CtrlK
BlogDocsLog inGet started
Tessl Logo

n8n-self-hosting

Deploy a production self-hosted n8n end-to-end to a fresh Linux VM over SSH, using Docker Compose behind a Caddy reverse proxy with automatic HTTPS. Use whenever the user wants to self-host, install, set up, provision, or deploy n8n on their own server/VPS/box (Hetzner, DigitalOcean, AWS EC2, bare metal, etc.) — in either single/regular mode or queue mode with workers — or to update, back up, restore, or harden such an instance. This is for SELF-HOSTED n8n (Docker), not n8n Cloud and not building workflows. The skill makes the agent ask single-vs-queue first, collect the domain/SSH/timezone inputs, generate fresh secrets on the box, and bring the stack up with TLS. Trigger on "deploy n8n", "self-host n8n", "install n8n on my server", "n8n docker compose", "n8n queue mode / workers / scaling", "n8n reverse proxy / SSL", "back up / update my n8n", or "we don't want to give every user the OAuth client secret" / "enable the Sign in with Google button" (credential overwrites).

73

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is n8n-self-hosting in czlonkowski/n8n-skills

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered operational runbook: an ordered preflight-to-handoff flow with genuine validation gates, copy-paste commands with expected outputs, and crisp delegation of detail to per-mode reference files. Its one material defect is that the bundle does not ship the referenced files — SINGLE_MODE.md, QUEUE_MODE.md, SECURITY.md, CREDENTIAL_OVERWRITES.md, and DAY2.md are cited (and steps depend on them for the openssl commands and Day-2 handoff) but absent, so the progressive-disclosure structure breaks at its first hop.

Suggestions

Ship the five referenced files (SINGLE_MODE.md, QUEUE_MODE.md, SECURITY.md, CREDENTIAL_OVERWRITES.md, DAY2.md) in the bundle — every pointer in the body currently dead-ends, and step 4 depends on SECURITY.md for the openssl secret-generation commands it defers to.

Inline the minimal openssl commands for N8N_ENCRYPTION_KEY (and POSTGRES_PASSWORD in queue mode) directly in step 4 so the launch-critical path survives even if a reference file is missing.

Trim the "What NOT to do" section to only novel items — "Don't publish 5678/5432/6379", "Don't put secrets in docker-compose.yml or the Caddyfile", and "Don't reuse another instance's encryption key" restate Rule 1 nearly verbatim.

DimensionReasoningScore

Conciseness

Largely lean and operational — it assumes competence and spends tokens only on n8n-specific gotchas ("a leftover placeholder becomes the literal password and Postgres/n8n fail to connect", "an exposed un-owned instance is a race"), which Claude cannot know a priori. It misses a 5 because of redundancy: the "What NOT to do" section restates Rule 1 items nearly verbatim ("Don't publish 5678/5432/6379", "Don't put secrets in docker-compose.yml or the Caddyfile", "Don't reuse another instance's encryption key") already covered above.

4 / 5

Actionability

Fully executable commands throughout, copy-paste ready: "curl -s ifconfig.me", "dig +short <fqdn>", "ssh <target> 'cat > <DATA_FOLDER>/docker-compose.yml' < assets/docker-compose.single.yml", "grep REPLACE_WITH_ .env", "docker compose exec n8n wget -qO- http://localhost:5678/healthz", "curl -fsS --retry 5 --retry-delay 10 https://<fqdn>/healthz", and the env-parity diff with process substitution. Each step states exactly what to run and what the expected output is ("{'status':'ok'}").

5 / 5

Workflow Clarity

A clear 8-step preflight→handoff sequence with explicit validation checkpoints and feedback loops: DNS mismatch → "stop... Have the user create the A record, wait for it to propagate, then continue"; a hard gate before launch ("grep REPLACE_WITH_ .env must return nothing — Before launching, confirm none are left unset"); and a verify step that separates failure modes (internal healthz vs. "cert is still pending, not that n8n is down") with retry logic, culminating in "don't declare success without this". The destructive/batch cap does not apply — validation is present and thorough.

5 / 5

Progressive Disclosure

The structure and signaling are excellent — a Reference files section enumerates each file with a one-line scope, and inline pointers land at the exact section needed ("the modules section of QUEUE_MODE.md"). But scored against the actual bundle, five of the six referenced files are missing: SINGLE_MODE.md, QUEUE_MODE.md, SECURITY.md, CREDENTIAL_OVERWRITES.md, and DAY2.md do not exist in the bundle (only the six assets/ templates are present). Navigation dead-ends for all per-mode and security detail, including the openssl commands step 4 depends on ("SECURITY.md has the commands") — this is worse than the "minor organization gaps" of the 4 anchor, though better than the 2 anchor since the overview itself is well organized and all asset paths resolve.

3 / 5

Total

17

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: it names the concrete capability with its exact mechanism, states what-and-when twice over with explicit trigger phrases and synonyms, and actively scopes itself against neighboring skills. The only deductions are the two non-n8n-qualified OAuth trigger phrases (minor conflict risk) and overall length — the behavioral-preview sentence ("The skill makes the agent ask single-vs-queue first...") is informative but pushes the description toward the verbosity the guidelines penalize.

DimensionReasoningScore

Specificity

Multiple concrete actions with comprehensive coverage: "Deploy a production self-hosted n8n end-to-end to a fresh Linux VM over SSH, using Docker Compose behind a Caddy reverse proxy with automatic HTTPS", plus "update, back up, restore, or harden", "generate fresh secrets on the box", and "bring the stack up with TLS". Every capability is a concrete, named action with the mechanism specified (Docker Compose, Caddy, SSH, Let's Encrypt via "automatic HTTPS"); there is no filler language.

5 / 5

Completeness

Explicitly answers both questions: the "what" opens the description ("Deploy a production self-hosted n8n end-to-end... using Docker Compose behind a Caddy reverse proxy") and the "when" is stated twice — "Use whenever the user wants to self-host, install, set up, provision, or deploy n8n" and the explicit "Trigger on" list. This matches the score-5 anchor (clear what AND when with concrete trigger phrases) exactly.

5 / 5

Trigger Term Quality

The trigger list is exhaustive and natural: "deploy n8n", "self-host n8n", "install n8n on my server", "n8n docker compose", "n8n queue mode / workers / scaling", "n8n reverse proxy / SSL", "back up / update my n8n" — plus user-voice synonyms ("self-host, install, set up, provision, or deploy", "server/VPS/box (Hetzner, DigitalOcean, AWS EC2, bare metal)"). It even captures paraphrased user intents like "we don't want to give every user the OAuth client secret".

5 / 5

Distinctiveness Conflict Risk

Mostly distinct: n8n appears in nearly every trigger, and the exclusions ("This is for SELF-HOSTED n8n (Docker), not n8n Cloud and not building workflows") sharply bound it against sibling skills. Minor overlap remains: the catch-all triggers "we don't want to give every user the OAuth client secret" / "enable the Sign in with Google button" are generic-sounding OAuth phrases that could fire for a Google-auth or OAuth skill outside an n8n context. Not clearly the 5 anchor ("minimal conflict risk") because of those two non-n8n-qualified phrases.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
czlonkowski/n8n-mcp
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.