Redis Production Config Linter

Paste a redis.conf and get the problems that cause real incidents, in severity order. Each finding says what breaks, not merely that a setting differs from a default.

Paste below, or drop a file anywhere on this panel

Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.

The answer appears here

Paste on the left and press Lint. Nothing leaves this tab.

Examples

Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.

Exposed with no password

The configuration behind essentially every public Redis compromise

bind 0.0.0.0
protected-mode no
port 6379

A cache that refuses writes

noeviction is the default, so this arrives by omission rather than by choice

requirepass hunter2
maxmemory 2gb

Persistence off

A restart loses everything, which is fine for a cache and not stated anywhere

requirepass hunter2
maxmemory 2gb
maxmemory-policy allkeys-lru
appendonly no
save ""

Common mistakes

These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

  1. Adding a bind line without setting a password

    protected-mode only refuses outside connections while there is no password and no bind. Adding a bind removes that guard, and an unauthenticated Redis on a network is remote code execution, not just a data leak.

    Instead:Set requirepass or ACL users before changing bind or protected-mode.

  2. Running a cache on the default eviction policy

    noeviction is the default and refuses writes at the limit while reads keep working. For a cache that is an outage arriving by omission.

    Instead:allkeys-lru or allkeys-lfu for a cache. Keep noeviction only where the data must not be dropped.

  3. Choosing a volatile- policy without TTLs on the keys

    Those policies only evict keys that have a TTL. With no TTLs there is nothing eligible, so they behave exactly like noeviction and the failure looks like a broken policy.

    Instead:Confirm keys actually get a TTL, or use the allkeys- variant.

The four failures worth checking before anything else

Redis ships with defaults chosen for a developer laptop, not for a server. Most production problems come from a small number of them being left alone.

An exposed instance with no password

protected-mode refuses outside connections while there is no password and no bind, which contains a default install. Adding a bind line or turning protected-mode off removes that guard, and an unauthenticated Redis reachable from a network is remote code execution rather than merely a data leak: CONFIG SET dir plus SAVE writes a file anywhere the process can write.

No maxmemory

With no limit Redis grows until the kernel's OOM killer terminates the process, losing everything not persisted. A limit turns that into either eviction or a clear OOM error to the client. Set it to roughly 60 to 70 percent of the host, because replication buffers, client output buffers and the fork that BGSAVE performs all live outside the limit.

noeviction on something used as a cache

noeviction is the default, and at the limit it refuses writes while reads keep working. For a datastore that is correct. For a cache it is an outage, and because it is the default it arrives by omission rather than by decision. The volatile- policies have a sharper version of the same trap: if no key has a TTL there is nothing eligible to evict, so they behave exactly like noeviction.

Persistence off by accident

appendonly defaults to no, and save "" disables snapshots. Together they mean a restart loses everything. That is a reasonable choice for a cache and a serious one for anything else, and the file should say which it is.

What this cannot see

It reads one file. It cannot see included files, command line arguments, runtime CONFIG SET changes, your network topology, or whether the port is actually reachable from anywhere dangerous. A clean result here means these particular rules found nothing, not that the deployment is safe.

More redis tools

Redis Hash Slot Calculator Which of the 16,384 slots does this key land in? Redis Hash Tag Tester Will these keys survive a multi-key command? Redis RESP Protocol Decoder Read what the server actually sent Redis RESP2 vs RESP3 Reply Decoder What the same reply looks like on each protocol Redis Command to RESP Exactly what your client puts on the socket Redis Glob Pattern Tester Redis globs are not shell globs Redis Connection URL Parser The path is the database number Redis Memory Unit Converter 1g and 1gb are not the same number Redis TTL Converter -1 and -2 are not durations Redis Stream ID Parser The first half is a millisecond timestamp redis.conf Validator Will Redis start with this file? redis.conf to CONFIG SET Which of these can you change without a restart? Redis ACL Rule Decoder What does this user actually get? Redis ACL Validator Find the rule that does nothing Redis INFO Analyzer The numbers INFO does not print Redis SLOWLOG Analyzer What blocked everyone else Redis CLUSTER NODES Parser Read the topology, and find the gap Redis Cluster Slot Distribution Who owns how much, and what is missing Redis Keyspace Notification Flags Why your events never arrive Redis Memory Calculator The encoding decides, not the data Redis Key Count to Memory The fixed cost per key Redis Encoding Threshold Calculator One field more, several times the memory Redis Bitmap Memory Calculator Sized by the highest bit, not the set ones Redis HyperLogLog Calculator 12 KB whether you count a thousand or a billion Redis Cluster Sizing Only 60% of each node is usable Redis RDB and AOF Size Calculator The fork needs memory, not disk Redis Replication Bandwidth Calculator How long the backlog actually covers Redis Connection Pool Calculator More connections is not more throughput Redis Pipeline Calculator It removes round trips, not work Redis Cache Hit Rate Calculator 99% to 90% is ten times the backend load Redis Eviction Policy Simulator volatile- with no TTLs is noeviction Redis Cost Estimator Your rates, so nothing goes stale Redis Config File Generator A redis.conf with the reasons in it Redis ACL Generator A user that can do exactly one job Redis Maxmemory Config Generator The limit, and the headroom it needs Redis Persistence Config Generator How much you can afford to lose Redis Lua Script Generator Atomic, and short enough to stay that way Redis TLS Config Generator Encrypted, and the old port actually closed Redis Sentinel Config Generator Failover that can actually be authorised Redis Cluster Config Generator Three primaries, and the bus port open Redis Docker Compose Generator Local Redis that is not on the internet Redis Client Config Generator Timeouts on both sides, and a sane pool Redis MEMORY STATS Analyzer Which number actually matters Redis Bigkeys Output Analyzer Elements are not bytes Redis CLIENT LIST Analyzer Find the connection hurting you Redis LATENCY Report Analyzer An empty report may mean nothing was recorded Redis Keyspace Prefix Analyzer Which key family is growing Redis SET Command Builder A plain SET clears the TTL Redis ZRANGE Query Builder REV reverses the argument order Redis SCAN Iteration Planner COUNT is a hint, not a page size Redis Key Name Validator Legal is not the same as workable Redis Cluster Compatibility Checker Works now, breaks when you shard

Elsewhere on the site