# Using a Secure Deployment Strategy with Docker Secrets and Environment Variables for Node-RED

**URL:** <https://discourse.nodered.org/t/using-a-secure-deployment-strategy-with-docker-secrets-and-environment-variables-for-node-red/77122>\
**Category:** Share Your Projects\
**Tags:** security, docker\
**Created:** [31 March 2023 19:35 UTC](https://discourse.nodered.org/t/using-a-secure-deployment-strategy-with-docker-secrets-and-environment-variables-for-node-red/77122 "2023-03-31T19:35:12Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shan](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Shan](https://discourse.nodered.org/u/Shan)\
**Post date:** [31 March 2023 19:35 UTC](https://discourse.nodered.org/t/using-a-secure-deployment-strategy-with-docker-secrets-and-environment-variables-for-node-red/77122/1 "2023-03-31T19:35:12Z")

</div>

Hi all,

I have a proof of concept on how to make Node-RED deployments with Docker and Docker Compose more secure thanks to the new updated _Docker Compose v2_ specifications.

Here is the repository that will help the community use a better strategy with Docker Secrets for Standalone Node-RED containers. This method removes the possible of obtaining the passwords (albeit hashed ones) from the environment variables upon performing `docker inspect` which is quite common way to abstract environment variables from running containers.

> **[GitHub - shantanoo-desai/nodered-docker-secure-deployment: A better strategy...](https://github.com/shantanoo-desai/nodered-docker-secure-deployment)**
>
> A better strategy to deploy a node-RED Docker Container with Environment Variables with Docker Secrets - GitHub - shantanoo-desai/nodered-docker-secure-deployment: A better strategy to deploy a nod...
