Chapter 01 · Redis Foundations, Redis 8, Deployment Choices, CLI, and Lab Setup
Install Redis or Start a Container, Connect with redis-cli, and Verify Server Metadata
Start a pinned Redis 8.10.1 container, connect with redis-cli, inspect server/configuration metadata, diagnose connection failures, and clean up safely.
Learning outcomes
AtlasMart needs a lab that another learner can reproduce on Windows, Linux, or macOS and that records exactly what Redis is running. The official Redis installation guidance supports Linux and macOS packages and uses Docker for Windows; Docker therefore provides the common path for this course. The lab deliberately pins the Redis 8.10.1 image instead of a moving tag.
Start a disposable Redis Open Source 8.10.1 container without exposing it beyond host loopback.
Connect with redis-cli and distinguish client reachability, authentication, RESP negotiation, and server metadata.
Inspect container identity, logs, TCP binding, configuration, logical database, client identity, and persistence state.
Diagnose wrong host/port/password and ephemeral-container-storage mistakes from concrete errors.
Cleanly stop and remove the lab without touching unrelated containers or data.
Examples use Redis Open Source 8.10.1 and the Docker Official
Image redis:8.10.1, pinned on purpose. The lab
publishes Redis only on host loopback
(127.0.0.1:6379) and uses disposable AtlasMart
credentials. Never reuse these sample credentials or point the
commands at a production endpoint.
1. Choose a reproducible installation path
Redis publishes installation guidance for Linux package managers, macOS Homebrew, and Docker. On Windows, the official Redis Open Source path is Docker running Linux containers. Native packages can be convenient, but package repositories may move to newer patch releases over time. A course lab that wants deterministic behavior should record the exact version and preferably pin an image/tag.
| Platform | Course recommendation | Why |
|---|---|---|
| Windows 10/11 | Docker Desktop, Linux containers | Matches official Redis Windows guidance and keeps cleanup isolated. |
| Linux | Docker for course parity; APT/RPM/Snap are valid alternatives | Container pins version; native service better matches host administration when intentionally studied. |
| macOS | Docker for parity; Homebrew is a valid alternative | Homebrew commonly tracks current releases, so record what it installs. |
2. Start a pinned loopback-only container
The Docker Official Image currently publishes
redis:8.10.1. The command below binds the host side
only to 127.0.0.1, so port 6379 is not
intentionally exposed on every host interface. It also requires
a disposable lab password and disables persistence for this
short installation exercise; Lesson 5 replaces this with an ACL
file and persistent volume.
docker pull redis:8.10.1docker run -d --name atlasmart-redis-ch01-quick -p 127.0.0.1:6379:6379 redis:8.10.1 redis-server --save "" --appendonly no --requirepass AtlasMart-QuickLab-Only-2026docker ps --filter name=atlasmart-redis-ch01-quickdocker logs --tail 50 atlasmart-redis-ch01-quick
PowerShell accepts the same command most reliably on one line; if you split it, use PowerShell’s backtick rather than the POSIX backslash. The port mapping is the security boundary that keeps the lab local. The sample password is public course material and is not suitable for any real environment.
3. Connect with redis-cli and prove which server answered
If redis-cli is not installed on the host, execute
it inside the container. This avoids adding another package and
makes the client version track the pinned image.
docker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli PINGdocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli HELLO 3docker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli INFO serverdocker exec atlasmart-redis-ch01-quick redis-cli --version
PING should return PONG.
HELLO 3 switches the connection to RESP3 and
returns properties including the exact server version, protocol
version, connection ID, mode, and role.
INFO server should independently report
redis_version:8.10.1. If those disagree with your
expectation, stop and investigate the endpoint instead of
continuing with a mislabeled lab.
4. Build the server/configuration evidence card
Administrative introspection is deliberately explicit.
CONFIG GET is powerful and may be restricted by
managed services or ACLs; use it only on this disposable lab or
where your operational role authorizes it.
docker inspect atlasmart-redis-ch01-quick --format '{{.Config.Image}} {{json .NetworkSettings.Ports}}'docker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli CONFIG GET binddocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli CONFIG GET protected-modedocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli CONFIG GET dirdocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli CONFIG GET savedocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli CONFIG GET appendonlydocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli ACL WHOAMIdocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli CLIENT INFOdocker exec -e REDISCLI_AUTH=AtlasMart-QuickLab-Only-2026 atlasmart-redis-ch01-quick redis-cli INFO keyspace
This quick lab authenticates as the default user
because requirepass is the
compatibility/simple-password path. Lesson 5 deliberately
disables that default user and creates named ACL identities.
