You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于PM2 9615端口Web界面的敏感数据防护与访问限制问询

Got it, let's tackle this PM2 Web UI security issue head-on—exposing sensitive config data like bank credentials, IPs, or passwords is a critical risk, so here are actionable solutions to lock things down:

限制PM2 Web UI仅允许特定域名访问

PM2's built-in Web UI doesn't have native domain whitelisting, but you can use a reverse proxy (like Nginx) to enforce this. Here's how:

  1. First, restrict PM2 Web UI to local access only
    Run the Web UI so it only listens on your server's localhost, preventing direct public exposure:

    pm2 web --listen 127.0.0.1:9615
    
  2. Configure Nginx as a reverse proxy with domain filtering
    Create or edit an Nginx server block to forward requests only from your allowed domain(s):

    server {
        listen 80;
        # List your allowed domains here (space-separated for multiple)
        server_name your-trusted-domain.com another-safe-domain.com;
    
        location / {
            # Block requests from unapproved domains
            if ($host !~* ^(your-trusted-domain.com|another-safe-domain.com)$) {
                return 403 Forbidden;
            }
            # Forward valid requests to the local PM2 Web UI
            proxy_pass http://127.0.0.1:9615;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
        }
    }
    

    After saving, reload Nginx with sudo nginx -s reload to apply changes. Now only requests to your specified domains will reach the PM2 Web UI.

其他同域名/额外防护方案

Beyond domain restriction, these steps will harden your setup even more:

  • HTTP Basic Authentication (adds a second layer)
    Pair domain filtering with username/password protection in Nginx. First, generate a password file:

    sudo htpasswd -c /etc/nginx/.pm2-ui-credentials pm2-admin
    

    Then add these lines to your Nginx location block:

    auth_basic "PM2 Web UI - Restricted Access";
    auth_basic_user_file /etc/nginx/.pm2-ui-credentials;
    

    Now even valid domain requests need a valid login to access the UI.

  • Remove sensitive data from ecosystem.config.js (root cause fix)
    Instead of storing secrets like bank info or passwords directly in your config file, use environment variables. Update your ecosystem.config.js to reference env vars:

    module.exports = {
      apps: [{
        name: "my-app",
        script: "app.js",
        env: {
          DB_PASSWORD: process.env.DB_PASSWORD,
          BANK_API_KEY: process.env.BANK_API_KEY
        }
      }]
    };
    

    Then set these variables before starting PM2 (or use a .env file with pm2 env commands). This way, sensitive data never shows up in the PM2 Web UI at all.

  • IP Whitelisting (for stricter control)
    If you want to limit access to specific IP addresses instead of (or alongside) domains, add these lines to your Nginx location block:

    allow 192.168.1.0/24; # Allow your internal network IP range
    allow 203.0.113.42;    # Allow a specific public IP
    deny all;              # Block everyone else
    
  • Switch to PM2 Plus (managed alternative)
    If you prefer a managed solution, PM2 Plus (the official paid monitoring service) avoids exposing local config secrets entirely. It offers built-in access controls like team permissions, IP whitelisting, and encrypted data transmission—no need to maintain your own proxy setup.

内容的提问来源于stack exchange,提问作者ABBADONK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 07:43:14