Redis ACL Validator

Paste ACL rules to find the ones that do not do what they look like. The reference list of categories is below the findings, since choosing the right category is most of writing a good rule set.

Paste below, or drop a file anywhere on this panel

Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.

The answer appears here

Paste on the left and press Audit. Nothing leaves this tab.

Examples

Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.

nopass

Any password authenticates, including an empty one

user metrics on nopass ~metrics:* +@read

Commands but no keys

Every command and no key access, which fails with an error naming the key

user worker on >pw +@all

Common mistakes

These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

  1. Putting the password in with `>`

    That takes clear text, which then lives in the config file, in shell history, and in any log that captured the command. Redis stores it hashed; everything upstream of Redis saw it.

    Instead:Use `#<sha256hex>`. ACL GETUSER shows existing hashes so you can convert without the original.

  2. Using -@slow to restrict a user

    @slow means every command not in @fast, which includes a great many ordinary ones. It is far more restrictive than it sounds and breaks applications in ways that look unrelated.

    Instead:Name the categories you want: +@read +@write +@keyspace.

  3. Upgrading to 7.0 with pub/sub users

    acl-pubsub-default changed from allchannels to resetchannels, so users that worked on 6.x lose channel access on upgrade.

    Instead:Grant `&pattern` explicitly rather than relying on the default.

Categories are the right tool, and two of them are traps

Granting individual commands does not survive Redis adding new ones. Categories do, which makes them the maintainable choice, with two caveats worth knowing before you rely on them.

Start from +@all and subtract

For an administrative user, +@all -@dangerous is clear and self-maintaining. For an application user the opposite is better: start from nothing and add +@read +@write +@keyspace, so a new Redis version cannot silently widen what the user can do.

@slow is not what it sounds like

It means every command not in @fast, which includes a great many ordinary commands. -@slow is far more restrictive than people expect and breaks applications in ways that look unrelated to the ACL.

@dangerous is a judgement, not a guarantee

It covers FLUSHALL, KEYS, CONFIG, SHUTDOWN, DEBUG and similar. It is a curated list maintained by Redis, so it is a good default and not a security boundary you can reason about from first principles. Check what it contains on your version with ACL CAT dangerous.

Rules are applied atomically

ACL SETUSER either applies every rule or none of them. A single unknown category rejects the whole command and the user is left exactly as it was, which is safe but means a typo produces no change rather than a partial one.

What this cannot see

It cannot evaluate a selector's contents, which is a Redis 7.0 feature for granting independent permission sets. It also cannot tell you whether the permissions are appropriate: only that they are probably not what the rules appear to say. ACL LOG on a running server shows what a user was actually denied, which is the best evidence for widening a rule set.

More redis tools

Redis Hash Slot Calculator Which of the 16,384 slots does this key land in? Redis Hash Tag Tester Will these keys survive a multi-key command? Redis RESP Protocol Decoder Read what the server actually sent Redis RESP2 vs RESP3 Reply Decoder What the same reply looks like on each protocol Redis Command to RESP Exactly what your client puts on the socket Redis Glob Pattern Tester Redis globs are not shell globs Redis Connection URL Parser The path is the database number Redis Memory Unit Converter 1g and 1gb are not the same number Redis TTL Converter -1 and -2 are not durations Redis Stream ID Parser The first half is a millisecond timestamp redis.conf Validator Will Redis start with this file? Redis Production Config Linter The settings that cause incidents redis.conf to CONFIG SET Which of these can you change without a restart? Redis ACL Rule Decoder What does this user actually get? Redis INFO Analyzer The numbers INFO does not print Redis SLOWLOG Analyzer What blocked everyone else Redis CLUSTER NODES Parser Read the topology, and find the gap Redis Cluster Slot Distribution Who owns how much, and what is missing Redis Keyspace Notification Flags Why your events never arrive Redis Memory Calculator The encoding decides, not the data Redis Key Count to Memory The fixed cost per key Redis Encoding Threshold Calculator One field more, several times the memory Redis Bitmap Memory Calculator Sized by the highest bit, not the set ones Redis HyperLogLog Calculator 12 KB whether you count a thousand or a billion Redis Cluster Sizing Only 60% of each node is usable Redis RDB and AOF Size Calculator The fork needs memory, not disk Redis Replication Bandwidth Calculator How long the backlog actually covers Redis Connection Pool Calculator More connections is not more throughput Redis Pipeline Calculator It removes round trips, not work Redis Cache Hit Rate Calculator 99% to 90% is ten times the backend load Redis Eviction Policy Simulator volatile- with no TTLs is noeviction Redis Cost Estimator Your rates, so nothing goes stale Redis Config File Generator A redis.conf with the reasons in it Redis ACL Generator A user that can do exactly one job Redis Maxmemory Config Generator The limit, and the headroom it needs Redis Persistence Config Generator How much you can afford to lose Redis Lua Script Generator Atomic, and short enough to stay that way Redis TLS Config Generator Encrypted, and the old port actually closed Redis Sentinel Config Generator Failover that can actually be authorised Redis Cluster Config Generator Three primaries, and the bus port open Redis Docker Compose Generator Local Redis that is not on the internet Redis Client Config Generator Timeouts on both sides, and a sane pool Redis MEMORY STATS Analyzer Which number actually matters Redis Bigkeys Output Analyzer Elements are not bytes Redis CLIENT LIST Analyzer Find the connection hurting you Redis LATENCY Report Analyzer An empty report may mean nothing was recorded Redis Keyspace Prefix Analyzer Which key family is growing Redis SET Command Builder A plain SET clears the TTL Redis ZRANGE Query Builder REV reverses the argument order Redis SCAN Iteration Planner COUNT is a hint, not a page size Redis Key Name Validator Legal is not the same as workable Redis Cluster Compatibility Checker Works now, breaks when you shard

Elsewhere on the site