N8N
🚀Installation
Preliminary
1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 3. ArgoCD is installed; if not, check 🔗link- Database postgresql has been installed, if not check 🔗link
1.prepare `n8n-middleware-credentials.yaml`
Details
kubectl get namespaces n8n > /dev/null 2>&1 || kubectl create namespace n8n
N8N_PASSWORD=$(kubectl -n database get secret postgresql-credentials -o jsonpath='{.data.password}' | base64 -d)
kubectl -n n8n create secret generic n8n-middleware-credential \
--from-literal=postgres-password="${N8N_PASSWORD}"2.prepare `deploy-n8n.yaml`
Details
kubectl -n argocd apply -f - <<EOF
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: n8n
spec:
project: default
source:
repoURL: https://community-charts.github.io/helm-charts
targetRevision: 1.16.36
helm:
releaseName: n8n
values: |
global:
security:
allowInsecureImages: true
image:
repository: n8nio/n8n
log:
level: info
encryptionKey: "ay-dev-n8n"
timezone: Asia/Shanghai
db:
type: postgresdb
externalPostgresql:
host: postgresql-hl.database.svc.cluster.local
port: 5432
username: "n8n"
database: "n8n"
existingSecret: "n8n-middleware-credential"
main:
count: 1
extraEnvVars:
"N8N_BLOCK_ENV_ACCESS_IN_NODE": "false"
"N8N_FILE_SYSTEM_ALLOWED_PATHS": "/home/node/.n8n-files"
"EXECUTIONS_TIMEOUT": "300"
"EXECUTIONS_TIMEOUT_MAX": "600"
"DB_POSTGRESDB_POOL_SIZE": "10"
"CACHE_ENABLED": "true"
"N8N_CONCURRENCY_PRODUCTION_LIMIT": "5"
"NODE_TLS_REJECT_UNAUTHORIZED": "0"
"N8N_SECURE_COOKIE": "false"
"WEBHOOK_URL": "https://webhook.n8n.dev.72602.online"
"QUEUE_BULL_REDIS_TIMEOUT_THRESHOLD": "60000"
"N8N_COMMUNITY_PACKAGES_ENABLED": "true"
"N8N_GIT_NODE_DISABLE_BARE_REPOS": "true"
"N8N_LICENSE_AUTO_RENEW_ENABLED": "true"
"N8N_LICENSE_RENEW_ON_INIT": "true"
persistence:
enabled: true
accessMode: ReadWriteOnce
storageClass: "local-path"
size: 50Gi
volumes:
- name: downloads-volume
hostPath:
path: /home/aaron/Downloads
type: DirectoryOrCreate
volumeMounts:
- name: downloads-volume
mountPath: /home/node/.n8n-files
resources:
requests:
cpu: 1000m
memory: 1024Mi
limits:
cpu: 2000m
memory: 2048Mi
worker:
mode: queue
count: 2
waitMainNodeReady:
enabled: false
extraEnvVars:
"N8N_FILE_SYSTEM_ALLOWED_PATHS": "/home/node/.n8n-files"
"EXECUTIONS_TIMEOUT": "300"
"EXECUTIONS_TIMEOUT_MAX": "600"
"DB_POSTGRESDB_POOL_SIZE": "5"
"QUEUE_BULL_REDIS_TIMEOUT_THRESHOLD": "60000"
"N8N_COMMUNITY_PACKAGES_ENABLED": "true"
"N8N_GIT_NODE_DISABLE_BARE_REPOS": "true"
"N8N_LICENSE_AUTO_RENEW_ENABLED": "true"
"N8N_LICENSE_RENEW_ON_INIT": "true"
persistence:
enabled: true
accessMode: ReadWriteOnce
storageClass: "local-path"
size: 50Gi
volumes:
- name: downloads-volume
hostPath:
path: /home/aaron/Downloads
type: DirectoryOrCreate
volumeMounts:
- name: downloads-volume
mountPath: /home/node/.n8n-files
resources:
requests:
cpu: 500m
memory: 1024Mi
limits:
cpu: 1000m
memory: 2048Mi
nodes:
builtin:
enabled: true
modules:
- crypto
- fs
external:
allowAll: true
packages:
- n8n-nodes-globals
npmRegistry:
enabled: true
url: http://mirrors.cloud.tencent.com/npm/
redis:
enabled: true
image:
registry: m.daocloud.io/docker.io
repository: bitnamilegacy/redis
master:
resourcesPreset: "small"
persistence:
enabled: true
accessMode: ReadWriteOnce
storageClass: "local-path"
size: 10Gi
ingress:
enabled: true
className: nginx
annotations:
kubernetes.io/ingress.class: nginx
cert-manager.io/cluster-issuer: self-signed-ca-issuer
