Updated: 28 September 2026 · Applies to: n8n 2.40 (Docker Compose) on Ubuntu 24.04 / 26.04 LTS

n8n is a workflow automation tool that you can run on your own server. This guide installs it with Docker Compose on an Ubuntu VPS, with a free HTTPS certificate from Let's Encrypt handled by Traefik. It follows n8n's official Docker Compose guide, with two additions that avoid problems later: the webhook address and a fixed encryption key.

Before you start

  • An Ubuntu 24.04 or 26.04 VPS with root or sudo access. We suggest at least 2 GB of RAM; give heavier workflows more.
  • A domain name. n8n will be reachable at a subdomain such as n8n.example.com.
  • Ports 80 and 443 must be reachable from the internet, because the certificate is requested over them.

1. Point a subdomain to the server

In the DNS settings of your domain add an A record: name n8n (or the subdomain you prefer), value YOUR-SERVER-IPV4. Wait a few minutes and check with ping n8n.example.com. If your DNS provider offers a proxy or CDN option for the record (for example Cloudflare's orange cloud), turn it off until the certificate has been issued.

2. Install Docker

Follow Docker's official instructions for Ubuntu: docs.docker.com/engine/install/ubuntu. Then check that both tools work:

docker --version
docker compose version

3. Open the firewall ports

If you use the Ubuntu firewall, allow SSH first so that you do not lock yourself out, then web traffic:

sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable

4. Create the project folder and settings

mkdir n8n-compose && cd n8n-compose
mkdir local-files
openssl rand -hex 32

Copy the random string from the last command: it is your encryption key. Now create the file .env (for example with nano .env) and fill in your own values:

DOMAIN_NAME=example.com
SUBDOMAIN=n8n
GENERIC_TIMEZONE=Europe/Berlin
SSL_EMAIL=you@example.com
N8N_ENCRYPTION_KEY=PASTE-THE-RANDOM-STRING-HERE

GENERIC_TIMEZONE decides when scheduled workflows start; pick your timezone name. Keep a copy of the encryption key outside the server (in a password manager): without it you cannot restore saved credentials (How to set and back up the n8n encryption key (N8N_ENCRYPTION_KEY)?).

5. Create the Compose file

Create compose.yaml in the same folder:

services:
  traefik:
    image: "traefik"
    restart: always
    command:
      - "--providers.docker=true"
      - "--providers.docker.exposedbydefault=false"
      - "--entrypoints.web.address=:80"
      - "--entrypoints.web.http.redirections.entryPoint.to=websecure"
      - "--entrypoints.web.http.redirections.entrypoint.scheme=https"
      - "--entrypoints.websecure.address=:443"
      - "--certificatesresolvers.mytlschallenge.acme.tlschallenge=true"
      - "--certificatesresolvers.mytlschallenge.acme.email=${SSL_EMAIL}"
      - "--certificatesresolvers.mytlschallenge.acme.storage=/letsencrypt/acme.json"
    ports:
      - "80:80"
      - "443:443"
    volumes:
      - traefik_data:/letsencrypt
      - /var/run/docker.sock:/var/run/docker.sock:ro

  n8n:
    image: n8nio/n8n
    restart: always
    ports:
      - "127.0.0.1:5678:5678"
    labels:
      - traefik.enable=true
      - traefik.http.routers.n8n.rule=Host(`${SUBDOMAIN}.${DOMAIN_NAME}`)
      - traefik.http.routers.n8n.tls=true
      - traefik.http.routers.n8n.entrypoints=web,websecure
      - traefik.http.routers.n8n.tls.certresolver=mytlschallenge
    environment:
      - N8N_ENFORCE_SETTINGS_FILE_PERMISSIONS=true
      - N8N_HOST=${SUBDOMAIN}.${DOMAIN_NAME}
      - N8N_PORT=5678
      - N8N_PROTOCOL=https
      - NODE_ENV=production
      - N8N_WEBHOOK_URL=https://${SUBDOMAIN}.${DOMAIN_NAME}/
      - N8N_PROXY_HOPS=1
      - N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
      - GENERIC_TIMEZONE=${GENERIC_TIMEZONE}
      - TZ=${GENERIC_TIMEZONE}
      - N8N_RESTRICT_FILE_ACCESS_TO=/files
    volumes:
      - n8n_data:/home/node/.n8n
      - ./local-files:/files

volumes:
  n8n_data:
  traefik_data:

Traefik takes the requests on ports 80 and 443 and obtains the certificate; n8n itself is only reachable on 127.0.0.1:5678 from the server. The n8n_data volume holds your workflows, credentials and settings. local-files is a folder on the server that workflows can read and write under the path /files.

6. Start n8n

sudo docker compose up -d
sudo docker compose ps

Both containers must show running. Watch the start with sudo docker compose logs -f n8n (stop with Ctrl+C).

7. Open n8n and create the owner account

Open https://n8n.example.com (your own subdomain). The first time, n8n asks you to set up the owner account: enter an email address and a strong password. n8n answers only over HTTPS; plain HTTP is redirected.

If it does not work

  • The browser warns about the certificate: the certificate is not issued yet, which can take a minute. If it stays, check that DNS points to this server, ports 80 and 443 are open in every firewall (also the one of your provider), and read sudo docker compose logs traefik.
  • The site does not load: check sudo docker compose ps and that the address in .env is spelled exactly like your DNS record.
  • Webhook URLs show localhost: see How to fix n8n webhooks that do not work (test URL, production URL, wrong address)?.
  • Use a fixed version: replace image: n8nio/n8n with a version, for example n8nio/n8n:2.40.7 (n8n's current stable release), and update on your schedule as described in How to update n8n (Docker Compose)?.

Next steps

Frequently asked questions

Do I need Traefik?
You need something that provides HTTPS. Traefik does it automatically. If you already run Nginx, use How to run n8n behind Nginx with a free SSL certificate? instead.

How much RAM does n8n need?
It depends on your workflows. Simple automations run in 2 GB; large data volumes or many parallel workflows need more. n8n's own page also recommends PostgreSQL once several people or many workflows run around the clock.

Can Ucartz install this for me?
Yes, see below.

Official documentation: n8n documentation: Docker Compose (n8n 2.40).

Need a server for n8n, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)