Requirements
FlowDesk is installed by running three containers (API, Dashboard, Tracker) on a Kubernetes cluster. Which cloud provider or deployment tooling you use is your organisation’s choice; as long as the requirements described here are met, the application behaves as expected.
Architecture
Section titled “Architecture”browser ──HTTPS──▶ [your ingress] ──┬──▶ flowdesk-web :3000 ──┐ ├──▶ flowdesk-tracker :3001 ──┤ (HTTP, server side) └──▶ flowdesk-api :8080 ◀─┘ │ PostgreSQL or SQL Server · Redis · RabbitMQ or Kafka │ outbound ──▶ licence server · Keycloak (if used) · SMTP/IMAP (if used)All three containers listen on plain HTTP and expect no TLS: the ingress in front of them terminates the certificate. Logs are written to stdout.
Kubernetes cluster
Section titled “Kubernetes cluster”- The
shftco/flowdesk-kuberneteschart usesapps/v1Deployment andnetworking.k8s.io/v1Ingress resources, which in practice means it works with Kubernetes 1.19 and later. SHFT documents no separate lower bound; any compatible cluster will do, k3s included. - ingress-nginx: the Ingress resource the chart renders expects
ingressClassName: nginx. - cert-manager: manages TLS certificates through a
ClusterIssuer(Let’s Encrypt, for example). If cert-manager is not installed, or you do not name an issuer, you have to manage TLS yourself. - A default
StorageClass: needed to provision persistent disks for the database and for file attachments (on k3s,local-pathis enough).
Database
Section titled “Database”PostgreSQL 14+ or SQL Server 2019+: you pick which one at install time with
Database:Provider (see Configuration). Both run from the same
image; changing later means migrating data, so decide up front. The chart ships with an
in-cluster PostgreSQL of demo/single-replica quality (postgres.enabled: true); to use a managed
database in production (RDS, Cloud SQL, Azure Database and so on) you turn that off and supply
your own connection string.
Redis 7+. Used for session/refresh tokens and general caching. The chart includes an
in-cluster Redis of demo/single-replica quality (redis.enabled: true); you can turn it off and
point at your own. Do not disable Redis in production.
Message queue: RabbitMQ or Kafka
Section titled “Message queue: RabbitMQ or Kafka”Background work (notifications, automation, inbound e-mail processing) runs over a message queue.
The choice is made with Messaging:Provider:
- RabbitMQ (default): the chart includes an in-cluster RabbitMQ 3.x of demo/single-replica quality, or you can point at your own.
- Kafka: you can point at your own Kafka cluster, or enable the chart’s single-node
in-cluster Kafka intended for demos (
messaging.kafka.inCluster.enabled). In aProductionenvironment a non-local broker cannot run over an unencrypted protocol (plaintext); the API refuses to start.
Authentication
Section titled “Authentication”The FlowDesk API supports e-mail/password, LDAP and Keycloak (OIDC) login providers
(Auth:Providers). If you are going to use Keycloak you need your organisation’s own Keycloak
server (26+ recommended): realm, client and user management stay entirely with you. For details
see Configuration.
E-mail (optional but recommended)
Section titled “E-mail (optional but recommended)”An SMTP account for outgoing notifications (welcome e-mail, one-time passwords); if you also want requests opened automatically from incoming mail, a mailbox with IMAP access. These settings are entered from the dashboard and need no environment variable; see E-mail settings.
Resource expectations
Section titled “Resource expectations”The default requests/limits values in the chart’s values.yaml are intended for a
single-replica, demo/small-scale installation; tune them in values.yaml for your production
load.
| Component | CPU (request / limit) | Memory (request / limit) |
|---|---|---|
| API | 250m / 1 | 256Mi / 1Gi |
| Dashboard (web) | 100m / 500m | 128Mi / 512Mi |
| Tracker | 100m / 500m | 128Mi / 512Mi |
| PostgreSQL (if in-cluster) | 250m / 1 | 256Mi / 1Gi |
| Redis (if in-cluster) | 50m / 250m | 64Mi / 256Mi |
| RabbitMQ (if in-cluster) | 100m / 500m | 256Mi / 512Mi |
Running everything in-cluster, total requests come to roughly 0.85 vCPU / ~1.1Gi memory and total limits to roughly 3.75 vCPU / ~3.75Gi memory.
Persistent disk (PVC) needs:
| Purpose | Default size | Impact if lost |
|---|---|---|
API: file attachments (/app/attachments) |
5Gi (grows over time) | Attachments and archived inbound e-mail are lost |
API: licence state (/var/lib/flowdesk) |
1Gi | Not critical; the installation re-registers with a new identity |
| PostgreSQL (if in-cluster) | 5Gi | All data is lost |
Network requirements
Section titled “Network requirements”Inbound (through the ingress): three separate hostnames, for the dashboard, the tracker and the API. Raise the request body size limit on your proxy (25 MB recommended): the default 1 MB limit truncates file attachments. The optional Knowledge Base adds three hostnames and a database of its own; see Knowledge Base.
Outbound (from the application):
| Target | What for | Required |
|---|---|---|
ghcr.io |
Pulling images (at deploy time only) | Yes |
license-api.flowdesk.com.tr |
Licence check, HTTPS, roughly every 12 hours | Yes (it also runs unlicensed, see Configuration) |
| Your Keycloak server | Authentication | If Keycloak is used |
| Your SMTP/IMAP server | Outgoing/incoming e-mail | If e-mail is used |
There is no connection directed from SHFT into your organisation’s systems; traffic is one-way and outbound from your organisation.
Decide before you start
Section titled “Decide before you start”- The image tags (versions) you will run; see Release Notes
- Hostnames for the dashboard, the API and the tracker
- Database: PostgreSQL or SQL Server
- Authentication provider: EmailPassword, LDAP or Keycloak
- Message queue: RabbitMQ or Kafka
- Whether you will run the optional Knowledge Base: it needs its own hostnames, database and decisions
When you are ready, move on to Installing with Helm.