# RE: Updating a Node-RED flow from the file system

**URL:** <https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169>\
**Category:** Dashboard\
**Tags:** node-red-dashboard\
**Created:** [25 August 2021 16:51 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169 "2021-08-25T16:51:02Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![awneil](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@awneil](https://discourse.nodered.org/u/awneil)\
**Post date:** [25 August 2021 16:51 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/1 "2021-08-25T16:51:02Z")

</div>

Ref:

> [@Updating a Node-RED flow from the file system](https://discourse.nodered.org/t/updating-a-node-red-flow-from-the-file-system/29205):
>
> Hello, I would like to know if it is possible to update and deploy a node-RED "flow" just by modifying files. Let me explain: If for example I have 10 machines with Node-RED, I would like to be able to update their flow and deploy it without having to go through the Node-RED GUI, but simply by modifying a file via SSH. The idea would be to modify 1x the flow via the Node-RED GUI and then push the new flow + deploy it via SSH on the 10 other endpoints. Is this possible? Thanks for your help. …

The thread established that it is, indeed, possible.

But it seems a bit risky - allowing to upload any arbitrary file which just happens to have the "json" file type.

Some sort of "signature" would seem beneficial - to give at least some reassurance that what was uploaded was actually intended as a Node-RED Flows file.

So the question is: how to do that? Are there any existing examples?

I'm thinking specifically in the case of a Node-RED Dashboard app.

---

<div class="post-metadata">

**Author:** ![LostiLama](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lostilama/32/42930_2.png) [@LostiLama](https://discourse.nodered.org/u/LostiLama)\
**Post date:** [25 August 2021 17:12 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/2 "2021-08-25T17:12:57Z")

</div>

its kinda possible my idea is to upload or download the files out of the .nodered directory . dowload no problem just copy but the upload is risky you have to stop nodered replace the file with a the new one and the start nodered again i dont know if it can done because the deploy button isnt a command

---

<div class="post-metadata">

**Author:** ![rko](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rko/32/45807_2.png) [@rko](https://discourse.nodered.org/u/rko)\
**Post date:** [26 August 2021 06:49 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/3 "2021-08-26T06:49:28Z")

</div>

We are doing this in our prototypes to quickly update a flow. After upload you just restart (which is same as a deploy). ~~What you can do for example, create a checksum of your flow and then ask the user to re-enter the sum to confirm it's the same file.~~  
Sorry, the checksum thing doesn't really make sense.

A flow itself can be risky too. So detecting whether it's an actual flow file does not really help here. "Password protection" is the only way, I guess.

---

<div class="post-metadata">

**Author:** ![awneil](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@awneil](https://discourse.nodered.org/u/awneil)\
**Post date:** [26 August 2021 11:41 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/4 "2021-08-26T11:41:04Z")

</div>

> [@LostiLama](#):
>
> have to stop nodered replace the file with a the new one and the start nodered again i dont know if it can done

As I said, that part isn't the problem - it's solved in the linked thread. And, as @rko said, restarting the system works for this.

The question is how to get (at least some) assurance that the uploaded file is intended for use as a Node-RED Flows file.

> [@rko](#):
>
> We are doing this in our prototypes to quickly update a flow

Yes - that's the kind of thing. But this would be for Flows that have already been "approved" for distribution (as in the linked thread)

> [@rko](#):
>
> A flow itself can be risky too. So detecting whether it's an actual flow file does not really help here

Agreed.

What I was thinking was some sort of "archive" or container that would contain the Flow file and its "checksum" - so the upload process would upload this "archive", decompress/unpack it, and check that the "checksum" is OK. Only then would it replace the Flows file & restart.

So the question is how to do that packaging/unpacking & checking in Node-RED.

---

<div class="post-metadata">

**Author:** ![rko](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rko/32/45807_2.png) [@rko](https://discourse.nodered.org/u/rko)\
**Post date:** [26 August 2021 12:32 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/5 "2021-08-26T12:32:18Z")

</div>

Have a look at the [Code](https://github.com/node-red/node-red/blob/master/packages/node_modules/@node-red/editor-client/src/js/ui/clipboard.js#L319) from Node-RED, hope I found the right bit where a flow is being validated before an import into the editor. Maybe you can re-use some or all of this. I am also not sure if there is a validation "feature" somewhere already .. you have to ask the experts.

