Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To deploy n8n on a VPS with a custom domain, run n8n and a reverse proxy such as Traefik as Docker Compose services, point your domain to the VPS, and configure the public HTTPS address—including WEBHOOK_URL—in n8n. Persist n8n’s data and the proxy’s certificate store so replacing a container does not discard them.

How the deployment fits together

The official n8n Compose example runs n8n and Traefik on a Linux server. Traefik accepts web traffic on ports 80 and 443, redirects HTTP to HTTPS, and obtains certificates through ACME. It routes requests for your chosen hostname to n8n. The example is documented at n8n’s Docker Compose server setup guide.

Your domain must resolve to the VPS’s public address, and inbound web traffic must be allowed to reach the proxy. n8n’s public host and webhook URL must match the address external users and services will use—not an internal container address.

Prepare the VPS, domain, and Docker

  1. Choose a Linux VPS and install Docker. Install Docker Engine and the Docker Compose plugin using the instructions for your Linux distribution. The n8n guide does not prescribe a VPS vendor or universal minimum server size.
  2. Create DNS for the hostname. Choose a subdomain such as n8n.example.com and configure DNS so it resolves to the VPS. Substitute your own domain throughout; the example hostname is not a real deployment address.
  3. Allow web traffic. Configure the VPS firewall and any upstream firewall to permit inbound TCP ports 80 and 443 to the server. These are the HTTP and HTTPS ports used by the documented proxy setup.
  4. Create a project directory and environment file. In a dedicated directory for the Compose project, create the .env file used by the configuration. Set the domain, subdomain, and certificate contact email values required by the official example, using your own values rather than copying placeholders.

Configure Docker Compose and the public URLs

Use the current Compose configuration from the official n8n setup guide rather than an unverified third-party recipe. Its two services have distinct roles: n8n runs the automation application, while Traefik handles public routing and TLS. The proxy’s ACME configuration needs the contact email from your environment file and a persistent certificate store.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set N8N_HOST to the selected subdomain and domain, declare the public protocol as HTTPS, and set WEBHOOK_URL to the complete public HTTPS address. For example, if your hostname is n8n.example.com, the webhook base address should use https://n8n.example.com/. The exact Compose variables and routing labels should remain consistent with the current official example.

This distinction matters for integrations: outside services call the public URL, while Docker services communicate over the Compose network. If the webhook URL points to a local or internal address, an external service cannot use it to reach your instance.

Persist n8n data and TLS certificates

The official basic Compose example mounts the n8n_data volume at /home/node/.n8n. n8n stores its SQLite database and encryption key there. The example also retains Traefik’s certificate data in a separate volume. Keep both volumes when updating or replacing containers; otherwise, n8n state or proxy certificate files may be lost.

SQLite is the database used in that basic example, not the only configuration n8n supports. The official n8n hosting examples repository also includes a Compose setup using PostgreSQL. Choose a database configuration supported by the relevant official example and account for its additional service and configuration; the available documentation does not establish a universal user-count or performance threshold for choosing one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
HP MicroServer Gen10 Plus Mini Tower Server, Intel Xeon E-2224 3.4GHz, 32GB RAM, 16TB Storage, RAID, Windows Server 2019
  • HP MicroServer Gen10 Plus Tower Server for Business with Microsoft Windows Server 2019 OS!
  • Intel Xeon E-2224 Quad-Core 3.4GHz 8MB CPU, Up To 4.6GHz Turbo
  • 32GB (2 x 16GB) DDR4 PC4-21300 2666MHz Unbuffered Memory
  • 16TB (4 x 4TB) 7.2K 6Gb/s SATA 3.5" HDDs in RAID
  • Hard drives and memory upgrades included separately NOT installed, installation required.

Start the stack and verify access

  1. From the directory containing the Compose project, run docker compose up -d.
  2. Open the configured HTTPS hostname in a browser, for example https://n8n.example.com. The official example expects the instance to be reachable at the HTTPS address formed from the configured subdomain and domain.
  3. Confirm that the address is served over HTTPS and that the n8n interface loads. Then check that any webhook or external integration configuration uses the same public HTTPS hostname.

Troubleshoot an unreachable instance

When the hostname does not load, check the network path before changing n8n settings:

  • DNS: Confirm the hostname resolves to the VPS’s current public address.
  • Firewall: Verify inbound ports 80 and 443 are allowed through both the VPS firewall and any provider-level firewall.
  • Proxy routing and certificate setup: Check the Traefik service, hostname labels, ACME configuration, and certificate-data volume against the current official Compose guide.
  • Public URL consistency: Ensure N8N_HOST, the HTTPS protocol setting, and WEBHOOK_URL all refer to the same public hostname.
  • Persistence: Verify that the expected named volumes are mounted if n8n state or certificate data appears to disappear after a container replacement.

Secure and maintain the instance

Keep public access behind HTTPS at the reverse proxy. Treat the environment file and its secrets as sensitive, and retain the persistent n8n and certificate volumes. n8n’s security audit can identify issues involving credentials, database queries, file-system access, risky community or custom nodes, unprotected webhooks, missing security settings, and outdated instances. Run it after deployment and review the findings rather than assuming that a working HTTPS page alone means the instance is secure.

n8n’s SSL guidance also describes terminating SSL/TLS with a reverse proxy or network load balancer in front of n8n: n8n SSL configuration guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Self-hosting or n8n Cloud?

Option Who operates infrastructure Control
Self-hosted on a VPS with Docker Compose You maintain the VPS, Docker, proxy, persistent storage, and operational security. Direct control over the runtime and deployment configuration.
n8n Cloud n8n provides the managed hosting option. Less infrastructure to operate yourself; it is not a VPS deployment.

n8n lists both Docker and Cloud among its hosting options in its hosting overview. The cited documentation does not provide current plan prices or a quantified total-cost comparison, so compare current terms directly if cost is the deciding factor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.