<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Khanh Nguyen</title>
    <description>The latest articles on DEV Community by Khanh Nguyen (@khanh_nguyen_04b1205f5a91).</description>
    <link>https://dev.to/khanh_nguyen_04b1205f5a91</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1559613%2F05e1dbdc-d265-4000-bdaf-e2cda4bacaea.jpg</url>
      <title>DEV Community: Khanh Nguyen</title>
      <link>https://dev.to/khanh_nguyen_04b1205f5a91</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/khanh_nguyen_04b1205f5a91"/>
    <language>en</language>
    <item>
      <title>I Moved My n8n Instance from Render to Azure</title>
      <dc:creator>Khanh Nguyen</dc:creator>
      <pubDate>Wed, 10 Jun 2026 04:01:55 +0000</pubDate>
      <link>https://dev.to/khanh_nguyen_04b1205f5a91/i-moved-my-n8n-instance-from-render-to-azure-1laa</link>
      <guid>https://dev.to/khanh_nguyen_04b1205f5a91/i-moved-my-n8n-instance-from-render-to-azure-1laa</guid>
      <description>&lt;p&gt;My n8n instance on Render worked perfectly.&lt;/p&gt;

&lt;p&gt;It was fast, simple, fully managed, and cost-effectiveness. And I barely had to think about infrastructure.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnlrmk0kxpx7bsvs0zz90.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnlrmk0kxpx7bsvs0zz90.png" alt=" " width="677" height="300"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h3&gt;
  
  
  So why move it?
&lt;/h3&gt;

&lt;p&gt;Because I wanted:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;More control over my environment&lt;/li&gt;
&lt;li&gt;Centralized cloud billing in Azure&lt;/li&gt;
&lt;li&gt;Hands-on experience with Infrastructure as Code (IaC), GitHub Actions, and cloud security&lt;/li&gt;
&lt;li&gt;A real-world project instead of another tutorial&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This post shares what I built and what I learned along the way.&lt;br&gt;&lt;br&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Repository
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;git&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;clone&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;https://github.com/TQKNG/lab-n8n-azure.git&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;em&gt;Check out README file for full guide&lt;/em&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  What I Wanted to Build
&lt;/h3&gt;

&lt;p&gt;I wanted a fully reproducible deployment where I could:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Deploy everything from GitHub Actions&lt;/li&gt;
&lt;li&gt;Authenticate to Azure without long-lived secrets (OIDC)&lt;/li&gt;
&lt;li&gt;Run n8n securely behind HTTPS&lt;/li&gt;
&lt;li&gt;Add identity + edge protection layers&lt;/li&gt;
&lt;li&gt;Tear everything down when not needed&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Think: personal SaaS-grade infrastructure, but lightweight&lt;br&gt;&lt;br&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Architecture
&lt;/h3&gt;

&lt;p&gt;This setup adds two important layers compared to a basic VM deployment:&lt;/p&gt;

&lt;p&gt;Cloudflare as the edge layer&lt;br&gt;
Azure AD (Entra ID) as the identity gate&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F6xmyyn6rtot9sldprler.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F6xmyyn6rtot9sldprler.png" alt=" " width="800" height="397"&gt;&lt;/a&gt;&lt;br&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  What Gets Deployed
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Compute&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Ubuntu 22.04 LTS VM (Azure)&lt;/li&gt;
&lt;li&gt;Trusted Launch enabled&lt;/li&gt;
&lt;li&gt;SSH key-based access&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Networking&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Virtual Network (isolated subnet)&lt;/li&gt;
&lt;li&gt;Network Security Group (restricted ports)&lt;/li&gt;
&lt;li&gt;Public IP behind controlled ingress&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Application&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;n8n (Docker container)&lt;/li&gt;
&lt;li&gt;Caddy reverse proxy (HTTPS + routing)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Edge &amp;amp; Identity&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cloudflare (DNS + protection layer)&lt;/li&gt;
&lt;li&gt;Azure AD (Entra ID authentication gate) 
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  GitHub Actions Pipeline
&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;To trace logs, I use below manually triggered workflows. These allows full lifecycle control from GitHub. Feel free to customize it based on your own workflow setup.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Setup → initialize repo variables&lt;/li&gt;
&lt;li&gt;OIDC bootstrap → configure Azure trust&lt;/li&gt;
&lt;li&gt;Verify → test authentication&lt;/li&gt;
&lt;li&gt;Deploy → run Bicep infrastructure&lt;/li&gt;
&lt;li&gt;Start → validate VM + n8n endpoint&lt;/li&gt;
&lt;li&gt;Teardown → destroy resources safely
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Key Security Layers
&lt;/h3&gt;

