1. Support
  2. Self-hosting
  3. Installation Guide
Self-hosting Administrators

Installation Guide

Deploy the Flomation platform on Enterprise Linux 8 & 9 — RHEL, Rocky Linux, AlmaLinux, Oracle Linux.

01 Overview

The Flomation platform consists of six components.

ComponentDescriptionType
flomation-sentinelIdentity and access management (authentication, users, sessions)Go service
flomation-apiCore API server (organisations, workflows, executions)Go service
flomation-launchTrigger/webhook ingress service (webhooks, QR codes, forms)Go service
flomation-editorWeb-based workflow editor UINode.js application
flomation-executorWorkflow execution engine (invoked by the Runner)Go CLI tool
flomation-runnerRemote execution agent (polls API for pending work)Go service

Architecture

Editor Web UI Sentinel Auth / IdAM API Core Service Launch Triggers Runner Agent Executor CLI Tool PostgreSQL Users

Each backend service (Sentinel, API, Launch) requires its own PostgreSQL database. These can run on the same PostgreSQL server for cost savings. The Runner polls the API for pending executions and invokes the Executor to run workflows.

02 Prerequisites

  • Enterprise Linux 8 or 9 (RHEL, Rocky Linux, AlmaLinux, Oracle Linux)
  • Root or sudo access
  • A PostgreSQL server (see Section 4)
  • Network connectivity between all component hosts
  • SMTP server (required for user registration email verification)

Recommended Install Order

Components should be installed and configured in this order, as later services depend on earlier ones:

  1. PostgreSQL database
  2. Sentinel (identity — no dependencies on other Flomation services)
  3. API (depends on Sentinel)
  4. Launch (depends on API)
  5. Editor (depends on API, Launch, and Sentinel)
  6. Executor and Runner (depend on API)

03 Install the Flomation Repository

Install the Flomation yum repository configuration package on each host that will run a Flomation component.

For EL8:

BASH
sudo dnf install -y https://flomation-packages-live.s3.eu-west-2.amazonaws.com/yum/flomation-repo-1.0.1-1.el8.noarch.rpm

For EL9:

BASH
sudo dnf install -y https://flomation-packages-live.s3.eu-west-2.amazonaws.com/yum/flomation-repo-1.0.1-1.el9.noarch.rpm

Verify the repository is available:

BASH
sudo dnf repolist | grep flomation

04 PostgreSQL Database

The Flomation platform requires a PostgreSQL database with the uuid-ossp and pgcrypto extensions.

Setting up and administering PostgreSQL is outside the scope of this guide. Ensure you have a running PostgreSQL instance accessible from the hosts running Sentinel, API, and Launch.

Create the Database

Connect to your PostgreSQL server and create a database and user for Flomation:

SQL
CREATE USER flomation WITH PASSWORD 'your-secure-password';

-- Create databases for each service
CREATE DATABASE flomation_sentinel OWNER flomation;
CREATE DATABASE flomation_api OWNER flomation;
CREATE DATABASE flomation_launch OWNER flomation;

-- Connect to each database and enable required extensions
\c flomation_sentinel
CREATE EXTENSION IF NOT EXISTS "uuid-ossp";
CREATE EXTENSION IF NOT EXISTS "pgcrypto";

\c flomation_api
CREATE EXTENSION IF NOT EXISTS "uuid-ossp";
CREATE EXTENSION IF NOT EXISTS "pgcrypto";

\c flomation_launch
CREATE EXTENSION IF NOT EXISTS "uuid-ossp";
CREATE EXTENSION IF NOT EXISTS "pgcrypto";
Note
Each service (Sentinel, API, Launch) requires its own database. They can share a single PostgreSQL server for cost savings. Each service manages its own tables and will run migrations automatically on first startup.

05 Install Flomation Sentinel

Sentinel provides identity and access management — authentication, user accounts, sessions, and MFA.

flomation-sentinel

Install

BASH
sudo dnf install -y flomation-sentinel

Configure

Create the configuration file:

BASH
sudo vi /opt/flomation/sentinel/config.json
JSON
{
  "listener": {
    "address": "0.0.0.0",
    "port": 8999,
    "url": "https://sentinel.example.com"
  },
  "database": {
    "hostname": "db.example.com",
    "port": 5432,
    "username": "flomation",
    "password": "your-secure-password",
    "database": "flomation_sentinel",
    "encryption_key": "PLACEHOLDER-GENERATE-A-SECURE-KEY",
    "ssl_mode": "require"
  },
  "security": {
    "cookie": {
      "domain": "example.com",
      "secure": true,
      "http_only": true,
      "expiration": 86400
    },
    "realm": "example.com",
    "secret": "PLACEHOLDER-GENERATE-A-SECURE-SECRET",
    "login_redirect": "https://editor.example.com/",
    "logout_redirect": "https://editor.example.com/logout"
  },
  "notification": {
    "enabled": true,
    "send_from": "noreply@example.com",
    "smtp": {
      "host": "smtp.example.com",
      "port": 587,
      "username": "smtp-user",
      "password": "smtp-password"
    }
  }
}

Set appropriate permissions on the configuration file:

BASH
sudo chown flomation:flomation /opt/flomation/sentinel/config.json
sudo chmod 640 /opt/flomation/sentinel/config.json

Configuration Reference

KeyEnv VariableDescription
listener.addressLISTEN_ADDRESSBind address (default: 127.0.0.1)
listener.portLISTEN_PORTListen port (default: 8999)
listener.urlLISTEN_URLExternal URL of this Sentinel instance
database.hostnameDB_HOSTNAMEPostgreSQL hostname
database.portDB_PORTPostgreSQL port
database.usernameDB_USERNAMEPostgreSQL username
database.passwordDB_PASSWORDPostgreSQL password
database.databaseDB_NAMEPostgreSQL database name
database.encryption_keyDB_ENCRYPTION_KEYEncryption key for sensitive data
database.ssl_modeDB_SSL_MODEPostgreSQL SSL mode (disable, require, etc.)
security.secretAUTH_SECRETSecret key for JWT token signing
security.realmAUTH_REALMAuthentication realm
security.login_redirectAUTH_LOGIN_REDIRECTRedirect URL after login
security.logout_redirectAUTH_LOGOUT_REDIRECTRedirect URL after logout
notification.enabledNOTIFICATIONS_ENABLEDEnable email notifications
notification.send_fromNOTIFICATIONS_SEND_FROMEmail sender address
notification.smtp.hostSMTP_HOSTSMTP server hostname
notification.smtp.portSMTP_PORTSMTP server port
notification.smtp.usernameSMTP_USERNAMESMTP username
notification.smtp.passwordSMTP_PASSWORDSMTP password

Start

BASH
sudo systemctl enable --now flomation-sentinel

Verify the service is running:

BASH
sudo systemctl status flomation-sentinel

06 Install Flomation API

The API server is the core of the platform — it manages organisations, workflows, executions, runners, and environments.

flomation-api

Install

BASH
sudo dnf install -y flomation-api

Configure

Create the configuration file:

BASH
sudo vi /opt/flomation/api/config.json
JSON
{
  "http": {
    "address": "0.0.0.0",
    "port": 8888
  },
  "database": {
    "hostname": "db.example.com",
    "port": 5432,
    "username": "flomation",
    "password": "your-secure-password",
    "database": "flomation_api",
    "encryption_key": "PLACEHOLDER-GENERATE-A-SECURE-KEY",
    "ssl_mode": "require"
  },
  "security": {
    "identity_service": "https://sentinel.example.com"
  },
  "launch": {
    "url": "https://launch.example.com"
  }
}

Set appropriate permissions:

BASH
sudo chown flomation:flomation /opt/flomation/api/config.json
sudo chmod 640 /opt/flomation/api/config.json

Configuration Reference

KeyEnv VariableDescription
http.addressLISTEN_ADDRESSBind address
http.portLISTEN_PORTListen port
database.hostnameDATABASE_HOSTNAMEPostgreSQL hostname
database.portDATABASE_PORTPostgreSQL port
database.usernameDATABASE_USERPostgreSQL username
database.passwordDATABASE_PASSWORDPostgreSQL password
database.databaseDATABASE_NAMEPostgreSQL database name
database.encryption_keyDATABASE_ENCRYPTION_KEYEncryption key for sensitive data
database.ssl_modeDATABASE_SSL_MODEPostgreSQL SSL mode
security.identity_serviceIDENTITY_SERVICEURL of the Sentinel instance
launch.urlLAUNCH_SERVICE_URLURL of the Launch instance

Start

BASH
sudo systemctl enable --now flomation-api

07 Install Flomation Launch

Launch is the trigger and webhook ingress service — it handles webhooks, QR codes, forms, tracking pixels, and scheduled triggers.

flomation-launch

Install

BASH
sudo dnf install -y flomation-launch

Configure

Create the configuration file:

BASH
sudo vi /opt/flomation/launch/config.json
JSON
{
  "http": {
    "address": "0.0.0.0",
    "port": 8081
  },
  "database": {
    "hostname": "db.example.com",
    "port": 5432,
    "username": "flomation",
    "password": "your-secure-password",
    "database": "flomation_launch",
    "encryption_key": "PLACEHOLDER-GENERATE-A-SECURE-KEY",
    "ssl_mode": "require"
  },
  "automate": {
    "url": "https://api.example.com"
  }
}

Set appropriate permissions:

BASH
sudo chown flomation:flomation /opt/flomation/launch/config.json
sudo chmod 640 /opt/flomation/launch/config.json

Configuration Reference

KeyDescription
http.addressBind address
http.portListen port
database.hostnamePostgreSQL hostname
database.portPostgreSQL port
database.usernamePostgreSQL username
database.passwordPostgreSQL password
database.databasePostgreSQL database name
database.encryption_keyEncryption key for sensitive data
automate.urlURL of the Flomation API instance
automate.key(Optional) API key for authenticating with the API

Start

BASH
sudo systemctl enable --now flomation-launch

08 Install Flomation Editor

The Editor is the web-based UI for designing and managing workflows. It is a Node.js application (React Router / SSR).

flomation-editor

Install

BASH
sudo dnf install -y flomation-editor

Configure

The Editor is configured via an environment file. Copy the sample and edit it:

BASH
sudo cp /opt/flomation/editor/etc/environment.sample /opt/flomation/editor/etc/environment
sudo vi /opt/flomation/editor/etc/environment
BASH
# Flomation Editor Configuration
AUTOMATE_API_URL=https://api.example.com
BILLING_API_URL=https://billing.example.com
TRIGGER_URL=https://launch.example.com
LOGIN_URL=https://sentinel.example.com
LAUNCH_URL=https://launch.example.com
PORT=8080
NODE_ENV=production

Set appropriate permissions:

BASH
sudo chown flomation:flomation /opt/flomation/editor/etc/environment
sudo chmod 640 /opt/flomation/editor/etc/environment

Configuration Reference

VariableDescriptionDefault
AUTOMATE_API_URLURL of the Flomation API instancehttp://localhost:8080
BILLING_API_URLURL of the Flomation Billing API instance (falls back to AUTOMATE_API_URL if unset)http://localhost:9085
TRIGGER_URLURL of the Flomation Launch instancehttp://localhost:8081
LOGIN_URLURL of the Flomation Sentinel instancehttp://localhost:8081
LAUNCH_URLPublic URL of the Flomation Launch instance, used for externally-reachable webhooks (Slack, Twilio, Teams)http://localhost:8081
PORTPort for the Editor to listen on8080
NODE_ENVNode.js environmentproduction

Start

BASH
sudo systemctl enable --now flomation-editor
Note
On first start, the Editor generates a run-config.js file from the environment variables. If you change the environment file, delete /opt/flomation/editor/build/client/run-config.js and restart the service for the changes to take effect.

09 Install Flomation Executor

The Executor is a command-line tool that runs workflow definitions. It is invoked by the Runner and does not run as a persistent service.

flomation-executor

Install

BASH
sudo dnf install -y flomation-executor

The Executor binary is installed to /opt/flomation/executor/ and added to the system PATH via /etc/profile.d/flomation-executor.sh.

No additional configuration is needed — the Runner passes all required parameters when invoking the Executor.

10 Install Flomation Runner

The Runner is a background agent that polls the Flomation API for pending workflow executions and invokes the Executor to run them.

flomation-runner

Install

Install both the Runner and Executor on the same host:

BASH
sudo dnf install -y flomation-runner flomation-executor

Obtain a Registration Code

Before configuring the Runner, you need a registration code from the API server. This is generated through the Flomation Editor UI after initial platform setup (see Section 11).

Configure

Create the configuration file:

BASH
sudo vi /opt/flomation/runner/config.json
JSON
{
  "runner": {
    "url": "https://api.example.com",
    "registration_code": "your-registration-code",
    "name": "runner-01",
    "checkin_timeout": 5,
    "certificate": "flomation-runner.pem"
  },
  "execution": {
    "max_concurrent_executors": 5,
    "execution_directory": "/opt/flomation/runner/workspace/",
    "executable_name": "flomation-executor"
  }
}

Create the workspace directory:

BASH
sudo mkdir -p /opt/flomation/runner/workspace
sudo chown flomation:flomation /opt/flomation/runner/workspace

Set appropriate permissions:

BASH
sudo chown flomation:flomation /opt/flomation/runner/config.json
sudo chmod 640 /opt/flomation/runner/config.json

Configuration Reference

KeyEnv VariableDescription
runner.urlFLOMATION_APIURL of the Flomation API instance
runner.registration_codeFLOMATION_REGISTRATION_CODERegistration code from the API
runner.nameFLOMATION_RUNNER_NAMEDisplay name for this runner
runner.checkin_timeoutFLOMATION_RUNNER_CHECKIN_TIMEOUTPoll interval in seconds (default: 5)
runner.certificateFLOMATION_RUNNER_CERTIFICATE_PATHRSA key filename (default: flomation-runner.pem)
execution.max_concurrent_executorsFLOMATION_RUNNER_MAX_EXECUTORSMax parallel executions (default: 5)
execution.execution_directoryFLOMATION_RUNNER_EXECUTION_DIRECTORYWorking directory for executions
execution.executable_nameFLOMATION_RUNNER_EXECUTABLE_NAMEName of the executor binary

Start

BASH
sudo systemctl enable --now flomation-runner
Note
On first start, the Runner automatically generates an RSA key pair (flomation-runner.pem) and registers itself with the API server.

11 First-Time Setup

Once all services are running, follow these steps to bootstrap the platform.

1. Register the First User

Sentinel provides a self-registration flow:

  1. Navigate to your Sentinel instance's /authenticate endpoint in a browser (e.g. https://sentinel.example.com/authenticate).
  2. Enter your email address. Since no accounts exist yet, Sentinel will present a registration prompt.
  3. Click Create account.
  4. Check your email for a verification message containing a link to set your password.
  5. Click the verification link and set your password.
Note
SMTP must be configured correctly in Sentinel for the verification email to be delivered. Check the Sentinel logs if the email does not arrive: sudo journalctl -u flomation-sentinel -f

2. Log In to the Editor

Navigate to your Editor instance (e.g. https://editor.example.com). You will be redirected to Sentinel to authenticate. Log in with the credentials you just created.

3. Create an Organisation

After logging in, the API automatically creates your user record. You can then create your first organisation through the Editor UI.

4. Register a Runner

To execute workflows, you need at least one Runner registered:

  1. In the Editor, navigate to the Runners section.
  2. Generate a registration code.
  3. Use this registration code in the Runner's config.json (see Section 10).
  4. Start (or restart) the Runner service.

12 Service Management

All Flomation services are managed via systemd. The RPM packages install service unit files to /etc/systemd/system/.

ServiceUnit Name
Sentinelflomation-sentinel.service
APIflomation-api.service
Launchflomation-launch.service
Editorflomation-editor.service
Runnerflomation-runner.service

Common operations:

BASH
# Start a service
sudo systemctl start flomation-api

# Stop a service
sudo systemctl stop flomation-api

# Restart a service
sudo systemctl restart flomation-api

# View service status
sudo systemctl status flomation-api

# View logs
sudo journalctl -u flomation-api -f

Log Files

Service logs are written to:

  • stdout/stderr logs: /opt/flomation/<component>/logs/<component>.log and .err
  • Symlink: /var/log/flomation/<component> points to the logs directory

File Locations

PathDescription
/opt/flomation/<component>/Application install directory
/opt/flomation/<component>/config.jsonConfiguration file (Go services)
/opt/flomation/<component>/etc/environmentEnvironment file (Editor)
/opt/flomation/<component>/logs/Log directory
/opt/flomation/snapshots/Upgrade snapshots
/var/log/flomation/<component>Log symlink
/etc/systemd/system/flomation-<component>.serviceSystemd unit file

Upgrades

To upgrade a component:

BASH
sudo dnf update flomation-api

The RPM upgrade process automatically:

  1. Stops the running service.
  2. Creates a snapshot of the current installation in /opt/flomation/snapshots/.
  3. Installs the new version.
  4. Restarts the service.

13 Firewall Configuration

If firewalld is enabled, you will need to open ports for each service running on the host. The specific ports depend on your configuration.

For example, to allow traffic to the API on port 8888:

BASH
sudo firewall-cmd --permanent --add-port=8888/tcp
sudo firewall-cmd --reload

Repeat for each service port as needed. Only open ports that need to be accessible from other hosts — services communicating on localhost do not require firewall rules.

14 SELinux

The Flomation RPM packages handle SELinux context configuration automatically during installation.

The packages set appropriate contexts for:

  • Application directories (usr_t)
  • Log directories (var_log_t)
  • Snapshot directories (usr_t)

If you encounter SELinux denials, check the audit log:

BASH
sudo ausearch -m avc -ts recent

To generate and apply a custom policy module if needed:

BASH
sudo ausearch -m avc -ts recent | audit2allow -M flomation-custom
sudo semodule -i flomation-custom.pp
Note
The RPM packages require policycoreutils-python-utils for SELinux context management. This is pulled in as a dependency automatically.

15 TLS Configuration

The Sentinel, API, and Launch services support TLS termination directly. This is the recommended way to serve Flomation over HTTPS — a separate reverse proxy is not required.

Direct TLS termination (recommended)

Place the certificate and private key in each service's installation root:

  • /opt/flomation/sentinel/certificate.crt and /opt/flomation/sentinel/certificate.key
  • /opt/flomation/api/certificate.crt and /opt/flomation/api/certificate.key
  • /opt/flomation/launch/certificate.crt and /opt/flomation/launch/certificate.key

When these files are present, the service serves HTTPS automatically.

When serving over HTTPS, also ensure:

  • Sentinel's security.cookie.secure is set to true.
  • The listener.url (Sentinel), security.identity_service (API), and all URL references in the Editor environment file use https:// URLs.

Editor

The Editor service does not support TLS termination directly. To serve the Editor over HTTPS, place it behind a reverse proxy such as nginx, HAProxy, or Caddy that handles TLS termination.

Example: nginx

NGINX
server {
    listen 80;
    server_name editor.example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    server_name editor.example.com;

    ssl_certificate     /etc/nginx/ssl/editor.crt;
    ssl_certificate_key /etc/nginx/ssl/editor.key;

    location / {
        proxy_pass http://127.0.0.1:8080;
        proxy_http_version 1.1;

        proxy_set_header Host              $host;
        proxy_set_header X-Real-IP         $remote_addr;
        proxy_set_header X-Forwarded-For   $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        proxy_set_header Upgrade    $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

Replace editor.example.com and the certificate paths with values appropriate for your environment.

Reverse proxy (optional for Sentinel, API, Launch)

A TLS-terminating reverse proxy such as HAProxy, nginx, or Caddy is also supported in front of Sentinel, API, and Launch. This can be useful for consolidating certificates, terminating TLS at the network edge, or fronting multiple services on a single hostname.

When using a reverse proxy, ensure the X-Forwarded-For and X-Forwarded-Proto headers are set correctly.

16 Troubleshooting

Service fails to start

Check the service logs:

BASH
sudo journalctl -u flomation-<component> -e --no-pager
sudo cat /opt/flomation/<component>/logs/<component>.err

Database connection errors

  • Verify PostgreSQL is running and accessible from the service host.
  • Check that the database credentials in config.json are correct.
  • Ensure the uuid-ossp and pgcrypto extensions are installed on the database.
  • If using SSL, verify the ssl_mode setting matches your PostgreSQL configuration.

Editor shows blank page or API errors

  • Verify the URLs in /opt/flomation/editor/etc/environment are correct and reachable from the user's browser (these are client-side URLs).
  • Delete /opt/flomation/editor/build/client/run-config.js and restart the Editor service to regenerate it from the environment file.

Runner cannot register

  • Verify the runner.url in the Runner's config.json points to the API server.
  • Ensure the registration code is valid and has not already been used.
  • Check that the Runner can reach the API server over the network.

Verification email not received

  • Check Sentinel logs for SMTP errors.
  • Verify SMTP settings in Sentinel's config.json.
  • Ensure notification.enabled is set to true.