Dragonfly is an in-memory data store that speaks the Redis and Memcached protocols, so existing clients and libraries work without code changes. Unlike Redis, it uses all CPU cores of the server with a multi-threaded, shared-nothing design, which helps on large instances with heavy traffic. In this tutorial you will install Dragonfly on Ubuntu 24.04, run it as a hardened systemd service, protect it with a password, configure memory limits and snapshots, and test it with redis-cli and a Memcached client.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS (x86_64 or arm64), for example a CubePath VPS, with a non-root user with
sudoprivileges. - At least 2 GB of RAM. Dragonfly shines on servers with several cores and more memory, but it runs fine on small instances for testing.
- If Redis is already installed and listening on port 6379, stop it first or use a different port for Dragonfly.
Step 1 - Downloading the Dragonfly binary
Dragonfly is distributed as a single static binary on its GitHub releases page. Download the latest release for your architecture. On x86_64 servers:
cd /tmp
curl -fsSLO https://github.com/dragonflydb/dragonfly/releases/latest/download/dragonfly-x86_64.tar.gz
On arm64 servers, download dragonfly-aarch64.tar.gz instead and adjust the file names in the next commands.
Extract the archive and install the binary into /usr/local/bin:
tar -xzf dragonfly-x86_64.tar.gz
sudo install -m 0755 dragonfly-x86_64 /usr/local/bin/dragonfly
Check that it runs:
dragonfly --version
dragonfly v1.x.x-...
Step 2 - Creating a user and directories
Dragonfly should not run as root. Create a system user without a login shell, a data directory for snapshots and a directory for its configuration:
sudo adduser --system --group --no-create-home --home /var/lib/dragonfly dragonfly
sudo install -d -o dragonfly -g dragonfly -m 0750 /var/lib/dragonfly
sudo install -d -m 0755 /etc/dragonfly
Step 3 - Writing the configuration file
Dragonfly is configured with command-line flags, and it can read them from a file with --flagfile. Keeping them in a file makes the systemd unit shorter and lets you change settings without editing the unit.
Generate a strong password and keep it somewhere safe:
openssl rand -base64 32
Create the configuration file:
sudo nano /etc/dragonfly/dragonfly.conf
Add the following flags, replacing your_strong_password with the value you just generated:
--bind=127.0.0.1
--port=6379
--requirepass=your_strong_password
--maxmemory=1gb
--cache_mode=true
--dir=/var/lib/dragonfly
--dbfilename=dump
--snapshot_cron=*/30 * * * *
--memcached_port=11211
What each flag does:
--bindand--port: listen only on localhost, port 6379. Change--bindto a private IP only if other servers need access (see Step 7).--requirepass: clients must authenticate with this password.--maxmemory: memory limit for the dataset. Leave headroom for the operating system and other services; on a 2 GB server, 1 GB is reasonable.--cache_mode=true: when memory is close tomaxmemory, Dragonfly evicts the least useful keys instead of returning out-of-memory errors. Set it tofalseif Dragonfly stores data that must never be dropped, such as queues.--dir,--dbfilenameand--snapshot_cron: write a snapshot to/var/lib/dragonflyevery 30 minutes, using a standard cron expression.--memcached_port: also accept Memcached protocol connections on port 11211. Omit this line if you only need Redis compatibility.
The file contains a password, so restrict who can read it:
sudo chown root:dragonfly /etc/dragonfly/dragonfly.conf
sudo chmod 0640 /etc/dragonfly/dragonfly.conf
Step 4 - Creating the systemd service
Create a unit file so systemd starts Dragonfly at boot and restarts it on failure:
sudo nano /etc/systemd/system/dragonfly.service
[Unit]
Description=Dragonfly in-memory data store
Documentation=https://www.dragonflydb.io/docs
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=dragonfly
Group=dragonfly
WorkingDirectory=/var/lib/dragonfly
ExecStart=/usr/local/bin/dragonfly --flagfile=/etc/dragonfly/dragonfly.conf --logtostderr
Restart=on-failure
RestartSec=5
LimitNOFILE=65535
NoNewPrivileges=true
ProtectSystem=full
ProtectHome=true
PrivateTmp=true
[Install]
WantedBy=multi-user.target
--logtostderr sends the logs to the journal, so you can read them with journalctl. Reload systemd and start the service:
sudo systemctl daemon-reload
sudo systemctl enable --now dragonfly
Check its status:
systemctl status dragonfly --no-pager
● dragonfly.service - Dragonfly in-memory data store
Loaded: loaded (/etc/systemd/system/dragonfly.service; enabled; preset: enabled)
Active: active (running) since ...
Confirm it is listening on both ports:
sudo ss -tlnp | grep dragonfly
LISTEN 0 ... 127.0.0.1:6379 0.0.0.0:* users:(("dragonfly",pid=...))
LISTEN 0 ... 127.0.0.1:11211 0.0.0.0:* users:(("dragonfly",pid=...))
If the service does not start, look at the logs with sudo journalctl -u dragonfly -n 50 --no-pager.
