# How to install Flowise with Docker Compose and HTTPS

> Run Flowise 3 with Docker Compose on Ubuntu or Debian, keep its data and encryption key on a volume, add HTTPS with Caddy and understand the archived status.

Difficulty: Intermediate\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

Flowise is a low-code tool for building LLM applications and agents: you connect nodes for models, prompts, document loaders, vector stores and tools on a canvas, then call the result through an API or an embeddable chat widget. It is open source.

> **Warning**
>
> Flowise is no longer developed. The maintainers announced a code freeze on 29 July 2026 and archived the GitHub repository on 13 August 2026; version 3.1.4 is the final release, and official support on GitHub and Discord ended on 31 August 2026. The code and Docker images remain available, but security problems found from now on will not be fixed upstream. Use this guide to run existing flows or evaluate them, keep the instance private, and consider [Langflow](/guides/install-langflow) or [Dify](/guides/install-dify) for new projects.

This guide runs the official `flowiseai/flowise` image, pinned to the last release, with Docker Compose. You keep the database, the credential encryption key and uploads on the host, set your own token secrets, create the administrator account through an SSH tunnel, publish Flowise over HTTPS with Caddy and connect a local Ollama server. Backups and the limits of updating an archived project close the guide.

## Prerequisites

- A server running **Ubuntu 24.04 LTS**, **Ubuntu 26.04 LTS**, **Debian 12** or **Debian 13** with Docker Engine and the Compose plugin, see [Install Docker on Ubuntu](/guides/install-docker-ubuntu) or [Install Docker on Debian](/guides/install-docker-debian).
- A non-root user with `sudo` rights and SSH key login, see [Secure a new Linux server](/guides/secure-a-new-linux-server) and [Set up SSH keys](/guides/ssh-keys).
- A domain name such as `flowise.example.com` with an A (and optionally AAAA) record pointing at the server, and Caddy from [Caddy reverse proxy](/guides/caddy-reverse-proxy).
- An API key for a model provider, or Ollama from [Install Ollama](/guides/install-ollama).

The project does not publish minimum hardware requirements. The following figures are a conservative starting point, not official or benchmarked numbers:

| Resource | Minimum (official) | Suggested starting point |
|---|---|---|
| CPU | Not published | 2 vCPU |
| RAM | Not published | 4 GB |
| Disk | Not published | 20 GB |

## Step 1 — Create the project folder and settings

Create `/opt/flowise` with a `data` folder for everything Flowise writes:

```bash
sudo mkdir -p /opt/flowise/data
sudo chown -R $USER:$USER /opt/flowise
cd /opt/flowise
```

Flowise reads its configuration from environment variables. Write them to `.env`, including random secrets for the login tokens. The documentation warns that leaving the JWT and session secrets unset falls back to default values, which makes forged tokens easier.

```bash
cat > .env <<EOF
PORT=3000
APP_URL=https://flowise.example.com
DATABASE_PATH=/home/node/.flowise
SECRETKEY_PATH=/home/node/.flowise
LOG_PATH=/home/node/.flowise/logs
BLOB_STORAGE_PATH=/home/node/.flowise/storage
JWT_AUTH_TOKEN_SECRET=$(openssl rand -hex 32)
JWT_REFRESH_TOKEN_SECRET=$(openssl rand -hex 32)
EXPRESS_SESSION_SECRET=$(openssl rand -hex 32)
TOKEN_HASH_SECRET=$(openssl rand -hex 32)
TRUST_PROXY=true
NUMBER_OF_PROXIES=1
DISABLE_FLOWISE_TELEMETRY=true
EOF
chmod 600 .env
sudo chown -R 1000:1000 data
```

The four path variables matter. Flowise encrypts the API keys you save as credentials with a key file. Its documented default location for that file is inside the application directory, which lives in the container and disappears when the container is recreated; setting `SECRETKEY_PATH` keeps the key on your volume. `DATABASE_PATH`, `LOG_PATH` and `BLOB_STORAGE_PATH` do the same for the SQLite database, logs and uploaded files. `TRUST_PROXY` and `NUMBER_OF_PROXIES=1` tell Flowise that one reverse proxy (Caddy) sits in front of it.

The image runs as the non-root `node` user (UID 1000) with its home in `/home/node`, so the `data` folder must belong to UID 1000.

## Step 2 — Write the Compose file

Create `/opt/flowise/compose.yaml`. It follows the repository's `docker/docker-compose.yml`, but pins the final release, reads all variables from `.env` and publishes the port on localhost only:

```yaml
services:
  flowise:
    image: flowiseai/flowise:3.1.4
    container_name: flowise
    restart: unless-stopped
    env_file: .env
    ports:
      - "127.0.0.1:3000:3000"
    extra_hosts:
      - "host.docker.internal:host-gateway"
    volumes:
      - ./data:/home/node/.flowise
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:3000/api/v1/ping"]
      interval: 10s
      timeout: 5s
      retries: 5
      start_period: 30s
    entrypoint: /bin/sh -c "sleep 3; flowise start"
```

Binding to `127.0.0.1` matters because Docker's published ports bypass ufw. The `extra_hosts` line lets the container reach Ollama on the host in Step 5.

## Step 3 — Start Flowise and check it

```bash
docker compose up -d
docker compose ps
curl -f http://127.0.0.1:3000/api/v1/ping
```

After about half a minute, `docker compose ps` should show the container as `healthy`, and the `ping` endpoint answers without an error. If the container restarts, read `docker compose logs --tail 50 flowise`; a permission error on `/home/node/.flowise` means the ownership step was skipped.

## Step 4 — Create the administrator account through an SSH tunnel

On the first visit, Flowise asks you to set up an account with a name, email address and password, and that account owns the instance. Do this before the site is public, so nobody else can claim it. On your own computer, open a tunnel:

```bash
ssh -L 3000:127.0.0.1:3000 youruser@203.0.113.10
```

Browse to `http://localhost:3000`, create the account with a long, unique password and sign in. Flowise stores passwords as bcrypt hashes and keeps sessions in HTTP-only cookies signed with the secrets from Step 1. Password-reset emails need SMTP settings (`SMTP_HOST`, `SMTP_PORT`, `SMTP_USER`, `SMTP_PASSWORD`, `SMTP_SECURE`, `SENDER_EMAIL`) in `.env`, for example `smtp.example.com` on port `587`; without them, keep the password in a password manager.

> **Note**
>
> Outbound port 25 is closed by default on HyperDC VPS. For services bought for a term of 3 months or longer, it is opened on request: [open a support ticket](/guides/support-tickets). Until then, send mail through an SMTP relay on port 587.

## Step 5 — Publish Flowise with Caddy and connect Ollama

Add a site block to `/etc/caddy/Caddyfile`. Because the project receives no more security fixes, the example only admits your own IP address; replace `198.51.100.24` with it, or remove the two matcher lines if the app must be public:

```caddyfile
flowise.example.com {
    @outside not remote_ip 198.51.100.24
    respond @outside 403
    reverse_proxy 127.0.0.1:3000
}
```

```bash
sudo systemctl reload caddy
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
curl -I https://flowise.example.com
```

From an allowed address you should see `HTTP/2 200`, from anywhere else `403`. Caddy forwards WebSocket and streaming responses without extra settings. Nginx ([guide](/guides/nginx-reverse-proxy-certbot)) or [Traefik](/guides/traefik-reverse-proxy) work as well.

To use Ollama on the same server, it must listen beyond `127.0.0.1` and ufw must admit the Flowise network. Set `OLLAMA_HOST` with a systemd drop-in, as the Ollama FAQ describes, then allow the Compose subnet:

```bash
sudo mkdir -p /etc/systemd/system/ollama.service.d
sudo tee /etc/systemd/system/ollama.service.d/override.conf <<'EOF'
[Service]
Environment="OLLAMA_HOST=0.0.0.0:11434"
EOF
sudo systemctl daemon-reload
sudo systemctl restart ollama
docker network inspect flowise_default | grep Subnet
sudo ufw allow from 172.18.0.0/16 to any port 11434 proto tcp
```

Use the subnet the `inspect` command prints instead of `172.18.0.0/16`. This rule only protects Ollama while ufw is active with its default deny policy, so confirm that `sudo ufw status verbose` shows `Status: active` and `deny (incoming)`, and that `nc -vz your-server-ip 11434` from another machine fails. Never open port 11434 to everyone, because Ollama has no authentication. In a flow, add the **ChatOllama** node, set its base URL to `http://host.docker.internal:11434` and enter a model name from `ollama list`. Large models run much faster on a [GPU server](/gpu-servers).

> **Note**
>
> Since Flowise 3.1.0 an HTTP security check is on by default and blocks requests to internal or unsafe addresses such as `localhost` and `127.0.0.1`. Leave it on (`HTTP_SECURITY_CHECK=true`). Turning it off lets any flow author make the server call internal services.

## Step 6 — Use PostgreSQL instead of SQLite (optional)

SQLite is fine for one person. For several users or many executions you can switch to PostgreSQL, which Flowise supports next to MySQL and MariaDB. Do this on a new installation, because changing the database does not copy existing flows. Add the connection settings to `.env`:

```bash
cat >> .env <<EOF
DATABASE_TYPE=postgres
DATABASE_HOST=postgres
DATABASE_PORT=5432
DATABASE_NAME=flowise
DATABASE_USER=flowise
DATABASE_PASSWORD=$(openssl rand -hex 24)
EOF
```

Then add a database service at the end of `compose.yaml`, indented under `services:`, and add `depends_on: [postgres]` to the `flowise` service:

```yaml
  postgres:
    image: postgres:16
    restart: unless-stopped
    environment:
      POSTGRES_USER: flowise
      POSTGRES_PASSWORD: ${DATABASE_PASSWORD}
      POSTGRES_DB: flowise
    volumes:
      - ./postgres:/var/lib/postgresql/data
```

Run `docker compose up -d` and check `docker compose logs flowise` for a successful database connection. The PostgreSQL service publishes no port, so it is reachable only from the Compose network.

## Back up and restore

Everything Flowise needs is in `/opt/flowise`: `data` (database, encryption key, uploads, logs), `.env` with the token secrets, `compose.yaml` and, if you use it, the `postgres` folder. The documentation recommends shutting Flowise down before a backup:

```bash
sudo mkdir -p /opt/backups
cd /opt/flowise
docker compose stop
sudo tar czf /opt/backups/flowise-$(date +%F).tar.gz -C /opt flowise
docker compose start
```

With PostgreSQL, also take a logical dump, the method the Flowise database page describes:

```bash
docker compose exec -T postgres pg_dump -U flowise flowise | gzip | sudo tee /opt/backups/flowise-db-$(date +%F).sql.gz > /dev/null
```

To restore, unpack the archive to `/opt` on a server with Docker and run `docker compose up -d` in `/opt/flowise`. Test a restore now and then, keep copies off the server, and remember that the archive contains the key that decrypts every saved credential.

## Updates and the end of Flowise development

There will be no Flowise release after 3.1.4, so `docker compose pull` will not bring new versions. What you can still do:

- Keep the operating system, Docker and Caddy updated, and keep access restricted as in Step 5.
- Watch the [Flowise repository](https://github.com/FlowiseAI/Flowise) and the "Future of Flowise" discussion for news about forks; evaluate any fork carefully before you trust it with credentials.
- Export the flows you rely on from the Flowise interface, so you can rebuild them in another tool.

When you move away, take a final backup, then stop the stack with `docker compose down` and remove `/opt/flowise` only after the new system works.

## Troubleshooting

### EACCES: permission denied, mkdir '/home/node/.flowise'

The container runs as UID 1000 and cannot write to the mounted folder. Run `sudo chown -R 1000:1000 /opt/flowise/data` and `docker compose up -d`.

### Saved credentials fail after the container was recreated

The encryption key was stored inside the container instead of on the volume, so Flowise generated a new one. Set `SECRETKEY_PATH=/home/node/.flowise` as in Step 1. Credentials encrypted with a lost key must be entered again.

### ChatOllama returns fetch failed or ECONNREFUSED

Ollama still listens on `127.0.0.1`, or ufw blocks the Docker subnet. Check `ss -tln | grep 11434`, compare the subnet with `sudo ufw status` and make sure the node uses `http://host.docker.internal:11434`.

### A tool or loader refuses to fetch an internal URL

This is the HTTP security check introduced in 3.1.0. Serve the resource from a public address or reconsider whether the flow should reach internal systems at all, instead of disabling the check globally.

### Caddy answers 403 Forbidden

Your current IP address is not the one in the `remote_ip` line. Update it (home connections often change address) and reload Caddy.

## Next steps

- Build new projects on a maintained tool: [Install Langflow](/guides/install-langflow) or [Install Dify](/guides/install-dify).
- Run local models with [Install Ollama](/guides/install-ollama).
- Read the [Flowise documentation](https://docs.flowiseai.com/) for node reference and API usage while it remains online.
- See server options on the [Flowise hosting](/flowise-hosting) page.

## Frequently asked questions

### Is Flowise still maintained?

No. The Flowise team froze the code on 29 July 2026 and archived the GitHub repository on 13 August 2026; 3.1.4 is the last release. The code and Docker images stay available, but no fixes are planned, so keep instances private and plan a move to a maintained tool.

### Do FLOWISE\_USERNAME and FLOWISE\_PASSWORD still work?

The Flowise documentation marks the username and password variables as deprecated. Flowise 3 uses email and password accounts stored in its database, signed with JWT secrets you set in .env; you create the first account in the browser.

### Where does Flowise store its data in this setup?

In /opt/flowise/data on the host, mounted at /home/node/.flowise: the SQLite database, the encryption key for saved credentials, uploaded files and logs. Back up that folder together with .env.

### Can I use PostgreSQL instead of SQLite?

Yes. Flowise supports SQLite, MySQL, MariaDB and PostgreSQL. Set DATABASE_TYPE=postgres and the connection variables before the first start; switching later does not move existing flows automatically.

---

Source: <https://hyperdc.com/guides/tutorials/install-flowise>\
Updated: 2026-10-09
