Your support encourages me to keep creating/supporting my open-source projects. If you found value in this project, you can buy me a coffee to keep me inspired.
Redis MCP Server is a Model Context Protocol server that provides tools for managing and interacting with Redis databases. Built on Alpine Linux for minimal footprint and maximum security, wrapped with mcp-proxy (replacing supergateway) for StreamableHTTP/SSE transport.
| Architecture | Tag Prefix | Status |
|---|---|---|
| x86-64 | amd64-<version> | Stable |
| ARM64 | arm64v8-<version> | Stable |
Multi-arch images automatically select the correct architecture for your system.
| Tag | Stability | Description | Use Case |
|---|---|---|---|
stable | High | Most stable release | Recommended for production |
latest | High | Latest stable release | Stay current with stable features |
0.5.1 | High | Specific version | Specific version |
beta | Low | Beta releases | Testing only |
CRITICAL: Do NOT expose this container directly to the internet without proper security measures (reverse proxy, SSL/TLS, authentication, firewall rules).
services:
redis-mcp-server:
image: mekayelanik/redis-mcp-server:stable
container_name: redis-mcp-server
restart: unless-stopped
ports:
- "8030:8030"
environment:
- PORT=8030
- INTERNAL_PORT=38011
- PUID=1000
- PGID=1000
- TZ=Asia/Dhaka
- PROTOCOL=SHTTP
# ENABLE_HTTPS=false is plaintext over the wire. Safe ONLY for loopback
# / trusted internal networks. Set to "true" for any public, multi-host,
# or untrusted deployment — HAProxy auto-generates a self-signed cert
# if none is mounted under /etc/haproxy/certs/.
- ENABLE_HTTPS=false
- HTTP_VERSION_MODE=auto
# mcp-proxy session model. Stateful by default — one stdio child shared
# across all sessions (multiplexed via JSON-RPC ids). Set to true only
# if full per-request isolation is required (memory-hostile).
- MCP_PROXY_STATELESS=false
# Cap virtual memory of the redis-mcp stdio child (MiB; 0 disables)
- REDIS_MAX_MEM_MB=1024
# HAProxy concurrency caps (0 disables)
- HAPROXY_FRONTEND_MAXCONN=64
- HAPROXY_SERVER_MAXCONN=16
# Redis connection settings
# - REDIS_URL=redis://localhost:6379
# - REDIS_HOST=localhost
# - REDIS_PORT=6379
# - REDIS_USERNAME=
# - REDIS_PWD=
# - REDIS_DB=0
# - REDIS_SSL=false
# - REDIS_SSL_CA_PATH=
# - REDIS_SSL_KEYFILE=
# - REDIS_SSL_CERTFILE=
# - REDIS_SSL_CERT_REQS=required
# - REDIS_SSL_CA_CERTS=
# - REDIS_CLUSTER_MODE=false
# Optional: require Bearer token auth at HAProxy layer
# - API_KEY=replace-with-strong-secret
hostname: redis-mcp-server
domainname: local
Deploy:
docker compose up -d
docker compose logs -f redis-mcp-server
docker run -d \
--name=redis-mcp-server \
--restart=unless-stopped \
-p 8030:8030 \
-e PORT=8030 \
-e INTERNAL_PORT=38011 \
-e PUID=1000 \
-e PGID=1000 \
-e TZ=Asia/Dhaka \
-e PROTOCOL=HTTP \
-e ENABLE_HTTPS=false \
-e HTTP_VERSION_MODE=auto \
mekayelanik/redis-mcp-server:stable
| Protocol | Endpoint | Description |
|---|---|---|
| SHTTP | http://host-ip:8030/mcp | Streamable HTTP (default; exposed simultaneously) |
| SSE | http://host-ip:8030/sse | Server-Sent Events (exposed simultaneously) |
| Health | http://host-ip:8030/healthz | Health check (answered by HAProxy, sub-millisecond) |
When HTTPS is enabled (ENABLE_HTTPS=true), use TLS endpoints:
| Protocol | Endpoint |
|---|---|
| SHTTP | https://host-ip:8030/mcp |
| SSE | https://host-ip:8030/sse |
WebSocket transport was dropped in the migration to
mcp-proxy. SettingPROTOCOL=WSwill now fail at startup with a clear message. UseSHTTPorSSEinstead.Security Warning: The container now defaults to HTTP (
ENABLE_HTTPS=false) for easier local setup. UseENABLE_HTTPS=truefor production, public networks, or any untrusted environment.ARM Devices: Allow 30-60 seconds for initialization before accessing endpoints.
