Admin API remains externally accessible after configuring adminHost for localhost
25.5K reputation · 07 Dec 2020, 14:24 UTC
When securing a Node-RED instance, administrators often set the adminHost property to 127.0.0.1 to limit the HTTP admin API to the loopback interface.
The goal is to confirm that this setting alone prevents any external host from reaching the editor UI and deploying flows, while preserving normal flow execution through HTTP input/output nodes.
Uncertainty remains about whether additional configuration—such as disabling httpAdminRoot or enabling adminAuth—is required, and whether changing adminHost could inadvertently affect other Node-RED components.
Does setting adminHost to 127.0.0.1 by itself block external access to the admin API?
Is it necessary to also modify httpAdminRoot or configure adminAuth for complete isolation?
Are there any side effects on standard HTTP nodes when the admin API is bound to localhost only?