# n8n

> Install n8n from the App Store, create the owner account behind the setup lock, back up workflows and the encryption key, update it, and know its network limits.

Source: https://zopanel.net/docs/app-n8n  
Updated: 2026-10-09

n8n is a visual workflow automation tool, a self-hosted alternative to Zapier or Make: a trigger (a webhook, a schedule, a new email) starts a chain of steps that call APIs, transform data and send messages. Choose it when you automate work across online services and want no per-task fees and your data on your own server. This page covers installing it from the **App Store**, the first-time setup, backups, updates and what the container can and cannot reach.

## Requirements

| Item | Value |
| --- | --- |
| Image | `n8nio/n8n:2.42.5` |
| Memory limit | 1024 MB, 1 CPU |
| Free disk to install | About 2.6 GB on the Docker disk the first time (the image plus 1 GB kept free for the server) |
| Docker | Installed on the server (**App Store → Install Docker**) |
| Domain | A domain or subdomain whose A record points to the server, for example `n8n.example.com` |

The memory limit counts toward the customer's package memory. Large workflows that hold many items or big files in memory may need more than 1 GB; see [Troubleshooting](#troubleshooting).

## Install n8n

### As an administrator

1. Open **App Store**. If you see **Docker is required**, click **Install Docker** first and wait for the task to finish.
2. On the **n8n** card, click **Install**.
3. Fill in the dialog:

   | Field | What to enter |
   | --- | --- |
   | **Domain** | The domain the app answers on, without `http://`, for example `n8n.example.com`. A new website is created for it. |
   | **Owner** | The hosting account the app belongs to. Its package limits apply to the container. |
   | **Free SSL (Let's Encrypt)** | Leave on. The certificate is issued at the end of the install if the domain already points to the server. |

4. Click **Install**. The task log shows the image download, the container start and finally `n8n is available at http://<domain>`.
5. If the log says `SSL could not be issued yet`, point the domain's A record to the server, then click **Issue certificate** on the website's **SSL** tab (see [SSL certificates](/docs/ssl)).

n8n has no extra install fields. ZoPanel sets these variables for you:

| Variable | Value | Purpose |
| --- | --- | --- |
| `N8N_HOST`, `N8N_PROTOCOL`, `N8N_PORT` | your domain, `https`, `5678` | The address n8n builds its links with |
| `WEBHOOK_URL` | `https://<domain>/` | Webhook URLs shown in the editor use your domain over HTTPS |
| `GENERIC_TIMEZONE` | `Asia/Ho_Chi_Minh` | Time zone of Schedule triggers and date functions |
| `N8N_ENCRYPTION_KEY` | a random key per install | Encrypts the credentials stored in n8n |
| `N8N_PROXY_HOPS` | `1` | n8n trusts nginx in front of it for the visitor's IP |

These variables cannot be edited from the panel. To use another time zone, set it per workflow in n8n (**Workflow settings → Timezone**).

### As a customer

Customers install from **App Store** in their own panel when their package allows it. The top of the page shows the quota, for example "Your plan: 0 of 2 applications · memory 0 of 4096 MB." The **Owner** field is not shown: the app belongs to your account.

The administrator controls this in **Packages → Docker apps** (`0` = none) and **RAM (MB)**. n8n needs 1024 MB of the package memory. See [Packages and limits](/docs/packages-limits).

## First-time setup

A new n8n install is behind a **setup lock**: the first person to open n8n creates the owner account, so ZoPanel shows everyone else "This app is being set up" until you finish.

**Important:** wait until SSL is issued before you set up n8n. ZoPanel runs n8n with `N8N_PROTOCOL=https`, and n8n's login cookie only works over HTTPS.

1. Open the website (**Websites → n8n.example.com**) and go to the **Docker** tab. Wait until the status is `running`.
2. In the **Setup lock is on** card, click **Open the app (only for me)**. A new tab opens your domain; this browser now gets through the lock (for 30 days).
3. The first start takes about half a minute. If the page shows that the site is busy or "n8n is starting up", wait; it reloads.
4. On the owner sign-up screen, enter your email, first and last name and a password (at least 8 characters, with a number and a capital letter), then click **Next**.
5. Answer or skip the short questionnaire. n8n may offer a free license key for some extra community features; this is optional.
6. Back on the **Docker** tab, click **Setup finished — open to everyone**. The lock is removed and webhooks start answering the public.

**Note:** while the lock is on, webhook calls from outside services also get the "being set up" page. Open the app to everyone before you test production webhooks.

## Essential settings

- **Users:** open **Settings → Users → Invite** to add colleagues. n8n normally emails the invitation; ZoPanel's n8n has no SMTP settings for this, so copy the invitation link n8n shows and send it yourself. Password reset by email is not available, so keep your owner password in a password manager.
- **Webhooks:** production webhook URLs look like `https://n8n.example.com/webhook/<path>` and test URLs `https://n8n.example.com/webhook-test/<path>`. Activate a workflow to make its production URL answer.
- **Credentials:** API keys and passwords you save in **Credentials** are encrypted with `N8N_ENCRYPTION_KEY`. Keep that key with your backups (see below).
- **Sending email from workflows:** the **Send Email** node can use any SMTP server. A mailbox created in the panel works: host = your mail server name, port `587` (STARTTLS) or `465` (SSL), the full address and its password.

## What the container can reach

Every App Store container runs behind ZoPanel's container firewall:

| Destination | Allowed? |
| --- | --- |
| Internet services and APIs (HTTPS, any public address) | Yes |
| Websites on this server through their public domain (ports 80/443) | Yes |
| Mail on this server (ports 25, 465, 587) | Yes |
| DNS | Yes |
| MariaDB, PostgreSQL, Redis or the panel on this server | **No** |
| Private networks (10.x, 172.16–31.x, 192.168.x, 100.64.x), loopback, cloud metadata | **No** |
| Other containers | **No** |

What this means for n8n:

- **A MySQL/MariaDB, Postgres or Redis node pointed at this server will not connect.** `localhost` and `127.0.0.1` inside the container are the container itself, and the server's database ports are blocked from containers, even if [Remote access](/docs/databases) is on. Use one of these instead:
  - put a small HTTPS endpoint on one of your websites (for example a PHP script that reads or writes the database with its own credentials) and call it with the **HTTP Request** node;
  - use a database on another server that accepts connections from this server's public IP.
- Calling your own websites by their public domain works, as does calling any public API.
- Services on a private network (an Ollama or database on a VPC address, a NAS at home) are not reachable.

## Where data lives and backups

The app's data is in `/var/lib/zopanel-apps/<instance>/`, where `<instance>` is the domain with dots replaced by hyphens (`n8n.example.com` → `n8n-example-com`). The container is named `zp-app-<instance>`.

| Path on the server | Content |
| --- | --- |
| `/var/lib/zopanel-apps/<instance>/data/` | n8n's `/home/node/.n8n`: the SQLite database with workflows, credentials and execution history, plus n8n's settings file |
| `/var/lib/zopanel-apps/<instance>/.env` | The variables above, including `N8N_ENCRYPTION_KEY` (root only) |

**What ZoPanel backs up and what it does not:**

- The **Backups** card on the website's **Docker** tab backs up the whole app folder, data and `.env` with the encryption key.
- Account backups and incremental backups cover the account's website folders, databases and mailboxes. **They do not include `/var/lib/zopanel-apps`**, so n8n's workflows and credentials are only in the app's own backups.
- The configuration backup (`.zpb`, see [Disaster recovery](/docs/disaster-recovery)) contains the panel database, which stores the app's settings and its generated variables, including the encryption key. It does not contain n8n's data.

