Why self-host Flowise on a VPS
Flowise handles sensitive data: OpenAI/Anthropic API keys, vectorised internal documents, conversation history, the business logic of your agents. On the shared cloud version, these elements pass through infrastructure you do not control. On a dedicated VPS, the Flowise canvas, the database and the embeddings all stay with you. You keep control of versions (flows evolve fast between releases), of the connectors you enable, and of model billing since you plug in your own keys. A VPS also lets you expose flows as a REST API to integrate them into your own applications, with no quota imposed by a vendor.
Another practical reason: Flowise Cloud plans limit the number of active flows, monthly executions and access to advanced nodes. On your VPS, none of these limits apply — you define the allocated resources yourself.
The concrete benefits of a self-hosted Flowise
- Full confidentiality of prompts, API keys and indexed documents, which never leave your server.
- Inference endpoints exposed as a REST API with no third-party rate limit.
- Free choice of model (OpenAI, Anthropic, Mistral, or a local LLM via Ollama on the same network).
- Controlled persistence of flows and vector stores in Docker volumes that you back up.
- Update when you decide, without suffering a forced canvas migration.
- Predictable cost: a single monthly VPS price, no pricing per flow or per execution.
- Advanced nodes without restriction: full access to all LangChain integrations, agent tools and vector store connectors.
Hardware and software requirements
Flowise itself is lightweight, but real-world usage depends on embeddings and vector stores. Budget at least 2 vCPUs and 2 GB of RAM for testing, and 4 vCPUs / 4 to 8 GB of RAM if you index large documents or run several concurrent flows. Plan for 20 GB of disk for the containers, vector stores and any local models.
On the software side: Docker and Docker Compose installed, a domain or subdomain (e.g. flowise.your-domain.com) pointing to the VPS IP, and port 443 open. If you plan to run a local LLM via Ollama, increase RAM to at least 8 GB (16 GB for 7B+ models at 4-bit quantisation). Prepare the API keys of the LLM providers you intend to use ahead of time.
Deploy Flowise with Docker and HTTPS
Prepare the VPS and Docker
Connect via SSH, update the system then install Docker with
curl -fsSL https://get.docker.com | sh. Check withdocker compose version. Create a dedicated folder:mkdir -p /opt/flowise && cd /opt/flowiseWrite the docker-compose.yml
Define the service with the official
flowiseai/flowiseimage, internal port3000, a named volume for persistence, and the essential environment variables:FLOWISE_USERNAME=admin FLOWISE_PASSWORD=strong_password FLOWISE_SECRETKEY_OVERWRITE=a_random_32_char_string DATABASE_PATH=/root/.flowise SECRET_ENCRYPTION_KEY=another_random_32_char_stringThe
flowise_datavolume must point to/root/.flowiseinside the container so that the SQLite database and vector stores survive restarts.Start the container
Run
docker compose up -dthendocker compose logs -fto confirm that Flowise is listening. At this stage it responds locally on127.0.0.1:3000, not exposed publicly, which is deliberate.Configure the reverse proxy
Install Caddy or Nginx Proxy Manager. With Caddy, a single line in the Caddyfile is enough:
flowise.your-domain.com { reverse_proxy localhost:3000 }Caddy obtains and renews the Let's Encrypt certificate automatically. If you prefer nginx, make sure to enable WebSockets (
proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection upgrade;) — Flowise needs them for real-time canvas updates.Secure access and keys
Harden authentication, restrict port 3000 to the loopback in the firewall (
ufw deny 3000), and add your LLM API keys directly in the Flowise interface (Credentials section) rather than in clear text in the compose file. TheFLOWISE_SECRETKEY_OVERWRITEvariable encrypts these credentials in the database; without it, they are stored in plain text.Test a flow and the API
Create a simple chatflow, publish it, then call its endpoint:
curl -X POST https://flowise.your-domain.com/api/v1/prediction/<id> \ -H 'Content-Type: application/json' \ -d '{"question":"test"}'To protect a chatflow endpoint with an API key, enable API Key Auth in the flow settings — each call must then carry
Authorization: Bearer <your_key>.Logging in for the first time
When you first open the URL, Flowise displays a setup screen that has you create the administrator account (email + password) before it gives access to the dashboard. Open it immediately after the installation.
