部署与运维

Security

Variable Type Default Description
N8N_BLOCK_ENV_ACCESS_IN_NODE Boolean false Whether to allow users to access environment variables in expressions and the Code node (false) or not (true).
N8N_BLOCK_FILE_ACCESS_TO_N8N_FILES Boolean true Set to true to block access to all files in the .n8n directory and user defined configuration files.
N8N_ENFORCE_SETTINGS_FILE_PERMISSIONS Boolean false Set to true to try to set 0600 permissions for the settings file, giving only the owner read and write access.
N8N_RESTRICT_FILE_ACCESS_TO String Limits access to files in these directories. Provide multiple files as a semicolon-separated list (";").
N8N_SECURITY_AUDIT_DAYS_ABANDONED_WORKFLOW Number 90 Number of days to consider a workflow abandoned if it's not executed.
N8N_CONTENT_SECURITY_POLICY String {} Set Content-Security-Policy headers as helmet.js nested directives object. For example, { "frame-ancestors": ["http://localhost:3000"] }
N8N_SECURE_COOKIE Boolean true Ensures that cookies are only sent over HTTPS, enhancing security.
N8N_SAMESITE_COOKIE Enum string: strict, lax, none lax Controls cross-site cookie behavior (learn more):<code>strict</code>: Sent only for first-party requests.<code>lax</code> (default): Sent with top-level navigation requests.<code>none</code>: Sent in all contexts (requires HTTPS).
N8N_GIT_NODE_DISABLE_BARE_REPOS Boolean false Set to true to prevent the Git node from working with bare repositories, enhancing security.
N8N_GIT_NODE_ENABLE_HOOKS Boolean false Set to true to allow the Git node to execute Git hooks.
N8N_POSTMESSAGE_ALLOWED_ORIGINS String Origins allowed to exchange postMessage commands with the editor when it's embedded in another page. Only relevant when embedding the editor is possible, for example when running with N8N_PREVIEW_MODE=true. Provide multiple origins as a comma-separated list, for example https://n8n.io,https://app.example.com. When empty (the default), the editor accepts messages from any origin.

Security policy using environment variables

Set N8N_SECURITY_POLICY_MANAGED_BY_ENV to true to manage the security policy from environment variables. See Manage instance settings using environment variables for how the activation pattern works.

Variable Type Default Description
N8N_SECURITY_POLICY_MANAGED_BY_ENV Boolean false Set to true to manage the security policy from environment variables. When true, n8n applies the security policy variables on every startup and locks the matching UI controls.
N8N_MFA_ENFORCED_ENABLED Boolean false Whether to enforce two-factor authentication for all users (true) or not (false).
N8N_PERSONAL_SPACE_PUBLISHING_ENABLED Boolean true Whether users can publish from their personal space (true) or not (false).
N8N_PERSONAL_SPACE_SHARING_ENABLED Boolean true Whether users can share resources from their personal space (true) or not (false).

官方原文和授权

本页来自 N8N 英文官方网站固定快照,并转换成 xueai 静态页面。内容以 N8N 持续更新的官方页面为准。

来源、授权与修改

本站保留许可证、固定提交号、社区作者和修改说明,不代表 n8n 对本站背书。

查看许可证查看来源和修改说明