Redis is an in-memory key-value store used as a cache, session store, message broker and fast database. In this tutorial you will install Redis on Ubuntu 24.04, require authentication with ACL users, limit its memory use, choose a persistence mode, optionally allow access from one application server, and back up and restore the dataset.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with enough RAM for your dataset plus headroom (1 GB is enough to follow along).
- A non-root user with
sudoprivileges. - UFW enabled with SSH allowed, if you plan to accept remote connections.
Step 1 - Installing Redis
Ubuntu 24.04 ships Redis 7.0 in its repositories, which is maintained with security updates for the release. Install it:
sudo apt update
sudo apt install redis-server
The package starts Redis and enables it at boot. Check the service:
sudo systemctl status redis-server
● redis-server.service - Advanced key-value store
Loaded: loaded (/usr/lib/systemd/system/redis-server.service; enabled; preset: enabled)
Active: active (running) since Thu 2026-09-25 10:02:41 UTC; 8s ago
Test it with the command-line client:
redis-cli ping
PONG
NoteIf you need Redis 8, add the official repository from
packages.redis.ioand install theredispackage instead. The configuration directives used in this guide are the same.
The files you will work with are:
| Path | Purpose |
|---|---|
/etc/redis/redis.conf | Main configuration |
/var/lib/redis/ | RDB snapshots and the AOF directory |
/var/log/redis/redis-server.log | Server log |
Before editing, keep a copy of the original configuration:
sudo cp /etc/redis/redis.conf /etc/redis/redis.conf.orig
Step 2 - Setting the kernel overcommit option
Redis forks a child process to write snapshots. With the kernel's default overcommit heuristic, that fork can fail on a busy server and Redis logs a warning about vm.overcommit_memory at startup. Set it to 1 persistently:
echo 'vm.overcommit_memory = 1' | sudo tee /etc/sysctl.d/60-redis.conf
sudo sysctl --system
Confirm the value:
sysctl vm.overcommit_memory
vm.overcommit_memory = 1
Step 3 - Requiring authentication with ACL users
By default Redis accepts commands from any local client without a password. Redis 6 and later use ACLs: named users, each with a password and a set of allowed commands and keys. You will define them in a separate ACL file so they can be managed with ACL SAVE later.
Create the ACL file with two users: default, used for administration, and appuser, limited to keys that start with app: and without dangerous commands such as FLUSHALL, CONFIG or KEYS:
sudo nano /etc/redis/users.acl
user default on >your_admin_password ~* &* +@all
user appuser on >your_app_password ~app:* &* +@all -@dangerous
Replace both passwords with long random strings; openssl rand -base64 32 generates a good one. Restrict access to the file, since it contains the passwords:
sudo chown redis:redis /etc/redis/users.acl
sudo chmod 640 /etc/redis/users.acl
Tell Redis to load it. Open the configuration:
sudo nano /etc/redis/redis.conf
Find the commented # aclfile /etc/redis/users.acl line and uncomment it:
aclfile /etc/redis/users.acl
When aclfile is set, the requirepass directive is ignored, so leave requirepass commented out. Restart Redis:
sudo systemctl restart redis-server
An unauthenticated client is now refused:
redis-cli ping
(error) NOAUTH Authentication required.
Log in as appuser. The --askpass option prompts for the password instead of putting it on the command line:
redis-cli --user appuser --askpass
Inside the client, check what the user can and cannot do:
127.0.0.1:6379> SET app:greeting "hello"
OK
127.0.0.1:6379> SET other:key "x"
(error) NOPERM No permissions to access a key
127.0.0.1:6379> FLUSHALL
(error) NOPERM User appuser has no permissions to run the 'flushall' command
For administrative commands, connect as default. redis-cli also reads the password from the REDISCLI_AUTH environment variable, which is convenient in scripts.
Step 4 - Limiting memory and choosing an eviction policy
Without a limit, Redis grows until the kernel's OOM killer stops it. Set maxmemory below the RAM you can spare, leaving room for the operating system and for the copy-on-write memory used while snapshots are written.
In /etc/redis/redis.conf, set:
maxmemory 512mb
maxmemory-policy allkeys-lru
Pick the policy based on how you use Redis:
| Policy | Behaviour | Use it for |
|---|---|---|
noeviction (default) | Writes fail with an error when memory is full | Primary data store, queues |
allkeys-lru | Evicts the least recently used keys | Pure cache |
volatile-lru | Evicts only keys with a TTL | Mixed cache and persistent data |
Restart and verify:
sudo systemctl restart redis-server
REDISCLI_AUTH='your_admin_password' redis-cli CONFIG GET maxmemory-policy
1) "maxmemory-policy"
2) "allkeys-lru"
Step 5 - Configuring persistence
Redis keeps data in memory and offers two ways to write it to disk:
- RDB snapshots: a compact point-in-time file (
dump.rdb), written periodically. Enabled by default. You can lose the writes since the last snapshot. - AOF (append-only file): logs every write. With
appendfsync everysecyou lose at most about one second of writes.
