Updated: 28 September 2026 · Applies to: n8n 2.40 (Docker) with Nginx and Certbot on Ubuntu 24.04 / 26.04 LTS
If Nginx already serves your websites, you can put n8n behind it and use a free Let's Encrypt certificate from Certbot. n8n's documentation recommends a reverse proxy for HTTPS. This guide runs n8n in Docker on the local port 5678 and lets Nginx handle the public address.
Before you start
- An Ubuntu 24.04 or 26.04 server with Docker installed (Docker's instructions).
- A DNS A record such as
n8n.example.comthat points to the server. - Ports 80 and 443 open in the firewall.
1. Start n8n on the local port only
Create a folder with a compose.yaml (and a .env with your GENERIC_TIMEZONE and N8N_ENCRYPTION_KEY, see How to install n8n with Docker Compose and HTTPS on an Ubuntu VPS?):
services:
n8n:
image: n8nio/n8n
restart: always
ports:
- "127.0.0.1:5678:5678"
environment:
- N8N_HOST=n8n.example.com
- N8N_PORT=5678
- N8N_PROTOCOL=https
- N8N_WEBHOOK_URL=https://n8n.example.com/
- N8N_PROXY_HOPS=1
- N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
- GENERIC_TIMEZONE=${GENERIC_TIMEZONE}
- TZ=${GENERIC_TIMEZONE}
volumes:
- n8n_data:/home/node/.n8n
volumes:
n8n_data:
sudo docker compose up -d
127.0.0.1:5678 means only the server itself can reach n8n directly. N8N_WEBHOOK_URL and N8N_PROXY_HOPS=1 are needed behind a proxy (How to fix n8n webhooks that do not work (test URL, production URL, wrong address)?).
2. Install Nginx and Certbot
sudo apt update sudo apt install -y nginx certbot python3-certbot-nginx
3. Create the Nginx site
Create /etc/nginx/sites-available/n8n:
server {
listen 80;
server_name n8n.example.com;
client_max_body_size 50M;
location / {
proxy_pass http://127.0.0.1:5678;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_read_timeout 300s;
}
}
The X-Forwarded-* headers are required by n8n behind a proxy. The Upgrade and Connection headers keep the editor's live connection working: n8n sends changes to the browser through WebSockets by default. Without them the editor may show "Connection lost".
Enable the site and test the configuration:
sudo ln -s /etc/nginx/sites-available/n8n /etc/nginx/sites-enabled/n8n sudo nginx -t sudo systemctl reload nginx
4. Get the certificate
sudo certbot --nginx -d n8n.example.com
Answer the questions (email address, agree to the terms) and choose to redirect HTTP to HTTPS. Certbot edits the site file and renews the certificate automatically. Test renewal with sudo certbot renew --dry-run.
5. Open n8n
Go to https://n8n.example.com and create the owner account.
Problems
- 502 Bad Gateway: n8n is not running. Check
sudo docker compose psand that the port inproxy_passis 5678. - "Connection lost" in the editor: the WebSocket headers (
Upgrade,Connection) are missing in the Nginx site. - Webhook URLs show the wrong address: How to fix n8n webhooks that do not work (test URL, production URL, wrong address)?.
- Large file uploads fail (413): raise
client_max_body_size. - Certbot cannot validate: DNS must point to this server, and port 80 must reach Nginx.
Frequently asked questions
Can I use the same Nginx for other sites?
Yes. Each site gets its own file with its own server_name.
Do I need N8N_PROXY_HOPS=1?
Yes, when exactly one proxy (here Nginx) sits in front of n8n. n8n's documentation asks for it together with the forwarded headers.
Official documentation: n8n documentation: Set up SSL.
Need a server for n8n, or a hand with the setup?
- n8n VPS hosting: a VPS made for self-hosted n8n.
- n8n setup service: we install n8n on your own server with SSL, backups and security.
- n8n automation services: workflows, integrations and consulting.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