Step 5 - Connecting with Redis clients
Any Redis client can talk to Dragonfly. Install redis-cli from the redis-tools package, which does not install a Redis server:
sudo apt install redis-tools
Connect and enter the password when prompted. --askpass keeps the password out of your shell history:
redis-cli --askpass
Inside the prompt, run a few commands with different data types:
127.0.0.1:6379> SET greeting "hello dragonfly"
OK
127.0.0.1:6379> GET greeting
"hello dragonfly"
127.0.0.1:6379> HSET user:1 name Alice plan pro
(integer) 2
127.0.0.1:6379> HGETALL user:1
1) "name"
2) "Alice"
3) "plan"
4) "pro"
127.0.0.1:6379> EXPIRE greeting 60
(integer) 1
Check which server you are connected to and how many threads it is using:
127.0.0.1:6379> INFO server
The output includes a dragonfly_version field and a thread_count field, which by default matches the number of CPU cores. To limit the threads, for example to leave cores for other services on the same server, add --proactor_threads=2 to the configuration file and restart the service.
Applications connect the same way they connect to Redis. For example, a connection URL in most client libraries looks like this:
redis://:[email protected]:6379/0
Step 6 - Using the Memcached protocol
Applications that use Memcached can point at port 11211 without changes. Test it with nc, which is installed by default on Ubuntu:
printf 'set session:42 0 300 5\r\nhello\r\nget session:42\r\n' | nc -q 1 127.0.0.1 11211
STORED
VALUE session:42 0 5
hello
END
The set command stores the 5-byte value hello under session:42 with a 300-second expiration, and get reads it back.
NoteThe Memcached protocol has no password authentication. Keep port 11211 bound to
127.0.0.1or to a private network that only your application servers can reach.
Step 7 - Allowing access from other servers (optional)
If your application runs on another server, bind Dragonfly to the private IP of this server instead of localhost. Edit /etc/dragonfly/dragonfly.conf and change the first line, replacing your_private_ip:
--bind=your_private_ip
Restart the service and allow only your application server through UFW:
sudo systemctl restart dragonfly
sudo ufw allow from your_app_server_ip to any port 6379 proto tcp
Never expose port 6379 or 11211 to the whole internet. From the application server, test the connection with redis-cli -h your_private_ip --askpass ping, which should answer PONG.
Step 8 - Checking snapshots and memory
Trigger a snapshot manually to confirm persistence works:
redis-cli --askpass BGSAVE
After a few seconds, list the data directory:
sudo ls -lh /var/lib/dragonfly
Dragonfly writes its own snapshot format, with a summary file and one file per thread, all using the .dfs extension and the dump prefix you set with --dbfilename. On restart, Dragonfly loads the latest snapshot automatically.
Check memory usage against the limit:
redis-cli --askpass INFO memory | grep -E 'used_memory_human|maxmemory_human'
used_memory_human:1.02MiB
maxmemory_human:1.00GiB
With cache_mode enabled, evicted_keys in INFO stats starts growing once the dataset reaches maxmemory. That is expected for a cache; if it grows quickly, increase --maxmemory or reduce the TTL of your keys.
Step 9 - Running a quick benchmark
redis-benchmark, included in redis-tools, gives a rough idea of throughput. Run it from the same server with 50 connections and 4 client threads:
redis-benchmark -h 127.0.0.1 -p 6379 -a your_strong_password -c 50 -n 200000 --threads 4 -t set,get -q
SET: 180000.00 requests per second, p50=0.223 msec
GET: 195000.00 requests per second, p50=0.207 msec
Your numbers depend on the CPU and on whether the benchmark client competes for the same cores. For a realistic comparison with Redis, run the benchmark from a separate machine on the private network and use the command mix and value sizes (-d) of your application.
Troubleshooting
The service exits right after starting. Read the last log lines with sudo journalctl -u dragonfly -n 50 --no-pager. Typical causes are a typo in a flag (Dragonfly refuses unknown flags) or port 6379 already in use by Redis. Check with sudo ss -tlnp | grep 6379 and stop Redis with sudo systemctl disable --now redis-server if needed.
NOAUTH Authentication required. The client connected without a password. Use redis-cli --askpass or pass the password in the client connection URL.
OOM command not allowed errors. The dataset reached maxmemory and cache_mode is off. Either enable --cache_mode=true if the data is a cache, or raise --maxmemory after checking free memory with free -h.
Snapshots are not written. Make sure /var/lib/dragonfly is owned by the dragonfly user and that the --snapshot_cron expression is valid.
Conclusion
Dragonfly is now running on Ubuntu 24.04 as a systemd service, protected by a password, limited in memory, writing snapshots every 30 minutes and accepting both Redis and Memcached clients. Because it is protocol compatible, you can switch an application from Redis by changing only its connection URL. As next steps, set up a replica on a second server with the REPLICAOF command, copy the snapshots in /var/lib/dragonfly to off-site storage, and monitor the service with a Prometheus scraper on its /metrics endpoint.
