Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (2.38.7, 2026-09-14), podman (2.38.7, 2026-09-14); Proxmox VM: docker (2.38.7, 2026-09-14), podman (2.38.7, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
n8n:
image: "n8nio/n8n:latest"
container_name: njorddeploy-n8n
ports:
- "5678:5678"
volumes:
- n8n_data:/home/node/.n8n
environment:
- "N8N_BASIC_AUTH_ACTIVE=true"
- "N8N_BASIC_AUTH_USER=njorduser"
- "N8N_BASIC_AUTH_PASSWORD=CHANGEMEPASSWORD123"
- "WEBHOOK_URL=http://your-n8n-domain.com"
- "GENERIC_TIMEZONE=UTC"
- "N8N_SECURE_COOKIE=false"
networks:
- njorddeploy_net
volumes:
n8n_data:
name: njorddeploy-n8n-data
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
N8N_WEB_PORT |
5678 |
The host port for accessing the n8n web interface. |
N8N_BASIC_AUTH_USER |
njorduser |
Username for n8n basic authentication. |
N8N_BASIC_AUTH_PASSWORD |
CHANGEMEPASSWORD123 |
Password for n8n basic authentication. CHANGE THIS IMMEDIATELY! |
N8N_WEBHOOK_URL |
http://your-n8n-domain.com |
The external URL that n8n uses to generate webhook endpoints. This must be accessible from outside the container. For example: http://your-n8n-domain.com or https://your-n8n-domain.com. You can also use a local IP and port (e.g. http://192.168.1.100:5678) if you only use webhooks internally on your local network (LAN) and do not need external triggers from public internet services. |
N8N_TIMEZONE |
UTC |
Set the timezone for n8n. Example: Europe/Berlin or America/New_York. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.