自托管 n8n 实战指南:VPS 成本、安全、备份与 GDPR 边界
Self-hosted n8n for business: VPS cost, security, backups and GDPR
自托管 n8n 免费的只是许可费,实际还需承担每月个位数到低两位数欧元的 VPS、域名、备份、更新和监控时间成本;低用量下 n8n Cloud 总成本往往更低。
“Self-hosted n8n is free” is true only about the licence. This article is about the rest — the server, the backups, the updates, and how much time it actually takes.
The n8n Community Edition carries no licence fee when self-hosted — the source code is public and deploying it on your own server costs nothing.
Running it is not zero, though. Budget for a small VPS (on the order of single-digit to low tens of euros a month), time for updates and working backups. At low workflow volume, n8n Cloud often works out cheaper on total cost once you count your own time.
Self-hosting pays off when you have at least one of these three reasons: the data must not leave your infrastructure, the execution volume would be expensive in the cloud, or you need custom code and libraries the cloud does not allow. If you have none of them, do not buy self-hosting.
The real cost of self-hosting
An honest comparison has to include the items that do not appear on an invoice. Here is the list I use when designing:
| Item | Self-hosted | n8n Cloud |
|---|---|---|
| Licence | €0 (Community Edition) | included in the subscription |
| Server | a small VPS, single-digit to low tens of € / month | €0 |
| Domain and certificate | domain annually, HTTPS certificate free | €0 |
| Backups | storage + setup | handled by the provider |
| Updates | your time or a supplier's | handled by the provider |
| Monitoring and outages | your time | handled by the provider |
| Subscription | €0 | from €20 / month on annual billing (Starter, 2,500 executions) |
| Scaling as you grow | a bigger server, one-off work | a higher plan |
n8n Cloud prices per the official n8n.io price list as at 5 September 2026. VPS prices depend on the provider and configuration — check both before deciding.
A simple rule: if maintenance takes you an hour a month and your cost rate is €20/h, self-hosting carries a hidden cost of €20 a month — roughly what the lowest cloud plan costs. The difference only starts to show at larger volumes, where cloud plans grow and a server does not.
What server you need
For ordinary company load — tens to low hundreds of executions a day, mostly API calls and text handling — a small VPS is enough. It gets more demanding in three cases:
- Large files. Processing bulky PDFs, images or video needs more memory and disk space.
- Concurrent executions. If a workflow fires in dozens of instances at once, you need more capacity and a different configuration.
- Your own database. A production deployment should not run on the built-in file database — a separate database is more stable and backs up better.
Do not start with a big server “just in case”. It is more sensible to start small, watch the load and grow it when the numbers show it — with a VPS that is a matter of minutes.
Security — the minimum that is not optional
n8n has access to your systems and holds the credentials to them. That makes it a sensitive piece of infrastructure, not “another app”.
- HTTPS and your own domain. The interface must never be reachable over an unencrypted connection.
- Strong authentication. Access to the interface protected and restricted, ideally at the network or IP level too.
- Credentials in environment variables. Never hard-coded in a workflow. Whoever has access to a workflow should not automatically see passwords.
- Updates. n8n releases often and some releases address security. An un-updated instance is the biggest risk in the whole solution.
- A separate environment for testing. Do not debug on the production instance that has access to live data.
The most common mistake I see: an instance exposed to the internet with no access restriction, holding the credentials to every company system. That is not automation, that is a single point that opens everything at once.
Backups: what to back up and how to verify it
With n8n there are three things to back up, and each is different:
Workflows
They export as JSON. Ideally automatically and into versioned storage — then you know what changed and when.
Credentials
Stored encrypted and tied to the instance's encryption key. Without a backup of that key they are unusable after a restore.
Database and history
Execution records. Useful for tracing, but bulky — decide how long to keep them.
A backup you have never restored is not a backup. Try a restore on a clean server at least once and time how long it takes. That is the only way to find out you are not missing exactly that encryption key.
GDPR and where the data goes
Self-hosting is often sold as “the GDPR solution”. That is a simplification that can be dangerous, so more precisely:
- What self-hosting solves: data processed in a workflow does not pass through the automation platform provider's infrastructure. One processor fewer.
- What it does not solve: if a workflow calls an external service — a language model, a translator, a data enrichment API — the data goes there. Self-hosting changes nothing about that.
- What it also does not solve: the lawfulness of the processing itself, information obligations, retention periods or processor agreements.
- What follows practically: in the design, every step where data leaves your infrastructure has to be named — and decided on individually.
This is a technical description of where data travels, not legal advice; assessing GDPR compliance belongs to your DPO or lawyer.
When to choose the cloud instead
- When there is nobody to administer a server. An un-updated instance is worse than a subscription.
- When the volume is small. At tens of executions a day the cloud is simpler and often cheaper on total cost.
- When nothing in the data is sensitive. Without that reason, self-hosting's main advantage is wasted.
- When you need a result this week. The cloud runs immediately; preparing a server, HTTPS and backups takes time.
I recommend a pragmatic route: start in the cloud, confirm the automation makes sense, and move to self-hosting only when there is a substantive reason. Workflows export as JSON, so moving does not mean building again from scratch.
FAQ
How does n8n count executions?
Per the official documentation, one execution is one run of a whole workflow regardless of the number of steps and the volume of data. That is why n8n works out better for long scenarios than tools that bill each module action separately.
Can we move from the cloud to self-hosting later?
Yes. Workflows export as JSON and import into your own instance; the credentials have to be set up again.
Who looks after the instance after deployment?
Either you or the supplier. What matters is that it is agreed in advance — the most common cause of trouble is an instance both sides believe the other one is updating.
Sources
- n8n — self-hosting documentation
- n8n — official price list (checked 5 September 2026)
- n8n — source code and licence
Originally published on nexflow.sk. I build n8n and Make.com automations for small businesses in Slovakia — see also n8n vs Make.com: which tool to choose.
来源:Google AI:DEV 作者专属(RSS) · dev.to