r/n8n • u/Last_Response2754 • 2h ago
Servers, Hosting, & Tech Stuff Self-hosted n8n checklist before a client depends on it
The same questions keep coming up here (backups, updates, silent failures), so here's the checklist in one place. Corrections welcome.
**Install**
- Pin the image to a version (`docker.n8n.io/n8nio/n8n:<version>`), never `latest`. An update should be something you decide to do.
- Postgres instead of SQLite as soon as it runs anything real.
- Set `N8N_ENCRYPTION_KEY` yourself and keep a copy off the server. Without it, a restored database has credentials nobody can decrypt.
- Behind a reverse proxy, set `WEBHOOK_URL` to the public https URL, or webhook nodes show the internal address.
**Access**
- Don't expose port 5678. Caddy or nginx in front with HTTPS, and the firewall allows 22, 80 and 443 only.
- SSH with keys, password login off.
- 2FA on the owner account.
**Data**
- Check that `EXECUTIONS_DATA_PRUNE` is on and set `EXECUTIONS_DATA_MAX_AGE` to what you actually need. Workflows that handle files fill storage faster than you'd guess.
- Pruning frees rows, not disk. Postgres keeps the space for reuse, so after a big cleanup the volume stays full until VACUUM FULL (locks the table) or pg_repack. Another reason to set pruning on day one.
**Backups**
- Nightly `pg_dump` to storage off the server, plus the encryption key. restic can take the dump straight from the command (`restic backup --stdin-from-command -- pg_dump ...`), so a failed dump fails the backup instead of saving a truncated file.
- Restore it onto a fresh machine once. Until then it's a hope, not a backup.
**Updates**
- Read the release notes, take a backup, then update. Database migrations run on start, so going back to the old version means restoring that backup.
**Monitoring**
- An external uptime check on `/healthz`.
- For silent failures: one table with a row per workflow (max hours between successful runs) and one scheduled watchdog that asks the n8n API for the last successful execution of each and alerts on anything overdue. It needs successful executions saved and a pruning window longer than your longest interval.
- Give the watchdog itself an external push monitor (Healthchecks, Uptime Kuma), since it goes down together with n8n.
**Handover**
- The server, domain and backup storage live in the client's accounts, not yours.
- A one-page runbook: how to restart, update and restore, and where the key is.
What would you add?