Use redis-cli safely for checks, key changes and scripts
You will connect to a Redis server, check that it answers, inspect and change a test key, and use output safely in shell scripts. The examples use the locally installed redis-cli 7.0.15 from Ubuntu's redis-tools package. Allow about 15 minutes if the server address and credentials are already known.
The route
Jump straight to the step you need, or tick off Done means at the end.
This is an operator's client, not a local database. Every command below runs against the server selected by its connection options. A typo in the host, port or database number can put a harmless test command on the wrong dataset, so identify the target before sending a write or deletion.
1. Check the client and target
Confirm which binary will run, then ask the default endpoint for a response. The default host is 127.0.0.1 and the default port is 6379.
$ command -v redis-cli
/usr/bin/redis-cli
$ redis-cli --version
redis-cli 7.0.15
$ redis-cli -h REDIS_HOST -p 6379 ping
PONG
Replace REDIS_HOST with a real hostname or address. If the server uses another port, pass it with -p. A connection refusal usually means that the endpoint is wrong or the service is not listening; it does not justify retrying writes against another host.
Checkpoint
Continue only when PING returns PONG from the intended server.
2. Run one command at a time
Put the Redis command and each argument after the connection options. Start with a key that is clearly yours. SET changes server data, so do not substitute a production key for this example.
$ redis-cli -h REDIS_HOST -p 6379 set cli:guide:test 'hello redis'
OK
$ redis-cli -h REDIS_HOST -p 6379 get cli:guide:test
hello redis
$ redis-cli -h REDIS_HOST -p 6379 exists cli:guide:test
1
When output goes to a terminal, Redis replies can include human-readable type labels. When output is redirected or piped, this installed client automatically uses raw output. Use --raw explicitly when a script needs the value without display formatting, or --json when you need typed, machine-readable replies.
$ redis-cli -h REDIS_HOST -p 6379 --raw get cli:guide:test
hello redis
$ redis-cli -h REDIS_HOST -p 6379 -3 --json get cli:guide:test
"hello redis"
3. Remove only the test key
DEL is a write operation and removes the named key. Check the name before running it. The integer reply is the number of keys removed, so 1 confirms that this command deleted one existing key and 0 means there was nothing to remove.
$ redis-cli -h REDIS_HOST -p 6379 del cli:guide:test
1
$ redis-cli -h REDIS_HOST -p 6379 exists cli:guide:test
0
There is no undo command in this workflow. If the key held valuable data, stop and use your Redis backup or application-specific recovery process. Do not use KEYS * as a casual inventory command on a busy or large database; it can block the server while it examines the keyspace.
Checkpoint
The example key is absent, while unrelated keys have not been named by any destructive command.
4. Find keys incrementally
Use the client's --scan mode to iterate through keys without asking Redis for the entire keyspace in one command. Add a narrow pattern and quote the shell wildcard so the shell does not expand it first.
$ redis-cli -h REDIS_HOST -p 6379 --scan --pattern 'cli:*'
cli:guide:another-test
cli:guide:cache
--scan lists keys in the selected database. It is an inventory, not a lock or a snapshot: keys can change while the iteration runs, and a key can be returned more than once. Treat names as candidates for a later, explicitly reviewed command. Inspect a value with GET only when you know it is a string; hashes, lists and other Redis data types need their matching commands such as HGETALL or LRANGE.
5. Pass data through stdin
Do not place a value containing secrets or awkward shell characters directly in the command line. The -x option reads the final argument from standard input, which also makes it useful for a pipeline.
$ printf '%s' 'value from stdin' | redis-cli -h REDIS_HOST -p 6379 -x set cli:guide:stdin
OK
$ redis-cli -h REDIS_HOST -p 6379 --raw get cli:guide:stdin
value from stdin
Remove this test key when you have checked it:
$ redis-cli -h REDIS_HOST -p 6379 del cli:guide:stdin
1
6. Handle authentication and TLS deliberately
Never put a real password in a shell history, shared process listing or pasted support transcript. The client accepts REDISCLI_AUTH, and --askpass prompts with masking. For an ACL user, supply --user USERNAME together with the password mechanism required by the server.
$ REDISCLI_AUTH='REPLACE_WITH_PASSWORD' redis-cli -h REDIS_HOST -p 6379 ping
PONG
$ redis-cli --askpass --user REDIS_USER -h REDIS_HOST -p 6379 ping
PONG
The first form can still expose the secret to a shell environment or debugging tool, so prefer --askpass for an interactive check. For TLS, use the server's CA file rather than disabling verification:
$ redis-cli --tls --cacert /path/to/ca.pem -h REDIS_HOST -p 6379 ping
PONG
--insecure skips certificate validation. Use it only for a tightly controlled diagnostic, never as the normal connection setting.
7. Make scripts fail visibly
Use -e when a shell script must receive a non-zero exit status for a Redis command error. Quote keys and values, keep the endpoint in a reviewed variable, and avoid putting broad deletion or migration loops into an untested one-liner.
$ redis-cli -h REDIS_HOST -p 6379 -e ping > /tmp/redis-ping.out
$ test "$(cat /tmp/redis-ping.out)" = PONG
$ echo 'Redis responded'
Redis responded
For repeated commands, -r runs the supplied command the requested number of times and -i adds an interval in seconds. This is easy to turn into load, so keep counts small and obtain approval before running it against a shared service.
$ redis-cli -h REDIS_HOST -p 6379 -r 2 ping
PONG
PONG
Done means
redis-cli --versionidentifies the client you are using, andPINGanswered from the intended endpoint.- Read and write commands named a deliberate test key or an explicitly reviewed production key.
--scanwas used for discovery, with a quoted pattern rather than a broad blocking key listing.- Secrets were not placed in command arguments or copied into shell history.
- Any test keys were removed, and no destructive command was run without a recovery plan.