The Self-Host Question: When n8n Pays Off
A $15/month VPS looks like a steal next to n8n Cloud Pro's $60/month bill. The arithmetic is real. The trap is hiding in the hours, the database backups, and the 3 AM page when Postgres locks up during a workflow that's mid-execution. Self-hosting n8n pays off — but only when you've counted the hours honestly.
The Headline Arithmetic (and Why It Lies)
The basic cost comparison is easy and seductive:
- n8n Cloud Pro: $60/month, capped at 10,000 executions/month, hosted/managed by n8n.io, backups handled, upgrades handled, support included.
- n8n self-hosted: $5-$20/month VPS (Hetzner CX21 at €5.83 ≈ $6.50; DigitalOcean Basic at $12-$24; Linode Nanode at $5), unlimited executions, you handle everything.
Annualized, that's $720/year on Cloud Pro vs. $60-$240/year on the VPS. A finance team looking at the line items will reach the same conclusion in thirty seconds: self-host and save 75-90%.
This arithmetic is technically correct and substantively misleading. The reason is that the $60/month from n8n.io includes things that the $15/month VPS does not include: a 24/7 on-call engineering team, a managed database with point-in-time restore, security patching, automated version upgrades, replication, monitoring, and an SLA. If you self-host, all of those become your problem. The question is whether your time, plus the risk-adjusted cost of an outage you didn't plan for, is worth the $45/month delta.
The right comparison isn't $60 vs $15. It's $60 vs ($15 + your hourly rate × hours you'll spend × risk-adjusted incident cost). When you do the full math, the break-even is at a specific workload size — and it's higher than most operator-builders guess.
The Real Cost Stack of Self-Hosting
Self-hosting n8n on a $15/month VPS produces six hidden cost categories beyond the VPS bill. Each is bounded but real.
1. Initial setup: 4-12 hours
For a competent operator-builder following the official n8n Docker Compose docs, initial setup is 2-4 hours: provision VPS, install Docker, pull the n8n image, mount a Postgres database, configure reverse proxy with Caddy or nginx, point a domain, configure TLS. For someone learning Linux administration in the process, expect 8-12 hours. None of this is hard, but it has to be done correctly the first time — workflows you build before backups are in place are workflows you can lose.
2. Database backups: 2-4 hours upfront, 30 minutes/month thereafter
n8n stores workflow definitions, credentials, executions history, and queue state in Postgres. Lose the database and you lose everything. A basic backup posture: nightly pg_dump to a separate object store (Backblaze B2 at $0.005/GB/month is the cheapest credible option, $6/TB; AWS S3 at $0.023/GB; Cloudflare R2 at $0.015/GB with no egress). Retention: 7 daily, 4 weekly, 12 monthly is a defensible default. Add a monthly restore test — actually pull last week's backup, spin up a fresh VPS, restore, verify workflows ran. The restore test is the difference between "we have backups" and "we have working backups." This stack costs about 30 minutes/month of attention plus $1-$5/month of storage.
3. Version upgrades: 1 hour per upgrade, 4-12 upgrades/year
n8n ships releases every 1-3 weeks. Most are minor; some are breaking. The discipline is: read release notes, snapshot the VPS, snapshot the database, deploy to a staging VPS first if your workflows are critical, run smoke tests, then deploy to production. For most operator-builders, monthly upgrades are sufficient. That's 12 upgrades/year at 1 hour each — 12 hours/year of attention, or one hour per month averaged.
4. Security patching: 30 minutes/month
Ubuntu LTS or Debian stable releases security updates regularly. Unattended-upgrades handles most automatically. The remaining work is reviewing logs, applying kernel patches (which require reboots), and rotating credentials. Budget 30 minutes/month.
5. Incidents and on-call: 2-8 hours/year, variable
This is the variable cost that breaks budgets. A VPS dies, the data center has an outage, the database lock-up wedges all workflows, a security incident requires forensic investigation. For a well-built self-hosted n8n at modest scale, expect 1-3 incidents per year averaging 2-3 hours each. For an undisciplined deployment (no backups, no monitoring, single point of failure), incidents are open-ended and existential.
6. Capability ceiling: opportunity cost
Self-hosted n8n on a single VPS handles tens of thousands of executions/month. Beyond that, you need queue mode, worker processes, Redis, multi-node deployment, and the operational complexity scales. n8n Cloud Pro handles up to 10K executions and the Enterprise tier handles much more. If your workload is going to grow past the single-VPS ceiling within a year, the time you'll spend re-architecting is a cost worth counting now.
