Chapter 01 · Redis Foundations, Redis 8, Deployment Choices, CLI, and Lab Setup
Build a Reproducible Lab with Configuration, Persistence Directory, Metrics, and Safe Authentication
Build the reusable Chapter 01 Redis lab with named ACL users, explicit persistence, a data volume, metrics, restart verification, and safe reset.
Learning outcomes
The quick container proved that Redis runs; it did not yet create a reusable course baseline. This final lesson establishes the Chapter 01 lab that later prompts can inherit: pinned Redis 8.10.1, named ACL identities, loopback-only host publication, explicit RDB+AOF configuration, a persistent Docker volume, observable metrics, and a reset path.
Build a repository-independent local lab from three small configuration files and a pinned container image.
Disable unauthenticated/default-user access and verify named administrative/application ACL identities.
Persist data to an explicit /data volume using AOF plus RDB and verify files/state before and after restart.
Collect server, memory, persistence, client, keyspace, and security evidence without destructive administration.
Perform safe failure/cleanup drills and distinguish persistence from tested backup/recovery.
Examples use Redis Open Source 8.10.1 and the Docker Official
Image redis:8.10.1, pinned on purpose. The lab
publishes Redis only on host loopback
(127.0.0.1:6379) and uses disposable AtlasMart
credentials. Never reuse these sample credentials or point the
commands at a production endpoint.
1. Lab directory and blast radius
Create a new disposable directory such as
redis-ch01-lab. It contains only
compose.yaml, redis.conf, and
users.acl. Docker creates one named/Compose-scoped
volume for Redis data. All course keys use the
atlasmart: prefix. Cleanup at the end removes only
this Compose project and its volume.
The two passwords below are deliberately published, disposable course credentials. They are acceptable only because the host port is bound to loopback and the environment contains no valuable data. Production secrets must be generated, stored, rotated, and delivered through an appropriate secret-management mechanism.
2. Define the pinned Compose service
services: redis: image: redis:8.10.1 container_name: atlasmart-redis-ch01 restart: "no" ports: - "127.0.0.1:6379:6379" command: ["redis-server", "/usr/local/etc/redis/redis.conf"] volumes: - ./redis.conf:/usr/local/etc/redis/redis.conf:ro - ./users.acl:/usr/local/etc/redis/users.acl:ro - atlasmart_redis_ch01_data:/datavolumes: atlasmart_redis_ch01_data:
The container listens on its own interface so Docker networking
can reach it, but Docker publishes the host endpoint only on
127.0.0.1. A persistent volume is mounted at
/data. The configuration and ACL files are
read-only inputs; the lab does not rely on mutating them with
CONFIG REWRITE or ACL SAVE.
3. Define persistence, network, and ACL configuration
bind 0.0.0.0protected-mode yesport 6379dir /datadbfilename dump.rdbappendonly yesappendfsync everysecappenddirname appendonlydirsave 300 10aclfile /usr/local/etc/redis/users.aclloglevel notice
appendonly yes enables AOF;
appendfsync everysec requests the common
every-second fsync policy; save 300 10 requests an
RDB snapshot after at least ten changes in five minutes. These
are course-lab settings, not universal production
recommendations. Chapter 17 will measure persistence tradeoffs
and data-loss windows.
user default offuser academy-admin on >AtlasMart-Admin-Lab-Only-2026 ~* &* +@alluser atlasmart-app on >AtlasMart-App-Lab-Only-2026 ~atlasmart:* &atlasmart:* +@read +@write +@connection -@dangerous
The default user is disabled.
academy-admin has broad lab administration rights.
atlasmart-app is restricted to
atlasmart: keys/channels and read/write/connection
categories, with dangerous commands removed last. Later security
lessons will tighten this further per workload.
4. Start the lab and verify identity before writing data
docker compose up -ddocker compose psdocker compose logs --tail 80 redisdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin PINGdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin HELLO 3docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin ACL WHOAMI
Do not proceed if the observed version is not 8.10.1, the
endpoint is not loopback-only on the host, or
ACL WHOAMI does not report
academy-admin. A lab should fail closed when its
identity differs from the course assumptions.
5. Verify configuration, persistence, memory, and connection evidence
docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO serverdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO memorydocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO persistencedocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO threadsdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO keyspacedocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin CONFIG GET dir dbfilename appendonly appendfsync appenddirname save protected-mode bind maxmemory maxmemory-policydocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin CLIENT LIST
INFO memory reports actual memory accounting; with
a tiny lab, allocator/RSS overhead can exceed logical dataset
bytes. maxmemory=0 on a self-managed 64-bit server
means no Redis-configured memory limit, not “unlimited physical
memory.” Do not copy that default into a production design
without a memory budget.
6. Prove application ACL boundaries
docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app SET atlasmart:session:7 active EX 600docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app HSET atlasmart:cart:991 item_count 2 subtotal_cents 7498docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app GET atlasmart:session:7# Expected denial: key pattern is outside ~atlasmart:*docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app SET otherapp:secret nope# Expected denial: dangerous admin command is outside the application roledocker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app CONFIG GET dir
Authorization errors are success criteria for the two negative tests. They prove the current ACL denies those operations; they do not prove the whole deployment is secure. Network reachability, TLS, secret storage, host/container isolation, and future feature-specific commands are separate controls.
