External data storage
File-based configuration
You can add _FILE to individual variables to provide their configuration in a separate file. Refer to Keeping sensitive data in separate files for more details.
Refer to External storage for more information on using external storage for binary data and execution data.
N8N_EXTERNAL_STORAGE_S3_HOST
String
-
Host of the n8n bucket in S3-compatible external storage. For example, s3.us-east-1.amazonaws.com
N8N_EXTERNAL_STORAGE_S3_BUCKET_NAME
String
-
Name of the n8n bucket in S3-compatible external storage.
N8N_EXTERNAL_STORAGE_S3_BUCKET_REGION
String
-
Region of the n8n bucket in S3-compatible external storage. For example, us-east-1
N8N_EXTERNAL_STORAGE_S3_ACCESS_KEY
String
-
Access key in S3-compatible external storage
N8N_EXTERNAL_STORAGE_S3_ACCESS_SECRET
String
-
Access secret in S3-compatible external storage.
N8N_EXTERNAL_STORAGE_S3_AUTH_AUTO_DETECT
Boolean
-
Use automatic credential detection to authenticate S3 calls for external storage. This will ignore the access key and access secret and use the default credential provider chain.
Azure Blob Storage
Enterprise-tier feature
You need an Enterprise license key to store execution data or binary data in Azure Blob Storage.
To store execution data in Azure Blob Storage, set N8N_EXECUTION_DATA_STORAGE_MODE to azure. To store binary data in Azure Blob Storage, set N8N_DEFAULT_BINARY_DATA_MODE to azure (refer to External storage). A single container can hold both. Configure the variables below; N8N_EXTERNAL_STORAGE_AZURE_CONTAINER_NAME is always required.
For authentication, choose one of these three options. n8n checks them in this order:
Connection string: set
N8N_EXTERNAL_STORAGE_AZURE_CONNECTION_STRING. This takes precedence over the other options, so n8n ignores the account name, key, and auto-detect when you set it. It's the simplest option and works well for local testing with Azurite.Auto-detect: set
N8N_EXTERNAL_STORAGE_AZURE_ACCOUNT_NAMEand setN8N_EXTERNAL_STORAGE_AZURE_AUTH_AUTO_DETECTtotrue. n8n authenticates through Azure'sDefaultAzureCredentialchain (managed identity, environment, or Azure CLI), so no key lives in your n8n configuration. Best for production on Azure.Account name and key: set
N8N_EXTERNAL_STORAGE_AZURE_ACCOUNT_NAMEandN8N_EXTERNAL_STORAGE_AZURE_ACCOUNT_KEY.
Set N8N_EXTERNAL_STORAGE_AZURE_ENDPOINT only if you use a custom endpoint, such as Azurite or a sovereign cloud.
N8N_EXTERNAL_STORAGE_AZURE_CONNECTION_STRING
String
-
Connection string for Azure Blob Storage. Takes precedence over the account name and key when set.
N8N_EXTERNAL_STORAGE_AZURE_ACCOUNT_NAME
String
-
Storage account name. Use with an account key or managed identity.
N8N_EXTERNAL_STORAGE_AZURE_ACCOUNT_KEY
String
-
Storage account key. Use with the account name.
N8N_EXTERNAL_STORAGE_AZURE_CONTAINER_NAME
String
-
Name of the blob container to store execution data and/or binary data in. Required for Azure Blob Storage.
N8N_EXTERNAL_STORAGE_AZURE_ENDPOINT
String
-
Custom blob endpoint, for example for Azurite or sovereign clouds.
N8N_EXTERNAL_STORAGE_AZURE_AUTH_AUTO_DETECT
Boolean
false
Authenticate via DefaultAzureCredential (managed identity, environment, or Azure CLI) instead of an account key. Ignores the account key when enabled.
Last updated
Was this helpful?