Meta tags:
Headings (most frequently used words):
authentication, token, based, basic, for, user, cluster, with, and, use, create, an, access, to, your, clusters, by, using, manage, users, support, google, cloud, list, view, information, about, delete, from, secure, stay, organized, collections, save, categorize, content, on, preferences, benefits, modes, best, practices, before, you, begin, connect, rotate, zero, downtime, logs, verify, client, the, console, cli, apis, assign, roles, enable, tokens, uri, string, flags, products, pricing, resources, engage,
Text of the page (most frequently used words):
the (227), token (145), #authentication (115), user (98), for (96), #cluster (95), based (67), basic (66), you (60), and (53), redis (50), region (43), auth (37), gcloud (36), using (35), clusters (35), use (34), username (33), can (31), users (30), create (30), your (27), following (27), memorystore (26), that (24), about (22), access (22), tokens (22), delete (22), command (21), cluster_id (20), beta (20), information (19), cli (19), applications (18), google (17), this (17), cloud (16), with (16), from (16), manage (15), enable (15), make (14), list (14), want (13), replacements (12), where (12), view (12), which (11), connect (10), located (10), connections (10), default (10), authenticate (9), code (8), more (8), logs (8), supported (8), client (8), instance (8), see (7), thumb (7), are (7), rotate (7), downtime (7), secure (7), iam (7), management (7), maintenance (7), resources (6), support (6), all (6), update (6), new (6), port (6), multiple (6), important (6), security (6), have (6), when (6), automatically (6), project (6), service (6), api (6), overview (6), vpc (6), terms (5), samples (5), down (5), generates (5), data (5), audit (5), string (5), method (5), existing (5), after (5), mode (5), roles (5), network (5), commands (5), console (5), application (5), networking (5), search (5), persistence (5), cross (5), other (4), monitor (4), into (4), address (4), ip_address (4), compute (4), connection (4), resource (4), deleting (4), auth_token (4), then (4), must (4), describe (4), retrieve (4), creates (4), configure (4), encryption (4), secret (4), best (4), practices (4), guides (4), tools (4), set (4), vector (4), scale (4), instances (4), need (3), content (3), registered (3), admin (3), these (3), without (3), causing (3), flags (3), environment (3), uri (3), usage (3), has (3), before (3), two (3), creating (3), supports (3), either (3), their (3), verify (3), lightweight (3), enabled (3), role (3), documentation (3), ensures (3), transit (3), manager (3), credentials (3), databases (3), monitoring (3), backups (3), cmek (3), certificate (3), authority (3), replication (3), capacity (3), quickstart (3), product (3), 한국어 (2), 日本語 (2), עברית (2), português (2), brasil (2), italiano (2), indonesia (2), français (2), español (2), américa (2), latina (2), deutsch (2), english (2), sign (2), action (2), site (2), youtube (2), started (2), pricing (2), products (2), understand (2), last (2), updated (2), 2026 (2), utc (2), page (2), licensed (2), under (2), license (2), send (2), feedback (2), only (2), second (2), valid (2), additional (2), zero (2), number (2), reserved (2), attempting (2), engine (2), environments (2), separate (2), single (2), because (2), one (2), prevent (2), name (2), lets (2), actions (2), end (2), multi (2), credential (2), deactivate (2), 000 (2), local (2), aren (2), conditions (2), apply (2), enabling (2), might (2), any (2), widely (2), restrict (2), editor (2), owner (2), consumer (2), connectivity (2), sure (2), version (2), billing (2), selector (2), apis (2), begin (2), section (2), recommend (2), layer (2), operational (2), overhead (2), controls (2), them (2), rotation (2), policy (2), modes (2), compatibility (2), migrate (2), workloads (2), benefits (2), addition (2), feature (2), pre (2), features (2), sdk (2), languages (2), frameworks (2), infrastructure (2), costs (2), storage (2), observability (2), migration (2), industry (2), solutions (2), distributed (2), hybrid (2), multicloud (2), analytics (2), pipelines (2), hosting (2), development (2), high (2), issues (2), troubleshoot (2), metrics (2), info (2), rdb (2), aof (2), customer (2), managed (2), shared (2), control (2), library (2), networks (2), reference (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, join, cookies, privacy, tech, twitter, events, blog, engage, training, certification, architecture, center, getting, github, system, status, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missing, missingtheinformationsamplesineed, otherdown, tell, except, otherwise, noted, details, java, trademark, oracle, its, affiliates, developers, policies, apache, creative, commons, attribution, activity, operations, associated, removes, first, both, sections, each, explained, better, suited, individual, line, tool, scripting, configuration, broken, variables, arguments, formatted, used, convenience, necessary, example, hostname, contained, uniform, identifier, methods, accessing, original, critical, invalidates, belongs, belong, having, kill, doesn, run, nodes, revoke, rights, including, created, allow, initially, acts, revocable, continue, until, they, removed, impacted, however, require, cause, try, requires, authenticated, requests, although, remain, unaffected, utilize, subsequent, attempts, just, standard, assign, installed, latest, running, least, 