Skip to content
BotServBotServ
n8nSelf-HostingProductionReverse ProxyHTTPS

n8n Self-Hosting

Self-host n8n with production setup, reverse proxy, HTTPS, database, backup, monitoring and practical examples.

S

schutzgeist

5 min read
n8n Self-Hosting

n8n Self-Hosting

What this article covers

  • Setting up n8n for production.
  • Configuring HTTPS, reverse proxy, and database.
  • Setting up backup, monitoring, and updates.
  • Preparing n8n for multiple users and teams.
  • Best practices for security, availability, and maintenance.

Introduction: n8n self-hosting explained

Installing n8n is straightforward. Running n8n in production is something else: HTTPS, reverse proxy, database, backup, monitoring, user management. This article shows how to not just get n8n running, but operate it reliably.

This article is for users who want to run n8n in production. You should already have n8n installed. See installing n8n for the basic setup.

Why do I need n8n self-hosting?

Imagine you’ve installed n8n locally and built a few workflows. Now you want your team to use it, with HTTPS, multiple users, backups, and monitoring. The local installation won’t cut it: you need a production setup.

n8n self-hosting at a glance

n8n self-hosting means running n8n on your server with HTTPS, reverse proxy, database, backup, and monitoring. Not just for testing, but for daily operations.

The core idea is this: run n8n not just to try it out, but to operate it reliably.

Who is this article for?

  • System administrators operating n8n in production.
  • Teams setting up n8n for multiple users.
  • Self-hosters running n8n professionally.
  • Decision makers evaluating n8n for their organization.

You’ll need some background with Docker, n8n, and Linux.

Key concepts

  • n8n - Workflow automation. Useful for: the tool itself.
  • Reverse proxy - intermediary in front of n8n. Useful for: HTTPS and routing.
  • Docker - Container platform. Useful for: running services.
  • Docker Compose - Multi-container orchestration. Useful for: complex setups.
  • PostgreSQL - Database. Useful for: production instead of SQLite.
  • Backup - Data protection. Useful for: workflows and credentials.
  • Monitoring - System oversight. Useful for: availability tracking.

Production setup

Docker Compose for production

version: "3.8"

services:
  n8n:
    image: n8nio/n8n:latest
    container_name: n8n
    restart: unless-stopped
    ports:
      - "127.0.0.1:5678:5678"  # Localhost only, reverse proxy in front
    environment:
      - N8N_HOST=0.0.0.0
      - N8N_PORT=5678
      - N8N_PROTOCOL=https
      - WEBHOOK_URL=https://n8n.deine-domain.de/
      - GENERIC_TIMEZONE=Europe/Berlin
      - TZ=Europe/Berlin
      - N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
      - DB_TYPE=postgresdb
      - DB_POSTGRESDB_HOST=postgres
      - DB_POSTGRESDB_PORT=5432
      - DB_POSTGRESDB_DATABASE=n8n
      - DB_POSTGRESDB_USER=n8n
      - DB_POSTGRESDB_PASSWORD=${DB_PASSWORD}
      - EXECUTIONS_DATA_PRUNE=true
      - EXECUTIONS_DATA_MAX_AGE=30
    volumes:
      - n8n_data:/home/node/.n8n
    networks:
      - n8n-network
    depends_on:
      - postgres

  postgres:
    image: postgres:16-alpine
    container_name: n8n-postgres
    restart: unless-stopped
    environment:
      - POSTGRES_DB=n8n
      - POSTGRES_USER=n8n
      - POSTGRES_PASSWORD=${DB_PASSWORD}
    volumes:
      - postgres_data:/var/lib/postgresql/data
    networks:
      - n8n-network

volumes:
  n8n_data:
  postgres_data:

networks:
  n8n-network:
    driver: bridge

Reverse proxy with Nginx

# /etc/nginx/sites-available/n8n
server {
    listen 443 ssl http2;
    server_name n8n.deine-domain.de;

    ssl_certificate /etc/letsencrypt/live/n8n.deine-domain.de/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/n8n.deine-domain.de/privkey.pem;

    location / {
        proxy_pass http://127.0.0.1:5678;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

TLS certificate with Let’s Encrypt

sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d n8n.deine-domain.de

See TLS certificates for details.

Database: SQLite vs. PostgreSQL

SQLitePostgreSQL
Simple, no extra installationRobust, production-ready
For small setupsFor large setups
Single-userMulti-user
Less performantMore performant
Easy backup (file-based)Complex backup (pg_dump)

For production: PostgreSQL is recommended.

Backup

Backing up n8n data

# Back up volume
docker run --rm \
  -v n8n_data:/data \
  -v $(pwd)/backup:/backup \
  alpine tar czf /backup/n8n-backup.tar.gz -C /data .

# Back up PostgreSQL
docker exec n8n-postgres pg_dump -U n8n n8n > backup/n8n-db.sql

Automated backups

# Cron job for daily backups
0 3 * * * docker run --rm -v n8n_data:/data -v /backup:/backup alpine tar czf /backup/n8n-$(date +\%Y\%m\%d).tar.gz -C /data .

