Redis is an in-memory key-value store used as a cache, session store, message broker and fast database. In this tutorial you will install Redis on Ubuntu 24.04, require authentication with ACL users, limit its memory use, choose a persistence mode, optionally allow access from one application server, and back up and restore the dataset.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS, for example a CubePath VPS, with enough RAM for your dataset plus headroom (1 GB is enough to follow along).
  • A non-root user with sudo privileges.
  • UFW enabled with SSH allowed, if you plan to accept remote connections.

Step 1 - Installing Redis

Ubuntu 24.04 ships Redis 7.0 in its repositories, which is maintained with security updates for the release. Install it:

sudo apt update
sudo apt install redis-server

The package starts Redis and enables it at boot. Check the service:

sudo systemctl status redis-server
● redis-server.service - Advanced key-value store
     Loaded: loaded (/usr/lib/systemd/system/redis-server.service; enabled; preset: enabled)
     Active: active (running) since Thu 2026-09-25 10:02:41 UTC; 8s ago

Test it with the command-line client:

redis-cli ping
PONG

The files you will work with are:

PathPurpose
/etc/redis/redis.confMain configuration
/var/lib/redis/RDB snapshots and the AOF directory
/var/log/redis/redis-server.logServer log

Before editing, keep a copy of the original configuration:

sudo cp /etc/redis/redis.conf /etc/redis/redis.conf.orig

Step 2 - Setting the kernel overcommit option

Redis forks a child process to write snapshots. With the kernel's default overcommit heuristic, that fork can fail on a busy server and Redis logs a warning about vm.overcommit_memory at startup. Set it to 1 persistently:

echo 'vm.overcommit_memory = 1' | sudo tee /etc/sysctl.d/60-redis.conf
sudo sysctl --system

Confirm the value:

sysctl vm.overcommit_memory
vm.overcommit_memory = 1

Step 3 - Requiring authentication with ACL users

By default Redis accepts commands from any local client without a password. Redis 6 and later use ACLs: named users, each with a password and a set of allowed commands and keys. You will define them in a separate ACL file so they can be managed with ACL SAVE later.

Create the ACL file with two users: default, used for administration, and appuser, limited to keys that start with app: and without dangerous commands such as FLUSHALL, CONFIG or KEYS:

sudo nano /etc/redis/users.acl
user default on >your_admin_password ~* &* +@all
user appuser on >your_app_password ~app:* &* +@all -@dangerous

Replace both passwords with long random strings; openssl rand -base64 32 generates a good one. Restrict access to the file, since it contains the passwords:

sudo chown redis:redis /etc/redis/users.acl
sudo chmod 640 /etc/redis/users.acl

Tell Redis to load it. Open the configuration:

sudo nano /etc/redis/redis.conf

Find the commented # aclfile /etc/redis/users.acl line and uncomment it:

aclfile /etc/redis/users.acl

When aclfile is set, the requirepass directive is ignored, so leave requirepass commented out. Restart Redis:

sudo systemctl restart redis-server

An unauthenticated client is now refused:

redis-cli ping
(error) NOAUTH Authentication required.

Log in as appuser. The --askpass option prompts for the password instead of putting it on the command line:

redis-cli --user appuser --askpass

Inside the client, check what the user can and cannot do:

127.0.0.1:6379> SET app:greeting "hello"
OK
127.0.0.1:6379> SET other:key "x"
(error) NOPERM No permissions to access a key
127.0.0.1:6379> FLUSHALL
(error) NOPERM User appuser has no permissions to run the 'flushall' command

For administrative commands, connect as default. redis-cli also reads the password from the REDISCLI_AUTH environment variable, which is convenient in scripts.

Step 4 - Limiting memory and choosing an eviction policy

Without a limit, Redis grows until the kernel's OOM killer stops it. Set maxmemory below the RAM you can spare, leaving room for the operating system and for the copy-on-write memory used while snapshots are written.

In /etc/redis/redis.conf, set:

maxmemory 512mb
maxmemory-policy allkeys-lru

Pick the policy based on how you use Redis:

PolicyBehaviourUse it for
noeviction (default)Writes fail with an error when memory is fullPrimary data store, queues
allkeys-lruEvicts the least recently used keysPure cache
volatile-lruEvicts only keys with a TTLMixed cache and persistent data

Restart and verify:

sudo systemctl restart redis-server
REDISCLI_AUTH='your_admin_password' redis-cli CONFIG GET maxmemory-policy
1) "maxmemory-policy"
2) "allkeys-lru"

Step 5 - Configuring persistence

Redis keeps data in memory and offers two ways to write it to disk:

  • RDB snapshots: a compact point-in-time file (dump.rdb), written periodically. Enabled by default. You can lose the writes since the last snapshot.
  • AOF (append-only file): logs every write. With appendfsync everysec you lose at most about one second of writes.

