Files
KNEL-TSYSDevStack-SupportSt…/Package-Workspace/Business-Apps/InvenTree/README.md
T
mrcharles 69d0d3e896 feat: add InvenTree Cloudron package (Business-Apps) [#658]
Official-image wrapper of inventree/inventree 1.5.2 (digest-pinned).
allauth OIDC provider JSON built from the platform env; invoke update
on boot; RQ worker behind the web-port gate; admin seeded with a
generated password. grind-stack: lowercase image names. 19th package.
Verified: health 200, SSO route 302s to issuer, migrations clean.

Detail: https://projects.knownelement.com/issues/658#note-5086
2026-09-06 19:12:02 -05:00

52 lines
2.2 KiB
Markdown

# InvenTree — Cloudron Package
[InvenTree](https://github.com/inventree/InvenTree) v1.5.2 — open-source
inventory management: parts and stock, BOMs, suppliers, purchase/build
orders, plugins, REST API. Django + PostgreSQL + Redis(RQ). Packaged as
an **official-image wrapper** around `inventree/inventree:1.5.2`
(digest-pinned). Upstream runs server and worker as separate compose
services; Cloudron is one container, so start.sh backgrounds
`invoke worker` gated on the web port (same pattern as NetBox).
## Authentication (auth gate: ✅ OIDC preferred)
django-allauth is built into core; `INVENTREE_SOCIAL_PROVIDERS`
(settings.py:1002) carries provider config. start.sh builds the
`openid_connect` provider from the Cloudron platform env:
```json
{"openid_connect": {"OAUTH_PKCE_ENABLED": true, "APPS": [{
"provider_id": "cloudron", "name": "Cloudron SSO",
"server_url": "<CLOUDRON_OIDC_ISSUER>", "client_id": "...", "secret": "..."
}]}}
```
- SSO login route: `https://<app-domain>/accounts/oidc/cloudron/login/`
- LDAP is also available in core (`INVENTREE_LDAP_*`) as an alternative.
- Local login remains for the admin.
**First-boot admin**: a local `admin` account is seeded with a
generated password stored at `/app/data/.admin_password` (read it via
the Cloudron file manager). Change it after first login, or set
`INVENTREE_ADMIN_EMAIL`/`INVENTREE_ADMIN_PASSWORD` app env vars to
control the seed yourself.
## Runtime layout
| Concern | How |
|---------|-----|
| Database | Cloudron `postgresql` addon |
| Cache/queues | Cloudron `redis` addon (cache DB 1; RQ default DB 0) |
| Schema + static | `invoke update` on every boot (migrations + collectstatic) |
| Worker | `invoke worker` backgrounded, gated on web port (post-migration) |
| Persistence | `/app/data` (localstorage): media/, static/, config.yaml, secret key, admin password |
| Health | `/api/system/health/` (upstream's own unauthenticated endpoint) |
## Notes
- Version upgrades: bump tag+digest, rebuild — `invoke update` migrates
on first boot.
- The image ENTRYPOINT's venv logic is bypassed (deps are baked in the
image); start.sh controls ordering instead.
- Package pattern + verification: repo `JOURNAL.md`, InvenTree section.