis RESP Protocol Decoder Read what the server actually sent Redis RESP2 vs RESP3 Reply Decoder What the same reply looks like on each protocol Redis Command to RESP Exactly what your client puts on the socket Redis Glob Pattern Tester Redis globs are not shell globs Redis Connection URL Parser The path is the database number Redis Memory Unit Converter 1g and 1gb are not the same number Redis TTL Converter -1 and -2 are not durations Redis Stream ID Parser The first half is a millisecond timestamp redis.conf Validator Will Redis start with this file? Redis Production Config Linter The settings that cause incidents redis.conf to CONFIG SET Which of these can you change without a restart? Redis ACL Rule Decoder What does this user actually get? Redis ACL Validator Find the rule that does nothing Redis INFO Analyzer The numbers INFO does not print Redis SLOWLOG Analyzer What blocked everyone else Redis CLUSTER NODES Parser Read the topology, and find the gap Redis Cluster Slot Distribution Who owns how much, and what is missing Redis Keyspace Notification Flags Why your events never arrive Redis Memory Calculator The encoding decides, not the data Redis Key Count to Memory The fixed cost per key Redis Encoding Threshold Calculator One field more, several times the memory Redis Bitmap Memory Calculator Sized by the highest bit, not the set ones Redis HyperLogLog Calculator 12 KB whether you count a thousand or a billion Redis Cluster Sizing Only 60% of each node is usable Redis RDB and AOF Size Calculator The fork needs memory, not disk Redis Replication Bandwidth Calculator How long the backlog actually covers Redis Connection Pool Calculator More connections is not more throughput Redis Pipeline Calculator It removes round trips, not work Redis Cache Hit Rate Calculator 99% to 90% is ten times the backend load Redis Eviction Policy Simulator volatile- with no TTLs is noeviction Redis Cost Estimator Your rates, so nothing goes stale Redis Config File Generator A redis.conf with the reasons in it Redis Maxmemory Config Generator The limit, and the headroom it needs Redis Persistence Config Generator How much you can afford to lose Redis Lua Script Generator Atomic, and short enough to stay that way Redis TLS Config Generator Encrypted, and the old port actually closed Redis Sentinel Config Generator Failover that can actually be authorised Redis Cluster Config Generator Three primaries, and the bus port open Redis Docker Compose Generator Local Redis that is not on the internet Redis Client Config Generator Timeouts on both sides, and a sane pool Redis MEMORY STATS Analyzer Which number actually matters Redis Bigkeys Output Analyzer Elements are not bytes Redis CLIENT LIST Analyzer Find the connection hurting you Redis LATENCY Report Analyzer An empty report may mean nothing was recorded Redis Keyspace Prefix Analyzer Which key family is growing Redis SET Command Builder A plain SET clears the TTL Redis ZRANGE Query Builder REV reverses the argument order Redis SCAN Iteration Planner COUNT is a hint, not a page size Redis Key Name Validator Legal is not the same as workable Redis Cluster Compatibility Checker Works now, breaks when you shard

    Elsewhere on the site