Software and AI

Self-Hosted n8n Setup and Maintenance

We install n8n on your company’s own server or in your own cloud subscription, design the workflows with you, and then keep the whole thing backed up, updated and monitored.

CybUP TeamLast updated: 8 min read

In short

n8n automation means running n8n, the source-available workflow automation tool, on infrastructure your company controls (self-hosted). It suits companies that want to automate repetitive work across email, CRM, spreadsheets, forms and APIs. CybUP handles the Ubuntu and Docker installation, PostgreSQL and queue mode configuration, credential security, backups, workflow design and an ongoing maintenance contract.

What is n8n and what do companies use it for?

n8n is a workflow automation tool that connects your applications and runs repetitive tasks on its own. When someone fills in a web form, a single workflow can create the record in your CRM, notify the sales team and send the customer a welcome email. Workflows are built visually by wiring nodes together, and you can drop in JavaScript or Python wherever the built-in nodes run out.

The main reason companies pick n8n is that they can run it on their own servers. Customer data, quotes and accounting exports never pass through a third-party automation platform; the workflows run on your infrastructure. That makes your data flows far easier to explain and audit under KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698).

Typical uses are unglamorous but they eat time: pulling incoming invoices out of email and filing them, compiling the weekly sales report from a spreadsheet and sending it to managers, triaging support requests, stock alerts. AI nodes can add summarisation or classification to a workflow; we cover that separately on our AI automation agency page.

How do you set up self-hosted n8n?

A production n8n setup runs on Ubuntu Server with Docker Compose, uses PostgreSQL as its database and sits behind a reverse proxy that terminates HTTPS. n8n ships with SQLite by default. That is fine for a handful of test workflows, but for a multi-user instance running around the clock PostgreSQL is the sounder foundation.

We install it on your server: a physical or virtual Linux machine in your office, or a VM in an Azure or AWS account opened in your company’s name. If the server isn’t ready yet, we start with Ubuntu Server setup. For workflows that receive webhooks, the domain name, the SSL certificate and firewall rules that open only the ports you need are all part of the job. We recommend keeping the editor behind a VPN rather than exposing it to the internet; only the webhook URLs need to be public.

Data persistence in Docker deserves a mention of its own. According to n8n’s Docker documentation, the .n8n directory holds the encryption key and other important files even when you use an external database. If that directory isn’t mounted on a persistent volume, the key can be lost when the container is recreated.

When do you need n8n queue mode and workers?

Queue mode is n8n’s scaling mode: the main instance only accepts work and hands execution over to separate worker processes. The n8n documentation explains that in this mode pending jobs are queued in Redis, PostgreSQL is required as the database, and the main instance’s encryption key must be shared with every worker.

Not every installation needs it. An accounting and sales automation running a few hundred executions a day sits comfortably on a single instance. Now take an e-commerce company whose order, shipping and stock workflows receive hundreds of webhooks a minute during a sale: a single process chokes and some executions time out. Two or three workers behind a queue spread the load and stop one long-running workflow from holding up the rest.

Before installing, we look at your current and expected execution volume, how long workflows take on average and whether they process files. The decision follows from those numbers. Adding Redis and workers when you don’t need them only adds maintenance.

“The encryption key of the main n8n instance must be shared with all worker and webhooks processor nodes to ensure these worker nodes are able to access credentials stored in the database.”

— n8n Docs — Queue mode

How do you secure credentials and access in n8n?

n8n encrypts the API keys and passwords of connected services before writing them to the database. The encryption key documentation notes that n8n generates the key automatically on first launch; we set it deliberately through the N8N_ENCRYPTION_KEY environment variable and keep a copy in your company’s password vault. Lose the key and the credentials in a restored backup cannot be decrypted.

On access, the owner account belongs to a named person and users are invited individually. Service accounts used in workflows get only the permissions they need: a workflow that reads a report has no business deleting records in the CRM. We put an authentication header or signature check on webhook endpoints, so nobody can trigger a workflow just by sending a request to a known URL.

  • Editor behind a VPN or an IP allow-list
  • Encryption key set as an environment variable and stored in a vault
  • Least privilege for service accounts
  • Authentication on webhook endpoints
  • Automatic security updates and logging on the server

How should you back up and update n8n?

A complete n8n backup has three parts: the PostgreSQL database, the .n8n directory that holds the encryption key, and the environment variables and Compose file that define the installation. n8n’s backup and restore guide states plainly that credentials cannot be restored without the encryption key. We also export workflows as JSON through the CLI and commit them to a repository with version history.

We never update straight on production. A backup is taken first, the release notes are read, and critical workflows are run against the new version in a test environment. n8n releases often, and some releases change how nodes behave. Under the maintenance contract, updates happen on a schedule with a rollback path ready.

The only way to know a backup works is to restore it. Every so often we restore it onto a separate machine and check that the workflows and credentials open correctly.

