Redis TLS Config Generator

Generate the TLS block for redis.conf. The trap is that TLS is a separate port: setting tls-port does not close the plaintext one, so an instance can look migrated while still accepting unencrypted connections on 6379.

Ports

Leaving the plaintext port open during a migration means a client that fails to negotiate TLS silently succeeds in the clear rather than failing loudly, so the migration looks finished when it is not.

Verification

Off means TLS encrypts the connection and authenticates nothing about the caller. That is transport security without access control.

Off leaves replication traffic in the clear, which is a full copy of the dataset crossing the network unencrypted. This is the setting most often missed, because clients work fine without it.

tls.conf

updates as you type

    Examples

    Worked setups you can load into the form above. Each one is a decision the generator makes differently, and the reason it makes it.

    Both ports open during a migration

    Unmigrated clients keep using plaintext, silently

    tls-port
    6379
    allow-plaintext
    yes

    TLS without client certificates

    Encrypted, but the client is still not identified

    tls-port
    6379
    client-certificates
    no

    Common mistakes

    These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

    1. Setting tls-port and thinking the migration is done

      The plaintext port stays open until port is set to 0, and a client using it looks exactly like one that is not.

      Instead:Set port 0 once every client has moved.

    2. Leaving tls-replication off

      The replication link stays unencrypted, so the whole dataset crosses the network in the clear on every full resync.

      Instead:Set tls-replication yes and tls-cluster yes.

    3. Pointing tls-ca-cert-file at a public CA bundle

      That would trust any certificate signed by any public CA, which is every certificate on the internet.

      Instead:Point it at the CA that signed your client certificates.

    4. Not tracking certificate expiry

      Expiry is a cluster-wide authentication outage that arrives without warning.

      Instead:Automate renewal and alert well before the date.

    Three connections, and TLS is configured separately for each

    A Redis node makes more than one kind of connection, and enabling TLS for clients does not enable it for the others.

    port 0 is what closes the plaintext listener

    Setting tls-port adds a TLS listener. It does not remove the plaintext one. Until port is set to 0, the instance still accepts unencrypted connections, and nothing in a successful client connection reveals which listener it used.

    Replication is a separate connection

    A replica connecting to its primary does not use TLS just because client TLS is on. tls-replication yes is what encrypts it, and without it the entire dataset crosses the network in the clear on every full resync.

    The cluster bus is another one again

    Nodes gossip over the bus port, and tls-cluster controls that independently. Leaving it off means cluster state and the node ids travel unencrypted while client traffic is protected.

    Encryption is not authentication

    TLS without client certificates gives confidentiality only: anyone who can reach the port still connects and authenticates with a password. tls-auth-clients yes requires a certificate signed by your CA, and that certificate can then serve as the identity an ACL is written against.

    Expiry is an outage with no warning

    Certificates expire on a date that is rarely diarised, and the failure is total authentication loss across the cluster. Redis reloads certificates on CONFIG SET, so renewal does not require a restart, which makes automating it straightforward.

    More redis tools

    Redis Hash Slot Calculator Which of the 16,384 slots does this key land in? Redis Hash Tag Tester Will these keys survive a multi-key command? Redis RESP Protocol Decoder Read what the server actually sent Redis RESP2 vs RESP3 Reply Decoder What the same reply looks like on each protocol Redis Command to RESP Exactly what your client puts on the socket Redis Glob Pattern Tester Redis globs are not shell globs Redis Connection URL Parser The path is the database number Redis Memory Unit Converter 1g and 1gb are not the same number Redis TTL Converter -1 and -2 are not durations Redis Stream ID Parser The first half is a millisecond timestamp redis.conf Validator Will Redis start with this file? Redis Production Config Linter The settings that cause incidents redis.conf to CONFIG SET Which of these can you change without a restart? Redis ACL Rule Decoder What does this user actually get? Redis ACL Validator Find the rule that does nothing Redis INFO Analyzer The numbers INFO does not print Redis SLOWLOG Analyzer What blocked everyone else Redis CLUSTER NODES Parser Read the topology, and find the gap Redis Cluster Slot Distribution Who owns how much, and what is missing Redis Keyspace Notification Flags Why your events never arrive Redis Memory Calculator The encoding decides, not the data Redis Key Count to Memory The fixed cost per key Redis Encoding Threshold Calculator One field more, several times the memory Redis Bitmap Memory Calculator Sized by the highest bit, not the set ones Redis HyperLogLog Calculator 12 KB whether you count a thousand or a billion Redis Cluster Sizing Only 60% of each node is usable Redis RDB and AOF Size Calculator The fork needs memory, not disk Redis Replication Bandwidth Calculator How long the backlog actually covers Redis Connection Pool Calculator More connections is not more throughput Redis Pipeline Calculator It removes round trips, not work Redis Cache Hit Rate Calculator 99% to 90% is ten times the backend load Redis Eviction Policy Simulator volatile- with no TTLs is noeviction Redis Cost Estimator Your rates, so nothing goes stale Redis Config File Generator A redis.conf with the reasons in it Redis ACL Generator A user that can do exactly one job Redis Maxmemory Config Generator The limit, and the headroom it needs Redis Persistence Config Generator How much you can afford to lose Redis Lua Script Generator Atomic, and short enough to stay that way Redis Sentinel Config Generator Failover that can actually be authorised Redis Cluster Config Generator Three primaries, and the bus port open Redis Docker Compose Generator Local Redis that is not on the internet Redis Client Config Generator Timeouts on both sides, and a sane pool Redis MEMORY STATS Analyzer Which number actually matters Redis Bigkeys Output Analyzer Elements are not bytes Redis CLIENT LIST Analyzer Find the connection hurting you Redis LATENCY Report Analyzer An empty report may mean nothing was recorded Redis Keyspace Prefix Analyzer Which key family is growing Redis SET Command Builder A plain SET clears the TTL Redis ZRANGE Query Builder REV reverses the argument order Redis SCAN Iteration Planner COUNT is a hint, not a page size Redis Key Name Validator Legal is not the same as workable Redis Cluster Compatibility Checker Works now, breaks when you shard

    Elsewhere on the site