美文网首页
redis.conf详解之protected-mode

redis.conf详解之protected-mode

作者: 小易哥学呀学 | 来源:发表于2021-11-18 08:39 被阅读0次

用法

打开保护模式
protected-mode yes
关闭保护模式
protected-mode no

用途

保护你的redis实例,防止被访问和利用。
大白话:只有本地能操作这个实例,外网不行。

注意事项:

1.保护模式默认是打开的。
2.保护模式生效后,只有本地回环和unix域套接字的请求可操作redis。
3.保护模式的生效条件:保护模式已打开未指定bind未指定密码
例如

protected-mode yes // 打开保护模式
#bind 127.0.0.1 //不绑定任何网络接口
#requirepass xiaoyi //不设置密码 

保护模式生效后非本地回环与unix domain socket连接将报错:

$ redis-cli -h 10.10.10.10
10.10.10.10:6379> set a 1
(error) DENIED Redis is running in protected mode because protected mode is enabled, no bind address was specified, no authentication password is requested to clients. In this mode connections are only accepted from the loopback interface. If you want to connect from external computers to Redis you may adopt one of the following solutions: 1) Just disable protected mode sending the command 'CONFIG SET protected-mode no' from the loopback interface by connecting to Redis from the same host the server is running, however MAKE SURE Redis is not publicly accessible from internet if you do so. Use CONFIG REWRITE to make this change permanent. 2) Alternatively you can just disable the protected mode by editing the Redis configuration file, and setting the protected mode option to 'no', and then restarting the server. 3) If you started the server manually just for testing, restart it with the '--protected-mode no' option. 4) Setup a bind address or an authentication password. NOTE: You only need to do one of the above things in order for the server to start accepting connections from the outside.

保护模式生效后本地回环与unix domain socket连接将成功:

$ redis-cli -h ::1
[::1]:6379> set a 1
OK
[::1]:6379>
$ redis-cli -h 127.0.0.1
127.0.0.1:6379> set a 1
OK
127.0.0.1:6379>

原生注释

# Protected mode is a layer of security protection, in order to avoid that
# Redis instances left open on the internet are accessed and exploited.
#
# When protected mode is on and if:
#
# 1) The server is not binding explicitly to a set of addresses using the
#    "bind" directive.
# 2) No password is configured.
#
# The server only accepts connections from clients connecting from the
# IPv4 and IPv6 loopback addresses 127.0.0.1 and ::1, and from Unix domain
# sockets.
#
# By default protected mode is enabled. You should disable it only if
# you are sure you want clients from other hosts to connect to Redis
# even if no authentication is configured, nor a specific set of interfaces
# are explicitly listed using the "bind" directive.

相关文章

  • redis.conf详解之protected-mode

    用法 打开保护模式 关闭保护模式 用途 保护你的redis实例,防止被访问和利用。大白话:只有本地能操作这个实例,...

  • Redis单机部署

    在redis.conf,将protected-mode no 在redis.conf bind 192.168.4...

  • redis-cli访问IP时报Could not connect

    redis.conf更换了默认的IP地址后,访问后一直报错: 之后尝试了很多方法或将protected-mode ...

  • redis.conf详解之include

    1、用法: 在 $yourPath/redis.conf 文件中添加以下配置 2、用途: 模块化配置,比如所有服务...

  • redis.conf详解之module

    1、用法: 在 $yourPath/redis.conf 文件中添加以下配置 2、module制作: 准备工作 1...

  • redis.conf详解之timeout

    用法 单位是秒 用途 在timeout时间内如果没有数据交互,redis侧将关闭连接。没有数据交互:redis客户...

  • redis.conf详解之port

    用法 用途 指定redis监听的端口。 注意事项: 1.默认是63792.配置为0时将不监听任何端口(也就是服务没...

  • redis.conf详解之bind

    用法 绑定到本机的其中一个ip 绑定到本机的两个ip,如果10.0.0.1无效redis依旧可以启动。 绑定到本机...

  • redis.conf详解之daemonize

    用法 作为非守护进程运行 作为守护进程运行 注意事项: 默认情况下,Redis不作为守护进程运行。如果以守护进程运...

  • redis.conf详解之pidfile

    用法 注意事项: 如果pidfile文件创建失败,也不会影响redis启动。配置了daemonize或pidfil...

网友评论

      本文标题:redis.conf详解之protected-mode

      本文链接:https://www.haomeiwen.com/subject/zmdhtrtx.html