Skip to content
Wasevo
BlogHosting & Servers 4 min read

Self-hosted n8n on a €5 VPS: the production setup we use

A production-ready self-hosted n8n setup: Docker Compose with PostgreSQL, a reverse proxy with TLS, queue mode, backups, monitoring and a safe update routine, from Wasevo's own instances.

Summarize with:

Share:

You can run n8n in production on a €5-10 VPS with 2 GB of RAM using Docker Compose, PostgreSQL and a reverse proxy that issues TLS certificates automatically. That is the setup Wasevo uses for its own automations and for clients who want unlimited executions and data on their own server. The parts people skip and later regret are the encryption key backup, the database dumps and the update routine. This guide covers all of them in the order we do them.

If you are still deciding between self-hosting and n8n Cloud, read Is n8n free? first. Self-hosting is cheaper at volume, but only if someone owns the maintenance.

1. Choose and prepare the server

  • A VPS with 2 vCPU and 2-4 GB RAM from Hetzner, DigitalOcean, Contabo or a similar provider, with 4 GB if you run AI nodes with large payloads
  • Ubuntu LTS with automatic security updates enabled
  • A non-root user with sudo, SSH keys only, password login disabled
  • A firewall allowing ports 22, 80 and 443 only
  • Docker Engine and the Docker Compose plugin from Docker's repository

Point a subdomain such as n8n.yourdomain.com at the server before you install anything, so the reverse proxy can issue a certificate on the first start.

2. Docker Compose with PostgreSQL and Caddy

The stack has three services: n8n, PostgreSQL and Caddy. Caddy terminates HTTPS and renews certificates automatically. In the n8n service, set N8N_HOST and WEBHOOK_URL to your subdomain, N8N_PROTOCOL to https and GENERIC_TIMEZONE to your zone. Add the DB_TYPE and PostgreSQL variables, and set N8N_ENCRYPTION_KEY to a long random string you generate once. Mount named volumes for n8n's data folder and for PostgreSQL so you can recreate the containers without losing anything.

SQLite, the default, is fine for a single user, but it does not support queue mode and it becomes the bottleneck as execution history grows. Starting on PostgreSQL avoids a database migration later.

3. Back up the encryption key

n8n encrypts every stored credential with N8N_ENCRYPTION_KEY. If you lose the key, you have to re-enter every credential. Store it in a password manager the day you create it and never regenerate it on an existing instance. Back up the key together with the database, because a restore needs both.

4. Queue mode when you grow

Once several workflows run at the same time, switch to queue mode. Add a Redis service, then run one main n8n process with EXECUTIONS_MODE=queue and one or more worker containers with the n8n worker command. The editor stays responsive under load and you can scale workers separately from the main process. Most teams need this only after a few thousand executions a day.

5. Backups you have tested by restoring

  • Nightly pg_dump of the n8n database to object storage (Backblaze B2, Hetzner Storage Box, S3) with 30-day retention
  • Weekly export of all workflows as JSON through the n8n CLI or REST API, kept in a Git repository
  • The encryption key stored separately in a password manager
  • A timed restore test once a quarter on a throwaway server, so you know whether recovery takes 20 minutes or a day

6. Monitoring that catches silent failures

  • An external uptime check on the /healthz endpoint every minute
  • An n8n error workflow that posts failed executions to Slack or email with the workflow name and the error
  • Disk, memory and CPU alerts on the VPS, because n8n's execution history can fill a disk quickly
  • Execution data pruning enabled (EXECUTIONS_DATA_PRUNE with a sensible max age) so the database stays small
  • Docker log rotation so container logs do not fill the disk

7. A safe update routine

n8n releases almost weekly. Pin a version tag rather than latest, read the release notes, take a backup, pull the new image, recreate the containers and run one test workflow. Doing this on a fixed day once a month keeps you current without surprise breaking changes. Keep the previous image available so a rollback is one command.

8. Security basics

  • Authentication on the editor at all times, through n8n's built-in user management or SSO on higher plans
  • Separate credentials per client or department, and least-privilege API keys
  • Verification tokens or signatures on incoming webhooks
  • A quarterly review of workflows that call external HTTP endpoints
  • Regular OS patching, which automatic security updates handle on Ubuntu

What it costs to run

Server €5-20 per month, object storage for backups under €2, a domain you already own, and about two hours of maintenance a month for updates, checks and the occasional fix. Compare that with n8n Cloud Pro at roughly €50 per month for 10,000 executions. Self-hosting costs less at higher volume, but not if nobody wants to spend the two hours.

When to let someone else run it

If nobody on the team wants to own updates, backups and incidents, self-hosting costs more than n8n Cloud in lost time and risk. Wasevo sets this stack up for a fixed price and keeps it running on a monthly hosting plan, with the backups, monitoring and update routine above included.

Frequently asked questions

A VPS with 2 vCPU and 2-4 GB RAM running Ubuntu with Docker is enough for most small and mid-size teams. Add RAM if you process large files or run AI nodes with big payloads.

WA

Written by

Waqas Ahmed Waseer

Founder & CEO of Wasevo. Builds SEO, software and AI automation for clients in the US, UK, Canada, Australia, Sweden and Pakistan since 2020.

Related Articles

Get new guides by email

One short email when we publish something useful. No spam; unsubscribe at any time.

Servers · Migrations · Maintenance

Keep it fast, backed up and updated.

Book a free call

15 minutes, no sales pitch