Connect Flowise to Ollama for a fully local AI stack
For high-performance RAG flows with no external API cost, connect Flowise to an Ollama container running on the same VPS through the internal Docker network (http://ollama:11434). You thus combine embeddings and generation locally: no data leaves the server, and latency drops since everything travels over the host's private network.
In your docker-compose.yml, add the Ollama service on the same Docker network as Flowise:
services:
ollama:
image: ollama/ollama
volumes:
- ollama_data:/root/.ollama
networks:
- flowise_net
flowise:
image: flowiseai/flowise
networks:
- flowise_net
...In Flowise, when you add an Ollama node (Chat Model or Embeddings), enter http://ollama:11434 as the base URL. Pull a model from inside the container: docker exec -it <ollama_id> ollama pull llama3.2. For embeddings, nomic-embed-text is a good starting point on 4 GB of RAM.
Useful environment variables
Flowise exposes around twenty configuration variables. The most useful ones in production:
FLOWISE_USERNAME and FLOWISE_PASSWORD — authentication for the admin interface. Mandatory as soon as the public port is open.
FLOWISE_SECRETKEY_OVERWRITE — encryption key for credentials stored in the database. If you change this value after first startup, existing credentials become unreadable.
DATABASE_TYPE — defaults to sqlite. For heavier load or a redundant deployment, switch to postgres and fill in DATABASE_HOST, DATABASE_PORT, DATABASE_USER, DATABASE_PASSWORD, DATABASE_NAME.
CORS_ORIGINS — list of origins allowed to call the prediction API from a browser. Example: https://your-app.com. Without this variable, CORS calls from another origin will be blocked.
BLOB_STORAGE_PATH — storage path for uploaded files (RAG documents). Defaults to ~/.flowise/storage; mount a dedicated volume if you index large corpora.
LOG_LEVEL — values: error, warn, info, verbose, debug. In production, warn is enough to keep logs manageable.
Updating Flowise without losing flows
Flowise releases regular updates that add nodes and fix flow behaviour. The update is non-destructive if your data is in a named volume.
docker compose pull
docker compose up -dFlowise automatically migrates the SQLite database on startup. Before each update, export your important flows via the canvas Export button (JSON file) — it is the simplest safety net.
If you use PostgreSQL, check the release notes before pulling the image: some versions introduce irreversible schema migrations. Keep a database backup (pg_dump) before updating.
Troubleshooting common errors
The canvas does not load or nodes disappear. Check that your reverse proxy properly passes WebSockets. With nginx, the Upgrade and Connection headers must be present. With Caddy, they are set automatically.
Error: FLOWISE_SECRETKEY_OVERWRITE is required. This variable was not required in earlier versions but has become so. Add it to your compose and restart — credentials already entered remain valid as long as the value matches the one used when they were stored.
The vector store loses its documents after restart. Check that the Docker volume path matches both BLOB_STORAGE_PATH and DATABASE_PATH. A misconfigured bind-mount stores data in an ephemeral container folder.
Calls to Ollama fail with ECONNREFUSED. The Ollama service must be on the same Docker network as Flowise. If Ollama runs outside Compose (systemd service, for instance), use the Docker gateway IP (172.17.0.1:11434) rather than localhost.
OpenAI/Anthropic credentials are rejected after migration. If FLOWISE_SECRETKEY_OVERWRITE changed between two deployments, secrets encrypted with the old key can no longer be decrypted. Delete and re-enter the credentials in the interface.
For a secure team deployment, enable authentication on each chatflow (the flow's API Key section) and create one key per external integration. That way, each application consuming a Flowise endpoint has its own revocable key without affecting the others.
The official documentation
For advanced configuration and tool-specific options, refer to the official Flowise documentation. This guide covers going live on a VPS; the vendor docs remain the reference for fine-tuning, major updates and specific use cases.