关于PM2 9615端口Web界面的敏感数据防护与访问限制问询
Got it, let's tackle this PM2 Web UI security issue head-on—exposing sensitive config data like bank credentials, IPs, or passwords is a critical risk, so here are actionable solutions to lock things down:
PM2's built-in Web UI doesn't have native domain whitelisting, but you can use a reverse proxy (like Nginx) to enforce this. Here's how:
First, restrict PM2 Web UI to local access only
Run the Web UI so it only listens on your server's localhost, preventing direct public exposure:pm2 web --listen 127.0.0.1:9615Configure Nginx as a reverse proxy with domain filtering
Create or edit an Nginx server block to forward requests only from your allowed domain(s):server { listen 80; # List your allowed domains here (space-separated for multiple) server_name your-trusted-domain.com another-safe-domain.com; location / { # Block requests from unapproved domains if ($host !~* ^(your-trusted-domain.com|another-safe-domain.com)$) { return 403 Forbidden; } # Forward valid requests to the local PM2 Web UI proxy_pass http://127.0.0.1:9615; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } }After saving, reload Nginx with
sudo nginx -s reloadto apply changes. Now only requests to your specified domains will reach the PM2 Web UI.
Beyond domain restriction, these steps will harden your setup even more:
HTTP Basic Authentication (adds a second layer)
Pair domain filtering with username/password protection in Nginx. First, generate a password file:sudo htpasswd -c /etc/nginx/.pm2-ui-credentials pm2-adminThen add these lines to your Nginx location block:
auth_basic "PM2 Web UI - Restricted Access"; auth_basic_user_file /etc/nginx/.pm2-ui-credentials;Now even valid domain requests need a valid login to access the UI.
Remove sensitive data from ecosystem.config.js (root cause fix)
Instead of storing secrets like bank info or passwords directly in your config file, use environment variables. Update yourecosystem.config.jsto reference env vars:module.exports = { apps: [{ name: "my-app", script: "app.js", env: { DB_PASSWORD: process.env.DB_PASSWORD, BANK_API_KEY: process.env.BANK_API_KEY } }] };Then set these variables before starting PM2 (or use a
.envfile withpm2 envcommands). This way, sensitive data never shows up in the PM2 Web UI at all.IP Whitelisting (for stricter control)
If you want to limit access to specific IP addresses instead of (or alongside) domains, add these lines to your Nginx location block:allow 192.168.1.0/24; # Allow your internal network IP range allow 203.0.113.42; # Allow a specific public IP deny all; # Block everyone elseSwitch to PM2 Plus (managed alternative)
If you prefer a managed solution, PM2 Plus (the official paid monitoring service) avoids exposing local config secrets entirely. It offers built-in access controls like team permissions, IP whitelisting, and encrypted data transmission—no need to maintain your own proxy setup.
内容的提问来源于stack exchange,提问作者ABBADONK