Adding up: 8 hours initial + 30 min/month backups + 1 hour/month upgrades + 30 min/month patching + 4 hours/year incidents = roughly 32 hours in year one, 28 hours in year two. At an operator-builder's loaded cost of $75-$150/hour (median for the role in 2026), that's $2,400-$4,200 of attention per year. Plus $200-$300 of VPS and storage.
The Break-Even: When Cloud Wins and When Self-Host Wins
n8n Cloud Pro: $720/year, no time cost (beyond using the product).
n8n self-hosted year one: $200 infra + 32 hours × $100/hour = $3,400. Year two: $200 + 28 hours × $100 = $3,000.
On this math, Cloud Pro is dramatically cheaper if you value your time at $100/hour. Self-host wins only when:
- You value your time at $25/hour or less. A side-project builder learning the stack as a skill investment is genuinely better off self-hosting. The "wasted" hours are also tuition.
- You're already running a VPS for something else and can co-locate. The marginal cost of running n8n on an existing $20/month VPS that already hosts your CI runner is closer to $0 than $3,400.
- Your workload exceeds n8n Cloud Pro's 10K-execution cap. At that point, you're upgrading to a more expensive tier or self-hosting anyway.
- Data sovereignty requires it. No amount of Cloud Pro pricing is acceptable if your legal team has said the data cannot leave your perimeter.
- You're at scale where the alternative is Enterprise pricing. n8n Enterprise is custom-priced but starts in the thousands of dollars per month. At that volume, self-host operational cost is dwarfed by the savings.
For most one-engineer operator-builder teams in the 1K-10K executions/month range, n8n Cloud Pro at $60/month is cheaper than self-hosted when you count your time honestly. The break-even tilts toward self-host above 10K executions, at $25/hour valuations, or when data sovereignty is mandatory.
Real Workload Examples
Workload A: A solo consultant's three lead-routing automations, 800 executions/month
This is the canonical "should I self-host?" question. A consultant has three workflows that route inbound leads, schedule meetings, and post to Slack. Total: 800 executions/month, well under any cap.
- n8n Cloud Pro: $60/month, $720/year.
- Self-host on a $5/month Hetzner CX11: $60/year infra. 32 hours year-one attention. At a $200/hour billable rate, that's $6,400 of foregone billable time.
Verdict: Cloud Pro. The consultant should buy their time back. Unless they want to learn Linux administration as a hobby, the $720/year is the cheapest answer.
Workload B: A mid-size marketing team's content-ops stack, 5,000 executions/month
Five workflows: lead-magnet-to-CRM, blog-post-to-social, content-calendar-management, attribution-reporting, and customer-feedback-routing. Volume: 5,000 executions/month.
- n8n Cloud Pro: $60/month, $720/year. Fits comfortably under the 10K cap.
- Self-host on a $12/month DigitalOcean droplet: $144/year infra. 32 hours year-one attention.
The marketing-ops manager building this is loaded at $90/hour fully-burdened. Self-host year-one cost: $144 + (32 × $90) = $3,024. Cloud Pro: $720. Verdict: Cloud Pro until the workload approaches the 10K cap or the team has a dedicated engineer who would absorb the attention anyway.
Workload C: A B2B SaaS platform team running 60 automations, 25,000 executions/month
The platform team manages cross-system data movement: CRM-to-billing, billing-to-finance, support-to-product, NPS-to-CRM, and dozens more. Volume: 25,000 executions/month, beyond Cloud Pro's 10K cap.
- n8n Cloud Pro at 25K executions: requires upgrade beyond Pro tier, custom Enterprise pricing in the $200-$500/month range, $2,400-$6,000/year.
- Self-host on a $40/month DigitalOcean droplet plus Postgres managed service ($15/month) plus Redis ($15/month): $840/year infra. 50 hours/year attention (more workflows, more incidents).
The platform team has an engineer whose loaded cost is $120/hour but whose marginal cost of running n8n is near zero (it's part of their role). Effective self-host cost: $840/year. Effective Cloud Pro/Enterprise cost: $2,400-$6,000/year. Verdict: self-host. The arithmetic supports it, the engineering attention is already budgeted, and the workload exceeds Cloud Pro's cap.
Workload D: A healthcare ISV with HIPAA-bound patient-record workflows, 2,000 executions/month
Three workflows handling patient intake, insurance verification, and appointment reminders. Volume: 2,000 executions/month, low by infrastructure standards. But the data is HIPAA-bound and the BAA list with n8n Cloud may not cover all subprocessors.
- n8n Cloud Pro: infeasible without a BAA matrix the legal team accepts. Even if cheaper on paper, compliance risk is the dominant variable.
