Deployment Overview of n8n on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu (recommended).
-
Privileges: Root or sudo access is required for package installation and Docker configuration.
-
Domain Name: A valid FQDN is required for SSL certificate issuance via Certbot.
-
Ports: The following ports must be open in the firewall:
-
80/tcp(HTTP) -
443/tcp(HTTPS)
FQDN of the final panel on the hostkey.in domain¶
The application is accessed via a specific subdomain template based on your server ID.
| Parameter | Value |
|---|---|
| Prefix | n8n |
| Domain | hostkey.in |
| Full template | n8n{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes the following directory structure for configuration and persistent data:
-
/root/n8n-compose-file/: Contains the Docker Compose configuration. -
/data/nginx/: Stores Nginx user configurations and Let's Encrypt challenge files. -
/data/nginx/user_conf.d/: Location of specific site configuration files. -
/data/nginx/letsencrypt/: Directory for ACME challenges. -
/data/n8n/: Main persistent data directory for the application. -
/data/n8n/files/: Dedicated directory for uploaded or processed files within n8n.
Application installation process¶
The installation is performed through a multi-step process involving system preparation and container orchestration:
-
System Preparation: The package manager (apt) is updated, and any interrupted dependency states are repaired to ensure environment stability.
-
Dependency Installation: Essential helper packages such as
curlanddnsutilsare installed. -
Docker Engine Setup: Docker is installed on the host system to facilitate containerized deployment.
-
Directory Initialization: The required directory structure for Nginx, configuration files, and application data is created with appropriate ownership (
root:rootor1000:1000). -
Configuration Generation:
-
An environment file for Certbot renewal intervals is created at
/data/nginx/nginx-certbot.env. -
Nginx configuration files are generated based on the assigned domain.
-
A Docker Compose file is prepared in
/root/n8n-compose-file/. -
Container Orchestration: The application and its proxy are started using
docker compose up -d.
Access Rights and Security¶
Security is managed through several layers:
-
Firewall (UFW): The firewall is configured to allow incoming traffic on ports 80 and 443.
-
Container Isolation: n8n is bound to the local loopback interface (
127.0.0.1) for its internal port, ensuring it is only accessible through the Nginx proxy. -
Permissions: Application data directories are owned by user
1000to ensure correct file permissions within the container.
Databases¶
The application uses an internal storage mechanism managed within the Docker volume. All persistent database information and workflow data are stored in:
/data/n8n
Docker Containers and Their Deployment¶
The deployment consists of two primary containers:
Nginx Proxy (SSL Management)¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d -
/data/nginx/letsencrypt:/var/www/letsencrypt -
Environment Variables:
-
CERTBOT_EMAIL: Configured via the provided email address. -
Restart Policy:
unless-stopped
n8n Application¶
-
Image:
docker.n8n.io/n8nio/n8n:latest -
Ports:
127.0.0.1:5678 -> 5678 -
Volumes:
-
/data/n8n:/home/node/.n8n -
/data/n8n/files:/files -
Environment Variables:
-
N8N_HOST: The configured FQDN. -
N8N_PROTOCOL:https -
NODE_ENV:production -
GENERIC_TIMEZONE: Configured based on the server settings (e.g.,Europe/Amsterdam). -
WEBHOOK_URL: Set to the application's public HTTPS URL. -
Restart Policy:
unless-stopped
Application Update Instructions¶
To update the n8n application to the latest version, navigate to the deployment directory and execute the following command: