# include /path/to/local.conf
# include /path/to/other.conf
# include /path/to/fragments/*.conf
loadmodule /usr/lib/redis/modules/rejson.so
loadmodule /usr/lib/redis/modules/redisbloom.so
loadmodule /usr/lib/redis/modules/redistimeseries.so
loadmodule /usr/lib/redis/modules/redisearch.so
bind * -::*
protected-mode no
# no - Block for any connection (remain immutable)
# yes - Allow for any connection (no protection)
# local - Allow only for local connections. Ones originating from the
port 6379
tcp-backlog 511
timeout 0
tcp-keepalive 300
################################# TLS/SSL #####################################
#tls-port 6379
#tls-cert-file /etc/redis/certs/haedongg.net.crt
#tls-key-file /etc/redis/certs/haedongg.net.key
#tls-ca-cert-file /etc/redis/certs/ca.crt
#tls-ca-cert-dir /etc/redis/certs/
#daemonize yes
supervised systemd
loglevel notice
logfile /var/log/redis/redis-server.log
databases 16
always-show-logo no
set-proc-title yes
proc-title-template "{title} {listen-addr} {server-mode}"
locale-collate ""
################################ SNAPSHOTTING ################################
# * After 3600 seconds (an hour) if at least 1 change was performed
# * After 300 seconds (5 minutes) if at least 100 changes were performed
# * After 60 seconds if at least 10000 changes were performed
save 600 1 300 10 60 1000 10 10000 1 100000
stop-writes-on-bgsave-error yes
rdbcompression yes
rdbchecksum yes
dbfilename haedongg.rdb
rdb-del-sync-files no
dir /xvdb/redis/
################################# REPLICATION #################################
# replicaof trino.haedongg.net 6379
replica-serve-stale-data yes
replica-read-only yes
repl-diskless-sync yes
repl-diskless-sync-delay 5
repl-diskless-sync-max-replicas 0
repl-diskless-load disabled
# repl-ping-replica-period 10
repl-disable-tcp-nodelay no
replica-priority 100
################################## SECURITY ###################################
# Redis ACL users are defined in the following format:
# user <username> ... acl rules ...
# For example:
# user worker +@list +@connection ~jobs:* on >ffa9203c493aa99
acllog-max-len 128
# Using an external ACL file
# aclfile /etc/redis/users.acl
################################### CLIENTS ####################################
# maxclients 10000
############################## MEMORY MANAGEMENT ################################
maxmemory 2G
# volatile-lru -> Evict using approximated LRU, only keys with an expire set.
# allkeys-lru -> Evict any key using approximated LRU.
# volatile-lfu -> Evict using approximated LFU, only keys with an expire set.
# allkeys-lfu -> Evict any key using approximated LFU.
# volatile-random -> Remove a random key having an expire set.
# allkeys-random -> Remove a random key, any key.
# volatile-ttl -> Remove the key with the nearest expire time (minor TTL)
# noeviction -> Don't evict anything, just return an error on write operations.
#
# LRU means Least Recently Used
# LFU means Least Frequently Used
# maxmemory-policy noeviction
# replica-ignore-maxmemory yes
############################# LAZY FREEING ####################################
lazyfree-lazy-eviction no
lazyfree-lazy-expire no
lazyfree-lazy-server-del no
replica-lazy-flush no
lazyfree-lazy-user-del no
lazyfree-lazy-user-flush no
################################ THREADED I/O #################################
io-threads 4
############################ KERNEL OOM CONTROL ##############################
oom-score-adj no
oom-score-adj-values 0 200 800
#################### KERNEL transparent hugepage CONTROL ######################
disable-thp yes
############################## APPEND ONLY MODE ###############################
appendonly no
appendfilename "appendonly.aof"
appenddirname "appendonlydir"