“n8n saves credentials to the database in encrypted form. Without the encryption key from the config file, or a custom N8N_ENCRYPTION_KEY, a restored database or encrypted credential export can't be decrypted.”

— n8n Docs — Backup and restore

n8n Community vs Enterprise: what is the difference?

Self-hosted n8n runs as the Community edition without a licence key; Enterprise needs a licence key to switch on additional features. According to n8n’s edition comparison, the Community edition does not include SSO (SAML, LDAP), projects, workflow and credential sharing, environments, external secrets, log streaming or Git-based version control. For a small team Community is usually enough; organisations that need permissions separated between departments and an audit trail should look at Enterprise.

The licence terms matter too. n8n is distributed under the Sustainable Use License. The licence FAQ explicitly allows internal business use as well as consulting and automation services; offering n8n to customers under your own brand, or charging for access to the n8n interface, is restricted. If you are thinking of embedding n8n in your own product, base that decision on the FAQ and, if necessary, on a conversation with n8n’s licensing team.

How do we design n8n workflows that don’t fail silently?

A good n8n workflow is designed around what happens when something goes wrong. Every critical workflow gets an error workflow attached: if an API doesn’t respond or data arrives in an unexpected shape, the right person is alerted and the record isn’t lost. Steps that are safe to repeat get retries; steps that aren’t, such as a payment instruction, get a check that prevents duplicate runs.

Each workflow gets a clear name, a descriptive note and an owner. Whoever opens it six months later should understand what it does and why. In workflows that handle personal data we pass only the fields that are needed and decide how long execution history is kept: n8n’s execution logs hold a copy of the data, which makes them part of your retention policy.

You can also build workflows that log WhatsApp enquiries in your CRM or send questions to a language model running in-house; see our WhatsApp AI chatbot and local LLM deployment pages.

What does an n8n maintenance contract cover?

A maintenance contract is the ongoing service that keeps n8n running, up to date and backed up after installation. We agree the scope with you; it usually covers server and n8n updates, backup checks and test restores, monitoring of failed executions, adapting workflows when a connected service changes its API, and new workflow requests.

For monitoring we track the server’s disk, memory and CPU, whether the n8n process is up, and alerts coming from error workflows. We work on site in Istanbul when needed and remotely anywhere else in Türkiye. If you already have an instance, we start with a free review and report on its condition.

What you receive

  • n8n running on your own server with Docker Compose, PostgreSQL and an HTTPS reverse proxy
  • Queue mode with Redis and workers, where the workload calls for it
  • Documented security settings: encryption key, users and access restrictions
  • A backup routine covering the database, the .n8n directory and workflow exports
  • Your first workflows, built with error workflows and alerts
  • A handover document covering the installation, the workflow list and restore steps

How we work

  1. 1

    Free review

    We talk through the work you want to automate, the applications involved and your server situation, then send a written quote.

  2. 2

    Infrastructure preparation

    The server, domain, SSL certificate, firewall rules and database are prepared; queue mode is planned if needed.

  3. 3

    Installation and hardening

    n8n is installed, the encryption key and users are set up, and access to the editor is restricted.

  4. 4

    Workflow build and testing

    Priority workflows are built with error handling and tested in a controlled way on real data.

  5. 5

    Handover and maintenance

    You receive the documentation and your team gets a short walkthrough; backups and updates continue under the maintenance contract.

Frequently asked questions

Do we have to host n8n on our own server?

No, n8n also runs its own cloud service. We install it on your server or in your own cloud subscription so that the data and workflows stay under your control. We weigh up which option fits based on how sensitive your data is and the IT resources you have in-house.

Is n8n free, or do we need a licence?

The self-hosted Community edition runs without a licence key, and internal business use is permitted under its licence terms. Features such as SSO, projects, sharing and Git-based version control need an Enterprise licence. We check the current terms against n8n’s official licence pages with you.

How long does an n8n setup take?

If the server is ready, the base installation and security settings are usually done within a few working days. The real timeline depends on how many workflows you need and the state of the APIs on the systems being connected. We give you a written schedule after the review.

What can n8n integrate with?

Besides the hundreds of services with ready-made nodes, any system with a REST API can be connected through the HTTP Request node. Databases, email, spreadsheets, CRMs and file servers are common examples. Older software without an API may need a workaround via its database or files.

Can you take over our existing n8n instance?

Yes. We first check the version, the database, the state of the backups, where the encryption key is kept and how workflows handle errors. We report the gaps, fix them with your approval and take over maintenance.

How much does it cost?

We send a written quote once we have reviewed the scope; the review is free. The quote lists installation, workflow development and maintenance as separate items.

Is there anything to watch out for under KVKK?

Yes. You need to document which personal data moves where in each workflow, how long execution logs are kept and whether any data goes to a service abroad. We add this to the workflow list during setup, and we recommend doing the legal assessment with your KVKK adviser.

Do you work remotely or on site?

n8n installation and maintenance are mostly done remotely over a secure connection. If n8n needs to go on a server inside your office in Istanbul, we also work on site.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.