# Moving cred files from one env to other

**URL:** <https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869>\
**Category:** General\
**Created:** [13 June 2022 16:14 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869 "2022-06-13T16:14:42Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [13 June 2022 16:14 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/1 "2022-06-13T16:14:43Z")

</div>

Hi Nick,

This is in discussion to the suggestion in the post

> [@MSSQL Plus Node - encrypt password when its an env variable - security pov?](https://discourse.nodered.org/t/mssql-plus-node-encrypt-password-when-its-an-env-variable-security-pov/58303):
>
> Hi Everyone, This is related to "node-red-contrib-mssql-plus" node. While i have opened a FR request for the same , i wanted to check with the forum as well. I have a situation where i cannot change the node credentials while deploying to prod env. And we need to put the DB credentials using env variables in settings.js so that the same deployment can work across envs. (Its a docker env). The challenge is - if we put the DB password in settings.js - its in plainview - leading to security ri…

We did the changes - and kept the cred file common across envs. Now the slave environments - fail on being able to decrypt the cred file.

Is there some key or something else which also should be kept common across environments ? I checked settings file but unable to find any such setting. So not sure.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [13 June 2022 16:23 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/2 "2022-06-13T16:23:02Z")

</div>

> [@SandeepA](#):
>
> Is there some key or something else which also should be kept common across environments ? I checked settings file but unable to find any such setting. So not sure.

If you had not set `credentialSecret` in your settings file, then Node-RED will have been displaying this warning every time it started up:

```auto

---------------------------------------------------------------------
Your flow credentials file is encrypted using a system-generated key.

If the system-generated key is lost for any reason, your credentials
file will not be recoverable, you will have to delete it and re-enter
your credentials.

You should set your own key using the 'credentialSecret' option in
your settings file. Node-RED will then re-encrypt your credentials
file using your chosen key the next time you deploy a change.
---------------------------------------------------------------------

```

If you have not yet set that key, then Node-RED will be using a system generated key. As the warning says, you should provide your own key via `credentialSecret` in the settings file, restart Node-RED, then deploy a change - that will cause it to reencrypt the credentials file using your key.

You can then copy the files to another device and as long as you have `credentialSecret` set, it will be able to read the file.

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [13 June 2022 16:31 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/3 "2022-06-13T16:31:02Z")

</div>

Noted. Will come back. Thanks Nick for the super prompt response.

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [13 June 2022 16:36 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/4 "2022-06-13T16:36:49Z")

</div>

Net-Net as i understoood crendentialSecret across all envs in my case needs to be same right ?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [13 June 2022 16:46 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/5 "2022-06-13T16:46:09Z")

</div>

> [@SandeepA](#):
>
> crendentialSecret across all envs in my case needs to be same

You need to use the same key on any device you want to decrypt the flows encrypted with that key.

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [13 June 2022 17:34 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/6 "2022-06-13T17:34:03Z")

</div>

Noted Nick. Once again Thank You.

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [14 June 2022 11:34 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/7 "2022-06-14T11:34:32Z")

</div>

Hi Nick,

1. We checked this. One of colleagues is running his NR using projects with project credentials set up. He is able to export cred file and flows.json to all other envs (including the ones without projects) ... without any challanges. He doesnt have any credentialSecret. Nor he gets any messages. I specifcially checked if his flows run and Yes.

Does this make sense ?

1. Also in our case NR GUI itself doesnt come up. NR keeps crashing with error messages in #4.

2. We are running NR via. kubernetes. How can we set the SAFE mode. I checked online. Found this link

[https://nodered.org/docs/getting-started/docker](https://nodered.org/docs/getting-started/docker)

Can i set NODE\_RED\_ENABLE\_SAFE\_MODE in the env. Will env read it from there ..against cmd line ?

#4) @Steve-Mcl ...

Adding you to this discussion .  
Background :- Per the discussion for keeping MSSQL credentials - we stored {MY\_USER} and {MY\_PASS} in cred file and have moved it other env. Problem is NR doesnt even come up.  
On startup - we see below MSSQL node errors by the process :-

14 Jun 05:44:38 - [info] [MSSQL-CN:APPNAME] Error connecting to server : [xxxx-appname-pet-sqlsvr.database.windows.net](http://xxxx-appname-pet-sqlsvr.database.windows.net), database : APPNAME\_DB, port : 1433, user :  
ConnectionError: Connection is closed.  
at Request.\_query (/usr/src/node-red/node\_modules/mssql/lib/base/request.js:497:37)  
at Request.\_query (/usr/src/node-red/node\_modules/mssql/lib/tedious/request.js:367:11)  
at /usr/src/node-red/node\_modules/mssql/lib/base/request.js:461:12  
at new Promise ()  
at Request.query (/usr/src/node-red/node\_modules/mssql/lib/base/request.js:460:12)  
at dynatraceRegularInvoke (/opt/dynatrace/oneagent/agent/bin/1.239.226.20220509-150249/any/nodejs/nodejsagent.js:2918:20)  
at Object.b.safeInvoke (/opt/dynatrace/oneagent/agent/bin/1.239.226.20220509-150249/any/nodejs/nodejsagent.js:2990:41)  
at Request.query (/opt/dynatrace/oneagent/agent/bin/1.239.226.20220509-150249/any/nodejs/nodejsagent.js:12178:15)  
at connection.node.execSql (/usr/src/node-red/node\_modules/node-red-contrib-mssql-plus/src/mssql.js:423:40)  
at doSQL (/usr/src/node-red/node\_modules/node-red-contrib-mssql-plus/src/mssql.js:779:25) {  
code: 'ECONNCLOSED'

Will this result in NR crashing ?