&lt;p&gt;This architecture is intentionally layered:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cloudflare → edge protection + TLS&lt;/li&gt;
&lt;li&gt;Azure AD → identity verification before access&lt;/li&gt;
&lt;li&gt;NSG → network-level filtering&lt;/li&gt;
&lt;li&gt;Caddy → HTTPS termination + reverse proxy&lt;/li&gt;
&lt;li&gt;Docker → container isolation&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This creates a simple zero-trust-inspired flow.&lt;/p&gt;

&lt;h3&gt;
  
  
  What I Learned
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;Azure OIDC is a game changer. No more storing long-lived secrets in GitHub.&lt;/li&gt;
&lt;li&gt;Bicep is actually pleasant. Much easier than ARM templates and still powerful.&lt;/li&gt;
&lt;li&gt;Cloudflare simplifies edge security. It reduces direct exposure of Azure resources.&lt;/li&gt;
&lt;li&gt;Infrastructure as Code changes everything. Even a small project becomes reproducible and disposable.

&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Next Step
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Add Azure Key Vault for secrets&lt;/li&gt;
&lt;li&gt;Add automated backups for n8n workflows&lt;/li&gt;
&lt;li&gt;Move monitoring to Azure Monitor dashboards&lt;/li&gt;
&lt;li&gt;Restrict SSH via IP allowlist or JIT access&lt;/li&gt;
&lt;li&gt;Evaluate Azure Container Apps instead of VM&lt;/li&gt;
&lt;li&gt;Add cost automation (auto shutdown dev environment)&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  Resources
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Project&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GitHub Repository: &lt;a href="https://github.com/TQKNG/lab-n8n-azure" rel="noopener noreferrer"&gt;https://github.com/TQKNG/lab-n8n-azure&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;n8n Documentation: &lt;a href="https://docs.n8n.io" rel="noopener noreferrer"&gt;https://docs.n8n.io&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Cloudfare Developer Docs: &lt;a href="https://developers.cloudflare.com/" rel="noopener noreferrer"&gt;https://developers.cloudflare.com/&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Azure&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Bicep Docs: &lt;a href="https://learn.microsoft.com/azure/azure-resource-manager/bicep" rel="noopener noreferrer"&gt;https://learn.microsoft.com/azure/azure-resource-manager/bicep&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Azure OIDC with GitHub Actions: &lt;a href="https://learn.microsoft.com/azure/developer/github/connect-from-azure-openid-connect" rel="noopener noreferrer"&gt;https://learn.microsoft.com/azure/developer/github/connect-from-azure-openid-connect&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Azure Well-Architected Framework: &lt;a href="https://learn.microsoft.com/azure/architecture/framework" rel="noopener noreferrer"&gt;https://learn.microsoft.com/azure/architecture/framework&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;CI/CD &amp;amp; Infra&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GitHub Actions Docs: &lt;a href="https://docs.github.com/actions" rel="noopener noreferrer"&gt;https://docs.github.com/actions&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Docker Docs: &lt;a href="https://docs.docker.com" rel="noopener noreferrer"&gt;https://docs.docker.com&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Caddy Server Docs: &lt;a href="https://caddyserver.com/docs" rel="noopener noreferrer"&gt;https://caddyserver.com/docs&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>azure</category>
      <category>devops</category>
      <category>bicep</category>
      <category>cicd</category>
    </item>
  </channel>
</rss>
