VM300 is an application VM dedicated to n8n: it runs automation workflows, delegates persistence to a services VM (PostgreSQL), and consumes the AI APIs of a separate GPU VM. This separation of application / data / compute lets each component evolve, be maintained and backed up on its own lifecycle.
✅ Deployed state
  • Ubuntu Server 24.04 LTS · Docker Engine + Compose
  • n8n 2.32.6 — pinned official image
  • Single instance, standard mode, without Redis
  • External PostgreSQL — encrypted connection, strong authentication
  • Remote Ollama API consumed by a validated workflow
  • Interface published over HTTPS by the shared reverse proxy
  • Persistence verified after container recreation and restart
🔒 Security of the current state
  • Application port kept on the internal network, public interface exposed only over HTTPS
  • System filtering + controlled Docker publishing
  • Secrets and encryption key outside Compose and outside Git
  • Pinned application image
  • Dedicated PostgreSQL database and role, encrypted link
  • No direct Internet redirection to VM300
  • Public origin, secure cookies, trust limited to the reverse proxy
  • Inspection of workflows and node types used
🧱 Internal architecture (VM300)
Docker isolation · reproducible deployment (Compose)
VM300
├── Ubuntu Server
├── Docker Engine
├── Docker Compose
└── conteneur n8n
    ├── moteur de workflows
    ├── interface d'administration
    ├── appels vers les services autorisés
    └── données binaires locales nécessaires

n8n deliberately runs as a single instance: Redis and queue mode are not added until a need for parallelism or high availability is demonstrated — which reduces the number of components to operate.

External components

🗄️ PostgreSQL (services VM)
  • Database reserved for the application
  • Separate application role, rights limited to what's needed
  • Encrypted connection · targeted network filtering
  • Recreating n8n deletes neither accounts nor workflows (data lives outside the container)
🧠 Ollama (GPU VM)
  • AI computation offloaded to the GPU node
  • VM300 calls an authorized Ollama API, with no GPU or model copy
  • Validated workflow: request preparation → HTTP call → model response → output normalization
🌐 Active Internet publishing

The editor is published over HTTPS at n8n.stephanemuraro.fr (authenticated admin interface and webhook URLs produced by the instance), behind the VM200 reverse proxy. VM300's application port is not exposed directly: every public request passes through VM200, which terminates HTTPS, selects the service by the requested name, and relays only the intended routes. A later separation under a dedicated webhook name remains possible if a need for stricter exposure is confirmed.

path of a public request
Utilisateur ou service externe
        ↓ HTTPS
Nom DNS public
        ↓
Routeur Internet
        ↓ trafic Web uniquement
VM200 — reverse proxy   (terminaison TLS · sélection par nom · routes autorisées)
        ↓ flux interne autorisé
VM300 — n8n
        ↓
PostgreSQL ou API IA selon le workflow
n8n is aware of its public HTTPS origin, trusts the expected proxy, and uses secure cookies. Authentication, the editor, running a workflow, reconnection and persistence have been validated from the Internet (external network).
🔄 Example — n8n workflow to AI
workflow (illustrative)
Trigger : Webhook
   → Nœud HTTP  : préparation de la requête
   → Nœud HTTP  : appel API Ollama (LLM local sur la VM GPU)
   → Nœud Function : normalisation de la réponse pour les étapes suivantes
   → Réponse : JSON structuré
🎯 Skills demonstrated
  • Reproducible Docker Compose deployment
  • Application / data / GPU compute separation
  • Encrypted PostgreSQL integration, least privilege
  • Controlled consumption of a remote LLM API
  • Design of persistent workflows
  • Preparing HTTPS publishing behind a reverse proxy
  • Secrets management and exposure surface reduction
Limits & open work:

Related pages

References & Sources

CategoryResourceURL
Official documentationn8n — Documentationdocs.n8n.io
Official documentationPostgreSQL — Documentationpostgresql.org/docs
Deployed versionn8n 2.32.6 · Ubuntu Server 24.04 LTS · VM300 (Docker)—
Licensen8n — Sustainable Use License (fair-code) · PostgreSQL — PostgreSQL Licensedocs.n8n.io — licence
Content of this pageShared under CC BY-SA 4.0creativecommons.org/licenses/by-sa/4.0