n8n workflow automation
n8n workflow automation
This pattern composes Compute, Network, and Block Storage into a self-hosted workflow-automation host you run on infrastructure you control.
What this template does#
Provisions a single instance running n8n, an open-source workflow-automation tool (a self-hosted alternative to Zapier or Make). You build workflows in the editor that connect APIs, databases, and services with triggers, branching, and scheduled runs:
- Compute instance that runs n8n in Docker, sized for n8n's basic SQLite mode (2 vCPU and 2 GiB RAM)
- Private network, subnet, router, port, and security group; a floating IP for public access
- A block volume mounted at
/var/lib/docker, so the n8n data (workflows, credentials, the SQLite database, and the encryption key) lives on a volume you can grow rather than on the boot disk - cloud-init installs Docker Engine and starts n8n from a compose file on first boot
n8n is the glue layer that wires together the services a project depends on. It runs the automation loop on a VM you own, which keeps credentials and workflow data on your infrastructure.
No credential ships with this template. n8n generates its own encryption key on first start and persists it on the data volume, and you set the owner account the first time you open the editor.
Parameters#
| Parameter | Description | Default |
|---|---|---|
key_name | SSH keypair name (must already exist) | No default |
flavor_name | Instance size (n8n SQLite mode runs on 2 vCPU / 2 GiB) | s1a.small |
image_name | Operating system image | Ubuntu-24.04 |
app_name | Display name prefix for resources | n8n |
volume_size | Block volume size in GiB, mounted at /var/lib/docker | 20 |
external_network | External network for floating IP allocation | PublicStatic |
private_cidr | CIDR for the private subnet | 10.40.0.0/24 |
editor_allowed_cidr | CIDR allowed to reach the editor on port 5678 | 10.40.0.0/24 |
db_type | Datastore backend: sqlite or postgres | sqlite |
postgres_host | PostgreSQL host (when db_type is postgres) | "" |
postgres_db | PostgreSQL database name (when db_type is postgres) | n8n |
postgres_user | PostgreSQL user (when db_type is postgres) | n8n |
Editor access and security#
The editor listens on port 5678 over plain HTTP. The security group restricts 5678 to editor_allowed_cidr, which defaults to the private network only, so the raw editor stays off the public internet. n8n's own user management gates the editor with an owner account you set on first visit. Reach the editor one of three ways:
- Put a reverse proxy (Caddy or Nginx) in front of n8n and serve the editor over HTTPS on 443. Point the domain's DNS A record at the floating IP, then set
N8N_HOST,N8N_PROTOCOL, andWEBHOOK_URLin/opt/n8n/.env. This is the recommended path for routine access. - Tunnel over SSH:
ssh -L 5678:localhost:5678 user@FLOATING_IP, then openhttp://localhost:5678. - Set
editor_allowed_cidrtoYOUR_IP/32to reach port 5678 directly from one address.
Ports 80 and 443 stay open for the reverse proxy you put in front; they carry no traffic until you add one.
Datastore#
The db_type parameter selects the backend:
sqlite(default): a file database on the data volume. No external service runs, which suits getting started and light use.postgres: points n8n at an external PostgreSQL database, such as a self-managed PostgreSQL instance. This is the production backend and the prerequisite for n8n's queue mode. Setpostgres_host,postgres_db, andpostgres_user, then addDB_POSTGRESDB_PASSWORDto/opt/n8n/.envon the instance and rundocker compose up -d. The password stays out of tfvars and the repo.
When to use this pattern#
Run a workflow-automation tool with a visual editor, scheduled triggers, and hundreds of service integrations on a VM you operate. n8n suits API-to-API glue, scheduled jobs, webhook handlers, and the orchestration steps around an AI agent.
For a single containerized app rather than the automation layer, use the Next.js app template or the Containerized app template. For the external datastore that backs production and queue mode, see self-managed PostgreSQL.
Estimated cost#
Monthly cost estimate
Pricing calculator ↗Sized as a custom package on shared vCPU.
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
n8n host
s1a.small · 2 shared vCPU, 2 GiB RAM, 0.5 Gbps
Runs n8n in Docker (workflow editor and execution engine), with workflow data on an attached volume.
n8n in basic SQLite mode runs on 2 vCPU and 2 GiB RAM. Size up, or move to the Postgres + queue mode, for high-volume or long-running workflows.
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Included in baseline
s1a.small
2 shared vCPU, 2 GiB RAM, 0.5 Gbps
Compute + RAM rate basis
2 vCPU + 2 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.
