n8n Self-Hosting
What this article covers
- Setting up n8n for production.
- Configuring HTTPS, reverse proxy, and database.
- Setting up backup, monitoring, and updates.
- Preparing n8n for multiple users and teams.
- Best practices for security, availability, and maintenance.
Introduction: n8n self-hosting explained
Installing n8n is straightforward. Running n8n in production is something else: HTTPS, reverse proxy, database, backup, monitoring, user management. This article shows how to not just get n8n running, but operate it reliably.
This article is for users who want to run n8n in production. You should already have n8n installed. See installing n8n for the basic setup.
Why do I need n8n self-hosting?
Imagine you’ve installed n8n locally and built a few workflows. Now you want your team to use it, with HTTPS, multiple users, backups, and monitoring. The local installation won’t cut it: you need a production setup.
n8n self-hosting at a glance
n8n self-hosting means running n8n on your server with HTTPS, reverse proxy, database, backup, and monitoring. Not just for testing, but for daily operations.
The core idea is this: run n8n not just to try it out, but to operate it reliably.
Who is this article for?
- System administrators operating n8n in production.
- Teams setting up n8n for multiple users.
- Self-hosters running n8n professionally.
- Decision makers evaluating n8n for their organization.
You’ll need some background with Docker, n8n, and Linux.
Key concepts
- n8n - Workflow automation. Useful for: the tool itself.
- Reverse proxy - intermediary in front of n8n. Useful for: HTTPS and routing.
- Docker - Container platform. Useful for: running services.
- Docker Compose - Multi-container orchestration. Useful for: complex setups.
- PostgreSQL - Database. Useful for: production instead of SQLite.
- Backup - Data protection. Useful for: workflows and credentials.
- Monitoring - System oversight. Useful for: availability tracking.
Production setup
Docker Compose for production
version: "3.8"
services:
n8n:
image: n8nio/n8n:latest
container_name: n8n
restart: unless-stopped
ports:
- "127.0.0.1:5678:5678" # Localhost only, reverse proxy in front
environment:
- N8N_HOST=0.0.0.0
- N8N_PORT=5678
- N8N_PROTOCOL=https
- WEBHOOK_URL=https://n8n.deine-domain.de/
- GENERIC_TIMEZONE=Europe/Berlin
- TZ=Europe/Berlin
- N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
- DB_TYPE=postgresdb
- DB_POSTGRESDB_HOST=postgres
- DB_POSTGRESDB_PORT=5432
- DB_POSTGRESDB_DATABASE=n8n
- DB_POSTGRESDB_USER=n8n
- DB_POSTGRESDB_PASSWORD=${DB_PASSWORD}
- EXECUTIONS_DATA_PRUNE=true
- EXECUTIONS_DATA_MAX_AGE=30
volumes:
- n8n_data:/home/node/.n8n
networks:
- n8n-network
depends_on:
- postgres
postgres:
image: postgres:16-alpine
container_name: n8n-postgres
restart: unless-stopped
environment:
- POSTGRES_DB=n8n
- POSTGRES_USER=n8n
- POSTGRES_PASSWORD=${DB_PASSWORD}
volumes:
- postgres_data:/var/lib/postgresql/data
networks:
- n8n-network
volumes:
n8n_data:
postgres_data:
networks:
n8n-network:
driver: bridge
Reverse proxy with Nginx
# /etc/nginx/sites-available/n8n
server {
listen 443 ssl http2;
server_name n8n.deine-domain.de;
ssl_certificate /etc/letsencrypt/live/n8n.deine-domain.de/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/n8n.deine-domain.de/privkey.pem;
location / {
proxy_pass http://127.0.0.1:5678;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
TLS certificate with Let’s Encrypt
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d n8n.deine-domain.de
See TLS certificates for details.
Database: SQLite vs. PostgreSQL
| SQLite | PostgreSQL |
|---|---|
| Simple, no extra installation | Robust, production-ready |
| For small setups | For large setups |
| Single-user | Multi-user |
| Less performant | More performant |
| Easy backup (file-based) | Complex backup (pg_dump) |
For production: PostgreSQL is recommended.
Backup
Backing up n8n data
# Back up volume
docker run --rm \
-v n8n_data:/data \
-v $(pwd)/backup:/backup \
alpine tar czf /backup/n8n-backup.tar.gz -C /data .