To back up n8n, click **Back up now** on the **Backups** card. Administrators can also set a **Schedule** (**Off**, **Every day** or **Every week**; off by default) and how many copies to **Keep** (1–60, default 7), then click **Save**. Each backup archives `/var/lib/zopanel-apps/<instance>/` into `/var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz`, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the copy is consistent. Older copies beyond **Keep** are removed, and a failed scheduled backup sends administrators the **Backup failed** alert.

To restore, an administrator clicks **Restore** next to a backup (customers ask their provider). n8n is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too.

These archives are not in account backups and stay on the same server. Copy important ones off it (for example with `scp` or `rclone` from `/var/backups/zopanel-apps/<instance>/`) and store them encrypted: they contain the encryption key. Restore an archive onto the same install; a new install on another server has its own encryption key, so move workflows and credentials there with the export below.

A portable export, which you can import into any n8n:

```bash
docker exec -u node zp-app-n8n-example-com n8n export:workflow --all --output=/home/node/.n8n/workflows.json
docker exec -u node zp-app-n8n-example-com n8n export:credentials --all --decrypted --output=/home/node/.n8n/credentials.json
```

The files appear in `/var/lib/zopanel-apps/n8n-example-com/data/`. The credentials file contains your secrets in plain text: move it somewhere safe and delete it from the server. Import them into another n8n with `n8n import:workflow --input=…` and `n8n import:credentials --input=…`.

Customers cannot run these commands, but can click **Back up now** on the **Docker** tab; the schedule and restores are done by the provider. For a copy of your own, download important workflows from the editor (**Download** in the workflow menu).

## Update n8n

1. Take a backup (**Back up now** on the **Backups** card). n8n migrates its database on start and an update cannot be undone from the panel.
2. On the website's **Docker** tab, click **Update to latest** (administrators only; customers ask their provider).
3. The task pulls the image in the current ZoPanel catalog and recreates the container. Data and the encryption key are kept. n8n is unavailable for the minute it takes to restart.

The catalog pins an exact n8n version (`2.42.5`), so **Update to latest** installs the version shipped with your ZoPanel release; newer n8n versions arrive with [ZoPanel updates](/docs/updating).

## Troubleshooting

| Symptom or message | What to do |
| --- | --- |
| Visitors or webhooks get "This app is being set up" | The setup lock is still on. Click **Setup finished — open to everyone** on the **Docker** tab. |
| n8n shows a warning about a secure cookie, or login loops | You opened it over `http://`. Issue SSL for the domain and open `https://<domain>`. |
| `not enough disk space: this app needs about 2.6 GB free and the server has … GB; free some space first` | Free disk space on the server, then install again. |
| `your plan does not include applications; ask your provider` / `your plan allows N application(s)` | The package's **Docker apps** limit is 0 or reached. |
| `n8n needs 1024 MB of memory; your plan has … MB and your apps use … MB` | Raise the package's **RAM (MB)** or remove another app. |
| `the app did not start listening: …` | The container did not answer within 2 minutes. Read the end of the message and **Application output** on the **Docker** tab, then click **Restart**. |
| A MySQL/Postgres/Redis node times out or is refused | Expected for databases on this server or a private network; see [What the container can reach](#what-the-container-can-reach). |
| Executions stop and the container restarts during a large workflow | The 1024 MB limit was reached. Process items in smaller batches (**Loop Over Items**) and avoid keeping large files in memory. |
| n8n will not start after you restored data into a new install, with an error about mismatching encryption keys | The data came from an install with a different key. Restore the backup onto the original install, or move workflows and credentials with the export and import commands. |
| Locked out of the owner account | As root: `docker exec -u node zp-app-<instance> n8n user-management:reset`, then set up the owner again. This removes all users; workflows and credentials stay. |

## Related

- [App Store and S3 storage](/docs/apps)
- [What each app does](/docs/app-catalog)
- [Packages and limits](/docs/packages-limits)
- [Databases](/docs/databases)
- [Backups](/docs/backups)
- [n8n documentation](https://docs.n8n.io) and [CLI commands](https://docs.n8n.io/hosting/cli-commands/)