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [14 June 2022 13:49 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/8 "2022-06-14T13:49:09Z")

</div>

Any luck on this ? Esp #1 ? So that we can at least bring the system up.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [14 June 2022 14:05 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/9 "2022-06-14T14:05:21Z")

</div>

> [@SandeepA](#):
>
> We checked this. One of colleagues is running his NR using projects with project credentials set up. He is able to export cred file and flows.json to all other envs (including the ones without projects) ... without any challanges. He doesnt have any credentialSecret. Nor he gets any messages. I specifcially checked if his flows run and Yes.

It depends. When you create a project, it asks if you want to encrypt credentials, and if so, what key to use. You don't have to set credentialSecret in your settings for for that - it is stored in project settings by the runtime.

Without know how they have set things up, it's hard to say what's happening.

> [@SandeepA](#):
>
> we stored {MY\_USER} and {MY\_PASS}

It should be `${MY_USER}`

> [@SandeepA](#):
>
> Can i set NODE\_RED\_ENABLE\_SAFE\_MODE in the env.

Yes, if Node-RED finds the env var `NODE_RED_ENABLE_SAFE_MODE` set to a value (other than `false`) it will start in safe mode.

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [14 June 2022 15:06 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/10 "2022-06-14T15:06:33Z")

</div>

> [@knolleary](#):
>
> It depends. When you create a project, it asks if you want to encrypt credentials, and if so, what key to use. You don't have to set credentialSecret in your settings for for that - it is stored in project settings by the runtime.
> 
> Without know how they have set things up, it's hard to say what's happening.

Noted. Thanks. Will continue checking once i get NR up.

> [@knolleary](#):
>
> It should be `${MY_USER}`

I meant user and password are being stored as ${MY\_USER} and ${MY\_PASSWORD}

> [@knolleary](#):
>
> Yes, if Node-RED finds the env var `NODE_RED_ENABLE_SAFE_MODE` set to a value (other than `false`) it will start in safe mode.

Great. Already set it up. That should at least get NR up.

Will update.

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [16 June 2022 13:27 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/11 "2022-06-16T13:27:31Z")

</div>

> [@knolleary](#):
>
> Yes, if Node-RED finds the env var `NODE_RED_ENABLE_SAFE_MODE` set to a value (other than `false`) it will start in safe mode.

We managed to get NR up for few seconds. Then again the pod went down. We are in docker env via. kubernetes.

Below is the message on start up.

`16 Jun 04:51:44 - [warn]

* * *

Your flow credentials file is encrypted using a system-generated key.

If the system-generated key is lost for any reason, your credentials  
file will not be recoverable, you will have to delete it and re-enter  
your credentials.

## You should set your own key using the 'credentialSecret' option in your settings file. Node-RED will then re-encrypt your credentials file using your chosen key the next time you deploy a change.

16 Jun 04:51:44 - [warn] Error loading credentials: SyntaxError: Unexpected token W in JSON at position 1  
16 Jun 04:51:44 - [warn] Error loading flows: Error: Failed to decrypt credentials  
16 Jun 04:51:44 - [info] \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
16 Jun 04:51:44 - [info] Flows stopped in safe mode. Deploy to start.  
16 Jun 04:51:44 - [info] \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
`

The SyntaxError messges towards the end - not clear. I would assume it uses its own key so should be oik. Or i should ignore it?

---

<div class="post-metadata">

**Author:** ![SandeepA](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sandeepa/32/63225_2.png) [@SandeepA](https://discourse.nodered.org/u/SandeepA)\
**Post date:** [18 July 2022 09:55 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/12 "2022-07-18T09:55:22Z")

</div>

> [@knolleary](#):
>
> It depends. When you create a project, it asks if you want to encrypt credentials, and if so, what key to use. You don't have to set credentialSecret in your settings for for that - it is stored in project settings by the runtime.
> 
> Without know how they have set things up, it's hard to say what's happening.

Mystery solved. My colleague was also distributing a file called `.config.runtime.json`  
Not sure why . But this is what he was doing and as a result NR - his instance - was using this for creds.

Thanks Nick . Your above inputs helped me resolve this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [16 September 2022 09:56 UTC](https://discourse.nodered.org/t/moving-cred-files-from-one-env-to-other/63869/13 "2022-09-16T09:56:11Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