489, components, note, initialize, install, learn, how, check, select, authenticates, confirm, ensure, complete, prerequisites, usernames, sent, plain, text, over, combine, transport, tls, provides, centralized, encrypted, vault, eliminates, sprawl, reduces, managing, manually, enforces, compliance, prevents, exposure, don, hardcode, instead, store, runtime, purposes, straightforward, sends, themselves, simple, primary, superuser, maintains, same, privileges, granted, adds, extra, protection, backward, time, supply, flexibility, gain, minimal, requirements, low, current, premises, already, facilitates, smooth, transition, solution, clients, identities, within, identity, subject, offerings, general, available, limited, launch, stage, descriptions, specific, preview, save, categorize, preferences, stay, organized, collections, home, isn, utilization, expensive, health, self, simulate, find, windows, build, llm, powered, langchain, integrate, technologies, json, limitations, query, syntax, indexing, vectors, dropindex, _list, generative, back, keys, custom, constraints, per, configurations, deletion, replica, count, work, secondary, scaling, terraform, provisioned, vpcs, provisioning, get, blocked, guidelines, node, specification, zone, availability, replicas, discover, start, free, skip, main,
Text of the page (random words):
manage multiple users to authenticate access to your clusters best practices for security purposes we recommend that you use the following best practices for basic token based authentication rotate user tokens use a rotation policy for user tokens use secret manager don t hardcode a user s basic token based authentication credentials in your application code instead store them in secret manager and retrieve them at runtime secret manager provides a centralized encrypted vault for user credentials which eliminates secret sprawl and reduces the operational overhead of managing credentials manually it enforces access controls by using iam and generates audit logs automatically this ensures compliance and prevents credential exposure combine basic token based authentication with transport layer security tls when you use basic token based authentication we recommend that you enable in transit encryption this ensures that usernames and tokens aren t sent in plain text over the network before you begin before you begin to secure your clusters by using basic token based authentication complete the prerequisites in this section verify client support for basic token based authentication to confirm that your client applications can support basic token based authentication ensure that the applications can use the auth command the default user authenticates to your client applications by using the following command auth token for this command token is the default user s authentication token all other users authenticate by using the following command auth username token for this command username and token are the user s username and authentication token for more information about the auth command see auth in the redis documentation use the google cloud console google cloud cli and apis to use the google cloud console gcloud cli and apis do the following in the google cloud console on the project selector page select or create a google cloud project go to the project selector make sure that billing is enabled for your project learn how to check if billing is enabled on a project install and initialize the google cloud cli gcloud cli note if you installed the gcloud cli then make sure you have the latest version by running gcloud components update to access the memorystore for redis cluster gcloud cli commands you need at least gcloud cli version 489 0 0 enable the memorystore for redis cluster api memorystore for redis cluster api enable the network connectivity api network connectivity api enable the service consumer management api service consumer management api assign roles to configure basic token based authentication for your clusters you must have one of these iam roles in your google cloud project roles redis admin the redis admin role roles owner the owner role roles editor the editor role manage basic token based authentication for clusters memorystore for redis cluster supports the following actions to manage basic token based authentication for clusters create a cluster with basic token based authentication enable basic token based authentication for a cluster create a basic token based authentication user for a cluster list basic token based authentication users for a cluster view information about a basic token based authentication user delete a basic token based authentication user from a cluster create a cluster with basic token based authentication by creating a cluster with basic token based authentication you have a lightweight and widely supported method to restrict a user s access to the cluster you can create the cluster by using the gcloud cli to create a cluster that has basic token based authentication enabled use the gcloud beta redis clusters create command gcloud beta redis clusters create cluster_id region region auth mode token auth make the following replacements cluster_id the id of the cluster that you want to create to use basic token based authentication region the region where you want the cluster to be located important after you enable basic token based authentication for the cluster the following