See Backup for details.

Monitoring

Health checks

# n8n health endpoint
curl http://localhost:5678/healthz

Monitoring with Prometheus

# Extend docker-compose.yml
services:
  prometheus:
    image: prom/prometheus
    volumes:
      - ./prometheus.yml:/etc/prometheus/prometheus.yml
    ports:
      - "9090:9090"

See Monitoring for details.

User management

Multiple users

n8n supports multiple users with different roles:

environment:
  - N8N_USER_MANAGEMENT_DISABLED=false
  - N8N_USER_MANAGEMENT_SMTP_HOST=smtp.example.com
  - N8N_USER_MANAGEMENT_SMTP_PORT=587
  - N8N_USER_MANAGEMENT_SMTP_USER=n8n@example.com
  - N8N_USER_MANAGEMENT_SMTP_PASS=${SMTP_PASSWORD}
  - N8N_USER_MANAGEMENT_SMTP_SENDER=n8n@example.com

Security considerations

  • Enforce HTTPS: Set N8N_PROTOCOL=https and WEBHOOK_URL=https.
  • Password policy: Require strong passwords for all users.
  • Two-factor authentication: Enable when available.
  • Firewall: Only expose port 443 (HTTPS) to the outside.
  • Encryption: Use N8N_ENCRYPTION_KEY for credentials.
  • Regular updates: Keep n8n current. See Docker updates.
  • Audit logging: Track access. See audit logging.

Practical example: n8n for teams

# docker-compose.yml for team setup
services:
  n8n:
    image: n8nio/n8n:latest
    environment:
      - N8N_HOST=0.0.0.0
      - N8N_PROTOCOL=https
      - WEBHOOK_URL=https://n8n.company.de/
      - DB_TYPE=postgresdb
      - DB_POSTGRESDB_HOST=postgres
      - N8N_USER_MANAGEMENT_DISABLED=false
      - N8N_USER_MANAGEMENT_SMTP_HOST=smtp.company.de
      - EXECUTIONS_DATA_PRUNE=true
      - EXECUTIONS_DATA_MAX_AGE=90
    # ... Rest as above

Common Pitfalls

  • SQLite in production: SQLite works for small setups, not production environments. Use PostgreSQL instead.
  • No HTTPS: Running n8n without HTTPS exposes you to security risks. Enable TLS.
  • No backups: Without backups, your workflows disappear if something fails.
  • No monitoring: You won’t notice outages without monitoring in place.
  • Credentials in plaintext: Set N8N_ENCRYPTION_KEY to encrypt sensitive data.
  • Unbounded execution history: Enable EXECUTIONS_DATA_PRUNE or your database will eventually fill up.

Further Reading

Key Takeaways:

  • n8n self-hosting essentials: HTTPS, reverse proxy, PostgreSQL, backups, monitoring.
  • SQLite for small setups, PostgreSQL for production.
  • Reverse proxy (Nginx) handles HTTPS and routing.
  • Backup strategy: protect your volume and database regularly.
  • Security foundations: HTTPS, strong passwords, firewall rules, encryption.

FAQ

What does n8n self-hosting mean?

n8n self-hosting means running n8n on your own server. You control your data, security, and availability. It’s not just installation, but reliable operation.

SQLite or PostgreSQL?

SQLite for small deployments (1-5 users), PostgreSQL for production. PostgreSQL is more robust, performant, and handles multi-user workloads better.

Do I need a reverse proxy?

Yes, in production. A reverse proxy (Nginx, Traefik) handles HTTPS, TLS certificates, and routing. n8n itself should never be exposed directly to the internet.

How do I enable HTTPS?

Use a reverse proxy with Let’s Encrypt. Certbot generates free TLS certificates. Set N8N_PROTOCOL=https and WEBHOOK_URL=https://…

How do I back up n8n?

Back up the n8n_data volume (workflows, credentials) and the database (PostgreSQL via pg_dump). Automate with a cron job.

How do I monitor n8n?

n8n provides a health endpoint (/healthz). Use Prometheus, Grafana, or simple health checks. Also monitor CPU, RAM, and disk space.

Can I have multiple users?

Yes. Set N8N_USER_MANAGEMENT_DISABLED=false and configure SMTP for invitation emails. Users can be invited and assigned different roles.

How do I secure n8n?

Enforce HTTPS, use strong passwords, configure your firewall (port 443 only), set N8N_ENCRYPTION_KEY, keep software updated, enable audit logging.

How do I update n8n?

Run docker compose pull && docker compose up -d. Back up first. n8n auto-migrates the database.

What does n8n self-hosting cost?

n8n is open source and free. You pay only for server costs (5-20 EUR/month) and optionally a domain (5-10 EUR/year).

References and Further Reading

Back to Blog
Share:

Related Posts