Block storage (50 GiB)
50 GiB at $0.08/GiB/mo
Public IP (included)
1 included with the custom package
Package promotional discount
Flat −$5.00/mo on the custom package (same promotion as named plans).
Included at no charge
These line items are zero on Quake AI. Many other providers meter them separately.
Data transfer (inbound and outbound)
Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.
AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.
Learn morePrivate networking
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
Pricing data last validated: . For current rates, check quake.ai/pricing.
Template source#
Show source (7 files)Hide source
data "openstack_images_image_v2" "os" {
name = var.image_name
most_recent = true
}
data "openstack_networking_network_v2" "external" {
name = var.external_network
}
resource "openstack_networking_network_v2" "private" {
name = "${var.app_name}-net"
admin_state_up = true
}
resource "openstack_networking_subnet_v2" "private" {
name = "${var.app_name}-subnet"
network_id = openstack_networking_network_v2.private.id
cidr = var.private_cidr
ip_version = 4
dns_nameservers = ["1.1.1.1", "8.8.8.8"]
}
resource "openstack_networking_router_v2" "main" {
name = "${var.app_name}-router"
external_network_id = data.openstack_networking_network_v2.external.id
}
resource "openstack_networking_router_interface_v2" "private" {
router_id = openstack_networking_router_v2.main.id
subnet_id = openstack_networking_subnet_v2.private.id
}
resource "openstack_networking_secgroup_v2" "n8n" {
name = "${var.app_name}-sg"
description = "SSH and HTTP/HTTPS for a reverse proxy; editor port 5678 restricted"
}
resource "openstack_networking_secgroup_rule_v2" "ssh" {
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 22
port_range_max = 22
remote_ip_prefix = "0.0.0.0/0"
security_group_id = openstack_networking_secgroup_v2.n8n.id
}
# 80 and 443 carry the editor when it is served over a domain with automatic
# TLS through a reverse proxy (Caddy or Nginx). They are not used until you put
# a proxy in front of n8n; see the reference page.
resource "openstack_networking_secgroup_rule_v2" "http" {
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 80
port_range_max = 80
remote_ip_prefix = "0.0.0.0/0"
security_group_id = openstack_networking_secgroup_v2.n8n.id
}
resource "openstack_networking_secgroup_rule_v2" "https" {
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 443
port_range_max = 443
remote_ip_prefix = "0.0.0.0/0"
security_group_id = openstack_networking_secgroup_v2.n8n.id
}
# Raw editor HTTP on 5678 is restricted to editor_allowed_cidr (the private
# network by default). Prefer a domain with TLS on 443 for routine access.
# n8n's own user management still gates the editor with an owner account set on
# first visit, but the port stays off the public internet by default.
resource "openstack_networking_secgroup_rule_v2" "editor" {
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 5678
port_range_max = 5678
remote_ip_prefix = var.editor_allowed_cidr
security_group_id = openstack_networking_secgroup_v2.n8n.id
}
resource "openstack_networking_port_v2" "n8n" {
name = "${var.app_name}-port"
network_id = openstack_networking_network_v2.private.id
security_group_ids = [openstack_networking_secgroup_v2.n8n.id]
fixed_ip {
subnet_id = openstack_networking_subnet_v2.private.id
}
depends_on = [openstack_networking_router_interface_v2.private]
}
resource "openstack_blockstorage_volume_v3" "data" {
name = "${var.app_name}-data"
size = var.volume_size
}
resource "openstack_compute_instance_v2" "n8n" {
name = var.app_name
flavor_name = var.flavor_name
key_pair = var.key_name
user_data = templatefile("${path.module}/cloud-init/n8n.yaml.tftpl", {
app_name = var.app_name
db_type = var.db_type
postgres_host = var.postgres_host
postgres_db = var.postgres_db
postgres_user = var.postgres_user
})
block_device {
uuid = data.openstack_images_image_v2.os.id
source_type = "image"
destination_type = "volume"
volume_size = 30
boot_index = 0
delete_on_termination = true
}
network {
port = openstack_networking_port_v2.n8n.id
}
}
resource "openstack_compute_volume_attach_v2" "data" {
instance_id = openstack_compute_instance_v2.n8n.id
volume_id = openstack_blockstorage_volume_v3.data.id
}
resource "openstack_networking_floatingip_v2" "n8n" {
pool = var.external_network
}
resource "openstack_networking_floatingip_associate_v2" "n8n" {
floating_ip = openstack_networking_floatingip_v2.n8n.address
port_id = openstack_networking_port_v2.n8n.id
}
variable "key_name" {
description = "SSH keypair name (must already exist in your project)"
type = string
}
variable "flavor_name" {
description = "Instance size. n8n in basic SQLite mode runs comfortably on 2 vCPU and 2 GiB RAM. Size up for heavy workflows or the Postgres + queue mode."