| Variable | Default | Description |
|---|---|---|
PORT | 8030 | External HAProxy port |
INTERNAL_PORT | 38011 | Internal mcp-proxy port (loopback) |
MCP_PROXY_STATELESS | false | Share one stdio child across sessions; flip to true for per-request isolation |
REDIS_MAX_MEM_MB | 0 | Virtual memory cap on redis-mcp child (0 disables) |
HAPROXY_FRONTEND_MAXCONN | (unset) | Cap concurrent connections at HAProxy frontend |
HAPROXY_SERVER_MAXCONN | (unset) | Cap concurrent connections to mcp-proxy backend |
PUID | 1000 | User ID for file permissions |
PGID | 1000 | Group ID for file permissions |
TZ | Asia/Dhaka | Container timezone (TZ database) |
PROTOCOL | SHTTP | Default transport protocol |
REDIS_URL | (empty) | Full Redis connection URL (e.g. redis://user:pass@host:6379) |
REDIS_HOST | 127.0.0.1 | Redis server hostname |
REDIS_PORT | 6379 | Redis server port |
REDIS_USERNAME | (empty) | Redis authentication username |
REDIS_PWD | (empty) | Redis authentication password |
REDIS_DB | 0 | Redis database number |
REDIS_SSL | false | Enable SSL for Redis connection (true, 1, t) |
REDIS_SSL_CA_PATH | (empty) | Path to SSL CA file |
REDIS_SSL_KEYFILE | (empty) | Path to SSL key file |
REDIS_SSL_CERTFILE | (empty) | Path to SSL certificate file |
REDIS_SSL_CERT_REQS | required | SSL certificate requirements |
REDIS_SSL_CA_CERTS | (empty) | Path to SSL CA certificates |
REDIS_CLUSTER_MODE | false | Enable Redis Cluster mode (true, 1, t) |
API_KEY | (empty) | Enables Bearer token auth (Authorization: Bearer <API_KEY>) |
CORS | (empty) | Comma-separated CORS origins, supports * |
ENABLE_HTTPS | false | Enables TLS termination in HAProxy |
TLS_CERT_PATH | /etc/haproxy/certs/server.crt | TLS cert path |
TLS_KEY_PATH | /etc/haproxy/certs/server.key | TLS private key path |
TLS_PEM_PATH | /etc/haproxy/certs/server.pem | Combined PEM file used by HAProxy |
TLS_CN | localhost | CN for auto-generated certificate |
TLS_SAN | DNS:<TLS_CN> | SAN for auto-generated certificate |
TLS_DAYS | 365 | Auto-generated cert validity period |
TLS_MIN_VERSION | TLSv1.3 | Minimum TLS protocol (TLSv1.2 or TLSv1.3) |
HTTP_VERSION_MODE | auto | auto, all, h1, h2, h3, h1+h2 |
RATE_LIMIT | 0 | Max requests per RATE_LIMIT_PERIOD per IP (0 = disabled) |
RATE_LIMIT_PERIOD | 10s | Sliding window for rate limiting (e.g., 10s, 1m, 1h) |
MAX_CONNECTIONS_PER_IP | 0 | Max concurrent connections per IP (0 = disabled) |
IP_ALLOWLIST | (empty) | Comma-separated IPs/CIDRs to allow (all others blocked) |
IP_BLOCKLIST | (empty) | Comma-separated IPs/CIDRs to block |
ENABLE_HTTPS=true and cert files are missing, the container auto-generates a self-signed certificate.TLS_CERT_PATH and TLS_KEY_PATH exist, they are merged into TLS_PEM_PATH and used directly.HTTP_VERSION_MODE=h3 (or auto) enables HTTP/3 only when HAProxy build includes QUIC; otherwise it safely falls back.API_KEY to enforce authentication at reverse proxy level.Authorization: Bearer <API_KEY>.RATE_LIMIT=100 to allow 100 requests per RATE_LIMIT_PERIOD (default 10s) per IP. Exceeding the limit returns HTTP 429 with a Retry-After header.MAX_CONNECTIONS_PER_IP=50 to cap concurrent connections per IP. Exceeding returns HTTP 429.IP_BLOCKLIST=192.0.2.0/24,198.51.100.5 to block specific IPs/CIDRs. Blocked IPs receive HTTP 403.IP_ALLOWLIST=10.0.0.0/8,192.168.1.0/24 to allow only listed IPs/CIDRs. All others receive HTTP 403. Localhost is always allowed.mcp-proxy runs the Redis MCP backend as a single long-lived stdio child and multiplexes all client sessions through it via JSON-RPC ids. This caps the expected memory footprint; the knobs below cap the worst case:
MCP_PROXY_STATELESS=false (default) — share one backend child across all sessions. Recommended for almost every deployment. Flip to true only when you genuinely need per-request isolation.REDIS_MAX_MEM_MB=1024 — caps the virtual-memory size of the redis-mcp child via prlimit --as. A runaway backend gets OOM-killed by the kernel before it exhausts the host.HAPROXY_FRONTEND_MAXCONN=64 + HAPROXY_SERVER_MAXCONN=16 — bound concurrent connections at the HAProxy layer so a burst cannot saturate the upstream stdio bridge./healthz is answered directly by HAProxy with a local 200 — Docker's container healthcheck no longer depends on upstream MCP readiness.Find your IDs and set them to avoid permission issues:
id username
# uid=1000(user) gid=1000(group)
- TZ=Asia/Dhaka # Bangladesh
- TZ=America/New_York # US Eastern
- TZ=Europe/London # UK
- TZ=UTC # Universal Time
| Client | SHTTP | SSE | Recommended |
|---|---|---|---|
| VS Code (Cline/Roo-Cline) | Yes | Yes | SHTTP |
| Claude Desktop | Yes | Yes | SHTTP |
| Claude CLI | Yes | Yes | SHTTP |
| Codex CLI | Yes | Yes | SHTTP |
| Codeium (Windsurf) | Yes | Yes | SHTTP |
| Cursor | Yes | Yes | SHTTP |
WebSocket transport was dropped in the migration to
mcp-proxy.
