# Possible to change the location of settings.js when running Node-RED as a service?

**URL:** <https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342>\
**Category:** General\
**Tags:** security\
**Created:** [12 August 2022 06:28 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342 "2022-08-12T06:28:34Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![janedoe123](https://avatars.discourse-cdn.com/v4/letter/j/b19c9b/32.png) [@janedoe123](https://discourse.nodered.org/u/janedoe123)\
**Post date:** [12 August 2022 06:28 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/1 "2022-08-12T06:28:34Z")

</div>

Hi all,

For security reason, I would like to change the location of settings.js when running Node-RED as a service.

Is it possible to do so?

(From what I've seen, it's only possible from the command line, hence my question).

Thank you

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [12 August 2022 06:44 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/2 "2022-08-12T06:44:08Z")

</div>

> [@janedoe123](#):
>
> it's only possible from the command line

Yes, the `-s` or `--settings` is the only means.

However, if you specify a `NODE_RED_HOME` env var then all files (including the settings.js file) will reside in the path specfied by `NODE_RED_HOME`

> [@janedoe123](#):
>
> For security reason, I would like to change the location of settings.js

Is it not enough to secure access to this file instead of moving it?

Also, cant you simply provide the settings file path via the `-s` option for your service?

---

<div class="post-metadata">

**Author:** ![janedoe123](https://avatars.discourse-cdn.com/v4/letter/j/b19c9b/32.png) [@janedoe123](https://discourse.nodered.org/u/janedoe123)\
**Post date:** [12 August 2022 07:20 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/3 "2022-08-12T07:20:54Z")

</div>

> Is it not enough to secure access to this file instead of moving it?

The whole system is 100% secure, however it still does not prevent somebody copying/cloning the content of the HDD/SSD, finding out the settings.js file and easily retrieving the code developed in Node-RED.

Therefore, I'm trying to find a way to even "hide" the settings.js as much as possible, rather than leaving it in the default folder.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 August 2022 08:14 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/4 "2022-08-12T08:14:18Z")

</div>

You should be able to specify it in the service file. For example, if you are using Debian/Ubuntu/Raspbian and installed using the recommended script then, in the service file /lib/systemd/system/nodered.service, you can set it in the ExecStart line or in NODE\_RED\_OPTIONS.

If you want to stop somebody copying the disc then encrypt the partition on the disc.

---

<div class="post-metadata">

**Author:** ![janedoe123](https://avatars.discourse-cdn.com/v4/letter/j/b19c9b/32.png) [@janedoe123](https://discourse.nodered.org/u/janedoe123)\
**Post date:** [12 August 2022 10:14 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/5 "2022-08-12T10:14:53Z")

</div>

Thanks a lot, @Colin

Sorry for asking here, I hope you don't mind. Which tool would you recommend to encrypt the partition?

There are so many out there... I see Cryptsetup coming back often, but is there anything even better than that?

---

<div class="post-metadata">

**Author:** ![ghayne](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ghayne/32/39_2.png) [@ghayne](https://discourse.nodered.org/u/ghayne)\
**Post date:** [12 August 2022 10:24 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/6 "2022-08-12T10:24:12Z")

</div>

Here is a good description:

> **[How To Encrypt Partition on Linux – devconnected](https://devconnected.com/how-to-encrypt-partition-on-linux/)**
>
> Learn how you can easily encrypt a partition on Linux using LUKS and the cryptsetup command. Encrypt partition using key file.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 August 2022 10:43 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/7 "2022-08-12T10:43:42Z")

</div>

> [@janedoe123](#):
>
> For security reason, I would like to change the location of settings.js

Why are you so worried about that particular file? How does knowing where it is allow access to your node-red code?

I am somewhat concerned that you appear to be doing fairly complex tasks such as attempting to make your site fully secure and taking it to such levels that you are worried about someone stealing the disk, but do not seem to have a basic knowledge of systemd scripts and disc encryption. If it is really important to you that everything is secure then I highly recommend consulting a professional, otherwise you may have left security holes lying around.

---

<div class="post-metadata">

**Author:** ![janedoe123](https://avatars.discourse-cdn.com/v4/letter/j/b19c9b/32.png) [@janedoe123](https://discourse.nodered.org/u/janedoe123)\
**Post date:** [12 August 2022 14:20 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/8 "2022-08-12T14:20:00Z")

</div>

Hi @Colin

I get your point, no offense taken. Let me give a little bit more of background:

The software runs on a Raspberry Pi, and the user must not have to type in a password to boot.