# Back up PostgreSQL
docker exec n8n-postgres pg_dump -U n8n n8n > backup/n8n-db.sql
Automated backups
# Cron job for daily backups
0 3 * * * docker run --rm -v n8n_data:/data -v /backup:/backup alpine tar czf /backup/n8n-$(date +\%Y\%m\%d).tar.gz -C /data .
See Backup for details.
Monitoring
Health checks
# n8n health endpoint
curl http://localhost:5678/healthz
Monitoring with Prometheus
# Extend docker-compose.yml
services:
prometheus:
image: prom/prometheus
volumes:
- ./prometheus.yml:/etc/prometheus/prometheus.yml
ports:
- "9090:9090"
See Monitoring for details.
User management
Multiple users
n8n supports multiple users with different roles:
environment:
- N8N_USER_MANAGEMENT_DISABLED=false
- N8N_USER_MANAGEMENT_SMTP_HOST=smtp.example.com
- N8N_USER_MANAGEMENT_SMTP_PORT=587
- N8N_USER_MANAGEMENT_SMTP_USER=n8n@example.com
- N8N_USER_MANAGEMENT_SMTP_PASS=${SMTP_PASSWORD}
- N8N_USER_MANAGEMENT_SMTP_SENDER=n8n@example.com
Security considerations
- Enforce HTTPS: Set N8N_PROTOCOL=https and WEBHOOK_URL=https.
- Password policy: Require strong passwords for all users.
- Two-factor authentication: Enable when available.
- Firewall: Only expose port 443 (HTTPS) to the outside.
- Encryption: Use N8N_ENCRYPTION_KEY for credentials.
- Regular updates: Keep n8n current. See Docker updates.
- Audit logging: Track access. See audit logging.
Practical example: n8n for teams
# docker-compose.yml for team setup
services:
n8n:
image: n8nio/n8n:latest
environment:
- N8N_HOST=0.0.0.0
- N8N_PROTOCOL=https
- WEBHOOK_URL=https://n8n.company.de/
- DB_TYPE=postgresdb
- DB_POSTGRESDB_HOST=postgres
- N8N_USER_MANAGEMENT_DISABLED=false
- N8N_USER_MANAGEMENT_SMTP_HOST=smtp.company.de
- EXECUTIONS_DATA_PRUNE=true
- EXECUTIONS_DATA_MAX_AGE=90
# ... Rest as above
Common Pitfalls
- SQLite in production: SQLite works for small setups, not production environments. Use PostgreSQL instead.
- No HTTPS: Running n8n without HTTPS exposes you to security risks. Enable TLS.
- No backups: Without backups, your workflows disappear if something fails.
- No monitoring: You won’t notice outages without monitoring in place.
- Credentials in plaintext: Set N8N_ENCRYPTION_KEY to encrypt sensitive data.
- Unbounded execution history: Enable EXECUTIONS_DATA_PRUNE or your database will eventually fill up.
Further Reading
- Installing n8n - Basic setup.
- n8n Guide - n8n in detail.
- n8n-Ollama Integration - Using Ollama with n8n.
- Docker Basics - Understanding Docker.
- Reverse Proxy - Setting up a reverse proxy.
- TLS Certificates - Enabling HTTPS.
- Backup - Data protection.
- Monitoring - Observability.
Key Takeaways:
- n8n self-hosting essentials: HTTPS, reverse proxy, PostgreSQL, backups, monitoring.
- SQLite for small setups, PostgreSQL for production.
- Reverse proxy (Nginx) handles HTTPS and routing.
- Backup strategy: protect your volume and database regularly.
- Security foundations: HTTPS, strong passwords, firewall rules, encryption.
FAQ
What does n8n self-hosting mean?
SQLite or PostgreSQL?
Do I need a reverse proxy?
How do I enable HTTPS?
How do I back up n8n?
How do I monitor n8n?
Can I have multiple users?
How do I secure n8n?
How do I update n8n?
What does n8n self-hosting cost?
References and Further Reading
- n8n Self-Hosting Docs - Official documentation.
- n8n Docker - Docker setup.
- Nginx Reverse Proxy - Reverse proxy guide.
- Let’s Encrypt - Free TLS certificates.


