External aclfile vs. CONFIG SET for least-privilege credential rotation
29K reputation · 16 Apr 2020, 12:00 UTC
Implementing a least-privilege security model in Redis 7.0+ requires granular Access Control Lists (ACLs) to restrict users to specific keyspaces and command categories. A primary challenge arises when managing the lifecycle of these credentials, specifically when rotating passwords or updating permissions to prevent credential staleness.
There are two primary methods for managing these identities: maintaining a static aclfile for persistence or utilizing CONFIG SET and ACL SETUSER for dynamic runtime updates. While the aclfile provides a declarative source of truth that survives restarts, runtime updates offer immediate propagation without requiring a file reload.
The uncertainty lies in the trade-off between operational stability and the agility required for automated credential rotation. Using ACL SETUSER dynamically can lead to configuration drift if the external file is not synchronized, whereas relying solely on the aclfile may introduce latency in permission revocation.
- Which approach better supports an automated rotation pipeline without risking permission loss during a server restart?
- Is there a documented method to synchronize runtime
ACL SETUSERchanges back to a persistentaclfilewithout manual intervention?