Skip to content

TutorialsAI & LLM

How to install Flowise with Docker Compose and HTTPS

Run Flowise 3 with Docker Compose on Ubuntu or Debian, keep its data and encryption key on a volume, add HTTPS with Caddy and understand the archived status.

  • Intermediate
  • 30 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Prerequisites
  2. Step 1 — Create the project folder and settings
  3. Step 2 — Write the Compose file
  4. Step 3 — Start Flowise and check it
  5. Step 4 — Create the administrator account through an SSH tunnel
  6. Step 5 — Publish Flowise with Caddy and connect Ollama
  7. Step 6 — Use PostgreSQL instead of SQLite (optional)
  8. Back up and restore
  9. Updates and the end of Flowise development
  10. Troubleshooting
  11. EACCES: permission denied, mkdir '/home/node/.flowise'
  12. Saved credentials fail after the container was recreated
  13. ChatOllama returns fetch failed or ECONNREFUSED
  14. A tool or loader refuses to fetch an internal URL
  15. Caddy answers 403 Forbidden
  16. Next steps

Flowise is a low-code tool for building LLM applications and agents: you connect nodes for models, prompts, document loaders, vector stores and tools on a canvas, then call the result through an API or an embeddable chat widget. It is open source.

This guide runs the official flowiseai/flowise image, pinned to the last release, with Docker Compose. You keep the database, the credential encryption key and uploads on the host, set your own token secrets, create the administrator account through an SSH tunnel, publish Flowise over HTTPS with Caddy and connect a local Ollama server. Backups and the limits of updating an archived project close the guide.

Prerequisites

The project does not publish minimum hardware requirements. The following figures are a conservative starting point, not official or benchmarked numbers:

ResourceMinimum (official)Suggested starting point
CPUNot published2 vCPU
RAMNot published4 GB
DiskNot published20 GB

Step 1 — Create the project folder and settings

Create /opt/flowise with a data folder for everything Flowise writes:

Bash
sudo mkdir -p /opt/flowise/data
sudo chown -R $USER:$USER /opt/flowise
cd /opt/flowise

Flowise reads its configuration from environment variables. Write them to .env, including random secrets for the login tokens. The documentation warns that leaving the JWT and session secrets unset falls back to default values, which makes forged tokens easier.

Bash
cat > .env <<EOF
PORT=3000
APP_URL=https://flowise.example.com
DATABASE_PATH=/home/node/.flowise
SECRETKEY_PATH=/home/node/.flowise
LOG_PATH=/home/node/.flowise/logs
BLOB_STORAGE_PATH=/home/node/.flowise/storage
JWT_AUTH_TOKEN_SECRET=$(openssl rand -hex 32)
JWT_REFRESH_TOKEN_SECRET=$(openssl rand -hex 32)
EXPRESS_SESSION_SECRET=$(openssl rand -hex 32)
TOKEN_HASH_SECRET=$(openssl rand -hex 32)
TRUST_PROXY=true
NUMBER_OF_PROXIES=1
DISABLE_FLOWISE_TELEMETRY=true
EOF
chmod 600 .env
sudo chown -R 1000:1000 data

The four path variables matter. Flowise encrypts the API keys you save as credentials with a key file. Its documented default location for that file is inside the application directory, which lives in the container and disappears when the container is recreated; setting SECRETKEY_PATH keeps the key on your volume. DATABASE_PATH, LOG_PATH and BLOB_STORAGE_PATH do the same for the SQLite database, logs and uploaded files. TRUST_PROXY and NUMBER_OF_PROXIES=1 tell Flowise that one reverse proxy (Caddy) sits in front of it.

The image runs as the non-root node user (UID 1000) with its home in /home/node, so the data folder must belong to UID 1000.