- Self-host on a HIPAA-eligible cloud provider (AWS with BAA, Azure with BAA, or a HIPAA-specialty VPS like Aptible): $40-$200/month infra. 40 hours/year attention.
Verdict: self-host on a HIPAA-eligible provider. This is the case where the arithmetic doesn't dominate the decision. Sovereignty forces the verdict.
The Failure Mode: Self-Hosting Without a Database Backup Plan
The single most common self-hosted-n8n incident in 2025-2026 is the data-loss event: the operator-builder set up the VPS, built dozens of workflows, ran for six months, and never set up backups. Then the VPS provider had an outage, or the disk filled up, or a misconfigured upgrade truncated the database. Every workflow definition, every credential, every saved execution history — gone.
Real incident pattern (composite)
A small agency self-hosted n8n in early 2025. They built 23 client-facing automations over 8 months. The lead engineer left in October. In December, the team applied an n8n version upgrade. The upgrade required a database migration. The migration ran on the live database with no backup. It failed partway through. The database was left in an inconsistent state. n8n wouldn't start. The agency had no recovery path — no nightly pg_dump, no point-in-time restore, no snapshot. They rebuilt every workflow from memory and from screenshots, losing two weeks of billable time. Total cost of the missing backup: ~$15,000 of agency time, plus client trust.
The backup posture you actually need
Six elements:
- Automated nightly pg_dump to a separate object store. Cron'd, not "I'll remember to do it."
- Off-server retention. The backup must survive the loss of the n8n VPS itself. Backblaze B2, S3, Cloudflare R2, or another provider's object store.
- Retention policy: 7 daily, 4 weekly, 12 monthly is a reasonable default. Adjust based on workflow volatility.
- Backup integrity check. Verify the dump completed without error. A 0-byte backup is worse than no backup because it gives false confidence.
- Quarterly restore test. Actually restore the backup to a fresh VPS, start n8n, verify a critical workflow runs. The first time you test restore should not be during an incident.
- Credential encryption key backed up separately. n8n encrypts credentials at rest. If you lose the encryption key, the backup is useless because every credential is unreadable. Back up the
N8N_ENCRYPTION_KEYenvironment value to a separate secrets manager (1Password vault, Vault, AWS Secrets Manager).
Database alternatives and trade-offs
n8n supports SQLite (default for small deployments), Postgres (recommended for production), and MySQL (less commonly used). SQLite is fine for personal/single-user instances but doesn't support queue mode and is harder to back up live. Postgres is the production-grade choice. Managed Postgres ($15-$50/month from DigitalOcean, Neon, or Supabase) eliminates the backup-and-replication problem at the cost of a fixed bill. For workloads where the backup discipline is uncertain, paying for managed Postgres is the cheapest insurance you can buy.
The Monitoring and Alerting Gap
Backups protect you from data loss. Monitoring protects you from knowing when you have a problem. Self-hosted n8n with no monitoring is the platform equivalent of running a server with no logs — the server may be working, may be on fire, you have no way to tell until a customer complains.
The five things to monitor
- Container health: is the n8n process running? Docker Compose's restart policy plus a healthcheck endpoint covers this. Add an uptime monitor (UptimeRobot free tier, Better Stack, or Healthchecks.io) that hits the public URL every 5 minutes.
- Disk usage: n8n's execution history can fill disks. Set a 60% alert. Configure n8n's data pruning (
EXECUTIONS_DATA_PRUNEand related env vars). - Database health: Postgres connection count, query latency, replication lag if you have a replica. Managed Postgres providers expose these by default.
- Workflow failure rate: n8n's workflow execution data includes success/failure counts. Pull this into a dashboard (Grafana, Datadog, or a simple cron-pushed metric).
- Queue depth (if using queue mode): if jobs are queueing faster than workers can drain them, you're heading for an incident. Watch the Redis queue depth.
None of these require expensive tooling. Uptime monitors, basic Grafana on a small VPS, and a Slack webhook for alerts cover 90% of what a managed service gives you, at a marginal cost of $0-$10/month.
The On-Call Question (and the 3 AM Page)
The honest question for any self-hosted deployment: who responds at 3 AM when something breaks?
The four answers
- "Nobody." The system is down until morning. Acceptable for low-stakes internal workflows. Unacceptable for customer-impacting flows.
- "Me, every time." Common for single-builder shops. Sustainable for 6-12 months. Burnout territory after that.
- "A rotation." Two or more people share a PagerDuty-style rotation. The lowest-cost version is two builders trading weeks.
