Flow-project bind redis to localhost for security

96 Views Asked by At

I'm learning flow tutorials and running into a security issue that the package "redis" used by flow is listening to the whole internet.

See https://redis.io/topics/security

The solution is to bind redis to 127.0.0.1 in redis.conf listed in above link. However it seems like flow is calling redis from ray, and I'm not sure how this works in flow.

Is there a fast solution to fix this?

Thanks!

1

There are 1 best solutions below

6
iOSPractice On

I'm answering this question here but future questions should be directed to the group slack for quicker answers! Sorry for the confusion; we've amended our website to point people there. https://join.slack.com/t/flow-users/shared_invite/enQtODQ0NDYxMTQyNDY2LTY1ZDVjZTljM2U0ODIxNTY5NTQ2MmUxMzYzNzc5NzU4ZTlmNGI2ZjFmNGU4YjVhNzE3NjcwZTBjNzIxYTg5ZmY

Answer here: You need to give ray a specific port to bind to. In your command line run: ray start --redis-port XXXX and then do ray.init(address)