# Redis tunnel

info

Available only with a [subscription](https://tuna.am/#pricing).

## Overview

Redis tunnel allows you to provide access to a Redis database and track executed queries in the inspector.

note

Redis tunnels are designed for debugging and working locally or in test environments, they do not support SSL connections. We do not recommend using this type of tunnels in production environments.

Starting with version **0.36.0**, tuna shows a [full-screen interface](https://tuna.am/en/docs/tunnels/tui.md) in the terminal with sessions and Redis commands.

## Examples

note

You can view all current flags, hints, and examples by calling help:

```shell
tuna redis --help

```

Almost all flags have corresponding [environment variables](https://tuna.am/en/docs/guides/environment-variables.md).

### Basic example

```shell
tuna redis 6379

```

### With IP address

```shell
tuna redis 10.0.0.1:6379

```

### Specifying a token

You can specify a particular token using the `--token` flag or the `TUNA_TOKEN` environment variable. Overriding follows the [configuration ordering](https://tuna.am/en/docs/guides/config-ordering.md) policy.

```shell
tuna redis 6379 --token=tt_***

```

### Specifying a connection region

You can specify a particular [region](https://tuna.am/en/docs/tunnels/guides/locations.md) using the `--location`/`-l` flag or the `TUNA_LOCATION` environment variable. Overriding follows the [configuration ordering](https://tuna.am/en/docs/guides/config-ordering.md) policy.

```shell
tuna redis 6379 --location=nl

```

### Static port

The value of the `--port`/`-p` flag can be an alias or an assigned port. You can reserve ports in the [dashboard](https://my.tuna.am/tcp_ports), and after restarting the tunnel the address will remain the same. For more details about ports, see the dedicated [guide](https://tuna.am/en/docs/tunnels/ports.md).

```shell
tuna redis 6379 --port=redis
tuna redis 6379 --port=35000

```

### IP subnet access restriction

You can define a whitelist of [subnets](https://en.wikipedia.org/wiki/Subnetwork) in CIDR format:

```shell
tuna redis 6379 --cidr-allow="10.0.0.1/32"

```

Or prohibit access from specific subnets:

```shell
tuna redis 6379 --cidr-deny="10.0.0.1/32"

```

You can combine them, for example specify a wide network and subtract private IPs:

```shell
tuna redis 6379 --cidr-allow="10.0.0.1/24" --cidr-deny="10.0.0.33/32"

```

You can also pass lists separated by commas:

```shell
tuna redis 6379 --cidr-allow="10.0.0.1/24,192.168.0.1/24" --cidr-deny="10.0.0.33/32,192.168.0.33/32"

```

## Query inspector

The request inspector lets you debug incoming requests, view headers and other information that can make application development easier. It is controlled by the `--inspect` flag or the `TUNA_INSPECT` environment variable.

### Configuration

The request inspector is enabled by default and is available at `http://127.0.0.1:4040`. If port `4040` is busy, the next free port will be selected. The address or port can be overridden using the `TUNA_INSPECT_ADDR` environment variable or the `inspectAddr` parameter in the [configuration file](https://tuna.am/en/docs/guides/config-file.md).

* `TUNA_INSPECT_ADDR=0.0.0.0` — listen on all interfaces
* `TUNA_INSPECT_ADDR=0.0.0.0:8080` — listen on all interfaces on port `8080`; if the port is busy, the next free one will be selected
* `TUNA_INSPECT_ADDR=8080` — listen on `127.0.0.1` on port `8080`; if the port is busy, the next free one will be selected

The resulting address will be printed to the console at startup:

![cli_redis](/docs/img/inspect/cli_redis.webp)

### Interface

On the left, a list of sessions is displayed, and on the right, the output of commands that were executed within the sessions.

![web_redis](/docs/img/inspect/web_redis.webp)
