Skip to content

Requirements

FlowDesk is installed by running three containers (API, Dashboard, Tracker) on a Kubernetes cluster. Which cloud provider or deployment tooling you use is your organisation’s choice; as long as the requirements described here are met, the application behaves as expected.

browser ──HTTPS──▶ [your ingress] ──┬──▶ flowdesk-web :3000 ──┐
├──▶ flowdesk-tracker :3001 ──┤ (HTTP, server side)
└──▶ flowdesk-api :8080 ◀─┘
│
PostgreSQL or SQL Server · Redis · RabbitMQ or Kafka
│
outbound ──▶ licence server · Keycloak (if used) · SMTP/IMAP (if used)

All three containers listen on plain HTTP and expect no TLS: the ingress in front of them terminates the certificate. Logs are written to stdout.

  • The shftco/flowdesk-kubernetes chart uses apps/v1 Deployment and networking.k8s.io/v1 Ingress resources, which in practice means it works with Kubernetes 1.19 and later. SHFT documents no separate lower bound; any compatible cluster will do, k3s included.
  • ingress-nginx: the Ingress resource the chart renders expects ingressClassName: nginx.
  • cert-manager: manages TLS certificates through a ClusterIssuer (Let’s Encrypt, for example). If cert-manager is not installed, or you do not name an issuer, you have to manage TLS yourself.
  • A default StorageClass: needed to provision persistent disks for the database and for file attachments (on k3s, local-path is enough).

PostgreSQL 14+ or SQL Server 2019+: you pick which one at install time with Database:Provider (see Configuration). Both run from the same image; changing later means migrating data, so decide up front. The chart ships with an in-cluster PostgreSQL of demo/single-replica quality (postgres.enabled: true); to use a managed database in production (RDS, Cloud SQL, Azure Database and so on) you turn that off and supply your own connection string.

Redis 7+. Used for session/refresh tokens and general caching. The chart includes an in-cluster Redis of demo/single-replica quality (redis.enabled: true); you can turn it off and point at your own. Do not disable Redis in production.

Background work (notifications, automation, inbound e-mail processing) runs over a message queue. The choice is made with Messaging:Provider:

  • RabbitMQ (default): the chart includes an in-cluster RabbitMQ 3.x of demo/single-replica quality, or you can point at your own.
  • Kafka: you can point at your own Kafka cluster, or enable the chart’s single-node in-cluster Kafka intended for demos (messaging.kafka.inCluster.enabled). In a Production environment a non-local broker cannot run over an unencrypted protocol (plaintext); the API refuses to start.

The FlowDesk API supports e-mail/password, LDAP and Keycloak (OIDC) login providers (Auth:Providers). If you are going to use Keycloak you need your organisation’s own Keycloak server (26+ recommended): realm, client and user management stay entirely with you. For details see Configuration.

An SMTP account for outgoing notifications (welcome e-mail, one-time passwords); if you also want requests opened automatically from incoming mail, a mailbox with IMAP access. These settings are entered from the dashboard and need no environment variable; see E-mail settings.

The default requests/limits values in the chart’s values.yaml are intended for a single-replica, demo/small-scale installation; tune them in values.yaml for your production load.

Component CPU (request / limit) Memory (request / limit)
API 250m / 1 256Mi / 1Gi
Dashboard (web) 100m / 500m 128Mi / 512Mi
Tracker 100m / 500m 128Mi / 512Mi
PostgreSQL (if in-cluster) 250m / 1 256Mi / 1Gi
Redis (if in-cluster) 50m / 250m 64Mi / 256Mi
RabbitMQ (if in-cluster) 100m / 500m 256Mi / 512Mi

Running everything in-cluster, total requests come to roughly 0.85 vCPU / ~1.1Gi memory and total limits to roughly 3.75 vCPU / ~3.75Gi memory.

Persistent disk (PVC) needs:

Purpose Default size Impact if lost
API: file attachments (/app/attachments) 5Gi (grows over time) Attachments and archived inbound e-mail are lost
API: licence state (/var/lib/flowdesk) 1Gi Not critical; the installation re-registers with a new identity
PostgreSQL (if in-cluster) 5Gi All data is lost

Inbound (through the ingress): three separate hostnames, for the dashboard, the tracker and the API. Raise the request body size limit on your proxy (25 MB recommended): the default 1 MB limit truncates file attachments. The optional Knowledge Base adds three hostnames and a database of its own; see Knowledge Base.

Outbound (from the application):

Target What for Required
ghcr.io Pulling images (at deploy time only) Yes
license-api.flowdesk.com.tr Licence check, HTTPS, roughly every 12 hours Yes (it also runs unlicensed, see Configuration)
Your Keycloak server Authentication If Keycloak is used
Your SMTP/IMAP server Outgoing/incoming e-mail If e-mail is used

There is no connection directed from SHFT into your organisation’s systems; traffic is one-way and outbound from your organisation.

  • The image tags (versions) you will run; see Release Notes
  • Hostnames for the dashboard, the API and the tracker
  • Database: PostgreSQL or SQL Server
  • Authentication provider: EmailPassword, LDAP or Keycloak
  • Message queue: RabbitMQ or Kafka
  • Whether you will run the optional Knowledge Base: it needs its own hostnames, database and decisions

When you are ready, move on to Installing with Helm.