Merge pull request #1571 from infosiftr/securing-redis

Add section on Redis security, warn about exposing it to host network
This commit is contained in:
Tianon Gravi 2019-09-12 16:55:47 -07:00 committed by GitHub
commit 44bb573b07
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 8 additions and 0 deletions

View File

@ -6,6 +6,14 @@ Redis is an open-source, networked, in-memory, key-value data store with optiona
%%LOGO%%
# Security
For the ease of accessing Redis from other containers via Docker networking, the "Protected mode" is turned off by default. This means that if you expose the port outside of your host (e.g., via `-p` on `docker run`), it will be open without a password to anyone. It is **highly** recommended to set a password (by supplying a config file) if you plan on exposing your Redis instance to the internet. For further information, see the following links about Redis security:
- [Redis documentation on security](https://redis.io/topics/security)
- [Protected mode](https://redis.io/topics/security#protected-mode)
- [A few things about Redis security by antirez](http://antirez.com/news/96)
# How to use this image
## start a redis instance