07-n8n.md
kstack: book: Centerpoint Home Lab chapter: AI & Automation page: N8N tags: [n8n, automation, workflows, integration]
Overview
emptyN8N is the workflow automation platform for the homelab. It connects services
together through visual, node-based workflows — handling tasks such as document
pipeline automation, audio transcription orchestration (Minuspod), API integrations,
scheduled jobs, and webhook-triggered processing.
N8N is the glue layer that ties together Whisper, Ollama, Paperless, and external APIs into end-to-end automated pipelines.
Access
https://n8n.home.local
LAN access via Step-CA TLS — basic auth
No external (internet-facing) Traefik route. Remote access via Tailscale.
Webhooks are received at https://n8n.home.local/webhook/... — internal and
Tailscale-reachable only.
Configuration
Image: n8nio/n8n:latest
Compose project: Standalone (managed via Portainer)
Ports
5678
TCP
N8N web UI and API (host-bound)
Traefik Labels
traefik.enable: "true"
traefik.docker.network: traefik-net
traefik.http.routers.n8n.rule: Host(`n8n.home.local`)
traefik.http.routers.n8n.entrypoints: websecure
traefik.http.routers.n8n.tls.certresolver: step-ca
traefik.http.services.n8n.loadbalancer.server.port: 5678
Internal-only route.
Environment Variables
N8N_HOST
n8n.home.local
N8N_PROTOCOL
https
N8N_PORT
5678
N8N_EDITOR_BASE_URL
https://n8n.home.local
WEBHOOK_URL
https://n8n.home.local
N8N_BASIC_AUTH_ACTIVE
true
N8N_BASIC_AUTH_USER
jeeves
N8N_BASIC_AUTH_PASSWORD
REDACTED
N8N_ENCRYPTION_KEY
REDACTED — encrypts stored credentials
N8N_PAYLOAD_SIZE_MAX
16 (MB)
EXECUTIONS_PROCESS
main
GENERIC_TIMEZONE
America/Toronto
N8N_ENCRYPTION_KEY encrypts all stored credentials (API keys, passwords) in the
N8N database. This key must remain constant — changing it invalidates all stored
credentials and they must be re-entered.
Volumes / Bind Mounts
/home/jeeves/docker/n8n/data
/home/node/.n8n
Workflows, credentials, execution history
All workflow definitions, credentials, and execution logs are stored in this bind-mounted directory. Back up before upgrades.
Networks
traefik-net
Exposes N8N UI and webhook endpoint
N8N calls other services by hostname (e.g. http://ollama.home.local:11434,
https://whisper.home.local) — it must be on traefik-net or have DNS
resolution for these names.
Dependencies
*.home.local DNS resolution (N8N calls other services by name)
Step-CA / Traefik for the n8n.home.local route
Services called by workflows: Ollama, Faster-Whisper, Paperless-NGX, external APIs
Notes / Gotchas
N8N_ENCRYPTION_KEY. If this key is
lost or rotated, all stored API keys and passwords must be re-entered manually.
EXECUTIONS_PROCESS=main runs workflow executions in the main process. For high
concurrency, consider EXECUTIONS_PROCESS=own with worker processes, but this
requires additional setup.
Webhook URLs are internal only (https://n8n.home.local/webhook/...). External
webhooks (e.g. from GitHub, Stripe) will not reach N8N unless a Tailscale exit
node or Traefik external route is configured.
N8N_PAYLOAD_SIZE_MAX=16 limits incoming webhook payload size to 16 MB. Increase
this if processing large audio or document payloads via webhook.
The latest tag may introduce breaking changes between workflow schema versions.
Pin to a specific N8N version before any significant workflow investments.
Last Updated: 2026-06-16