After hours of research, the only answers I can find are:

- Glue your SD card
- Welder/Solder a metallic plate on top of the SD card
- Physically lock your SD card with a special enclosure

Needless to say, if encrypting the partition is actually doable, is it possible to have the application (Node-RED) installed in partition A (unencrypted for instance) but all the important files such as Node-RED flows stored in partition B (obviously encrypted)?

Therefore my questions. I've done my due diligence, I just can't find how to avoid somebody to simply copy/paste the content of the SD card.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 August 2022 14:30 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/9 "2022-08-12T14:30:28Z")

</div>

Gluing the card in won't be enough. You must also stop someone plugging in a USB stick and copying to that. Also you will need to make sure there is no network access to the device, by wifi or ethernet, and no way of enabling the wifi or plugging in an ethernet cable. Possibly that would need you to destroy the network chips or connector.

You didn't explain why you are particularly concerned about settings.js, or is that no longer a requirement?

---

<div class="post-metadata">

**Author:** ![janedoe123](https://avatars.discourse-cdn.com/v4/letter/j/b19c9b/32.png) [@janedoe123](https://discourse.nodered.org/u/janedoe123)\
**Post date:** [12 August 2022 14:36 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/10 "2022-08-12T14:36:09Z")

</div>

Hi @Colin

I've implemented all that I could think off to protect the SD card content while in use:

- Two SSH users
- Basic SSH user only in order to connect to the machine using SSH over a different port than 22
- Super user that cannot be used to directly log in to the machine using SSH: the only SSH access is via the basic user, then I need to connect to the super user via that basic user
- Root user disabled/deleted
- Node-RED GUI protected with a password
- Followed by Node-RED GUI disabled (!)
- Wifi disabled with the config file / raspi-config.
- All Ethernet ports disabled (except the native one obviously)
- etc.

All the above is great (and definitely a good security) while nobody has physically access to the SD card.

However, that's definitely not enough if somebody is able to access the content of the SD card, which as you know, is extremely easy to do so.

One question: Is it possible to have the application (Node-RED) installed in partition A (unencrypted for instance) but all the important files such as Node-RED flows stored in partition B (obviously encrypted)?

I'm looking at a way for particular files/folders to not be accessible/readable, even with the SD card in hand.

Why I am concerned about settings.js: because once having access to settings.js, one can easily find the flows filename and path, then copy the file, and years of work are gone...

Edit: Have you ever heard of [ZYMBIT - ZYMKEY4, Essential Security for Raspberry Pi](https://www.zymbit.com/zymkey/) ?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 August 2022 14:51 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/11 "2022-08-12T14:51:58Z")

</div>

> [@janedoe123](#):
>
> Is it possible to have the application (Node-RED) installed in partition A  
> (unencrypted for instance) but all the important files such as Node-RED flows stored in partition B (obviously encrypted)?

Yes, note though, that when node-red is running the disk will be decrypted.

> [@janedoe123](#):
>
> - Two SSH users
> - Basic SSH user only in order to connect to the machine using SSH over a different port than 22
> - Super user that cannot be used to directly log in to the machine using SSH: the only SSH access is via the basic user, then I need to connect to the super user via that basic user

If the user can unplug the SD card then he could plug it into a PC and change all those settings so he can SSH in as superuser. Then, once node-red is running he would be able to access the flows.

---

<div class="post-metadata">

**Author:** ![janedoe123](https://avatars.discourse-cdn.com/v4/letter/j/b19c9b/32.png) [@janedoe123](https://discourse.nodered.org/u/janedoe123)\
**Post date:** [12 August 2022 14:54 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/12 "2022-08-12T14:54:26Z")

</div>

Thanks a lot, @Colin

I'm going to give a try to: [ZYMBIT - ZYMKEY4, Essential Security for Raspberry Pi](https://www.zymbit.com/zymkey/)

Have you ever heard of it?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 August 2022 15:08 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/13 "2022-08-12T15:08:39Z")

</div>

> [@janedoe123](#):
>
> Have you ever heard of it?

No, but that does not mean anything.

As I said earlier, if it is that important then you really should take advice from a professional consultant.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 August 2022 19:50 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/14 "2022-08-12T19:50:25Z")

</div>

> [@janedoe123](#):
>
> encrypt the partition?

Just remember that those tools only help security when the server is turned off, not when it is running. To have encrypted data when running, you really need a hardware security module where you can offload some security processing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [11 October 2022 19:50 UTC](https://discourse.nodered.org/t/possible-to-change-the-location-of-settings-js-when-running-node-red-as-a-service/66342/15 "2022-10-11T19:50:44Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