7. Force an RDB snapshot and inspect AOF/RDB artifacts
AOF is already receiving writes according to the configured
policy. Trigger BGSAVE only in this disposable lab
to make the RDB artifact easy to inspect; in production,
background persistence can create fork/copy-on-write and I/O
pressure that must be planned.
docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin BGSAVEdocker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO persistencedocker exec atlasmart-redis-ch01 sh -lc 'find /data -maxdepth 2 -type f -print -exec ls -lh {} \;'docker volume ls --filter name=atlasmart_redis_ch01_data
Modern Redis uses multi-part AOF files under an append-only directory plus a manifest. The exact filenames can evolve, so teach the relationship—base/incremental AOF state and manifest—rather than hard-coding one generated sequence number. The presence of these files is still not a backup drill.
8. Restart verification: persistence is observable
docker compose restart redisdocker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app GET atlasmart:session:7docker exec -e REDISCLI_AUTH=AtlasMart-App-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user atlasmart-app HGETALL atlasmart:cart:991docker exec -e REDISCLI_AUTH=AtlasMart-Admin-Lab-Only-2026 atlasmart-redis-ch01 redis-cli --user academy-admin INFO persistence
If the session key expired during the exercise, its absence is expected TTL behavior, not necessarily persistence failure. The cart key has no TTL in this lesson and should survive the restart. Compare persistence load fields and startup logs before declaring success.
9. Deliberately wrong approach: persistence in an ephemeral path
A learner starts redis:8.10.1 with AOF enabled
but mounts no durable volume, writes important data, removes
the container, and assumes AOF means the data must still
exist. The persistence files lived inside the deleted
container filesystem, so the operational durability boundary
was wrong.
The fix is not merely “turn on AOF.” Make the target path explicit, place it on storage with known durability semantics, monitor disk/headroom and rewrite/fork behavior, back up the data independently, and run an actual restore/reconciliation drill. Chapter 24 will treat backup/restore as an operational capability rather than a file-existence checkbox.
10. Cleanup/reset and reproducibility record
docker compose down -vdocker ps -a --filter name=atlasmart-redis-ch01docker volume ls --filter name=atlasmart_redis_ch01_data
Keep the three configuration files if you want to repeat the
chapter. Delete them only after confirming they contain no real
secrets—the published credentials are intentionally lab-only. Do
not use docker system prune as course cleanup
because it can remove unrelated resources.
Chapter 01 reproducibility record:
- Redis Open Source: 8.10.1 (re-check current security release before future generation).
-
Image: Docker Official Image
redis:8.10.1; host port 6379 bound to loopback only. - Topology: standalone; no replicas, Sentinel, or Cluster yet.
-
Protocol: RESP2 by default, RESP3 demonstrated with
HELLO 3. - Security: named ACL users in the persistent lab; TLS not configured because traffic stays on local host/container lab network.
- Logical DB: DB0 by default; DB1 used only for the standalone semantic demonstration in Lesson 4.
-
Persistence: AOF every-second fsync plus RDB save rule; volume
at
/data. - maxmemory/eviction: observe actual defaults; Chapter 18 designs a memory budget before changing them.
- Search/JSON/vector/time-series/probabilistic capabilities: present in Redis 8 distributions but not required for Chapter 01 labs.
11. Production judgment
This lab intentionally chooses clarity over production completeness. A production Redis platform still needs explicit TLS/private-network design, secret rotation, replica/failover topology, maxmemory and eviction policy, backup destination and restore testing, monitoring/alerts, client timeout/retry/pool policy, capacity headroom, security patching, and change/upgrade runbooks. Managed services shift who implements parts of that list but do not remove application responsibility.
The chapter is now ready to move into key design. Chapter 02 begins with naming schemes, namespaces, hash tags, cardinality, expiration, scanning, type introspection, and lifecycle policy—using this same AtlasMart lab vocabulary.
12. Summary and next step
You built an explicit Redis 8.10.1 lab whose server identity, network exposure, ACL identity, configuration source, data directory, persistence files, client connections, memory state, and restart behavior can all be inspected. More importantly, you separated three commonly conflated ideas: persistence writes recoverable server state, replication creates live copies, and backups require independent restorable artifacts plus drills.
Check your understanding
- Why disable the default user in the persistent lab?
- Why can appendonly yes still fail to protect data after docker rm?
- What does a successful restart test prove?
- Why is maxmemory=0 not a production sizing plan?
- What is the safe cleanup command for this lab?
Review the answers
It removes implicit unauthenticated/default-user access and forces clients to prove a named ACL identity with explicit permissions.
If /data is only inside the container filesystem, deleting the container can delete the persistence files. Durability depends on the storage boundary as well as Redis settings.
It proves this lab reloaded the tested keys from its configured persisted state under the tested restart path. It does not prove off-host backup, disaster recovery, or every crash scenario.
It means Redis has no configured memory cap in that mode; the host still has finite RAM and Redis also needs overhead, buffers, persistence/fork headroom, and possibly index memory.
docker compose down -v from the lab directory, after confirming the Compose project is the intended disposable environment. It avoids broad Docker pruning.
Authoritative references
- Run Redis Open Source on Docker — pinned images, config mounts, redis-cli, and /data persistence
- Redis security — network boundaries and protected mode
- Redis ACL — users, command categories, key/channel patterns, and ACL files
- Redis persistence — RDB, AOF, fsync, multi-part AOF, and recovery considerations
- INFO command — server, client, memory, persistence, thread, and topology evidence
- Redis Open Source 8.10 release notes — 8.10.1 security baseline and 8.10 features