I am planning to invest some time to improve the update procedure because it is a real time-saver, especially if the Node-RED system is far away and only the customer has access to it. But unfortunately I have to finish some other work first.

Archive etc. should be no problem.

---

<div class="post-metadata">

**Author:** ![awneil](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@awneil](https://discourse.nodered.org/u/awneil)\
**Post date:** [26 August 2021 13:10 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/6 "2021-08-26T13:10:39Z")

</div>

> [@rko](#):
>
> the Node-RED system is far away and only the customer has access to it

Likewise.

In my case, the customer should only be uploading files that have been provided, so they should already be validated as "good" for Node-RED.  
So the issue really is to just make sure they don't "accidentally" load something that isn't a provided file.

I guess I really only need some distinct text string within the file ...

---

<div class="post-metadata">

**Author:** ![rko](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rko/32/45807_2.png) [@rko](https://discourse.nodered.org/u/rko)\
**Post date:** [26 August 2021 13:16 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/7 "2021-08-26T13:16:58Z")

</div>

Yes, I think then you could add another `json object` along with `flow object` and your import procedure should check if it's there. Uploading something else will fail, because the mentioned bit is missing. Or you just add something into your flow to make life easier (and keep it a valid flow file).

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [26 August 2021 14:11 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/8 "2021-08-26T14:11:36Z")

</div>

Put the flows in a dedicated folder and only allow selection from that folder. Disable write access to the folder for unauthorised users.

---

<div class="post-metadata">

**Author:** ![awneil](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@awneil](https://discourse.nodered.org/u/awneil)\
**Post date:** [26 August 2021 14:20 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/9 "2021-08-26T14:20:45Z")

</div>

It's not about authorising the user - it's about ensuring that what the user uploads is a proper Flows file for the application.

Recognising a key text string within the JSON file does the trick; eg,

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/6/d6858875f5aa4ac0de75a6334da090a6dcef4daa.png)

Not secure against malicious users, of course - but that's not the purpose here.

---

<div class="post-metadata">

**Author:** ![davidz](https://avatars.discourse-cdn.com/v4/letter/d/a88e57/32.png) [@davidz](https://discourse.nodered.org/u/davidz)\
**Post date:** [27 August 2021 18:18 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/10 "2021-08-27T18:18:32Z")

</div>

Your solution of a special string works.

Alternatively, you can encrypt the new flow file with a tool such as OpenSSL and distribute it to the client. This makes the flow secure and hard to crack.

Once the client upload the file, you decrypt the file with OpenSSL and verify it before you deploy the flow.

---

<div class="post-metadata">

**Author:** ![awneil](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@awneil](https://discourse.nodered.org/u/awneil)\
**Post date:** [27 August 2021 21:32 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/11 "2021-08-27T21:32:26Z")

</div>

and how to do that in Node-RED?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [28 August 2021 07:04 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/12 "2021-08-28T07:04:04Z")

</div>

> [@awneil](#):
>
> how to do that in Node-RED?

There are a few crypto type contrib nodes

[https://flows.nodered.org/search?term=crypto&type=node](https://flows.nodered.org/search?term=crypto&type=node)

---

<div class="post-metadata">

**Author:** ![davidz](https://avatars.discourse-cdn.com/v4/letter/d/a88e57/32.png) [@davidz](https://discourse.nodered.org/u/davidz)\
**Post date:** [28 August 2021 15:48 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/13 "2021-08-28T15:48:53Z")

</div>

You may use the "exec" node. To encrypt a file, you can use command

```auto
sudo openssl aes-256-cbc -e -k password -iter 3 -in filename -out encrypted_filename

```

To decrypt:  
sudo openssl aes-256-cbc -d -k password -iter 3 -in encrypted\_filename -out filename

Note:  
. Replace the password with your own password.  
. Increase 3 to a larger number for better security

For a group of files, you can first tar the files, and then use openssl to encrypt it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [11 September 2021 15:49 UTC](https://discourse.nodered.org/t/re-updating-a-node-red-flow-from-the-file-system/50169/14 "2021-09-11T15:49:32Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