type = string
default = "s1a.small"
}
variable "image_name" {
description = "Operating system image. Ubuntu 24.04 is the recommended base."
type = string
default = "Ubuntu-24.04"
}
variable "app_name" {
description = "Display name prefix for compute and network resources"
type = string
default = "n8n"
}
variable "volume_size" {
description = "Block volume size in GiB, mounted at /var/lib/docker so the n8n data (workflows, credentials, SQLite database, encryption key) lives on a volume you can grow rather than on the boot disk."
type = number
default = 20
}
variable "external_network" {
description = "Shared external network for router gateway and floating IPs; defaults to PublicStatic (persisted FIP / production pattern). Override with PublicEphemeral for ephemeral demos."
type = string
default = "PublicStatic"
}
variable "private_cidr" {
description = "CIDR for the private tenant network the instance lives in"
type = string
default = "10.40.0.0/24"
}
variable "editor_allowed_cidr" {
description = "CIDR allowed to reach the n8n editor on port 5678. Defaults to the private network only, so the editor is not exposed to the public internet on its raw port. Reach it over an SSH tunnel, or (recommended) serve it over a domain with HTTPS on 443 behind a reverse proxy. To allow direct access from your workstation, set this to YOUR_IP/32."
type = string
default = "10.40.0.0/24"
}
variable "db_type" {
description = "Datastore backend. 'sqlite' (default) bundles a file database on the data volume and needs no external service. 'postgres' points n8n at an external PostgreSQL database (the recommended path for production and the prerequisite for queue mode); supply the connection in the postgres_* variables and the password in /opt/n8n/.env on the instance (never in tfvars)."
type = string
default = "sqlite"
validation {
condition = contains(["sqlite", "postgres"], var.db_type)
error_message = "db_type must be either \"sqlite\" or \"postgres\"."
}
}
variable "postgres_host" {
description = "PostgreSQL host for db_type = \"postgres\" (for example the private IP of a self-managed-postgres instance). Ignored when db_type is sqlite."
type = string
default = ""
}
variable "postgres_db" {
description = "PostgreSQL database name for db_type = \"postgres\". Ignored when db_type is sqlite."
type = string
default = "n8n"
}
variable "postgres_user" {
description = "PostgreSQL user for db_type = \"postgres\". The password is never set here: add DB_POSTGRESDB_PASSWORD to /opt/n8n/.env on the instance and restart. Ignored when db_type is sqlite."
type = string
default = "n8n"
}
output "instance_id" {
description = "ID of the compute instance running n8n"
value = openstack_compute_instance_v2.n8n.id
}
output "floating_ip" {
description = "Public floating IP address of the n8n host"
value = openstack_networking_floatingip_v2.n8n.address
}
output "private_ip" {
description = "Private IP address of the instance"
value = openstack_compute_instance_v2.n8n.access_ip_v4
}
output "editor_url" {
description = "n8n editor URL on port 5678. Reachable from editor_allowed_cidr (the private network by default; tunnel over SSH, or put a reverse proxy in front and use HTTPS on 443)."
value = "http://${openstack_networking_floatingip_v2.n8n.address}:5678"
}
terraform {
required_version = ">= 1.6.0"
required_providers {
openstack = {
source = "terraform-provider-openstack/openstack"
version = "~> 2.0"
}
}
}
provider "openstack" {}
# Required: SSH keypair must already exist in your project
key_name = "YOUR_KEY_NAME"
# Recommended: restrict the editor (port 5678) to your workstation IP.
# Leave unset to keep 5678 reachable only from the private network and tunnel
# over SSH, or put a reverse proxy in front and use HTTPS on 443.
# editor_allowed_cidr = "203.0.113.10/32"
# Datastore: sqlite (default, bundled) or postgres (external, recommended for
# production and required for queue mode). For postgres, set the connection
# below and add DB_POSTGRESDB_PASSWORD to /opt/n8n/.env on the instance.
# db_type = "postgres"
# postgres_host = "10.50.0.12"
# postgres_db = "n8n"
# postgres_user = "n8n"
# flavor_name = "s1a.small"
# image_name = "Ubuntu-24.04"
# app_name = "n8n"
# volume_size = 20
# external_network = "PublicStatic"
# private_cidr = "10.40.0.0/24"
#cloud-config
package_update: true
packages:
- ca-certificates
- curl
write_files:
- path: /opt/n8n/docker-compose.yml
permissions: "0644"
content: |
services:
n8n:
image: docker.n8n.io/n8nio/n8n:latest
restart: unless-stopped
ports:
- "5678:5678"
env_file:
- /opt/n8n/.env
volumes:
- n8n_data:/home/node/.n8n
volumes:
n8n_data:
- path: /opt/n8n/.env
permissions: "0600"