conditions apply you can manage up to 1 000 local users after you enable basic token based authentication for the cluster you can t deactivate this authentication mode after you create a cluster with basic token based authentication memorystore for redis cluster creates the default user and generates an authentication token for the user automatically enable basic token based authentication for a cluster by enabling basic token based authentication for a cluster you have a lightweight and widely supported method to restrict a user s access to the cluster the default user can authenticate to the cluster by using just their token all other users authenticate by using a standard username and token for more information see verify client support for basic token based authentication enabling basic token based authentication might cause downtime for applications that try to create new connections because memorystore for redis cluster requires authenticated requests although existing connections remain unaffected to utilize basic token based authentication for any subsequent connection attempts to the cluster you must update your applications for more information see connect to a cluster by using basic token based authentication you can enable basic token based authentication for a cluster by using the gcloud cli to enable basic token based authentication use the gcloud beta redis clusters update command gcloud beta redis clusters update cluster_id region region auth mode token auth make the following replacements cluster_id the id of the cluster for which you want to enable basic token based authentication region the region where the cluster is located important after you enable basic token based authentication for the cluster the following conditions apply memorystore for redis cluster creates the default user and generates an authentication token for the user automatically existing connections aren t impacted however new client connections require users to authenticate to access your applications you can manage up to 1 000 local users you can t deactivate this authentication mode create a basic token based authentication user for a cluster by creating a basic token based authentication user for a cluster you configure the cluster to allow multi user authentication after the user logs in initially this authentication mode acts as a secure and revocable credential for new connections the user can continue to use the authentication token until either they delete it or the user is removed you can create a basic token based authentication user by using the gcloud cli to create the user use the gcloud beta redis clusters create token auth user command gcloud beta redis clusters create token auth user cluster_id region region token auth user username make the following replacements cluster_id the id of the cluster for which you want to create a basic token based authentication user region the region where the cluster is located username the username of the user important you can t delete the default user when you either create a cluster with basic token based authentication or enable basic token based authentication for the cluster memorystore for redis cluster creates this user automatically when a basic token based authentication user including the default user is created memorystore for redis cluster creates an authentication token for the user automatically list basic token based authentication users for a cluster you can retrieve a list of basic token based authentication users for a cluster by using the gcloud cli to list the users use the gcloud beta redis clusters token auth users list command gcloud beta redis clusters token auth users list cluster cluster_id region region make the following replacements cluster_id the id of the cluster for which you want to retrieve a list of basic token based authentication users region the region where the cluster is located view information about a basic token based authentication user you can view information about a basic token based authentication user by using the gcloud cli to view information about the user use the gcloud beta redis clusters token auth users describe command gcloud beta redis clusters token auth users describe username cluster cluster_id region region make the following replacements username the username of the basic token based authentication user about which you want to view information cluster_id the id of the cluster to which the user can authenticate region the region where the cluster is located delete a basic token based authentication user from a cluster by deleting a basic token based authentication user from a cluster you revoke the user s access rights to the cluster important you can t delete the default user from the cluster you can delete a basic token based authentication user from a cluster by using the gcloud cli to delete the user use the gcloud beta redis clusters token auth users delete command gcloud beta redis clusters token auth users delete username cluster cluster_id region region make the following replacements username the username of the basic token based authentication user cluster_id the id of the cluster from which you want to delete the user region the region where the cluster is located for the user that you re deleting memorystore for redis cluster doesn t end existing connections to end these connections run the following command on all nodes in the cluster client