Cluster mode locally
Nodes advertise an address a client outside Compose cannot reach
- topology
- cluster
- version
- 7.4
Generate a Compose file for local Redis. Two defaults in Docker make this worth generating rather than typing: published ports go to every interface, and an unnamed volume means the data dies on the next docker compose down.
Worked setups you can load into the form above. Each one is a decision the generator makes differently, and the reason it makes it.
Nodes advertise an address a client outside Compose cannot reach
Bound to localhost, with a named volume so down is not destructive
These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.
Docker publishes to every interface and writes its own firewall rules, so the host firewall does not stop it. An unauthenticated Redis on a reachable address is remote code execution.
Instead:Bind it to 127.0.0.1, or do not publish it.
docker compose down removes it, and down is a routine command.
Instead:Use a named volume.
Dependent services connect before Redis answers, producing intermittent failures on the first request.
Instead:Add a healthcheck that runs redis-cli ping.
It has no password, no TLS and no resource limits, because those cannot be generated meaningfully.
Instead:Treat it as a starting point and add all three.
Neither is a Redis problem. Both bite harder with Redis than with most images, because an unauthenticated Redis reachable from a network is not merely a data leak.
ports: 6379:6379 publishes to every interface, and on many setups this bypasses the host firewall entirely, because Docker writes its own iptables rules. An unauthenticated Redis on a reachable address allows an attacker to write a file anywhere the process can write, which is remote code execution rather than a data leak.
Without a named volume, everything written is removed with the container, and docker compose down is a routine command rather than a destructive one. A named volume survives down and is removed only by down -v.
A container reporting healthy on process liveness alone will accept dependent services before Redis is answering. A healthcheck that runs redis-cli ping is the difference between a clean start and an intermittent failure on the first request.
Nodes advertise the address they are configured with, so a client outside the Compose network receives an internal container IP it cannot reach. cluster-announce-ip and cluster-announce-port are what fix that, and the bus port must be published as well.
The file has no password, no TLS and no resource limits, because they would be placeholders. It is a local development environment written to be safe on a laptop, not a production deployment.