In 2026, enterprise data privacy regulations, API usage quotas, and third-party SaaS price hikes have turned self-hosting into the gold standard for workflow automation. Modern technical teams can no longer afford to pump proprietary customer data, sensitive CRM records, and confidential telemetry through shared cloud platforms. Instead, deploying n8n directly onto dedicated virtual private infrastructure delivers limitless execution capacity, maximum execution speed, and absolute sovereign control.
Furthermore, n8n does not exist in an isolated bubble. When paired with intelligent runtime agents like Hermes and autonomous browser automation engines like OpenClaw, self-hosted n8n becomes the central nervous system of an enterprise automation architecture. In this comprehensive guide, we will walk through the exact, production-hardened deployment architecture for self-hosting n8n on an isolated VPS, complete with PostgreSQL persistence, reverse proxy TLS termination, automated credential encryption, and unified orchestration.
Why Self-Host n8n in 2026?
Self-hosting n8n is fundamentally different from using a hosted automation SaaS. When you run n8n on your own dedicated instance:
- Zero Execution Limits: Cloud pricing models charge per task or workflow execution. On your private VPS, you can execute millions of webhook triggers and scheduled loops without recurring per-run penalty fees.
- Data Sovereignty and Compliance: Sensitive payloads, API tokens, and internal database queries stay within your own VPC boundary. No foreign SaaS stores your encrypted payloads.
- Ecosystem Interoperability: Direct low-latency network communication with internal microservices, localized vector databases, autonomous scrapers like OpenClaw, and terminal AI runtimes like Hermes.
- Custom Integrations and Community Nodes: Build and mount proprietary community nodes, custom Python/Node scripts, and internal binary tools directly into the execution container.
However, running n8n in production requires sound DevOps hygiene. You cannot rely on an ephemeral SQLite database or an exposed raw port. A production-ready n8n node requires PostgreSQL, dedicated data volumes, automated TLS encryption, and rigorous process isolation.
Architectural Topology
A resilient self-hosted n8n deployment consists of four architectural tiers:
[ Inbound HTTPS / Webhook Traffic ]
│
▼
[ Caddy / Traefik Reverse Proxy ] (Automatic TLS & Let's Encrypt)
│
▼
[ n8n Core Container ]
│ │
▼ ▼
[ PostgreSQL 16 ] [ OpenClaw / Hermes Local API ]
(Relational DB) (Agent & Scraper Workloads)
By placing n8n on an internal Docker network alongside PostgreSQL, the database port is never exposed to the public Internet, dramatically reducing your attack surface.
Step-by-Step Production Deployment
1. Host Hardening & System Preparation
Provision an isolated Linux VPS (Ubuntu 24.04 LTS or Debian 12) with at least 2 vCPUs and 4 GB RAM. If you plan to coordinate continuous AI pipelines alongside OpenClaw scrapers or Hermes LLM agents, an 8 GB RAM instance (such as the Overmanager PRO tier) is strongly recommended.
Update host repositories and install Docker Engine with the Compose plugin:
sudo apt update && sudo apt upgrade -y
sudo apt install -y curl ufw fail2ban ca-certificates gnupg
# Install Docker
curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
sudo usermod -aG docker $USER
Configure the host firewall to allow only SSH, HTTP, and HTTPS:
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
2. Crafting the Docker Compose Stack
Create a dedicated workspace directory on your server:
mkdir -p /opt/overmanager/n8n-stack
cd /opt/overmanager/n8n-stack
Create your production environment file .env. Be sure to replace the placeholder passwords and domain names with your real production values:
# General Domain Settings
DOMAIN_NAME=n8n.yourcompany.com
SUBDOMAIN=n8n
SSL_EMAIL=support@yourcompany.com
# PostgreSQL Credentials
POSTGRES_USER=n8n_master
POSTGRES_PASSWORD=SuperSecretDatabaseKey2026!
