6.5.27 PM2 (Node.js)
Reload PM2 as the account that runs your apps
The PM2 (Node.js process manager) template writes the certificate and private key to the configured paths, then runs pm2 reload all. The reload lets applications that read their TLS files at startup load the new certificate.
PM2 uses a rolling reload in cluster mode and a restart in fork mode. Whether clients see an interruption depends on the app’s shutdown behavior and active connections.
Set the file paths
Set Certificate Destination and Private Key Destination to the exact files your app loads. The certificate file includes the intermediate chain.
The app must read these files from disk when it starts. If the certificate is built into the app or loaded from an environment variable, a reload won’t pick up the new one.
The account that runs your app must be able to read the key file. Check the file’s owner and permissions.
Reload as the right user
PM2 keeps a separate process list for each user. By default, the template reloads root’s applications.
If you edit the script, keep the export HOME=/root line (or use su - as below). The agent runs as a background service, and without that line PM2 can’t find your apps.
If your apps run under a different account, switch the template to advanced mode and reload as that user. For a user named node:
su - node -c "pm2 reload all"
To reload one app instead of all of them, use pm2 reload my-app.
If pm2 can’t be found
If Node and PM2 were installed with nvm or into a home folder, the agent may not find pm2. Run which pm2 as the app’s user to get the full path, then use it in advanced mode:
/root/.nvm/versions/node/v20.11.0/bin/pm2 reload all
Common problems
- The reload lists no apps, or the old certificate is still served: PM2 ran as the wrong user. Reload as the account that started the apps.
- “pm2: command not found”: use the full path to
pm2. - The app fails to start after the reload: check its logs and confirm that its account can read the certificate and private key.