Deploy Windmill v1 Scripts, Flows and Internal Apps

Turn Python and TS scripts into workflows, UIs and cron jobs with workers.

Deploy Windmill v1 Scripts, Flows and Internal Apps

Just deployed

Just deployed

Windmill Native Worker

windmill-labs/windmill:1.830.0

Just deployed

Just deployed

Just deployed

Deploy and Host Windmill with Railway

Windmill is an open-source developer platform that turns Python, TypeScript, Go, Bash and SQL scripts into flows, auto-generated UIs, internal apps, webhooks and cron jobs. This community template runs the full self-hosted stack on Railway: API server, scalable worker pool, native worker, editor services and Postgres.

About Hosting Windmill

A production Windmill install is more than one container. The server serves the UI and REST API and runs database migrations; workers pull jobs from a queue stored in Postgres and execute your code; a native worker handles lightweight queries and HTTP calls in-process; the windmill-extra service provides editor autocompletion and a step-through debugger over websockets. Because Railway gives each service a single public port, a small Caddy proxy sends editor websocket paths to windmill-extra and everything else to the server. Everything except the proxy stays on Railway's private network, all images are pinned to the same Windmill release, and the default admin password is replaced automatically on first boot.

Common Use Cases

  • Turn one-off Python or TypeScript scripts into shareable tools with generated input forms
  • Run scheduled jobs and data syncs (ETL, reports, clean-ups) with retries and run history
  • Chain scripts into multi-step flows with branches, approvals and error handlers
  • Build internal apps and dashboards on top of existing databases and APIs
  • Expose scripts as authenticated webhooks for other systems to call

Dependencies for Windmill Hosting

  • Windmill server and workers (ghcr.io/windmill-labs/windmill:1.830.0)
  • Windmill Extra for the editor's language servers and debugger (ghcr.io/windmill-labs/windmill-extra:1.830.0)
  • PostgreSQL 18 (Railway's postgres-ssl:18), which also holds Windmill's job queue
  • Caddy 2.11 as the public path-routing proxy
  • A one-shot bootstrap job (curl) that replaces the default admin password

Deployment Dependencies

Implementation Details

ServiceRolePublicScaling
ProxyCaddy; routes /ws/*, /ws_debug/*, /ws_mp/* to Windmill Extra, everything else to WindmillYes (only public service)1
WindmillAPI server and UI (MODE=server), runs migrations on startNo1
Windmill WorkerDefault worker group: Python, TypeScript, Bash, Go and other jobsNo3 replicas (adjustable)
Windmill Native Workernative worker group, 8 in-process workers for queries and HTTP callsNo1
Windmill ExtraLanguage servers and debugger behind one gatewayNo1
Admin BootstrapOne-shot job that replaces the default admin password, then stopsNo–
PostgresDatabase and job queue, persistent volumeNo1

First login

  1. Wait until all services are deployed and the Admin Bootstrap logs show Password of admin@windmill.dev rotated. The job stopping afterwards is expected.
  2. Copy WINDMILL_ADMIN_PASSWORD from the Admin Bootstrap service's Variables tab.
  3. Open the Proxy service's public URL and sign in as admin@windmill.dev with that password.
  4. In Instance settings, confirm the Base URL, then add your own user as superadmin, sign in with it, and change or disable admin@windmill.dev.
  5. If the bootstrap job failed for any reason, sign in immediately with Windmill's default password changeme and change it, because the URL is public.

Scaling workers

Each default worker replica runs one job at a time. Raise or lower the Windmill Worker replica count in its service settings; new replicas register themselves on Windmill's Workers page. Workers keep their dependency cache on local disk, so the first run of a script with new packages after a redeploy or on a new replica downloads them again. Do not attach a volume at /tmp/windmill/cache: replicas cannot use volumes, and an empty volume would hide runtimes the image pre-installs there. Postgres allows 100 connections by default; past about 10 worker replicas, lower the server's DATABASE_CONNECTIONS or raise Postgres max_connections.

Pinning and upgrading

Windmill, Windmill Worker, Windmill Native Worker and Windmill Extra all use release 1.830.0. To upgrade, back up the Postgres volume, then set the same new tag (see https://github.com/windmill-labs/windmill/releases) on all four services and deploy; the server applies database migrations on start. Database migrations are not designed to be rolled back, so test upgrades in a separate Railway environment first.

Limits on Railway

Railway does not offer privileged containers, so nsjail sandboxing is unavailable and per-job PID isolation may fall back to none (check worker logs). Treat everyone who can write scripts as trusted. Enterprise-only parts of the upstream stack (search indexer, multiplayer) and the Docker-in-Docker and SMTP email-trigger options are not included.

Why Deploy Windmill on Railway?

Railway runs each Windmill component as its own service with private networking, managed Postgres with a persistent volume, and per-service logs and metrics, so the worker pool can grow by changing a replica count instead of editing compose files on a server. You pay for the resources the stack actually uses, and every image tag is pinned so upgrades happen when you choose.


Template Content

More templates in this category

View Template
N8N Main + Worker
Deploy and Host N8N with Inactive worker.

jakemerson
121
View Template
Evolution API with n8n
Automate WhatsApp workflows with Evolution API, n8n, and Postgres.

codestorm
101
View Template
Postgres Backup
Cron-based PostgreSQL backup to bucket storage

Railway Templates
870