Sign inSign up

detoxd/redis

By detoxd

•Updated 6 months ago

Image
0

1.4K

detoxd/redis repository overview

⁠Redis - Detoxd Hardened Image

⁠Overview

Redis is an open-source, in-memory data structure store used as a database, cache, message broker, and streaming engine. Created by Salvatore Sanfilippo in 2009, Redis supports various data structures including strings, hashes, lists, sets, sorted sets, bitmaps, hyperloglogs, and geospatial indexes.

⁠Common Use Cases

  • Caching - High-speed data caching for web applications
  • Session Storage - Storing user sessions with automatic expiration
  • Message Queue - Pub/sub messaging and task queues
  • Real-time Analytics - Leaderboards, counters, rate limiting
  • Geospatial Data - Location-based queries and radius searches
  • Full-text Search - With Redis Search module

⁠Security Concerns

Redis has historically been a target for attacks:

  • Unauthenticated Access - Default configuration has no password
  • Command Injection - Dangerous commands can modify server state
  • Remote Code Execution - CONFIG and MODULE commands can load malicious code
  • Data Exposure - All data stored in memory can be dumped
  • Denial of Service - Memory exhaustion, slow commands

⁠What Detoxd Does

⁠Dangerous Command Restrictions

Disables or renames high-risk commands:

  • FLUSHDB - Deletes all keys in current database
  • FLUSHALL - Deletes all keys in all databases
  • DEBUG - Debugging commands with security implications
  • CONFIG - Runtime configuration modification
⁠System Hardening
  • Updates all system packages to latest versions
  • Removes unnecessary packages and tools
  • Removes setuid/setgid bits from binaries
  • Cleans package caches and temporary files
⁠Best Practices Applied
  • Minimal base image
  • Security-focused defaults
  • Reduced attack surface
# redis.conf security settings
bind 127.0.0.1 ::1
protected-mode yes
requirepass YOUR_STRONG_PASSWORD_HERE

# Rename dangerous commands
rename-command FLUSHDB ""
rename-command FLUSHALL ""
rename-command DEBUG ""
rename-command CONFIG ""
rename-command SHUTDOWN SHUTDOWN_SECUREKEY
rename-command SLAVEOF ""
rename-command REPLICAOF ""
rename-command SCRIPT ""
rename-command EVAL ""

# Disable Lua scripting if not needed
rename-command EVALSHA ""

# Resource limits
maxmemory 256mb
maxmemory-policy allkeys-lru
maxclients 1000

# Disable dangerous features
enable-module-command no

⁠Environment Variables

# Enable authentication
REDIS_PASSWORD=your_secure_password

# Bind to specific interface
REDIS_BINDING=127.0.0.1

# Set memory limit
REDIS_MAXMEMORY=256mb

⁠References

Tag summary

Content type

Image

Digest

sha256:7420dcf0d…

Size

32.9 MB

Last updated

6 months ago

docker pull detoxd/redis:8.6.1-alpine3.23-detox.1