Chapter 01 · Redis Foundations, Redis 8, Deployment Choices, CLI, and Lab Setup

Build a Reproducible Lab with Configuration, Persistence Directory, Metrics, and Safe Authentication

Build the reusable Chapter 01 Redis lab with named ACL users, explicit persistence, a data volume, metrics, restart verification, and safe reset.

Intermediate110–140 minutesCompose + persistence + ACL labRedis Open Source 8.10.1Free/local-firstLast reviewed: September 6, 2026

Learning outcomes

The quick container proved that Redis runs; it did not yet create a reusable course baseline. This final lesson establishes the Chapter 01 lab that later prompts can inherit: pinned Redis 8.10.1, named ACL identities, loopback-only host publication, explicit RDB+AOF configuration, a persistent Docker volume, observable metrics, and a reset path.

01

Build a repository-independent local lab from three small configuration files and a pinned container image.

02

Disable unauthenticated/default-user access and verify named administrative/application ACL identities.

03

Persist data to an explicit /data volume using AOF plus RDB and verify files/state before and after restart.

04

Collect server, memory, persistence, client, keyspace, and security evidence without destructive administration.

05

Perform safe failure/cleanup drills and distinguish persistence from tested backup/recovery.

Course lab baseline

Examples use Redis Open Source 8.10.1 and the Docker Official Image redis:8.10.1, pinned on purpose. The lab publishes Redis only on host loopback (127.0.0.1:6379) and uses disposable AtlasMart credentials. Never reuse these sample credentials or point the commands at a production endpoint.

1. Lab directory and blast radius

Create a new disposable directory such as redis-ch01-lab. It contains only compose.yaml, redis.conf, and users.acl. Docker creates one named/Compose-scoped volume for Redis data. All course keys use the atlasmart: prefix. Cleanup at the end removes only this Compose project and its volume.

Sample-secret warning

The two passwords below are deliberately published, disposable course credentials. They are acceptable only because the host port is bound to loopback and the environment contains no valuable data. Production secrets must be generated, stored, rotated, and delivered through an appropriate secret-management mechanism.

2. Define the pinned Compose service

yaml · compose.yaml
services:  redis:    image: redis:8.10.1    container_name: atlasmart-redis-ch01    restart: "no"    ports:      - "127.0.0.1:6379:6379"    command: ["redis-server", "/usr/local/etc/redis/redis.conf"]    volumes:      - ./redis.conf:/usr/local/etc/redis/redis.conf:ro      - ./users.acl:/usr/local/etc/redis/users.acl:ro      - atlasmart_redis_ch01_data:/datavolumes:  atlasmart_redis_ch01_data:

The container listens on its own interface so Docker networking can reach it, but Docker publishes the host endpoint only on 127.0.0.1. A persistent volume is mounted at /data. The configuration and ACL files are read-only inputs; the lab does not rely on mutating them with CONFIG REWRITE or ACL SAVE.

3. Define persistence, network, and ACL configuration

redis.conf · redis.conf
bind 0.0.0.0protected-mode yesport 6379dir /datadbfilename dump.rdbappendonly yesappendfsync everysecappenddirname appendonlydirsave 300 10aclfile /usr/local/etc/redis/users.aclloglevel notice

appendonly yes enables AOF; appendfsync everysec requests the common every-second fsync policy; save 300 10 requests an RDB snapshot after at least ten changes in five minutes. These are course-lab settings, not universal production recommendations. Chapter 17 will measure persistence tradeoffs and data-loss windows.

acl · users.acl
user default offuser academy-admin on >AtlasMart-Admin-Lab-Only-2026 ~* &* +@alluser atlasmart-app on >AtlasMart-App-Lab-Only-2026 ~atlasmart:* &atlasmart:* +@read +@write +@connection -@dangerous

The default user is disabled. academy-admin has broad lab administration rights. atlasmart-app is restricted to atlasmart: keys/channels and read/write/connection categories, with dangerous commands removed last. Later security lessons will tighten this further per workload.

4. Start the lab and verify identity before writing data

shell / PowerShell · start and inspect the Compose lab
docker compose up -ddocker compose psdocker compose logs --tail 80 redisdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin PINGdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin HELLO 3docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin ACL WHOAMI

Do not proceed if the observed version is not 8.10.1, the endpoint is not loopback-only on the host, or ACL WHOAMI does not report academy-admin. A lab should fail closed when its identity differs from the course assumptions.

5. Verify configuration, persistence, memory, and connection evidence

shell / PowerShell · administrative evidence card
docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO serverdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO memorydocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO persistencedocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO threadsdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO keyspacedocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin CONFIG GET dir dbfilename appendonly appendfsync appenddirname save protected-mode bind maxmemory maxmemory-policydocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin CLIENT LIST

INFO memory reports actual memory accounting; with a tiny lab, allocator/RSS overhead can exceed logical dataset bytes. maxmemory=0 on a self-managed 64-bit server means no Redis-configured memory limit, not “unlimited physical memory.” Do not copy that default into a production design without a memory budget.

6. Prove application ACL boundaries

shell / PowerShell · write allowed AtlasMart state as the application user
docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app SET atlasmart:session:7 active EX 600docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app HSET atlasmart:cart:991 item_count 2 subtotal_cents 7498docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app GET atlasmart:session:7# Expected denial: key pattern is outside ~atlasmart:*docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app SET otherapp:secret nope# Expected denial: dangerous admin command is outside the application roledocker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app CONFIG GET dir

Authorization errors are success criteria for the two negative tests. They prove the current ACL denies those operations; they do not prove the whole deployment is secure. Network reachability, TLS, secret storage, host/container isolation, and future feature-specific commands are separate controls.