Configure in .vscode/settings.json:
{
"mcp.servers": {
"redis-mcp": {
"url": "http://host-ip:8030/mcp",
"transport": "http"
}
}
}
With API_KEY:
claude mcp add-json redis-mcp '{"type":"http","url":"http://localhost:8030/mcp","headers":{"Authorization":"Bearer <YOUR_API_KEY>"}}'
Without API_KEY:
claude mcp add-json redis-mcp '{"type":"http","url":"http://localhost:8030/mcp"}'
Configure in ~/.codex/config.json:
{
"mcpServers": {
"redis-mcp": {
"transport": "http",
"url": "http://host-ip:8030/mcp"
}
}
}
Configure in .codeium/mcp_settings.json:
{
"mcpServers": {
"redis-mcp": {
"transport": "http",
"url": "http://host-ip:8030/mcp"
}
}
}
Configure in ~/.cursor/mcp.json:
{
"mcpServers": {
"redis-mcp": {
"transport": "http",
"url": "http://host-ip:8030/mcp"
}
}
}
Verify with MCP Inspector:
npm install -g @modelcontextprotocol/inspector
mcp-inspector http://host-ip:8030/mcp
| Network Mode | Complexity | Performance | Use Case |
|---|---|---|---|
| Bridge | Easy | Good | Default, isolated |
| Host | Moderate | Excellent | Direct host access |
| MACVLAN | Advanced | Excellent | Dedicated IP |
services:
redis-mcp-server:
image: mekayelanik/redis-mcp-server:stable
ports:
- "8030:8030"
Benefits: Container isolation, easy setup, works everywhere
Access: http://localhost:8030/mcp
services:
redis-mcp-server:
image: mekayelanik/redis-mcp-server:stable
network_mode: host
Benefits: Maximum performance, no NAT overhead, no port mapping needed
Considerations: Linux only, shares host network namespace
Access: http://localhost:8030/mcp
services:
redis-mcp-server:
image: mekayelanik/redis-mcp-server:stable
mac_address: "AB:BC:CD:DE:EF:01"
networks:
macvlan-net:
ipv4_address: 192.168.1.100
networks:
macvlan-net:
driver: macvlan
driver_opts:
parent: eth0
ipam:
config:
- subnet: 192.168.1.0/24
gateway: 192.168.1.1
Benefits: Dedicated IP, direct LAN access
Considerations: Linux only, requires additional setup
Access: http://192.168.1.100:8030/mcp
docker compose pull
docker compose up -d
docker image prune -f
docker pull mekayelanik/redis-mcp-server:stable
docker stop redis-mcp-server && docker rm redis-mcp-server
# Run your original docker run command
docker image prune -f
docker run --rm \
-v /var/run/docker.sock:/var/run/docker.sock \
containrrr/watchtower \
--run-once \
redis-mcp-server
# Check Docker version
docker --version
# Verify port availability
sudo netstat -tulpn | grep 8030
# Check logs
docker logs redis-mcp-server
# Get your IDs
id $USER
# Update configuration with correct PUID/PGID
# Fix volume permissions if needed
sudo chown -R 1000:1000 /path/to/volume
# Test connectivity
curl http://localhost:8030/mcp
curl http://host-ip:8030/mcp
curl -k https://localhost:8030/mcp
curl -k https://host-ip:8030/mcp
# Check firewall
sudo ufw status
# Verify container
docker inspect redis-mcp-server | grep IPAddress
docker logs -f redis-mcp-serverdocker stats redis-mcp-serverWhen reporting issues, include:
# System info
docker --version && uname -a
# Container logs
docker logs redis-mcp-server --tail 200 > logs.txt
# Container config
docker inspect redis-mcp-server > inspect.json
Your support encourages me to keep creating/supporting my open-source projects. If you found value in this project, you can buy me a coffee to keep me inspired.
Docker Image Issues:
Redis MCP Issues:
We welcome contributions:
GPL License. See LICENSE for details.
Redis MCP server has its own license - see upstream repository.
Content type
Image
Digest
sha256:27e6e4273…
Size
69.8 MB
Last updated
about 1 month ago
docker pull mekayelanik/redis-mcp-server