How to securely pass a password to a PM2 nodejs app?

Viewed 173

Right now I'm passing sensitive data to PM2 using env variables. This way the PASSWORD is available to all node instances via process.env.PASSWORD.

get_password () {
  read -s -p "Enter password:"
  if [[ -z $REPLY ]]; then
    get_password
  else
    echo $REPLY
  fi
}

PASSWORD=$(get_password) || exit 1

eval "PASSWORD=$PASSWORD pm2 start ecosystem.config.js"

I have concerns regarding the security of this, because I've just learned here(point 2) that:

The initial environment of a process is generally visible in ps

It made me rethink my approach.

Instead I could use readline NPM package to ask user for password, but it's not a great solution, because if I, say, have 8 running instances, then I need to manually enter the password 8 times.

What would you advice?

0 Answers
Related