7. Force an RDB snapshot and inspect AOF/RDB artifacts

AOF is already receiving writes according to the configured policy. Trigger BGSAVE only in this disposable lab to make the RDB artifact easy to inspect; in production, background persistence can create fork/copy-on-write and I/O pressure that must be planned.

shell / PowerShell · create and inspect persistence evidence
docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin BGSAVEdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO persistencedocker exec atlasmart-redis-ch01 sh -lc 'find /data -maxdepth 2 -type f -print -exec ls -lh {} \;'docker volume ls --filter name=atlasmart_redis_ch01_data

Modern Redis uses multi-part AOF files under an append-only directory plus a manifest. The exact filenames can evolve, so teach the relationship—base/incremental AOF state and manifest—rather than hard-coding one generated sequence number. The presence of these files is still not a backup drill.

8. Restart verification: persistence is observable

shell / PowerShell · restart the same service and verify state reload
docker compose restart redisdocker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app GET atlasmart:session:7docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app HGETALL atlasmart:cart:991docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO persistence

If the session key expired during the exercise, its absence is expected TTL behavior, not necessarily persistence failure. The cart key has no TTL in this lesson and should survive the restart. Compare persistence load fields and startup logs before declaring success.

9. Deliberately wrong approach: persistence in an ephemeral path

Failure case

A learner starts redis:8.10.1 with AOF enabled but mounts no durable volume, writes important data, removes the container, and assumes AOF means the data must still exist. The persistence files lived inside the deleted container filesystem, so the operational durability boundary was wrong.

The fix is not merely “turn on AOF.” Make the target path explicit, place it on storage with known durability semantics, monitor disk/headroom and rewrite/fork behavior, back up the data independently, and run an actual restore/reconciliation drill. Chapter 24 will treat backup/restore as an operational capability rather than a file-existence checkbox.

10. Cleanup/reset and reproducibility record

shell / PowerShell · remove only this lab and its data volume
docker compose down -vdocker ps -a --filter name=atlasmart-redis-ch01docker volume ls --filter name=atlasmart_redis_ch01_data

Keep the three configuration files if you want to repeat the chapter. Delete them only after confirming they contain no real secrets—the published credentials are intentionally lab-only. Do not use docker system prune as course cleanup because it can remove unrelated resources.

Chapter 01 reproducibility record:

  • Redis Open Source: 8.10.1 (re-check current security release before future generation).
  • Image: Docker Official Image redis:8.10.1; host port 6379 bound to loopback only.
  • Topology: standalone; no replicas, Sentinel, or Cluster yet.
  • Protocol: RESP2 by default, RESP3 demonstrated with HELLO 3.
  • Security: named ACL users in the persistent lab; TLS not configured because traffic stays on local host/container lab network.
  • Logical DB: DB0 by default; DB1 used only for the standalone semantic demonstration in Lesson 4.
  • Persistence: AOF every-second fsync plus RDB save rule; volume at /data.
  • maxmemory/eviction: observe actual defaults; Chapter 18 designs a memory budget before changing them.
  • Search/JSON/vector/time-series/probabilistic capabilities: present in Redis 8 distributions but not required for Chapter 01 labs.

11. Production judgment

This lab intentionally chooses clarity over production completeness. A production Redis platform still needs explicit TLS/private-network design, secret rotation, replica/failover topology, maxmemory and eviction policy, backup destination and restore testing, monitoring/alerts, client timeout/retry/pool policy, capacity headroom, security patching, and change/upgrade runbooks. Managed services shift who implements parts of that list but do not remove application responsibility.

The chapter is now ready to move into key design. Chapter 02 begins with naming schemes, namespaces, hash tags, cardinality, expiration, scanning, type introspection, and lifecycle policy—using this same AtlasMart lab vocabulary.

12. Summary and next step

You built an explicit Redis 8.10.1 lab whose server identity, network exposure, ACL identity, configuration source, data directory, persistence files, client connections, memory state, and restart behavior can all be inspected. More importantly, you separated three commonly conflated ideas: persistence writes recoverable server state, replication creates live copies, and backups require independent restorable artifacts plus drills.

Check your understanding

  1. Why disable the default user in the persistent lab?
  2. Why can appendonly yes still fail to protect data after docker rm?
  3. What does a successful restart test prove?
  4. Why is maxmemory=0 not a production sizing plan?
  5. What is the safe cleanup command for this lab?
Review the answers

It removes implicit unauthenticated/default-user access and forces clients to prove a named ACL identity with explicit permissions.

If /data is only inside the container filesystem, deleting the container can delete the persistence files. Durability depends on the storage boundary as well as Redis settings.

It proves this lab reloaded the tested keys from its configured persisted state under the tested restart path. It does not prove off-host backup, disaster recovery, or every crash scenario.

It means Redis has no configured memory cap in that mode; the host still has finite RAM and Redis also needs overhead, buffers, persistence/fork headroom, and possibly index memory.

docker compose down -v from the lab directory, after confirming the Compose project is the intended disposable environment. It avoids broad Docker pruning.

Authoritative references

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.