n8n behind HTTPS on your own domain

To use n8n properly you need an address such as n8n.asuaempresa.ao, with a padlock. There are four pieces: a DNS record pointing at the VPS, a proxy that speaks HTTPS, a certificate, and the WEBHOOK_URL variable telling n8n its public address. Without the last one, n8n shows webhook addresses with localhost in them, and no outside service can reach them.

Step by step

1 Create the DNS record. An A record for n8n (a subdomain) with the VPS IP address. See how to configure a domain DNS and, to find the IP, where to find your VPS IP address. Wait for propagation.
2 Install a reverse proxy on the VPS (Nginx is the best documented) and make it forward the domain to 127.0.0.1:5678. The full guide is Nginx as a reverse proxy in front of a container.
3 Let real-time connections through. The n8n editor uses them. In Nginx that means proxy_http_version 1.1 and passing the Upgrade and Connection headers. Without it the editor opens but says it lost the connection.
4 Get the certificate. Let’s Encrypt, through Certbot, is the usual road. See HTTPS for a container: a certificate and a domain.
5 Tell n8n its address. In the compose file set WEBHOOK_URL to the full address, https://n8n.asuaempresa.ao/, with the trailing slash. Check the official documentation to see whether your version also wants the host and protocol variables. Then run docker compose up -d to recreate the container.
6 Test. Open the address in the browser, create a workflow with a Webhook node and confirm that the address it shows already starts with https://n8n.asuaempresa.ao.

What goes wrong

Symptom Likely cause What to do
Webhook addresses show localhost:5678 WEBHOOK_URL missing, or the container was not recreated. Fix the variable and run docker compose up -d again.
The editor opens but says the connection was lost The proxy does not pass real-time connections. Add proxy_http_version 1.1 and the Upgrade and Connection headers.
502 Bad Gateway The proxy cannot reach n8n: container stopped, wrong port. Check docker compose ps and confirm 127.0.0.1:5678 in the proxy.
The certificate is not issued The DNS record does not point at the VPS yet, or port 80 is closed. Check DNS and the firewall: ports and firewall.
“Too many redirects” Cloudflare in the wrong mode in front of the proxy. See switching on SSL at Cloudflare without breaking the site.
A typo in WEBHOOK_URL breaks every webhook. If you change domain, the addresses you already gave to outside services stop working. After any change, copy the address from the Webhook node again, wherever you use it.
Use a subdomain just for n8n. It is easy to move to another server (change one A record) and it does not get mixed up with the company website.

The domain does not point at the VPS yet? We will show you what has to be in the DNS.

Open a support ticket

SEE ALSO

Installing n8n with Docker Compose on a VPS

HTTPS for a container: a certificate and a domain

Nginx as a reverse proxy in front of a container

DNS records explained: A, CNAME, MX, TXT and TTL

RECOMMENDED PRODUCT

Register your .ao domain

Secure your company name before someone else registers it. from 30.000,00 Kz/yr

Search a domain
  • 0 Users Found This Useful
Was this answer helpful?