For a pure cache you can disable both with save "" and appendonly no. For data you need to keep, enable AOF alongside RDB. In /etc/redis/redis.conf, set:

appendonly yes
appendfsync everysec

Restart Redis and confirm AOF is active:

sudo systemctl restart redis-server
REDISCLI_AUTH='your_admin_password' redis-cli INFO persistence | grep -E 'aof_enabled|rdb_last_bgsave_status'
rdb_last_bgsave_status:ok
aof_enabled:1

Redis 7 stores the AOF as several files in /var/lib/redis/appendonlydir/.

Step 6 - Allowing remote connections (optional)

Skip this step if your application runs on the same server. By default Redis binds to 127.0.0.1 -::1 and keeps protected-mode yes. To accept connections from another server on a private network, edit the bind line in /etc/redis/redis.conf:

bind 127.0.0.1 -::1 your_server_private_ip

Restart Redis and allow port 6379 only from the application server:

sudo systemctl restart redis-server
sudo ufw allow from your_app_server_ip to any port 6379 proto tcp

From the application server, test with the appuser credentials:

redis-cli -h your_server_private_ip --user appuser --askpass ping
PONG

Step 7 - Backing up and restoring data

redis-cli --rdb asks the server for a fresh snapshot and saves it locally, which works whether or not AOF is enabled. Create a backup directory and take a backup:

sudo install -d -m 700 /var/backups/redis
sudo REDISCLI_AUTH='your_admin_password' redis-cli --rdb "/var/backups/redis/dump-$(date +%Y%m%d-%H%M%S).rdb"
sending REPLCONF capa eof
sending REPLCONF rdb-only 1
SYNC sent to master, writing 175 bytes to '/var/backups/redis/dump-20260925-104512.rdb'
Transfer finished with success.

To run this every night, put the command in a root-owned script that reads the password from a file with mode 600 and schedule it with a systemd timer, as with any other backup job. Copy the files off the server too.

Restoring an RDB file

When AOF is enabled, Redis loads the AOF at startup and ignores dump.rdb, so a restore needs a few extra steps. Stop Redis and move the current AOF directory aside:

sudo systemctl stop redis-server
sudo mv /var/lib/redis/appendonlydir /var/lib/redis/appendonlydir.old

Copy the backup into place with the right owner:

sudo cp /var/backups/redis/dump-20260925-104512.rdb /var/lib/redis/dump.rdb
sudo chown redis:redis /var/lib/redis/dump.rdb

Set appendonly no in /etc/redis/redis.conf, then start Redis so it loads the RDB file:

sudo systemctl start redis-server

Turn AOF back on at runtime. Redis rewrites a new AOF from the data it just loaded:

REDISCLI_AUTH='your_admin_password' redis-cli CONFIG SET appendonly yes

Finally, set appendonly yes again in /etc/redis/redis.conf so the setting survives the next restart, check your keys with DBSIZE, and remove /var/lib/redis/appendonlydir.old once you are satisfied.

Troubleshooting

Redis does not start after editing the configuration: run sudo journalctl -u redis-server -n 30 and read /var/log/redis/redis-server.log. A typo in users.acl or wrong file permissions on it are common causes.

NOPERM errors in the application: the ACL user lacks access to that key pattern or command. Check with ACL LOG as the default user, which lists recent denied commands and the reason.

OOM command not allowed when used memory > 'maxmemory': memory is full and the policy is noeviction. Raise maxmemory, set TTLs on keys, or switch to an eviction policy if the data is a cache.

MISCONF Redis is configured to save RDB snapshots, but it's currently unable to persist to disk: the background save failed, usually due to a full disk or the fork failing. Check df -h /var/lib/redis and the overcommit setting from Step 2.

Conclusion

Redis is now running on Ubuntu 24.04 with ACL-based authentication, a memory limit with an eviction policy that matches your workload, durable persistence and a tested backup and restore procedure. As next steps, watch INFO memory and SLOWLOG GET to spot memory growth and slow commands, set TTLs on cache keys, and consider Redis replication with Sentinel if you need automatic failover.