Step 2 — Write the Compose file

Create /opt/flowise/compose.yaml. It follows the repository's docker/docker-compose.yml, but pins the final release, reads all variables from .env and publishes the port on localhost only:

YAML
services:
  flowise:
    image: flowiseai/flowise:3.1.4
    container_name: flowise
    restart: unless-stopped
    env_file: .env
    ports:
      - "127.0.0.1:3000:3000"
    extra_hosts:
      - "host.docker.internal:host-gateway"
    volumes:
      - ./data:/home/node/.flowise
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:3000/api/v1/ping"]
      interval: 10s
      timeout: 5s
      retries: 5
      start_period: 30s
    entrypoint: /bin/sh -c "sleep 3; flowise start"

Binding to 127.0.0.1 matters because Docker's published ports bypass ufw. The extra_hosts line lets the container reach Ollama on the host in Step 5.

Step 3 — Start Flowise and check it

Bash
docker compose up -d
docker compose ps
curl -f http://127.0.0.1:3000/api/v1/ping

After about half a minute, docker compose ps should show the container as healthy, and the ping endpoint answers without an error. If the container restarts, read docker compose logs --tail 50 flowise; a permission error on /home/node/.flowise means the ownership step was skipped.

Step 4 — Create the administrator account through an SSH tunnel

On the first visit, Flowise asks you to set up an account with a name, email address and password, and that account owns the instance. Do this before the site is public, so nobody else can claim it. On your own computer, open a tunnel:

Bash
ssh -L 3000:127.0.0.1:3000 youruser@203.0.113.10

Browse to http://localhost:3000, create the account with a long, unique password and sign in. Flowise stores passwords as bcrypt hashes and keeps sessions in HTTP-only cookies signed with the secrets from Step 1. Password-reset emails need SMTP settings (SMTP_HOST, SMTP_PORT, SMTP_USER, SMTP_PASSWORD, SMTP_SECURE, SENDER_EMAIL) in .env, for example smtp.example.com on port 587; without them, keep the password in a password manager.

Step 5 — Publish Flowise with Caddy and connect Ollama

Add a site block to /etc/caddy/Caddyfile. Because the project receives no more security fixes, the example only admits your own IP address; replace 198.51.100.24 with it, or remove the two matcher lines if the app must be public:

Caddyfile
flowise.example.com {
    @outside not remote_ip 198.51.100.24
    respond @outside 403
    reverse_proxy 127.0.0.1:3000
}
Bash
sudo systemctl reload caddy
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
curl -I https://flowise.example.com

From an allowed address you should see HTTP/2 200, from anywhere else 403. Caddy forwards WebSocket and streaming responses without extra settings. Nginx (guide) or Traefik work as well.

To use Ollama on the same server, it must listen beyond 127.0.0.1 and ufw must admit the Flowise network. Set OLLAMA_HOST with a systemd drop-in, as the Ollama FAQ describes, then allow the Compose subnet:

Bash
sudo mkdir -p /etc/systemd/system/ollama.service.d
sudo tee /etc/systemd/system/ollama.service.d/override.conf <<'EOF'
[Service]
Environment="OLLAMA_HOST=0.0.0.0:11434"
EOF
sudo systemctl daemon-reload
sudo systemctl restart ollama
docker network inspect flowise_default | grep Subnet
sudo ufw allow from 172.18.0.0/16 to any port 11434 proto tcp

Use the subnet the inspect command prints instead of 172.18.0.0/16. This rule only protects Ollama while ufw is active with its default deny policy, so confirm that sudo ufw status verbose shows Status: active and deny (incoming), and that nc -vz your-server-ip 11434 from another machine fails. Never open port 11434 to everyone, because Ollama has no authentication. In a flow, add the ChatOllama node, set its base URL to http://host.docker.internal:11434 and enter a model name from ollama list. Large models run much faster on a GPU server.

Step 6 — Use PostgreSQL instead of SQLite (optional)

SQLite is fine for one person. For several users or many executions you can switch to PostgreSQL, which Flowise supports next to MySQL and MariaDB. Do this on a new installation, because changing the database does not copy existing flows. Add the connection settings to .env:

Bash
cat >> .env <<EOF
DATABASE_TYPE=postgres
DATABASE_HOST=postgres
DATABASE_PORT=5432
DATABASE_NAME=flowise
DATABASE_USER=flowise
DATABASE_PASSWORD=$(openssl rand -hex 24)
EOF

Then add a database service at the end of compose.yaml, indented under services:, and add depends_on: [postgres] to the flowise service:

YAML
  postgres:
    image: postgres:16
    restart: unless-stopped
    environment:
      POSTGRES_USER: flowise
      POSTGRES_PASSWORD: ${DATABASE_PASSWORD}
      POSTGRES_DB: flowise
    volumes:
      - ./postgres:/var/lib/postgresql/data

Run docker compose up -d and check docker compose logs flowise for a successful database connection. The PostgreSQL service publishes no port, so it is reachable only from the Compose network.