content: |
# n8n runtime configuration for ${app_name}.
# The editor is gated by n8n's own user management: set the owner account
# on first visit. n8n generates and persists its encryption key under the
# n8n_data volume on first start; do not destroy that volume or you lose
# the ability to decrypt stored credentials.
N8N_PORT=5678
GENERIC_TIMEZONE=UTC
# When you put a domain and reverse proxy in front, set these so webhook
# URLs and the editor use the public HTTPS host:
# N8N_HOST=n8n.example.com
# N8N_PROTOCOL=https
# WEBHOOK_URL=https://n8n.example.com/
%{ if db_type == "postgres" ~}
DB_TYPE=postgresdb
DB_POSTGRESDB_HOST=${postgres_host}
DB_POSTGRESDB_PORT=5432
DB_POSTGRESDB_DATABASE=${postgres_db}
DB_POSTGRESDB_USER=${postgres_user}
# Add the password here on the instance and run `docker compose up -d` to
# apply. Never commit it to tfvars or the repo:
# DB_POSTGRESDB_PASSWORD=
%{ else ~}
# Bundled SQLite database; the file lives under the n8n_data volume. No
# external datastore is required in this mode.
DB_TYPE=sqlite
%{ endif ~}
runcmd:
- |
set -e
# The data volume attaches as /dev/sdb on this platform (not /dev/vdb).
# Mount it at /var/lib/docker before Docker is installed so the n8n named
# volume (workflows, credentials, SQLite database, encryption key) lives on
# the resizable volume rather than the boot disk.
DEV=/dev/sdb
for i in $(seq 1 30); do [ -b "$DEV" ] && break; sleep 5; done
if ! blkid "$DEV" >/dev/null 2>&1; then mkfs.ext4 -F -L n8ndata "$DEV"; fi
mkdir -p /var/lib/docker
mount "$DEV" /var/lib/docker
grep -q "$DEV" /etc/fstab || echo "$DEV /var/lib/docker ext4 defaults,nofail 0 2" >> /etc/fstab
# Install Docker Engine plus the compose plugin from Docker's convenience
# script, then bring n8n up from the compose file written above.
curl -fsSL https://get.docker.com | sh
cd /opt/n8n
docker compose up -d
# n8n workflow automation
Single compute instance running [n8n](https://n8n.io), a self-hosted workflow-automation tool (a self-hosted alternative to Zapier or Make) on infrastructure you control. After apply, you open the editor, set the owner account, and build workflows that connect APIs, databases, and services with triggers, branching, and scheduled runs.
**Network class:** production — `external_network` defaults to `PublicStatic` for persisted floating IPs and multi-tier stacks; override with `PublicEphemeral` for ephemeral demos.
The instance provisions a private network, a floating IP, and a block volume mounted at `/var/lib/docker` so the n8n data (workflows, credentials, the SQLite database, and the encryption key) lives on a resizable volume. cloud-init installs Docker Engine and brings n8n up from a compose file on first boot.
## Where this fits
n8n is the "glue" layer vibecoders reach for: it wires together the services a project depends on without writing a standalone integration service for each one. It runs the automation loop on a VM you own rather than on a third-party SaaS, which keeps credentials and workflow data on your infrastructure.
## Prerequisites
- OpenTofu >= 1.6.0 or Terraform >= 1.6.0
- Quake AI account with OpenStack credentials
- An existing SSH keypair in your project (the value of `key_name` must match that keypair)
## Resource baseline
n8n in basic SQLite mode runs on 2 vCPU and 2 GiB RAM. The default `s1a.small` flavor leaves headroom for Docker plus moderate workflow volume. Size up, or move to the Postgres + queue mode, for high-volume or long-running workflows.
## Usage
1. Clone or copy this template directory
2. Copy `terraform.tfvars.example` to `terraform.tfvars` and fill in your values
3. Source your OpenStack credentials: `source openrc.sh`
4. Initialize: `tofu init`
5. Preview: `tofu plan`
6. Apply: `tofu apply`
After apply, cloud-init takes a few minutes to install Docker and start n8n on first boot. Then reach `editor_url` from the outputs and complete the first-run setup, which creates your owner account. No credential ships with this template.
