# Only make node-red accessible from localmachine

**URL:** <https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086>\
**Category:** General\
**Tags:** docker\
**Created:** [18 September 2024 21:31 UTC](https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086 "2024-09-18T21:31:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JePi](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@JePi](https://discourse.nodered.org/u/JePi)\
**Post date:** [18 September 2024 21:31 UTC](https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086/1 "2024-09-18T21:31:38Z")

</div>

I run node-red in a container (in raspian) but what I do I cant get it to accept **only** connection on the localhost. Either its world or its no one. Have tried enable the settings.js row  
uiHost: "127.0.0.1",  
but that makes it non accessible from anywhere.  
The docker-compose have for node-red,  
ports:

- "127.0.0.1:1880:1880"

This is so strange. It seems what I do Inside uiHost matters more then that of docker  
With UIhost commented and this line in compise I have world access...

I have tried with localhost also as uihost but the result is same. No one can access it

---

<div class="post-metadata">

**Author:** ![E1cid](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/e1cid/32/77971_2.png) [@E1cid](https://discourse.nodered.org/u/E1cid)\
**Post date:** [18 September 2024 22:46 UTC](https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086/2 "2024-09-18T22:46:34Z")

</div>

You could whitelist ip's [How to 'whitelist' IP address's that can access Node RED](https://discourse.nodered.org/t/how-to-whitelist-ip-addresss-that-can-access-node-red/83990) courtesy of @marcus-j-davies

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [19 September 2024 01:15 UTC](https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086/3 "2024-09-19T01:15:54Z")

</div>

There's a way to make node-red only listen on localhost - I can't remember what it is off the top of my head. Normally the node-red express servers listen on 0.0.0.0 which allows external and internal access and you can change that to a specific address .

Ah, here we go. In settings.js:

```javascript
    /** By default, the Node-RED UI accepts connections on all IPv4 interfaces.
     * To listen on all IPv6 addresses, set uiHost to "::",
     * The following property can be used to listen on a specific interface. For
     * example, the following would only allow connections from the local machine.
     * This can be useful security when putting NR behind a reverse proxy on the same device.
     */
    // uiHost: process.env.HOST || '127.0.0.1',

```

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [19 September 2024 06:28 UTC](https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086/4 "2024-09-19T06:28:20Z")

</div>

Good old docker. The uihost setting can restrict it to listening on just that network interface, but because it’s inside a container 127.0.0.1 is just the inside of that container so the browser running outside can’t get to it.

There is a way to tell docker to use only the host network (usually not advisable) or simpler don’t use docker.

I think the magic in compose is network\_mode: “host”. But then that container will be fully exposed on the host network ( ie all ports etc)

---

<div class="post-metadata">

**Author:** ![greengolfer](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/greengolfer/32/28276_2.png) [@greengolfer](https://discourse.nodered.org/u/greengolfer)\
**Post date:** [19 September 2024 06:53 UTC](https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086/5 "2024-09-19T06:53:17Z")

</div>

I would suggest :

- run with bridge mode (not host…)
- have “172.17.0.1:1880:1880” in the ports configuration of your docker compose.

172.17.0.1 is (kinda) the router entry to the docker bridge network.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [18 December 2024 06:53 UTC](https://discourse.nodered.org/t/only-make-node-red-accessible-from-localmachine/91086/6 "2024-12-18T06:53:38Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
