Skip to content

n8n n8n

Description / nameInput element
Container Registry
Container Configuration Root Path
Timezone
User ID
Group ID
n8n Host Port
n8n /config Path

Build Status Last Commit

Fair-code workflow automation platform with native AI capabilities — combine visual building with custom code and 400+ integrations.

Port 5678
Registry ghcr.io/daemonless/n8n
Daemonless daemonless/n8n
Source n8n-io/n8n
Website n8n.io

Version Tags

Tag Description Best For
latest Upstream Binary. Built from official release. Most users — recommended.

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.

Deployment

services:
  n8n:
    image: "ghcr.io/daemonless/n8n:latest"
    container_name: n8n
    environment:
      - N8N_ENCRYPTION_KEY=your-encryption-key-here  # Encryption key for credentials (keep safe!)
      - PUID=1000  # User ID for the application process
      - PGID=1000  # Group ID for the application process
      - TZ=UTC  # Timezone for the container
      - N8N_SECURE_COOKIE=  # Set to false if accessing over HTTP without TLS
    volumes:
      - "/path/to/containers/n8n:/config"
    ports:
      - "5678:5678"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

1
2
3
4
5
6
7
8
9
podman run -d --name n8n \
  -p 5678:5678 \
  -e N8N_ENCRYPTION_KEY=your-encryption-key-here \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e N8N_SECURE_COOKIE= \
  -v /path/to/containers/n8n:/config \
  ghcr.io/daemonless/n8n:latest

Save as run.sh, then run sh run.sh.

- name: Deploy n8n
  containers.podman.podman_container:
    name: n8n
    image: "ghcr.io/daemonless/n8n:latest"
    state: started
    restart_policy: always
    env:
      N8N_ENCRYPTION_KEY: "your-encryption-key-here"
      PUID: "1000"
      PGID: "1000"
      TZ: "UTC"
      N8N_SECURE_COOKIE: ""
    ports:
      - "5678:5678"
    volumes:
      - "/path/to/containers/n8n:/config"

Save as n8n-deploy.yaml, then run ansible-playbook n8n-deploy.yaml.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

1
2
3
4
5
6
7
8
# .env

DIRECTOR_PROJECT=n8n
N8N_ENCRYPTION_KEY=your-encryption-key-here
PUID=1000
PGID=1000
TZ=UTC
N8N_SECURE_COOKIE=
# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  n8n:
    name: n8n
    options:
      - container: 'args:--pull'
      - expose: '5678:5678 proto:tcp'
    oci:
      user: root
      environment:
        - N8N_ENCRYPTION_KEY: !ENV '${N8N_ENCRYPTION_KEY}'
        - PUID: !ENV '${PUID}'
        - PGID: !ENV '${PGID}'
        - TZ: !ENV '${TZ}'
        - N8N_SECURE_COOKIE: !ENV '${N8N_SECURE_COOKIE}'
    volumes:
      - N8N_CONFIG_PATH: /config
volumes:
  N8N_CONFIG_PATH:
    device: '/path/to/containers/n8n'
1
2
3
4
5
6
7
# Makejail

ARG tag=latest

OPTION container=boot
OPTION overwrite=force
OPTION from=ghcr.io/daemonless/n8n:${tag}

Save the files above, then run appjail-director up.

appjail oci run -Pd \
  -o overwrite=force \
  -o container="args:--pull" \
  -o virtualnet=":<random> default" \
  -o nat \
  -o expose="5678:5678 proto:tcp" \
  -e N8N_ENCRYPTION_KEY=your-encryption-key-here \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e N8N_SECURE_COOKIE= \
  -o fstab="/path/to/containers/n8n /config <pseudofs>" \
  ghcr.io/daemonless/n8n:latest n8n

Save the files above, then run sh run.sh.

Experimental

Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.

services:
  n8n:
    name: n8n
    image: "ghcr.io/daemonless/n8n:latest"
    network:
      - mode: host
    environment:
      - N8N_ENCRYPTION_KEY=your-encryption-key-here
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - N8N_SECURE_COOKIE=
    volumes:
      - "/path/to/containers/n8n:/config"

Save as bastille-compose.yml, then run bastille up.

1
2
3
4
5
6
7
8
bastille create -O \
  --env N8N_ENCRYPTION_KEY=your-encryption-key-here \
  --env PUID=1000 \
  --env PGID=1000 \
  --env TZ=UTC \
  --env N8N_SECURE_COOKIE= \
  --volume /path/to/containers/n8n /config \
  n8n ghcr.io/daemonless/n8n:latest inherit

Interactive Configuration

Parameters

Environment Variables

Variable Default Description
N8N_ENCRYPTION_KEY your-encryption-key-here Encryption key for credentials (keep safe!)
PUID 1000 User ID for the application process
PGID 1000 Group ID for the application process
TZ UTC Timezone for the container
N8N_SECURE_COOKIE `` Set to false if accessing over HTTP without TLS

Volumes

Path Description
/config Configuration directory (database, workflows)

Ports

Port Protocol Description
5678 TCP Web UI

Implementation Details

  • Architectures: amd64
  • User: bsd (UID/GID set via PUID/PGID). Defaults to 1000:1000.
  • Base: Built on ghcr.io/daemonless/base (FreeBSD 15.1).

Need help? Join our Discord community.