Ii

ITFlow IT Documentation and MSP Platform

AWS Applications

ITFlow, the open source IT documentation and MSP management platform, ready the moment it boots with a per instance administrator credential.

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

ITFlow is an open source IT documentation and business management platform built for managed service providers and internal IT teams. It gives you one authoritative place to record every client along with their contacts, locations, assets, networks, racks and credentials, then runs the work around them: tickets with email parsing and a client portal, projects, invoices, quotes, recurring billing and expenses, plus domain and SSL certificate expiry tracking. An encrypted credential vault with TOTP support keeps client passwords and second factors under the same roof as the documentation that explains them.

It suits managed service providers replacing a costly professional services automation suite, and internal IT teams who want their documentation, ticketing and asset inventory in one system they fully own and control.

Why the cloudimg image

cloudimg delivers ITFlow fully installed behind Apache with MariaDB, served over HTTPS from the moment the instance boots, which matters for a product that stores your clients' passwords and TOTP secrets in an encrypted vault. The image is secure by default and carries no usable credential at all: rather than shipping a pre installed copy whose password would have to be rotated, ITFlow installs itself on your own instance at first boot, generating its own database password, its own administrator password and its own TLS certificate, and writing the credentials to a file only the root user can read. That ordering is deliberate, because ITFlow derives the credential vault's encryption key from the administrator password, so the per instance password has to be the original one rather than a replacement. The image is hardened past a stock install: the web installation wizard is deleted rather than merely disabled, PHP execution is blocked in the writable document tree, and scheduled jobs run from a system timer instead of a public web endpoint. Your database and uploaded client documents live on a dedicated data volume, the base is fully patched with unattended security upgrades enabled, and every deployment is paired with a step by step deploy guide and backed by 24/7 cloudimg support.

Common uses

  • A self hosted documentation and ticketing platform for a managed service provider
  • One source of truth for client assets, networks and credentials
  • Invoicing, quoting and recurring billing alongside the documentation it bills for

Key features

  • ITFlow IT documentation and MSP management platform preinstalled with PHP 8.3, Apache and MariaDB and served over HTTPS. Manage clients, contacts, locations, assets, networks and racks, an encrypted credential vault with TOTP, tickets with email parsing and a client portal, projects, invoices, quotes, recurring billing and expenses, plus domain and SSL certificate expiry tracking.
  • No administrator password exists anywhere in the image: ITFlow is installed on your own instance at first boot, which generates its own database password, administrator password and TLS certificate and stores the administrator password in a root only file. The web installation wizard is deleted, PHP execution is blocked in the customer writable document tree, and scheduled jobs run from a system timer rather than a public web endpoint.
  • A dedicated data volume holds the database and your uploaded client documents, ticket attachments and invoice PDFs, and the image is paired with a cloudimg deployment guide executed end to end against this exact build. Backed by 24/7 cloudimg expert support.

See it running

Real screenshots taken while testing this image against its deployment guide.

ITFlow IT Documentation and MSP Platform screenshot 1 ITFlow IT Documentation and MSP Platform screenshot 2 ITFlow IT Documentation and MSP Platform screenshot 3 ITFlow IT Documentation and MSP Platform screenshot 4

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

ITFlow is a widely used open source IT documentation and business management platform built for managed service providers and internal IT teams. It gives you one authoritative place to record every client along with their contacts, locations, assets, networks and credentials, then runs the work around them: tickets with email parsing and a client portal, projects, invoices, quotes, recurring billing, expenses, and domain and SSL certificate expiry tracking. This image delivers ITFlow 26.07 with its full stack configured and hardened, so you have a working platform within minutes of launch, eliminating hours of manual dependency installation, web server configuration, database setup, TLS provisioning and hardening that a self managed deployment requires. The current release available is ITFlow 26.07.

Application Stack

ITFlow is a PHP application running on PHP 8.3 with OPcache and the mysqli, intl, curl, mbstring, gd and xml extensions, served by Apache with libapache2-mod-php. MariaDB provides the database over a local unix socket. The scheduled jobs (mail queue, ticket email parser, domain and certificate refresher) run every five minutes from a systemd timer using the PHP command line, never from a public web endpoint.

No Credential Ships In The Image

ITFlow derives its encrypted credential vault master key from the administrator password, so the account must be created with its final password rather than rotated afterwards. This image therefore installs ITFlow on your own instance at first boot using ITFlow's own official installer, with a database password, an administrator password and a TLS certificate all generated uniquely for that instance. The administrator password is written to a root only file and its location is shown in the login banner. There is no default credential to find, and none to change.

Served Over HTTPS, Hardened Beyond A Stock Install

The platform is served over HTTPS from the moment it starts, which matters for a product that stores your clients' passwords and TOTP secrets in an encrypted vault. The certificate is self signed and generated for your instance, so your browser asks you to accept it the first time; the paired guide walks through installing a certificate from your own certificate authority or from Let's Encrypt. The image goes further than a stock install: the web installation wizard is deleted rather than merely disabled, PHP execution is blocked in the customer writable document and attachment tree, and the vendored library tree and command line installers are denied from the web.

Dedicated Data Volume

A dedicated data volume holds the MariaDB database and your uploaded client documents, ticket attachments and invoice PDFs, keeping customer data independent of the operating system disk so it can be snapshotted and grown on its own.

cloudimg Support

24/7 technical support by email and chat. Help with ITFlow deployment, TLS certificate installation including Let's Encrypt, mail and ticket email parsing setup, client portal configuration, credential vault and TOTP usage, invoicing, quoting and recurring billing, domain and SSL certificate expiry tracking, upgrades, backup and restore, and MariaDB administration.

Use Cases

Run an MSP practice management and IT documentation platform in your own VPC for data residency or compliance. Track clients, assets, networks and an encrypted credential vault; route inbound email into tickets with a client portal; and manage projects, quotes, invoices and recurring billing from one self hosted application.

All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

Related technologies

it documentationmsp softwarepsa softwaremanaged service providerit asset managementticketing systemcredential vaultclient portalopen source