ITFlow, the open source IT documentation and MSP management platform, ready the moment it boots with a per instance administrator credential.
ITFlow is an open source IT documentation and business management platform built for managed service providers and internal IT teams. It gives you one authoritative place to record every client along with their contacts, locations, assets, networks, racks and credentials, then runs the work around them: tickets with email parsing and a client portal, projects, invoices, quotes, recurring billing and expenses, plus domain and SSL certificate expiry tracking. An encrypted credential vault with TOTP support keeps client passwords and second factors under the same roof as the documentation that explains them.
It suits managed service providers replacing a costly professional services automation suite, and internal IT teams who want their documentation, ticketing and asset inventory in one system they fully own and control.
cloudimg delivers ITFlow fully installed behind Apache with MariaDB, served over HTTPS from the moment the instance boots, which matters for a product that stores your clients' passwords and TOTP secrets in an encrypted vault. The image is secure by default and carries no usable credential at all: rather than shipping a pre installed copy whose password would have to be rotated, ITFlow installs itself on your own instance at first boot, generating its own database password, its own administrator password and its own TLS certificate, and writing the credentials to a file only the root user can read. That ordering is deliberate, because ITFlow derives the credential vault's encryption key from the administrator password, so the per instance password has to be the original one rather than a replacement. The image is hardened past a stock install: the web installation wizard is deleted rather than merely disabled, PHP execution is blocked in the writable document tree, and scheduled jobs run from a system timer instead of a public web endpoint. Your database and uploaded client documents live on a dedicated data volume, the base is fully patched with unattended security upgrades enabled, and every deployment is paired with a step by step deploy guide and backed by 24/7 cloudimg support.
Real screenshots taken while testing this image against its deployment guide.
This is a repackaged open source software product wherein additional charges apply for cloudimg support services.
ITFlow is a widely used open source IT documentation and business management platform built for managed service providers and internal IT teams. It gives you one authoritative place to record every client along with their contacts, locations, assets, networks and credentials, then runs the work around them: tickets with email parsing and a client portal, projects, invoices, quotes, recurring billing, expenses, and domain and SSL certificate expiry tracking. This image delivers ITFlow 26.07 with its full stack configured and hardened, so you have a working platform within minutes of launch, eliminating hours of manual dependency installation, web server configuration, database setup, TLS provisioning and hardening that a self managed deployment requires. The current release available is ITFlow 26.07.
Application Stack
ITFlow is a PHP application running on PHP 8.3 with OPcache and the mysqli, intl, curl, mbstring, gd and xml extensions, served by Apache with libapache2-mod-php. MariaDB provides the database over a local unix socket. The scheduled jobs (mail queue, ticket email parser, domain and certificate refresher) run every five minutes from a systemd timer using the PHP command line, never from a public web endpoint.
No Credential Ships In The Image
ITFlow derives its encrypted credential vault master key from the administrator password, so the account must be created with its final password rather than rotated afterwards. This image therefore installs ITFlow on your own instance at first boot using ITFlow's own official installer, with a database password, an administrator password and a TLS certificate all generated uniquely for that instance. The administrator password is written to a root only file and its location is shown in the login banner. There is no default credential to find, and none to change.
Served Over HTTPS, Hardened Beyond A Stock Install
The platform is served over HTTPS from the moment it starts, which matters for a product that stores your clients' passwords and TOTP secrets in an encrypted vault. The certificate is self signed and generated for your instance, so your browser asks you to accept it the first time; the paired guide walks through installing a certificate from your own certificate authority or from Let's Encrypt. The image goes further than a stock install: the web installation wizard is deleted rather than merely disabled, PHP execution is blocked in the customer writable document and attachment tree, and the vendored library tree and command line installers are denied from the web.
Dedicated Data Volume
A dedicated data volume holds the MariaDB database and your uploaded client documents, ticket attachments and invoice PDFs, keeping customer data independent of the operating system disk so it can be snapshotted and grown on its own.
cloudimg Support
24/7 technical support by email and chat. Help with ITFlow deployment, TLS certificate installation including Let's Encrypt, mail and ticket email parsing setup, client portal configuration, credential vault and TOTP usage, invoicing, quoting and recurring billing, domain and SSL certificate expiry tracking, upgrades, backup and restore, and MariaDB administration.
Use Cases
Run an MSP practice management and IT documentation platform in your own VPC for data residency or compliance. Track clients, assets, networks and an encrypted credential vault; route inbound email into tickets with a client portal; and manage projects, quotes, invoices and recurring billing from one self hosted application.
All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.