- "A vendor." Pay n8n Cloud Pro and let n8n.io's on-call team respond. The premium you pay for managed hosting is largely this.
Option 4 is what you're buying with Cloud Pro. The $60/month premium over a $15 VPS is roughly the cost of someone else being on call. For workloads that warrant a real on-call posture, this premium is often worth it even at scale.
The Hybrid Approach: Cloud for Critical, Self-Host for Volume
Mature operator-builder teams sometimes split: critical, customer-facing workflows on n8n Cloud Pro for the SLA and on-call coverage, high-volume internal workflows on self-hosted for the cost. This is a defensible architecture, and the operational overhead of running both (one set of credentials per platform, two upgrade paths, two monitoring stacks) is manageable for a team with at least one engineer.
The split rule of thumb: if a workflow's failure has a customer-visible blast radius within 4 hours, put it on Cloud. If the workflow is internal and a 24-hour delay is acceptable, self-host is fine. Apply this rule per workflow, not per company.
Self-Host Day-One Checklist (Twelve Items)
If your verdict is self-host, this is the minimum-viable launch checklist. Items 1-6 are non-negotiable; 7-12 are strongly recommended.
- VPS provisioned with at least 2 vCPU, 4 GB RAM, 40 GB SSD. Latest LTS Linux.
- Docker and Docker Compose installed. n8n image pulled and running.
- Postgres database configured (managed or self-managed). n8n pointed at it.
- Reverse proxy with TLS configured (Caddy is the easiest path; nginx works).
- Nightly automated pg_dump to off-server object storage. Tested.
N8N_ENCRYPTION_KEYbacked up to a separate secrets manager.- Unattended-upgrades enabled. Reboot policy decided (manual or automatic).
- Uptime monitor pointed at the public URL, alerting to Slack or email.
- Disk-usage alert at 60% via a simple cron + curl-to-Slack script.
- Runbook document: how to restart n8n, how to restore from backup, where the encryption key lives.
- Quarterly restore test scheduled on the calendar.
- n8n's execution data pruning configured (don't let history fill the disk).
Going live without items 1-6 is the failure mode that produces the agency-data-loss incident. Don't.
When the Self-Host Decision Is Reversible (and When It Isn't)
If you self-host and later decide Cloud Pro is the better choice, the migration is straightforward but tedious: export your workflows as JSON, recreate credentials in Cloud Pro, import, verify, switch DNS or webhooks. Plan a few hours per workflow. For 10-20 workflows, that's a one-week project.
Going the other way — from Cloud Pro to self-hosted — has the same shape. Workflow JSON is portable; credentials must be recreated; webhooks must be redirected.
What's not reversible is data lost during self-hosting because you didn't have backups. That's not a migration; that's an extinction event for those workflows.
Self-hosting is reversible. Data loss from self-hosting without backups is not. The backup discipline is the difference between "we'll reconsider in six months" and "we'll be rebuilding for two weeks."
Key Takeaways
- The $60-vs-$15 comparison is misleading. The real comparison is $60 vs ($15 + your hourly rate × hours spent + risk-adjusted incident cost). At median operator-builder hourly rates, Cloud Pro is cheaper than self-host for most one-engineer teams in the 1K-10K executions/month range.
- Self-host pays off when: you value your time at $25/hour or less, you're already running a VPS, your workload exceeds the 10K cap, data sovereignty requires it, or you're at scale where Enterprise pricing dominates.
- The six hidden cost categories of self-hosting: initial setup (4-12 hours), database backups (2-4 hours upfront + 30 min/month), version upgrades (12 hours/year), security patching (30 min/month), incidents (2-8 hours/year), and capability ceiling (opportunity cost).
- The most common self-host incident is data loss from no backups. The fix is automated nightly pg_dump to off-server storage, with retention policy, integrity checks, quarterly restore tests, and the encryption key backed up separately.
- n8n Cloud Pro at $60/month is partly the cost of someone else being on call. If you're not willing to be on call yourself, that premium is what you're paying for.
- The hybrid approach (Cloud for critical, self-host for volume) is defensible. Apply the split per workflow, not per company. Rule of thumb: customer-visible blast radius within 4 hours = Cloud; internal with 24-hour delay tolerance = self-host.
- The self-host day-one checklist has 12 items. Items 1-6 are non-negotiable: VPS, Docker, Postgres, TLS proxy, automated backups, encryption key backup. Going live without these is the failure mode.
- Self-host vs Cloud is reversible. Data loss is not. The backup discipline is the difference between "we'll reconsider" and "we'll be rebuilding for two weeks."
Skill.re