# Air-gapped Node-RED instance - how to update palette and function node modules

**URL:** <https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195>\
**Category:** General\
**Created:** [6 March 2024 16:52 UTC](https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195 "2024-03-06T16:52:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![christopher-lambe](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/christopher-lambe/32/69369_2.png) [@christopher-lambe](https://discourse.nodered.org/u/christopher-lambe)\
**Post date:** [6 March 2024 16:52 UTC](https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195/1 "2024-03-06T16:52:42Z")

</div>

I need to install Node-RED on a air-gapped server. Below is a brief overview of my standard way to install Node-RED as an enterprise system.  
I reckon if I install on a networked server and copied the node-red folder over then everything should work fine (node.js 20 is already installed)

The challenge is installing new nodes in the palette or function node modules.  
My plan is to do install on the networked server first and just copy the C:\node-red\3.1.3\node-red-9802\node\_modules folder from the networked server as needed.  
**I would appreciate some feedback if that is bad idea or not.**

Install node.js 20

```auto
mkdir c:\node-red
mkdir c:\node-red\3.1.3
cd c:\node-red\3.1.3
npm install --unsafe-perm node-red@3.1.3

```

First start of Node-RED on port 9802 in a command prompt:  
`"c:\Program Files\nodejs\node.exe" "c:\node-red\3.1.3\node_modules\node-red\red.js" -p 9802 -u "c:\node-red\3.1.3\node-red-9802"`

Node-RED creates  
`c:\node-red\3.1.3\node-red-9802\`  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/1/71792dc6781a0a3beb0a5270e16d782f38ac1324.png)

Close the command prompt after the "[info] Started flows" startup message appears  
Edit the C:\node-red\3.1.3\node-red-9802\settings.js as needed adding admin password, SSL certificates...

Configure a windows service for Node-RED with NSSM non sucking service manager.

```auto
Path: C:\Program Files\nodejs\node.exe
Startup directory: C:\node-red\3.1.3\node_modules\node-red
Arguments: red.js -p 9802 -u C:\node-red\3.1.3\node-red-9802

```

Give the windows service a local or domain user for rights on local folders or windows shares.

Connect to the editor and install new nodes in the palette and also deploy a function node with some standard modules like luxon or node-firebird  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/5/95fcb38af926533b6bccc3a5062281f53f901508.png)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [6 March 2024 17:40 UTC](https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195/2 "2024-03-06T17:40:41Z")

</div>

Hi @christopher-lambe

It's not necessarly a bad idea.

But one thing to potentially ensure - is that you are running a [rebuild](https://docs.npmjs.com/cli/v7/commands/npm-rebuild) on (and in the folder of the runtime' working directory) the server that is actually running Node RED, after you move the **node\_modules** folder.

especially important if the hosts are different architectures.

Now for the spanner.....

Have you not considered **nodesDir** settings?

```auto
/** Node-RED scans the `nodes` directory in the userDir to find local node files.
     * The following property can be used to specify an additional directory to scan.
     */
nodesDir: '/home/nol/.node-red/nodes',

```

This is a directory that can house additional Nodes that will be loaded by the runtime.  
it might be an area that can help

Admittedly, this might widen the air gap a slight, but still, may help

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [6 March 2024 18:09 UTC](https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195/3 "2024-03-06T18:09:35Z")

</div>

> [@christopher-lambe](#):
>
> just copy

Well, that folder can become really very large with lots of small files which can kill copy performance. It would be better to do a smarter sync rather than a straight copy. You could use `rsync` for that. However, as well as the `node_modules` folder, you also need to update the package.json file. And, of course, to restart Node-RED afterwards.

Noting that you cannot do this across different platform types (eg. Linux\>Windows or the opposite). I don't think that a simple post copy `npm rebuild` will work - or if it does, I'm not convinced it would be always successful.

> [@christopher-lambe](#):
>
> `c:\node-red`

I think that might be a privileged folder on newer Windows OS's? You need to decide which UID will run the Node-RED service - if running as SYSTEM, you might be OK. But probably not if using a standard UID (which is a lot safer).

---

<div class="post-metadata">

**Author:** ![christopher-lambe](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/christopher-lambe/32/69369_2.png) [@christopher-lambe](https://discourse.nodered.org/u/christopher-lambe)\
**Post date:** [6 March 2024 18:12 UTC](https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195/4 "2024-03-06T18:12:56Z")

</div>

I did't mention it above but I would stop and start the windows service reponsible for the Node-RED instance while copying the new node-modules folder across. Not optimal. I will check out the node rebuild command as suggested.

The nodesDir looks promising but is there a way to tell the API to look for new node packages there while it is running and "import" them too? It looks like this directory is read once only on startup.

This Node-RED API method looks promising too and can accept "full path to a directory containing the node module"  
[https://nodered.org/docs/api/admin/methods/post/nodes/](https://nodered.org/docs/api/admin/methods/post/nodes/)

Node-RED really is the most fun rabbit hole that just keeps on giving.

---

<div class="post-metadata">

**Author:** ![christopher-lambe](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/christopher-lambe/32/69369_2.png) [@christopher-lambe](https://discourse.nodered.org/u/christopher-lambe)\
**Post date:** [6 March 2024 20:08 UTC](https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195/5 "2024-03-06T20:08:28Z")

</div>

I am tring this out at the moment. Node-RED API.  
[https://nodered.org/docs/api/admin/methods/post/nodes/](https://nodered.org/docs/api/admin/methods/post/nodes/)

The post method can install from the npm repository or from a local tgz file.  
The npm repository was sucessful:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/a/da3e69fad2acbc58adb808855e1c7463e91fc7ff.png)

But the local tgz was not. I used npm to install tinycolor2 to a local folder. Then npm pack to make a tgz file and copied that to the node red folder and tried to install it.

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/6/96f30d864433f3031f113c35f5160689c2e98909.png)

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/a/da07279d29575c2856b6fde2913b456c8b26ce58.png)

So I tried with

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/7/67d6217549002b669536ad6e1cf41e1fb24212e8.png)  
Which gave this error.

> 6 Mar 20:59:05 - [info] Installing module: tinycolor2, version: latest  
> 6 Mar 20:59:07 - [info] Installed module: tinycolor2  
> 6 Mar 20:59:07 - [warn] Installation of module tinycolor2 failed:  
> 6 Mar 20:59:07 - [warn] ------------------------------------------  
> 6 Mar 20:59:07 - [warn] undefined  
> 6 Mar 20:59:07 - [warn] ------------------------------------------  
> Error: Install failed  
> at c:\node-red\3.1.3\node\_modules@node-red\registry\lib\installer.js:285:25  
> at process.processTicksAndRejections (node:internal/process/task\_queues:95:5)  
> 6 Mar 20:59:07 - [error] Error: Install failed

It looks like the method will only install actual node-red node modules and not any arbitrary npm package

Which brings me back to my question above:

> The nodesDir looks promising but is there a way to tell the API to look for new node packages there while it is running and "import" them too? It looks like this directory is read once only on startup.

This also looks like it will only install node-red nodes and not arbitrary npm packages such as axios for example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [4 June 2024 20:08 UTC](https://discourse.nodered.org/t/air-gapped-node-red-instance-how-to-update-palette-and-function-node-modules/86195/6 "2024-06-04T20:08:51Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