Seeing default here is therefore documented state,
not a production recommendation.
5. Failure drills: wrong port, missing authentication, and the wrong endpoint
Safe labs are more useful when failure is observable. These drills change no server state.
# 1) Wrong port: expect connection refused / cannot connect.redis-cli -h 127.0.0.1 -p 6380 PING# 2) Correct port but no password: expect NOAUTH.redis-cli -h 127.0.0.1 -p 6379 PING# 3) Do NOT paste a production URI here.# First print/inspect the endpoint you intend to use, then connect explicitly.redis-cli -h 127.0.0.1 -p 6379
A connection-refused error points first to
address/listener/container state.
NOAUTH Authentication required proves you reached
Redis but have not established an authorized identity. An
authentication failure proves neither that the server is the
intended environment nor that your account should have more
privileges—verify endpoint and credentials independently.
6. Deliberately wrong approach: moving tags and accidental public exposure
docker run -p 6379:6379 redis:latest combines two
avoidable problems: a moving image tag and a host port
published on all interfaces by default. The Docker Official
Image documentation also warns that its container-oriented
defaults are designed for container networking, so publishing
the port without authentication/network controls can expose
Redis.
The correction is the pinned redis:8.10.1 image
plus 127.0.0.1:6379:6379, authentication, and a
configuration you can inspect. In production, go further:
isolate Redis on private networks, use ACLs, use TLS where
traffic crosses trust boundaries, manage secrets outside source
code, and patch security releases promptly.
7. Cleanup/reset
Cleanup targets only the named disposable container. It does not prune images, volumes, or unrelated Docker resources.
docker rm -f atlasmart-redis-ch01-quickdocker ps -a --filter name=atlasmart-redis-ch01-quick
The final command should show no matching container. Keeping the pulled image is harmless and makes the Lesson 5 lab faster; remove it only if you intentionally want to reclaim space.
8. Production judgment
An installation is production-ready only after much more than
PONG: version/support policy, private network
reachability, named least-privilege identities, TLS,
persistence/backup, replication/failover, maxmemory/eviction,
monitoring, client timeout/retry policy, capacity headroom, and
tested upgrades all matter. A container makes packaging
repeatable; it does not supply those guarantees automatically.
Next, Lesson 4 goes below redis-cli to RESP itself
and explains how client connections, logical databases, command
atomicity, and Redis’s mostly single-threaded command-execution
model relate.
9. Summary and next step
You now have a pinned Redis 8.10.1 quick lab that is reachable
only through host loopback, requires authentication, exposes its
metadata through HELLO/INFO, and can
be removed without collateral cleanup. The important habit is
evidentiary: prove image, endpoint, version, protocol,
configuration, identity, and persistence before teaching or
debugging higher-level behavior.
Check your understanding
- Why does this course pin redis:8.10.1 instead of redis:latest?
- Why bind Docker to 127.0.0.1:6379 rather than simply -p 6379:6379?
- What does NOAUTH tell you?
- Why use HELLO 3 and INFO server together?
- Why is the quick lab not the final course configuration?
Review the answers
A moving tag can resolve to a different server after a pull, making commands, defaults, security posture, and reproducibility change without the lesson changing.
The explicit host IP keeps the published port on loopback for this local lab instead of intentionally exposing it on every host interface.
You reached a Redis endpoint that requires authentication, but your connection is not yet authenticated. It does not prove that the endpoint is the intended environment.
HELLO proves negotiated protocol/connection metadata; INFO server independently exposes server metadata. Cross-checking helps catch wrong-endpoint assumptions.
It uses the default user with a disposable password and disables persistence for setup simplicity. Lesson 5 replaces it with named ACL users and persistent configuration.
Authoritative references
- Install Redis Open Source — official platform installation paths
- Run Redis Open Source on Docker — Docker startup, config, persistence, and redis-cli guidance
- Redis Open Source 8.10 release notes — 8.10.1 security baseline
- HELLO command — RESP negotiation and connection/server metadata
- INFO command — server, memory, persistence, thread, and topology statistics
- Redis security — network exposure and protected mode