Skip to main content
See All Integrations

Redis

Protect access to Redis services through Pomerium TCP routes.

First-party Pomerium access capability

Categories
Databases, Non-HTTP Services

Overview

Redis is an in-memory data store that uses the RESP protocol over TCP, normally on port 6379. Redis Cluster clients can follow MOVED and ASK responses to several advertised nodes.

Redis can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Redis. Redis remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium TCP route for the private service. Start a local tunnel with Pomerium CLI or Pomerium Desktop and point the normal service client to the loopback listener.

Keep upstream TLS, service authentication, and service authorization active. Use a distinct local port for each protected route.

Use a single-endpoint tunnel only when it matches the Redis topology. For Redis Cluster, design and test access to every node address that clients can receive.

Example

An administrator starts a local Pomerium tunnel for a private standalone Redis endpoint. The Redis client connects to the loopback port. Redis keeps ACLs, passwords, command permissions, and TLS.

Considerations

  • Redis Cluster clients discover and connect to several advertised nodes. One local tunnel does not cover that topology.
  • Preserve Redis authentication, ACLs, and TLS. Do not expose an unauthenticated Redis endpoint behind only a broad route policy.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect the RabbitMQ management interface and message protocols with separate HTTP and TCP routes.

  • Protect access to MongoDB services through Pomerium TCP routes.

  • Protect access to private TCP services through Pomerium routes.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo