Windmill is an open-source workflow-automation / internal-apps platform
that turns scripts (Python, JS/TS, Go, Bash, SQL, Rust, ...) into HTTP
endpoints, scheduled jobs, and visual flows. It is PostgreSQL-only —
it uses Postgres LISTEN/NOTIFY for job queuing, so no Redis is required,
making it a clean Cloudron fit.
- Wraps the official ghcr.io/windmill-labs/windmill:1.514.1 image in
single-container server mode (embedded default worker)
- start.sh composes DATABASE_URL from the Cloudron postgresql addon and
waits for the DB (bash /dev/tcp, no pg_isready dependency)
- HTTP port 8000, health check on /api/version, 2GB memory limit
- OIDC/SAML supported via the in-app Admin Settings UI (post-install)
- Validated end-to-end: throwaway postgres + windmill ran migrations and
returned /api/version => "CE v1.514.1", HTTP 200
Gardening: STATUS/README/JOURNAL updated (9/~57 packaged; Automation
1/4). Windmill logged as a new OIDC-preferred completed package.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
7.1 KiB
Project Status
Human read-only. Agents maintain this file automatically after each work session. Do not edit by hand — the next agent run will overwrite it.
Last updated: 2026-07-30 by Crush (GLM-5.2) — Windmill packaged (OIDC, PostgreSQL, no Redis); draw.io + Windmill validated end-to-end with docker.
Current State: STABLE (packaging phase, ongoing)
Cloudron packaging pipeline is operational. 9 of ~57 upstream applications are packaged, committed, and pushed. Packaging templates exist for the core patterns. The gardening protocol (this file + AGENTS.md) keeps docs in sync.
Completed Packages (9)
| # | Application | Category | Pattern | Port(s) | Addons |
|---|---|---|---|---|---|
| 1 | Webhook | API-Gateway | Multi-stage (Go) | 9000 | localstorage |
| 2 | APISIX | API-Gateway | Official-image wrapper | 9080, 9180, 9443 | localstorage, etcd |
| 3 | Healthchecks | Monitoring | Django + PostgreSQL | 8000 | localstorage, postgresql |
| 4 | Review Board | Development | Django + PostgreSQL | 8080 | localstorage, postgresql |
| 5 | WireViz Web | Documentation-Tools | Python build | 3005 | localstorage |
| 6 | Puter | Development | Multi-stage (Node.js) | 4100 | localstorage, postgresql |
| 7 | Corteza | Low-Code | Pre-compiled binaries | 80 | localstorage, postgresql |
| 8 | draw.io | Documentation-Tools | Official-image wrapper + auth proxy | 8080 | none (stateless) |
| 9 | Windmill | Automation | Official-image wrapper + start.sh | 8000 | localstorage, postgresql |
Each package lives in Package-Workspace/<Category>/<app>/ and contains a
Dockerfile, CloudronManifest.json, README.md, CHANGELOG.md, logo.png,
and (where relevant) start.sh + .env.example.
Packaging Patterns Established
- Official-image wrapper — APISIX, Healthchecks, Review Board
- Multi-stage build — Webhook (Go), Puter (Node.js)
- Python build — WireViz Web
- Django + PostgreSQL — Healthchecks, Review Board
- Pre-compiled binaries — Corteza (download + extract from upstream releases)
Templates live in Package-Templates/ (python-app, django-app, official-wrapper).
Full write-ups of each pattern + challenges are in JOURNAL.md.
Progress by Category
| Category | Apps | Packaged | Notes |
|---|---|---|---|
| API-Gateway | 2 | 2/2 (100%) ✅ | Category complete |
| Development | 4 | 2/4 | reviewboard, puter done |
| Documentation-Tools | 3 | 2/3 | wireviz-web, draw.io done |
| Low-Code | 3 | 1/3 | corteza done |
| Monitoring | 6 | 1/6 | healthchecks done |
| Automation | 4 | 1/4 | windmill done |
| Business-Apps | 8 | 0/8 | |
| Collaboration | 2 | 0/2 | |
| Communication | 1 | 0/1 | |
| Data-Management | 2 | 0/2 | |
| DevOps-Tools | 1 | 0/1 | |
| Financial-Payments | 1 | 0/1 | |
| Financial-Trading | 1 | 0/1 | |
| Infrastructure | 6 | 0/6 | |
| Legal | 1 | 0/1 | |
| Project-Management | 1 | 0/1 | |
| Scientific-Computing | 2 | 0/2 | |
| Security | 5 | 0/5 | |
| System-Administration | 2 | 0/2 |
Auth Status
Auth capability is a hard gate before packaging (see AGENTS.md § Authentication Policy). ✅ = OIDC preferred, ⚠️ = LDAP acceptable (risk flag), 🔄 = auth-proxy (no users), ❌ = local-only (unacceptable / blocked-on-auth).
Completed packages (9)
| App | OIDC | LDAP | Verdict | Note |
|---|---|---|---|---|
| Webhook | n/a | n/a | 🔄 proxy-eligible | No user concept; auth-gap: needs httpAuth proxy added |
| APISIX | plugin | plugin | ⚠️ risk | openid-connect/ldap-auth gateway plugins (edge auth, not dashboard) |
| Healthchecks | no | no | 🔄 proxy-eligible | REMOTE_USER_HEADER support; consider httpAuth proxy |
| Review Board | no | yes | ⚠️ risk (LDAP) | SAML 2.0 via plugin; built-in LDAP/AD backend |
| WireViz Web | n/a | n/a | 🔄 proxy-eligible | Stateless, no users; auth-gap: needs httpAuth proxy added |
| Puter | no | no | ❌ risk | Own user system, no SSO federation — needs revisit |
| Corteza | yes | no | ✅ preferred | Native OIDC via auth.external.providers.openid-connect.* |
| draw.io | n/a | n/a | 🔄 proxy | Packaged with httpAuth.type=proxy (no users, stateless) |
| Windmill | yes | no | ✅ preferred | Packaged; OIDC configured via Admin Settings UI (no env vars) |
Candidates researched
| App | OIDC | LDAP | Verdict | Note |
|---|---|---|---|---|
| NetBox | yes | yes | ✅ auth, ❌ Redis | OIDC+LDAP native, but HARD Redis dep (Cloudron has none) — Complex |
| Gophish | no | no | ❌ blocked | Local admin login only, no SSO — do not package until auth added |
Immediate queue: research next OIDC/auth-proxy candidates (Sentry, SigNoz,
Langfuse, Fleet, InvenTree, GoAlert) and pick the cleanest wins.
Deferred: NetBox (bundle Valkey+supervisor — significant), Gophish
(blocked-on-auth).
Tech debt: add httpAuth proxy to Webhook + WireViz Web (stateless apps);
revise Puter auth.
Known Issues
| Issue | Impact | Status |
|---|---|---|
| Inventory count drift | GitUrlList.txt has 57 apps; README inventory table lists 55; some entries differ (e.g. todogroup/policies, CraigChat/craig in GitUrlList but not README table) |
Reconcile on next packaging pass — treat GitUrlList.txt as source of truth |
| Erroneous "Warp" packaged marker | README inventory row marked Warp ✅ Packaged, but Warp is a duplicate (per RESUME) and no package dir exists | Fixed in this session (README marker removed) |
| No CI / build validation | Packages are built but not regression-tested in a pipeline | Future: cloudron build + manifest lint in CI |
| Packages not exercised on a live Cloudron | Untested end-to-end on the production Cloudron VPS | Future: install-test a sample package |
| Architecture is amd64-only | Pre-compiled-binary + multi-stage packages target linux/amd64 | Acceptable for current target host |
Pending (next session priorities)
- Reconcile the app inventory — make GitUrlList.txt ↔ README inventory table ↔ Package-Workspace agree on the exact app set + categories.
- Pick the next quick wins — prefer apps with official Docker images (e.g. Windmill, DataHub, Sentry/SigNoz, NetBox, InvenTree).
- Validate one package end-to-end on the Cloudron VPS to prove the packaging patterns in production, not just at build time.
- Stand up CI —
cloudron build+ CloudronManifest.json schema lint on every package change. - Continue category-by-category until all ~57 apps are packaged.
Repository Summary
| Component | Details |
|---|---|
| Goal | Package ~57 upstream FLOSS apps for Cloudron (TSYS PaaS of choice) |
| Upstream source list | GitUrlList.txt (57 repos) |
| Workspace | Package-Workspace/<Category>/<app>/ (cloned upstream repo/ dirs are gitignored) |
| Templates | Package-Templates/ (python-app, django-app, official-wrapper) |
| Git remote | ssh://git@git.knownelement.com:29418/KNEL/TSYSDevStack-SupportStack-Cloudron.git (origin/main) |
| Sibling project | TSYSDevStack-SupportStack-LocalWorkstation (local Docker-Compose dev stack) |