nginx.ingress.kubernetes.io/proxy-connect-timeout: "300"
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
nginx.ingress.kubernetes.io/proxy-body-size: "50m"
nginx.ingress.kubernetes.io/upstream-keepalive-connections: "50"
nginx.ingress.kubernetes.io/upstream-keepalive-timeout: "60"
nginx.ingress.kubernetes.io/enable-cors: "true"
nginx.ingress.kubernetes.io/cors-allow-origin: "https://webhook.n8n.dev.72602.online:32443"
nginx.ingress.kubernetes.io/cors-allow-methods: "GET, POST, OPTIONS, PUT, DELETE"
nginx.ingress.kubernetes.io/cors-allow-headers: "DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization"
nginx.ingress.kubernetes.io/cors-allow-credentials: "true"
hosts:
- host: n8n.dev.72602.online
paths:
- path: /
pathType: Prefix
- host: webhook.n8n.dev.72602.online
paths:
- path: /
pathType: Prefix
tls:
- hosts:
- n8n.dev.72602.online
- webhook.n8n.dev.72602.online
secretName: n8n.dev.72602.online-tls
webhook:
mode: queue
url: "https://webhook.n8n.dev.72602.online"
autoscaling:
enabled: false
waitMainNodeReady:
enabled: true
resources:
requests:
cpu: 200m
memory: 256Mi
limits:
cpu: 512m
memory: 512Mi
chart: n8n
destination:
server: https://kubernetes.default.svc
namespace: n8n
syncPolicy:
syncOptions:
- CreateNamespace=true
- ApplyOutOfSyncOnly=false
EOF3.sync by argocd
Details
argocd app sync argocd/n8nUsing AY ACR Image Mirror
Using DaoCloud Mirror
Preliminary
1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 3. ArgoCD is installed; if not, check 🔗link- Database postgresql has been installed, if not check 🔗link
1.verify retained credentials and storage
Details
kubectl get namespace n8n
kubectl -n n8n get secret n8n-middleware-credential n8n-encryption-key-existing
kubectl -n n8n get pvcImportant
The live credentials and PVCs are retained state. Do not delete, recreate, or replace them when updating the Argo CD Application.
2.review and publish the canonical source `manifests/n8n-argocd.yaml`
The n8n Argo CD Application is parent-managed by argocd/ops-docs from the repository’s main branch and manifests path. n8n itself is manually synced after the parent Application has converged. The current chart is 1.24.42 and n8n is 2.40.5.
Details
git diff --check
git diff -- manifests/n8n-argocd.yaml
git status --short
git add manifests/n8n-argocd.yaml
git commit -m "fix(n8n): configure AI model requests"
git push origin main3.wait for parent convergence, then manually sync n8n
Details
argocd app get argocd/ops-docs --insecure --grpc-web
argocd app sync argocd/n8n --insecure --grpc-web
argocd app get argocd/n8n --insecure --grpc-web
kubectl -n n8n rollout status deployment/n8n --timeout=300sVerify parent argocd/ops-docs is synced before manually syncing argocd/n8n. Review the Application diff and confirm the existing credentials and PVCs remain unchanged.
4.verify
Details
argocd app get argocd/n8n --insecure --grpc-web
kubectl -n n8n rollout status deployment/n8n --timeout=300s
kubectl -n n8n get pods
curl -sS -o /dev/null -w '%{http_code}\n' https://n8n.72602.space/healthz
curl -sS -o /dev/null -w '%{http_code}\n' https://n8n.72602.space/healthz/readiness
curl -sS -o /dev/null -w '%{http_code}\n' https://n8n.72602.space/Confirm the Application is Synced and Healthy, the main Pod is Ready without restarts, and the health/readiness endpoints and public editor return HTTP 200.