ChecklistN8N & Zapier Workflows
Self-hosted n8n in production: an operating checklist
A single n8n container with the default database is fine for trying ideas. It is not how business-critical workflows should run. This checklist covers the architecture, configuration, secrets, data retention, backups, upgrades and monitoring that a self-hosted n8n installation needs before other teams depend on it, with references to n8n's own documentation for each setting.
On this page
- Reference architecture for a production n8n installation
- Architecture and configuration items
- Why the encryption key deserves its own backup procedure
- Credentials, data retention and recovery items
- Upgrading n8n without surprises
- Monitoring signals and what each one tells you
- Where self-hosted n8n installations usually go wrong
- Questions and answers
- Sources
Reference architecture for a production n8n installation
Queue mode separates the process that receives work from the processes that do it, so a slow workflow cannot block incoming webhooks.
- Reverse proxy and TLS
Terminates HTTPS, routes editor traffic and webhook traffic, and keeps internal ports private.
- Main and webhook processes
The main instance serves the editor, runs schedules and receives webhooks; optional webhook processors scale intake separately.
- Redis queue
Holds the IDs of executions waiting to run, so intake and execution can scale independently.
- Worker processes
Pull queued executions, run them and write results back; add workers to add capacity.
- PostgreSQL
Shared store for workflows, encrypted credentials and execution data, reachable by every process.
Architecture and configuration items
Why the encryption key deserves its own backup procedure
Credentials, data retention and recovery items
Upgrading n8n without surprises
n8n releases often. A routine that takes an hour per upgrade is cheaper than recovering from an untested one.
Pin the running version
Reference an exact image tag rather than a moving one such as latest, so no process upgrades by accident when a container restarts.
Read the release notes for every version you skip
Look for breaking changes, database migrations and node behaviour changes that affect workflows you run.
Upgrade a staging instance first
Restore a recent production backup into staging, upgrade it and run the listed workflows against test endpoints.
Back up, then upgrade production
Take a fresh database backup, stop or drain workers, upgrade every process to the same version and let migrations finish before resuming.
Watch the first hours closely
Compare failed-execution counts and queue depth with the previous day, and keep the rollback path (previous image and backup) ready until they settle.
Monitoring signals and what each one tells you
n8n provides health endpoints on the main process, optional health checks on workers and a metrics endpoint for self-hosted instances4.
| Signal | Where it comes from | What to alert on |
|---|---|---|
| Liveness | The health endpoint on each process (enable it on workers explicitly) | A process that stops responding or restarts repeatedly |
| Readiness | The readiness endpoint, which reports when the database is connected and migrated | An instance receiving traffic before it is ready, often after an upgrade |
| Queue depth | Redis and the metrics endpoint, once metrics are enabled | Waiting executions growing steadily, a sign workers are short of capacity |
| Failed executions | Error workflows that post to a channel or ticketing system | Any failure in a business-critical workflow, and rising failure rates elsewhere |
| Database health | Your PostgreSQL monitoring | Connection exhaustion, storage growth from execution data and slow queries |
Where self-hosted n8n installations usually go wrong
Starting on SQLite and never moving
Early signalThe pilot instance quietly became production and now holds months of execution data in one file.
MitigationMove to PostgreSQL before other teams depend on the instance, and plan the migration as a project.
Access-control features assumed rather than checked
Early signalThe design expects single sign-on, role-based access or separate environments that the chosen plan does not include.
MitigationCheck n8n's current plan comparison for each feature before committing to the operating model.
No owner for the platform itself
Early signalWorkflow builders each assume someone else handles upgrades, backups and certificates.
MitigationName a platform owner with time allocated, separate from the owners of individual workflows.
Questions and answers
Should we run n8n on Docker Compose or Kubernetes?
Docker Compose on a well-managed virtual machine is enough for many teams and is simpler to operate. Kubernetes makes sense when you already run it, need workers to scale automatically or want the same deployment patterns as your other services. Either way, keep PostgreSQL and Redis on managed or separately backed-up services rather than inside the same container stack.
How many n8n workers do we need?
Start small and measure. Watch queue depth and execution duration under real load, then add workers when waiting executions build up during peaks. Long-running workflows tie up worker slots, so moving very slow steps into sub-workflows or external services can matter as much as adding capacity. Balance worker count and concurrency against your database connection limits.
Do we need separate n8n instances for development and production?
For anything business-critical, yes. Build and test changes on a non-production instance with test credentials, then promote them. n8n's environments feature uses Git-based source control on paid plans; without it, export workflow files to a repository and import them into production through a reviewed change, so nobody edits live workflows directly.
Is n8n Cloud a better option than self-hosting?
It can be, if your main reasons for self-hosting were convenience rather than data control. n8n Cloud removes the infrastructure work on this page. Self-hosting is worth the effort when data must stay in your environment, workflows must reach systems on a private network or you need control over upgrade timing and retention that a managed service does not offer.
Sources
- Configuring queue mode — n8n Docs · checked 10 October 2026
- External secrets — n8n Docs · checked 10 October 2026
- Execution data — n8n Docs · checked 10 October 2026
- Monitoring — n8n Docs · checked 10 October 2026