For a pure cache you can disable both with save "" and appendonly no. For data you need to keep, enable AOF alongside RDB. In /etc/redis/redis.conf, set:
appendonly yes
appendfsync everysec
Restart Redis and confirm AOF is active:
sudo systemctl restart redis-server
REDISCLI_AUTH='your_admin_password' redis-cli INFO persistence | grep -E 'aof_enabled|rdb_last_bgsave_status'
rdb_last_bgsave_status:ok
aof_enabled:1
Redis 7 stores the AOF as several files in /var/lib/redis/appendonlydir/.
Step 6 - Allowing remote connections (optional)
Skip this step if your application runs on the same server. By default Redis binds to 127.0.0.1 -::1 and keeps protected-mode yes. To accept connections from another server on a private network, edit the bind line in /etc/redis/redis.conf:
bind 127.0.0.1 -::1 your_server_private_ip
Restart Redis and allow port 6379 only from the application server:
sudo systemctl restart redis-server
sudo ufw allow from your_app_server_ip to any port 6379 proto tcp
From the application server, test with the appuser credentials:
redis-cli -h your_server_private_ip --user appuser --askpass ping
PONG
WarningRedis traffic is unencrypted by default. Never expose port 6379 to the whole internet; keep it on a private network or set up TLS before connecting across untrusted networks.
Step 7 - Backing up and restoring data
redis-cli --rdb asks the server for a fresh snapshot and saves it locally, which works whether or not AOF is enabled. Create a backup directory and take a backup:
sudo install -d -m 700 /var/backups/redis
sudo REDISCLI_AUTH='your_admin_password' redis-cli --rdb "/var/backups/redis/dump-$(date +%Y%m%d-%H%M%S).rdb"
sending REPLCONF capa eof
sending REPLCONF rdb-only 1
SYNC sent to master, writing 175 bytes to '/var/backups/redis/dump-20260925-104512.rdb'
Transfer finished with success.
To run this every night, put the command in a root-owned script that reads the password from a file with mode 600 and schedule it with a systemd timer, as with any other backup job. Copy the files off the server too.
Restoring an RDB file
When AOF is enabled, Redis loads the AOF at startup and ignores dump.rdb, so a restore needs a few extra steps. Stop Redis and move the current AOF directory aside:
sudo systemctl stop redis-server
sudo mv /var/lib/redis/appendonlydir /var/lib/redis/appendonlydir.old
Copy the backup into place with the right owner:
sudo cp /var/backups/redis/dump-20260925-104512.rdb /var/lib/redis/dump.rdb
sudo chown redis:redis /var/lib/redis/dump.rdb
Set appendonly no in /etc/redis/redis.conf, then start Redis so it loads the RDB file:
sudo systemctl start redis-server
Turn AOF back on at runtime. Redis rewrites a new AOF from the data it just loaded:
REDISCLI_AUTH='your_admin_password' redis-cli CONFIG SET appendonly yes
Finally, set appendonly yes again in /etc/redis/redis.conf so the setting survives the next restart, check your keys with DBSIZE, and remove /var/lib/redis/appendonlydir.old once you are satisfied.
Troubleshooting
Redis does not start after editing the configuration: run sudo journalctl -u redis-server -n 30 and read /var/log/redis/redis-server.log. A typo in users.acl or wrong file permissions on it are common causes.
NOPERM errors in the application: the ACL user lacks access to that key pattern or command. Check with ACL LOG as the default user, which lists recent denied commands and the reason.
OOM command not allowed when used memory > 'maxmemory': memory is full and the policy is noeviction. Raise maxmemory, set TTLs on keys, or switch to an eviction policy if the data is a cache.
MISCONF Redis is configured to save RDB snapshots, but it's currently unable to persist to disk: the background save failed, usually due to a full disk or the fork failing. Check df -h /var/lib/redis and the overcommit setting from Step 2.
Conclusion
Redis is now running on Ubuntu 24.04 with ACL-based authentication, a memory limit with an eviction policy that matches your workload, durable persistence and a tested backup and restore procedure. As next steps, watch INFO memory and SLOWLOG GET to spot memory growth and slow commands, set TTLs on cache keys, and consider Redis replication with Sentinel if you need automatic failover.