kill user username manage basic token based authentication for users memorystore for redis cluster supports the following actions to manage basic token based authentication for users create an authentication token for a user list authentication tokens for a user view information about an authentication token for a user delete an authentication token from a user create an authentication token for a user by creating an authentication token for a user you can rotate the user s existing token without causing downtime to your applications important users can have up to two authentication tokens having two tokens lets you rotate the user tokens for your applications with no downtime you can create an authentication token for a user by using the gcloud cli to create the user use the gcloud beta redis clusters token auth users create auth token command gcloud beta redis clusters token auth users create auth token username cluster cluster_id region region make the following replacements username the username of the user for which you want to create an authentication token cluster_id the id of the cluster that the user can access by using the token region the region where the cluster is located list authentication tokens for a user you can retrieve a list of authentication tokens for a user by using the gcloud cli to list the tokens use the gcloud beta redis clusters token auth users auth tokens list command gcloud beta redis clusters token auth users auth tokens list token auth user username cluster cluster_id region region make the following replacements username the username of the user to which the authentication tokens belong cluster_id the id of the cluster that the user can access by using the authentication tokens region the region where the cluster is located view information about an authentication token for a user you can view information about an authentication token for a user by using the gcloud cli to view the information use the gcloud beta redis clusters token auth users auth tokens describe command gcloud beta redis clusters token auth users auth tokens describe auth_token cluster cluster_id region region token auth user username make the following replacements auth_token the name of the authentication token about which you want to view information cluster_id the id of the cluster that the user can access by using the token region the region where the cluster is located username the username of the user to which the authentication token belongs delete an authentication token from a user deleting an authentication token from a user is a critical security action that invalidates the token important if this is the only authentication token for the user then you can t delete it if you want to rotate the token then you must create an additional token for the user before you can delete the original token you can delete an authentication token from a user by using the gcloud cli to delete the token use the gcloud beta redis clusters token auth users auth tokens delete command gcloud beta redis clusters token auth users auth tokens delete auth_token cluster cluster_id region region token auth user username make the following replacements auth_token the name of the authentication token that you want to delete from the user cluster_id the id of the cluster that you want to prevent the user from accessing by deleting the token region the region where the cluster is located username the username of the user that has a token that you want to delete connect to a cluster by using basic token based authentication you can use the following methods to connect to a cluster by using basic token based authentication uniform resource identifier uri string this single formatted string is used for convenience because all necessary connection information for example the user s username and token and the cluster s ip address and hostname is contained in one string flags this method is better suited for individual command line tool usage scripting or environments where the configuration is broken down into separate environment variables by using multiple separate arguments in the following sections each connection method is explained use a uri string to connect from a compute engine vm or a supported environment by using a uri string use the following command redis cli u redis username token ip_address port make the following replacements username the username of the user that s attempting to connect to the cluster token the user s authentication token ip_address the ip address of the cluster port the port number that s reserved for the cluster use flags to connect from a compute engine vm or a supported environment by using flags use the following command redis cli user username a token h ip_address p port make the following replacements username the username of the user that s attempting to connect to the cluster token the user s authentication token ip_address the ip address of the cluster port the port number that s reserved for the cluster rotate a user s authentication token with zero downtime to rotate a user s authentication token without causing downtime to your applications do the following create an additional authentication token for the user memorystore for redis cluster generates a second valid token both tokens are valid update your applications update your applications to use the new token delete the authentication token for the user memorystore for...
|