Nothing accepted the TCP connection: Redis down, bound to a different interface, or firewalled. Each layer has a one-command check — and the protected-mode/allowlist variants fail differently (auth, not refused), which narrows it fast.
systemctl status redis-server plus the log. Common crash cause: maxmemory policies or a bad config edit; the service then fails at every boot until the config is fixed.
Default bind 127.0.0.1 refuses external interfaces. Setting bind 0.0.0.0 without also handling protected-mode (no password + non-loopback = refuse) leaves a half-open config that still refuses.
Cloud security groups, ufw, or the container network. nc -zv from the app host distinguishes network-block (timeout) from actively-refused (nothing listening there).
systemctl status redis-server --no-pager ; ss -ltnp | grep 6379 # 127.0.0.1:6379 only = bind config
nc -zv -w 3 <redis-host> 6379 # refused = not listening/filtered-refused; timeout = firewall drop
# redis.conf: bind 0.0.0.0 protected-mode no requirepass <strong-pass> — plus a firewall rule scoped to the app hosts
# compose: redis://redis:6379 (service DNS) — localhost inside the app container is the app container, never the redis one
The localhost-in-containers trap deserves its own headline: every container has its own network namespace, so 127.0.0.1:6379 from the app container refuses even when redis runs one hop away. An internet-exposed Redis without auth is typically compromised within minutes: opening the bind without requirepass is not a shortcut, it's an incident.
redis-cli defaults to the socket/loopback where Redis listens; your app connects over the network where bind/firewall rules apply. Same daemon, different path, different gatekeepers.
No: protected-mode refuses non-loopback connections when no auth is configured. It's a safety net against accidental exposure — the real access control is requirepass/ACL plus the firewall.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.