Activity
Mon
Wed
Fri
Sun
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
What is this?
Less
More

Owned by Nazar

PP
Peak Pulse Agency

1 member • Free

Memberships

The AI Advantage

64k members • Free

Home Lab Explorers

1k members • Free

AI Automation Society Plus

3k members • $94/month

AI Automation Society

202.6k members • Free

Content Academy

13.5k members • Free

SW
SWS Private Community

3k members • Free

AI Automation Agency Hub

272.6k members • Free

Agency Owners

17.7k members • Free

1 contribution to Home Lab Explorers
n8n Exposure
Hey everyone, I’m exploring the safest way to expose an n8n instance to the internet so it can work with external services, and I’d love your input on hardening practices. I see a lot of deployment guides but far fewer security deep-dives. My setup - Proxmox cluster - Virtualized pfSense - Ubuntu 24.04 server (Docker) - Official n8n Docker behind Traefik - Isolated VLAN for this stack (blocked from other VLANs) - Cloudflare Tunnel connector on a separate VM (same LAN) - UFW: default-deny inbound; SSH allowed only from a specific IP - Docker publishes 80/443 for Traefik (UFW doesn’t interfere with Docker’s chain) - SSH via keys (no passwords) - Fail2Ban enabled What I’m asking: 1. What additional layers would you add for an internet-facing n8n (especially auth, network controls, rate-limiting)? 2. Any Traefik or Cloudflare Tunnel rules you recommend (mTLS, WAF, IP allow-lists, Cloudflare Access, etc.)? 3. Gotchas you’ve hit with Docker/UFW/Traefik interplay or n8n webhooks under tunnels? 4. Monitoring/logging tools you’ve found helpful for detecting abuse (and sane defaults for alerts)? 5. Goal: A practical, defense-in-depth checklist others can reuse. Suggestions, examples, and “don’t do this” stories are all welcome. Thanks in advance!
1 like • Oct 31
Hi @Brandon Lee, Thanks for getting back to me, Part of my n8n workflows will need to have webhooks for external tigers, and as I do understand, I will need to have some sort of way that external triggers will hit my n8n instance. Is it even possible to make it securely, or its best to host on VPs for these things?
1-1 of 1
Nazar Khomyshyn
1
2points to level up
@nazar-khomyshyn-1833
Peak Pulse Agency CoFounder. We help busy business owners grow fast with AI, automation, and high-converting digital systems without hiring a big team

Active 5h ago
Joined Oct 25, 2025
Powered by