appendfsync everysec
no-appendfsync-on-rewrite no
auto-aof-rewrite-percentage 100
auto-aof-rewrite-min-size 64mb
aof-load-truncated yes
aof-use-rdb-preamble yes
aof-timestamp-enabled no
################################ SHUTDOWN #####################################
shutdown-timeout 5
# The options used on signaled shutdown can include the following values:
# default: Saves RDB snapshot only if save points are configured.
# Waits for lagging replicas to catch up.
# save: Forces a DB saving operation even if no save points are configured.
# nosave: Prevents DB saving operation even if one or more save points are configured.
# now: Skips waiting for lagging replicas.
# force: Ignores any errors that would normally prevent the server from exiting.
# shutdown-on-sigint default
# shutdown-on-sigterm default
################################ REDIS CLUSTER ###############################
# cluster-enabled yes
################################## SLOW LOG ###################################
slowlog-log-slower-than 10000
slowlog-max-len 128
################################ LATENCY MONITOR ##############################
latency-monitor-threshold 0
############################# EVENT NOTIFICATION ##############################
notify-keyspace-events ""
############################### ADVANCED CONFIG ###############################
hash-max-listpack-entries 512
hash-max-listpack-value 64
list-max-listpack-size -2
list-compress-depth 0
set-max-intset-entries 512
set-max-listpack-entries 128
set-max-listpack-value 64
zset-max-listpack-entries 128
zset-max-listpack-value 64
hll-sparse-max-bytes 3000
stream-node-max-bytes 4096
stream-node-max-entries 100
activerehashing yes
client-output-buffer-limit normal 0 0 0
client-output-buffer-limit replica 256mb 64mb 60
client-output-buffer-limit pubsub 32mb 8mb 60
# Client eviction is configured using the maxmemory-clients setting as follows:
# 0 - client eviction is disabled (default)
# maxmemory-clients 1g
# maxmemory-clients 5%
# proto-max-bulk-len 512mb
hz 10
dynamic-hz yes
aof-rewrite-incremental-fsync yes
rdb-save-incremental-fsync yes
########################### ACTIVE DEFRAGMENTATION #######################
jemalloc-bg-thread yes
#------------------------------
# GENERAL
#------------------------------
bind 127.0.0.1 ::1 # Change to 0.0.0.0 for remote access (secure with firewall!)
protected-mode yes
port 6379
tcp-backlog 511
#------------------------------
# SECURITY
#------------------------------
requirepass StrongRedisPasswordHere # Set a strong password
rename-command FLUSHALL "" # Disable dangerous commands (optional)
rename-command CONFIG "" # Disable config changes at runtime (optional)
#------------------------------
# PERSISTENCE
#------------------------------
save 900 1
save 300 10
save 60 10000
stop-writes-on-bgsave-error yes
rdbcompression yes
rdbchecksum yes
dbfilename dump.rdb
dir /var/lib/redis
# Append Only File (AOF) for durability
appendonly yes
appendfilename "appendonly.aof"
appendfsync everysec
no-appendfsync-on-rewrite no
#------------------------------
# MEMORY MANAGEMENT
#------------------------------
maxmemory 1gb # Adjust based on system RAM
maxmemory-policy allkeys-lru # Use LRU eviction
lazyfree-lazy-eviction yes # Improve eviction performance
#------------------------------
# LOGGING
#------------------------------
loglevel notice
logfile /var/log/redis/redis-server.log
#------------------------------
# BACKGROUND OPERATIONS
#------------------------------
daemonize no # systemd doesn't require daemon mode
supervised systemd # enable systemd supervision
pidfile /var/run/redis/redis-server.pid
#------------------------------
# NETWORKING & PERFORMANCE
#------------------------------
tcp-keepalive 300
timeout 0 # No idle timeout
#---------------------------------
# BASIC SENTINEL CONFIGURATION
#---------------------------------
port 26379
bind 0.0.0.0 # Allow external access (secure with firewall!)
daemonize no
supervised systemd
logfile "/var/log/redis/sentinel.log"
dir "/var/lib/redis"
#---------------------------------
# MONITOR TARGET REDIS MASTER
# Syntax: sentinel monitor <name> <ip> <port> <quorum>
#---------------------------------
sentinel monitor mymaster 192.168.1.100 6379 2
#---------------------------------
# AUTHENTICATION (REQUIRED IF REDIS HAS PASSWORD)
#---------------------------------
sentinel auth-pass mymaster StrongRedisPasswordHere
#---------------------------------
# FAILOVER BEHAVIOR
#---------------------------------
sentinel down-after-milliseconds mymaster 5000 # Time to consider master down
sentinel parallel-syncs mymaster 1 # Sync slaves one at a time
sentinel failover-timeout mymaster 10000 # Total time before failing over
#---------------------------------
# CLIENT NOTIFICATIONS
#---------------------------------
sentinel notification-script mymaster /etc/redis/sentinel-notify.sh
sentinel client-reconfig-script mymaster /etc/redis/sentinel-reconfig.sh