
Redis
Protect access to Redis services through Pomerium TCP routes.
Overview
Redis is an in-memory data store that uses the RESP protocol over TCP, normally on port 6379. Redis Cluster clients can follow MOVED and ASK responses to several advertised nodes.
Redis can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Redis. Redis remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium TCP route for the private service. Start a local tunnel with Pomerium CLI or Pomerium Desktop and point the normal service client to the loopback listener.
Keep upstream TLS, service authentication, and service authorization active. Use a distinct local port for each protected route.
Use a single-endpoint tunnel only when it matches the Redis topology. For Redis Cluster, design and test access to every node address that clients can receive.
Example
An administrator starts a local Pomerium tunnel for a private standalone Redis endpoint. The Redis client connects to the loopback port. Redis keeps ACLs, passwords, command permissions, and TLS.
Considerations
- Redis Cluster clients discover and connect to several advertised nodes. One local tunnel does not cover that topology.
- Preserve Redis authentication, ACLs, and TLS. Do not expose an unauthenticated Redis endpoint behind only a broad route policy.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
Sources and official resources
- RedisOfficial website
- Redis securityOfficial documentation
- Redis TLSPrimary source
- Redis Cluster specificationPrimary source
- Tunneled Redis connectionsPomerium documentation
- Pomerium non-HTTP accessPomerium documentation
- Pomerium clientsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