Back up and restore

Everything Flowise needs is in /opt/flowise: data (database, encryption key, uploads, logs), .env with the token secrets, compose.yaml and, if you use it, the postgres folder. The documentation recommends shutting Flowise down before a backup:

Bash
sudo mkdir -p /opt/backups
cd /opt/flowise
docker compose stop
sudo tar czf /opt/backups/flowise-$(date +%F).tar.gz -C /opt flowise
docker compose start

With PostgreSQL, also take a logical dump, the method the Flowise database page describes:

Bash
docker compose exec -T postgres pg_dump -U flowise flowise | gzip | sudo tee /opt/backups/flowise-db-$(date +%F).sql.gz > /dev/null

To restore, unpack the archive to /opt on a server with Docker and run docker compose up -d in /opt/flowise. Test a restore now and then, keep copies off the server, and remember that the archive contains the key that decrypts every saved credential.

Updates and the end of Flowise development

There will be no Flowise release after 3.1.4, so docker compose pull will not bring new versions. What you can still do:

  • Keep the operating system, Docker and Caddy updated, and keep access restricted as in Step 5.
  • Watch the Flowise repository and the "Future of Flowise" discussion for news about forks; evaluate any fork carefully before you trust it with credentials.
  • Export the flows you rely on from the Flowise interface, so you can rebuild them in another tool.

When you move away, take a final backup, then stop the stack with docker compose down and remove /opt/flowise only after the new system works.

Troubleshooting

EACCES: permission denied, mkdir '/home/node/.flowise'

The container runs as UID 1000 and cannot write to the mounted folder. Run sudo chown -R 1000:1000 /opt/flowise/data and docker compose up -d.

Saved credentials fail after the container was recreated

The encryption key was stored inside the container instead of on the volume, so Flowise generated a new one. Set SECRETKEY_PATH=/home/node/.flowise as in Step 1. Credentials encrypted with a lost key must be entered again.

ChatOllama returns fetch failed or ECONNREFUSED

Ollama still listens on 127.0.0.1, or ufw blocks the Docker subnet. Check ss -tln | grep 11434, compare the subnet with sudo ufw status and make sure the node uses http://host.docker.internal:11434.

A tool or loader refuses to fetch an internal URL

This is the HTTP security check introduced in 3.1.0. Serve the resource from a public address or reconsider whether the flow should reach internal systems at all, instead of disabling the check globally.

Caddy answers 403 Forbidden

Your current IP address is not the one in the remote_ip line. Update it (home connections often change address) and reload Caddy.

Next steps

Frequently asked questions

Is Flowise still maintained?

No. The Flowise team froze the code on 29 July 2026 and archived the GitHub repository on 13 August 2026; 3.1.4 is the last release. The code and Docker images stay available, but no fixes are planned, so keep instances private and plan a move to a maintained tool.

Do FLOWISE_USERNAME and FLOWISE_PASSWORD still work?

The Flowise documentation marks the username and password variables as deprecated. Flowise 3 uses email and password accounts stored in its database, signed with JWT secrets you set in .env; you create the first account in the browser.

Where does Flowise store its data in this setup?

In /opt/flowise/data on the host, mounted at /home/node/.flowise: the SQLite database, the encryption key for saved credentials, uploaded files and logs. Back up that folder together with .env.

Can I use PostgreSQL instead of SQLite?

Yes. Flowise supports SQLite, MySQL, MariaDB and PostgreSQL. Set DATABASE_TYPE=postgres and the connection variables before the first start; switching later does not move existing flows automatically.

Sources

Generare Parolă

Please confirm