# Block a Node-red user from using OS commands

**URL:** https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300
**Category:** General
**Created:** [14 September 2023 09:06 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300 "2023-09-14T09:06:24Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![josekavunkal](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/josekavunkal/32/18505_2.png) [@josekavunkal](https://discourse.nodered.org/u/josekavunkal)
#### Post date: [14 September 2023 09:06 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/1 "2023-09-14T09:06:24Z")

</div>

Can we block a Node-red user from using OS commands using Exec or similar node?

---

<div class="post-metadata">

### Author: ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)
#### Post date: [14 September 2023 09:10 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/2 "2023-09-14T09:10:26Z")

</div>

you can disable the exec node via `nodesExcludes` in settings,js

```auto
nodesExcludes: ["75-exec.js"],

```

---

<div class="post-metadata">

### Author: ![Trying\_to\_learn](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/trying_to_learn/32/28400_2.png) [@Trying\_to\_learn](https://discourse.nodered.org/u/Trying_to_learn)
#### Post date: [14 September 2023 09:10 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/3 "2023-09-14T09:10:31Z")

</div>

I believe that is beyond the scope of Node-Red.

---

<div class="post-metadata">

### Author: ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)
#### Post date: [14 September 2023 09:15 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/4 "2023-09-14T09:15:37Z")

</div>

Additionally, you can turn off external function modules or add entries to allow/deny list

see [Configuration : Node-RED](https://nodered.org/docs/user-guide/runtime/configuration)

---

<div class="post-metadata">

### Author: ![gregorius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gregorius/32/73816_2.png) [@gregorius](https://discourse.nodered.org/u/gregorius)
#### Post date: [14 September 2023 10:58 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/5 "2023-09-14T10:58:32Z")

</div>

Can't I then just use the function node to call `exec`? There are probably many ways around this - Jsonata expression? A malicious user will always find a way ...

---

<div class="post-metadata">

### Author: ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)
#### Post date: [14 September 2023 11:09 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/6 "2023-09-14T11:09:05Z")

</div>

The user account which runs Node-red (Linux anyway) should not have elevated permissions such as sudo, then does it matter if they can access OS commands?

---

<div class="post-metadata">

### Author: ![josekavunkal](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/josekavunkal/32/18505_2.png) [@josekavunkal](https://discourse.nodered.org/u/josekavunkal)
#### Post date: [14 September 2023 11:32 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/7 "2023-09-14T11:32:18Z")

</div>

We are running multiple instance for a single OS user. One way is to create a non sudo user for all these instances .as you said

---

<div class="post-metadata">

### Author: ![josekavunkal](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/josekavunkal/32/18505_2.png) [@josekavunkal](https://discourse.nodered.org/u/josekavunkal)
#### Post date: [14 September 2023 11:34 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/8 "2023-09-14T11:34:04Z")

</div>

We can block exec node as others have mentioned .But still a malicious user may always find a way .

---

<div class="post-metadata">

### Author: ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)
#### Post date: [14 September 2023 12:50 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/9 "2023-09-14T12:50:41Z")

</div>

> [@gregorius](#):
>
> Can't I then just use the function node to call `exec`?

No. not if access to `process` is inhibited:

> [@Steve-Mcl](#):
>
> you can turn off external function modules or add entries to allow/deny list
> 
> see [Configuration : Node-RED](https://nodered.org/docs/user-guide/runtime/configuration)

\_The function node runs in the context of a [NodeJS VM](https://nodejs.org/api/vm.html) with limited scope by default)

but, so long as the user can install something (via palette for example) there will always be a a way.

Key to locking down, as other have suggested, is limited accounts.

There are other avenues and approaches to explore too (run NR in docker/k8s, SSO login for accessing node-red, coupled with audit logging, good backups)

---

<div class="post-metadata">

### Author: ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)
#### Post date: [14 September 2023 12:56 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/10 "2023-09-14T12:56:02Z")

</div>

> [@josekavunkal](#):
>
> We are running multiple instance for a single OS user. One way is to create a non sudo user for all these instances

Hi again, I hate to sound like a broken record - I seem to be saying this more and more lately, but something like [FlowFuse](https://flowfuse.com/docs/install/introduction/) does pretty much everything you want - user management, easy setup of permitted modules, multiple instances, runs in docker or k8s, has platform/team/instance/user level audit logging, point in time snapshots etc. You can of course pay for it (hosted, ready made, secured, SSO sign in etc) but it _is_ open source - just like Node-RED!

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [14 September 2023 14:43 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/11 "2023-09-14T14:43:02Z")

</div>

> [@josekavunkal](#):
>
> One way is to create a non sudo user for all these instances .as you said

You should ALWAYS be doing that for a production instance of node-red. This is one of the weaker aspects of the Node-RED documentation stemming from its origins.

Treat Node-RED as another microservice and similar to any other web server. Run it under a dedicated user with limited access outside its own folders. And don't install Node-RED globally.

For a true multi-user configuration, run each user in their own container or even their own VM. If using containers, use something like Kubernetes and not Docker to orchestrate everything.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [13 November 2023 14:43 UTC](https://discourse.nodered.org/t/block-a-node-red-user-from-using-os-commands/81300/12 "2023-11-13T14:43:10Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
