Right now I'm passing sensitive data to PM2 using env variables. This way the PASSWORD is available to all node instances via process.env.PASSWORD.
get_password () {
read -s -p "Enter password:"
if [[ -z $REPLY ]]; then
get_password
else
echo $REPLY
fi
}
PASSWORD=$(get_password) || exit 1
eval "PASSWORD=$PASSWORD pm2 start ecosystem.config.js"
I have concerns regarding the security of this, because I've just learned here(point 2) that:
The initial environment of a process is generally visible in ps
It made me rethink my approach.
Instead I could use readline NPM package to ask user for password, but it's not a great solution, because if I, say, have 8 running instances, then I need to manually enter the password 8 times.
What would you advice?