## Editor access and security
The editor listens on port 5678 over plain HTTP. The security group restricts 5678 to `editor_allowed_cidr`, which defaults to the private network only, so the raw editor is not exposed to the public internet. n8n's own user management still gates the editor with an owner account set on first visit. Choose one of:
- **Recommended:** put a reverse proxy (Caddy or Nginx) in front of n8n and serve the editor over HTTPS on 443. Point the domain's DNS A record at `floating_ip`, then set `N8N_HOST`, `N8N_PROTOCOL`, and `WEBHOOK_URL` in `/opt/n8n/.env`.
- **SSH tunnel:** `ssh -L 5678:localhost:5678 user@<floating_ip>`, then open `http://localhost:5678`.
- **Direct, scoped:** set `editor_allowed_cidr` to your workstation IP (`YOUR_IP/32`) to reach 5678 directly from one address.
Ports 80 and 443 stay open for the reverse proxy you put in front; they carry no traffic until you add one.
## Datastore
`db_type` selects the backend:
- `sqlite` (default): a file database on the data volume. No external service. Best for getting started and light use.
- `postgres`: points n8n at an external PostgreSQL database (for example a [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres) instance). This is the recommended production backend and the prerequisite for n8n's queue mode. Set `postgres_host`, `postgres_db`, and `postgres_user`, then add `DB_POSTGRESDB_PASSWORD` to `/opt/n8n/.env` on the instance and run `docker compose up -d`. The password is never set in tfvars or committed.
## How the instance is provisioned
cloud-init:
1. Mounts the data volume at `/var/lib/docker` (formatting it on first boot) and adds an `/etc/fstab` entry so it persists across reboots.
2. Writes `/opt/n8n/docker-compose.yml` and `/opt/n8n/.env` (the datastore settings follow `db_type`).
3. Installs Docker Engine from `https://get.docker.com` and runs `docker compose up -d`, which starts n8n on port 5678. n8n generates and persists its encryption key under the `n8n_data` volume on first start.
## Variables
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `key_name` | string | yes | n/a | SSH keypair name (must already exist in your project) |
| `flavor_name` | string | no | `s1a.small` | Instance size (n8n SQLite mode runs on 2 vCPU / 2 GiB) |
| `image_name` | string | no | `Ubuntu-24.04` | Operating system image |
| `app_name` | string | no | `n8n` | Display name prefix for resources |
| `volume_size` | number | no | `20` | Block volume size in GiB, mounted at `/var/lib/docker` |
| `external_network` | string | no | `PublicStatic` | Persisted FIP / production default; override with `PublicEphemeral` for demos |
| `private_cidr` | string | no | `10.40.0.0/24` | CIDR for the private subnet |
| `editor_allowed_cidr` | string | no | `10.40.0.0/24` | CIDR allowed to reach the editor on port 5678 |
| `db_type` | string | no | `sqlite` | Datastore backend: `sqlite` or `postgres` |
| `postgres_host` | string | no | `""` | PostgreSQL host (db_type = postgres) |
| `postgres_db` | string | no | `n8n` | PostgreSQL database name (db_type = postgres) |
| `postgres_user` | string | no | `n8n` | PostgreSQL user (db_type = postgres) |
## Outputs
| Name | Description |
| --- | --- |
| `floating_ip` | Public floating IP assigned to the instance |
| `private_ip` | Private IP address of the instance |
| `editor_url` | n8n editor URL on port 5678 |
| `instance_id` | Compute instance ID |
## Scope
This is a single-VM n8n host that you operate, not a managed automation cloud. It is CPU-only and runs in one region. For scale and resilience, move to the Postgres + queue mode (a Postgres datastore plus n8n worker processes) and size the host up.
## Documentation
See also: [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres), [Coolify host](/resources/iac-templates/coolify-host)
Resources, parameters, and variables
key_namerequiredflavor_name="s1a.small"image_name="Ubuntu-24.04"app_name="n8n"volume_size=20external_network="PublicStatic"private_cidr="10.40.0.0/24"editor_allowed_cidr="10.40.0.0/24"db_type="sqlite" validation {postgres_host=""postgres_db="n8n"postgres_user="n8n"
Customize this pattern#
- Customize a template's image and flavor
- Add a block volume to a template
- Parameterize a template with a tfvars file
See also#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
See Also
Terraform and OpenTofu on Quake AI
Prerequisite
Networks
Prerequisite
Authoring IaC templates for Quake AI
Shares: Volumes, Security Groups
Deploy an API gateway with the api-gateway template
Shares: Volumes, Security Groups
Deploy a regional edge cache with the edge-cache template
Shares: Volumes, Security Groups