POSTGRES_DB=n8n_enterprise
# n8n Core Configuration
N8N_ENCRYPTION_KEY=GenerateAStrong32CharacterHexSecretHere
N8N_HOST=n8n.yourcompany.com
N8N_PORT=5678
N8N_PROTOCOL=https
NODE_ENV=production
WEBHOOK_URL=https://n8n.yourcompany.com/
GENERIC_TIMEZONE=UTC
# Execution Pruning & Performance
EXECUTIONS_DATA_PRUNE=true
EXECUTIONS_DATA_MAX_AGE=168
EXECUTIONS_DATA_PRUNE_MAX_COUNT=50000
Now, create the docker-compose.yml file:
services:
postgres:
image: postgres:16-alpine
container_name: n8n_postgres
restart: unless-stopped
environment:
POSTGRES_USER: ${POSTGRES_USER}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
POSTGRES_DB: ${POSTGRES_DB}
volumes:
- postgres_storage:/var/lib/postgresql/data
networks:
- n8n_internal_net
healthcheck:
test: ["CMD-SHELL", "pg_isready -h localhost -U ${POSTGRES_USER} -d ${POSTGRES_DB}"]
interval: 5s
timeout: 5s
retries: 10
n8n:
image: docker.n8n.io/n8nio/n8n:latest
container_name: n8n_core
restart: unless-stopped
depends_on:
postgres:
condition: service_healthy
environment:
- DB_TYPE=postgresdb
- DB_POSTGRESDB_HOST=postgres
- DB_POSTGRESDB_PORT=5432
- DB_POSTGRESDB_DATABASE=${POSTGRES_DB}
- DB_POSTGRESDB_USER=${POSTGRES_USER}
- DB_POSTGRESDB_PASSWORD=${POSTGRES_PASSWORD}
- N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
- N8N_HOST=${N8N_HOST}
- N8N_PORT=${N8N_PORT}
- N8N_PROTOCOL=${N8N_PROTOCOL}
- WEBHOOK_URL=${WEBHOOK_URL}
- NODE_ENV=${NODE_ENV}
- GENERIC_TIMEZONE=${GENERIC_TIMEZONE}
- EXECUTIONS_DATA_PRUNE=${EXECUTIONS_DATA_PRUNE}
- EXECUTIONS_DATA_MAX_AGE=${EXECUTIONS_DATA_MAX_AGE}
- EXECUTIONS_DATA_PRUNE_MAX_COUNT=${EXECUTIONS_DATA_PRUNE_MAX_COUNT}
volumes:
- n8n_storage:/home/node/.n8n
- /opt/overmanager/shared_assets:/data/shared
networks:
- n8n_internal_net
- proxy_net
caddy:
image: caddy:2-alpine
container_name: n8n_proxy
restart: unless-stopped
ports:
- "80:80"
- "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile
- caddy_data:/data
- caddy_config:/config
networks:
- proxy_net
volumes:
postgres_storage:
n8n_storage:
caddy_data:
caddy_config:
networks:
n8n_internal_net:
internal: true
proxy_net:
internal: false
3. Configuring Reverse Proxy TLS with Caddy
Caddy provides zero-touch Let’s Encrypt certificate acquisition and renewal. Create Caddyfile in the same directory:
n8n.yourcompany.com {
reverse_proxy n8n:5678 {
flush_interval -1
}
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
X-Content-Type-Options "nosniff"
X-Frame-Options "SAMEORIGIN"
Referrer-Policy "strict-origin-when-cross-origin"
}
tls support@yourcompany.com
}
Start the stack in detached mode:
docker compose up -d
Verify that all three containers report healthy status:
docker compose ps
Integrating n8n with OpenClaw and Hermes
The true power of modern self-hosting unlocks when n8n, OpenClaw, and Hermes collaborate in real-time on your private server:
- The Webhook Bridge: Create an n8n Webhook Trigger node listening for outbound events from OpenClaw scrapers. When OpenClaw detects real-time regulatory filings or website updates, it posts the raw payload into n8n.
- The Intelligence Filter: Inside n8n, route the structured content to a Hermes reasoning node or LLM sub-agent. Hermes analyzes the sentiment, extracts structured JSON entities, and scores the relevance of the lead.
- Downstream Execution: n8n immediately updates your production PostgreSQL database, alerts key executives via private Slack or Telegram channels, and triggers billing updates.
Because all three runtimes operate inside the same protected private infrastructure, internal network latency is less than 0.5ms, and no sensitive customer records ever leave your firewall.
Pruning and Data Hygiene
Without execution pruning, high-throughput n8n instances can quickly accumulate millions of execution logs, bloating PostgreSQL storage and degrading database query speeds.
Notice the environment variables we set in our Docker Compose stack:
EXECUTIONS_DATA_PRUNE=true: Tells n8n to routinely discard historic execution logs.EXECUTIONS_DATA_MAX_AGE=168: Retains execution logs for exactly 7 days (168 hours), sufficient for audit trails without runaway disk usage.EXECUTIONS_DATA_PRUNE_MAX_COUNT=50000: Hard ceiling on the total number of retained historical logs.
Overmanager: Zero-DevOps n8n Infrastructure
While configuring Docker Compose, Caddy TLS, and PostgreSQL healthchecks is rewarding for seasoned infrastructure engineers, ongoing maintenance—such as operating system security patches, PostgreSQL version upgrades, automated nightly snapshot rotations, and zero-downtime container updates—consumes dozens of engineering hours every month.
With Overmanager, you obtain the best of both worlds:
- Dedicated Private Hardware: Your n8n, OpenClaw, and Hermes runtimes run on isolated, private bare-metal instances, never on noisy shared multitenant infrastructure.
- Turnkey Setup: One-click provisioning deploys production-grade n8n with pre-configured PostgreSQL, automatic SSL certificates, and integrated monitoring.
- Automated Nightly Backups: Encrypted off-site snapshots ensure that your workflows, credentials, and execution history can be restored instantly in the event of an emergency.
Whether you manage your stack manually or leverage Overmanager’s automated management plane, self-hosting n8n in 2026 delivers unmatched performance, privacy, and sovereignty for enterprise automation.