⚙️ Automated workflow & credential restoration system for self-hosted environments

242 views · ⚙️ DevOps & CI/CD

Description

n8n Restore workflows & credentials from Disk - Self-Hosted Solution

This n8n template provides a safe and intelligent restore solution for self-hosted n8n instances, allowing you to restore workflows and credentials from disk backups.

Perfect for disaster recovery or migrating between environments, this workflow automatically identifies your most recent backup and provides a manual restore capability that intelligently excludes the current workflow to prevent conflicts. Works seamlessly with date-organized backup folders.

Good to know

How it works

Restore Process (Manual)

  1. Manual trigger with configurable pinned data options (credentials: true/false, workflows: true/false)
  2. The Init node sets up all necessary paths, timestamps, and configuration variables using your environment settings
  3. The workflow scans your backup folder and automatically identifies the most recent backup
  4. If restoring credentials:
    • Direct import from the latest backup folder using n8n’s import command
    • Credentials are imported with their encrypted format intact
  5. If restoring workflows:
    • Scans the backup folder for all workflow JSON files
    • Creates a temporary folder with all workflows from the backup
    • Intelligently excludes the current restore workflow to prevent conflicts
    • Imports all other workflows using n8n’s import command
    • Cleans up temporary files automatically
  6. Optional email notifications provide detailed restore summaries with command outputs

How to use

Prerequisites

Initial Setup

  1. Configure your environment variables:

    • N8N_ADMIN_EMAIL: Your email for notifications (optional)
    • N8N_BACKUP_FOLDER: Location where your backups are stored (e.g., /files/n8n-backups)
    • N8N_PROJECTS_DIR: Projects root directory
    • GENERIC_TIMEZONE: Your local timezone
    • N8N_ENCRYPTION_KEY: Required if restoring credentials to a new environment (see dedicated section below)
  2. Update the Init node:

    • (Optional) Configure your email here: const N8N_ADMIN_EMAIL = $env.N8N_ADMIN_EMAIL || 'youremail@world.com';
    • Set PROJECT_FOLDER_NAME to "Workflow-backups" (or your preferred name)
    • Set credentials to "n8n-credentials" (or your backup credentials folder name)
    • Verify BACKUP_FOLDER path matches where your backups are stored
  3. Ensure your Docker setup has:

    • Mounted volume containing backups (e.g., /local-files:/files)
    • Access to n8n’s CLI import commands
    • Proper file system permissions (read access to backup directories)

Performing a Restore

  1. Open the workflow and locate the “Start Restore” manual trigger node
  2. Edit the pinned data to choose what to restore:
    • credentials: true - Restore credentials
    • workflows: true - Restore workflows
    • Set both to true to restore everything
  3. Click “Execute workflow” on the “Start Restore” node to execute the restore
  4. The workflow will automatically find the most recent backup (latest date)
  5. Check the console logs or optional email for detailed restore summary

Important Notes

⚠ Critical: N8N_ENCRYPTION_KEY Configuration

Why this is critical: n8n generates an encryption key automatically on first launch and saves it in the ~/.n8n/config file. However, if this file is lost (for example, due to missing Docker volume persistence), n8n will generate a NEW key, making all previously encrypted credentials inaccessible.

When you need to configure N8N_ENCRYPTION_KEY:

How credentials encryption works:

Solution: Retrieve and configure the encryption key

Step 1: Get the key from your source environment

# Check if the key is defined in environment variables
docker-compose exec n8n printenv N8N_ENCRYPTION_KEY

If this command returns nothing, the key is auto-generated and stored in n8n’s data volume:

# Enter the container
docker-compose exec n8n sh

# Check configuration file
cat /home/node/.n8n/config

# Exit container
exit

Step 2: Configure the key in your target environment

Option A: Using .env file (recommended for security)

# Add to your .env file
N8N_ENCRYPTION_KEY=your_retrieved_key_here

Then reference it in docker-compose.yml:

services:
  n8n:
    environment:
      - N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}

Option B: Directly in docker-compose.yml (less secure)

services:
  n8n:
    environment:
      - N8N_ENCRYPTION_KEY=your_retrieved_key_here

Step 3: Restart n8n

docker-compose restart n8n

Step 4: Now restore your credentials

Only after configuring the encryption key, run the restore workflow with credentials: true.

Best practice for future backups:

Requirements

Existing Backups

Environment

Credentials (Optional)

Technical Notes

Smart Workflow Exclusion

Timezone Handling

Security

Troubleshooting

Common Issues

  1. No backups found: Verify the N8N_BACKUP_FOLDER path is correct and contains date-formatted folders
  2. Permission errors: Ensure Docker user has read access to backup directories
  3. Path not found: Verify all volume mounts in docker-compose.yml match your backup location
  4. Import fails: Check that backup files are in valid n8n export format
  5. Workflow conflicts: The workflow automatically excludes itself, but ensure backup files are properly named
  6. Credentials not restored: Verify the backup contains a n8n-credentials folder with credential files
  7. Credentials decrypt error: Ensure N8N_ENCRYPTION_KEY matches the source environment

Version Compatibility


This workflow is designed for self-hosted server backup restoration. For FTP/SFTP remote backups, see the companion workflow “n8n Restore from FTP”.

Works best with backups from: “Automated n8n Workflows & Credentials Backup to Local/Server Disk & FTP”

🔗 Nodes Used

Send Email, Stop and Error

📥 Import

Download workflow.json and import into n8n: Workflow menu → Import from File

📖 Importing guide · 🔑 Credential setup