Cordys CRM Review: A Self-Hosted AI CRM You Run With One Docker Command
🔥 Cordys 是由飞致云匠心打造的新一代的开源 AI CRM 系统,深度融合信息化、数字化与智能化能力,支持私有化部署,全面保障企业数据安全与主权。
At a glance
- What is it?
- Cordys CRM is a Spring Boot and Vue customer relationship management system from FIT2CLOUD, shipped as a single Docker image with a bundled BI layer and an open AI skills interface. The trade-off is a restrictive licence and a young feature set.
- Who is it for?
- Adopt Cordys CRM if you want a CRM you host yourself, you are comfortable with Docker on Linux, and you accept the FIT2CLOUD Open Source License terms, which forbid replacing the Cordys logo and copyright notices and require derivative works to stay under GPLv3. Do not adopt it if you need a mature partner and commission module set, if your procurement team requires an OSI-standard licence with no branding clause, or if you cannot run MySQL and Redis alongside the app.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 10 days ago.
- What is it written in?
- Mainly Java, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 20, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Cordys CRM Is For, and Who It Is Not For
Cordys CRM is a customer relationship management system built by FIT2CLOUD, the company behind JumpServer, 1Panel, MaxKB and DataEase. The README describes it as a new-generation open source AI CRM and positions private deployment as its main selling point: the data stays on infrastructure you control, and the project advertises an open API plus standard interfaces for custom integration.
The target reader is a sales or operations team inside an organisation that cannot or will not put its customer pipeline into a SaaS CRM. That constraint is usually regulatory, contractual, or internal policy. It matters because the alternative products in this space are almost all hosted, and the ones that are not hosted tend to be older and harder to extend.
It is a poor fit for a two-person team with no server. The README's own quick start assumes a Linux server with Docker installed. If nobody on your side can keep a container running, patch it, and watch disk usage on the mounted volume, the hosted option wins on total cost regardless of licence.
The feature set is also young. The repository's own roadmap shows the code was open sourced in November 2025 at v1.3.0, with contract, quotation and tender modules arriving in December 2025 and order, invoice, payment and business-registration modules in the first half of 2026. A CRM that gained its order module in 2026 is not the same animal as one that has carried orders for a decade.
The Architecture Behind the Docker Image
The stack is conventional and readable from the repository layout. The backend is Spring Boot, the frontend is Vue.js with Naive-UI and Vant-UI, and the middleware is MySQL plus Redis. Everything is packaged for Docker. The repository root holds separate backend, frontend and installer directories, a Maven wrapper (mvnw, mvnw.cmd) and a pom.xml, which tells you the build is Maven-based and that you can compile the backend yourself rather than only consuming the image.
Two ports are exposed. The README maps 8081 and 8082 to the host and tells you to open http://<your server IP>:8081/ in a browser. The README does not say what 8082 serves, so treat that as something to confirm in the online documentation rather than assume.
State lives on a bind mount: the container writes to /opt/cordys and the README maps it to ~/cordys on the host. That single directory is what you back up. It is also the thing that will fill your disk, since MySQL data and any uploaded files land there.
The intelligence layer is the part that differs from a conventional CRM. Cordys exposes a CRM Skills interface, published as a separate repository (1Panel-dev/CordysCRM-skills), and the README names OpenClaw and WorkBuddy as assistants that connect to it. There is also an MCP Server opened in v1.2.0 and a completed integration with MaxKB, FIT2CLOUD's agent platform. The BI side is DataEase, which the README says is fused into the product for sales-data visualisation. So the architecture is less a monolith with an AI button and more a CRM core with two documented extension surfaces: skills for assistants, and DataEase for reporting.
Installing Cordys CRM and Logging In for the First Time
The README gives a one-command install. It assumes a Linux host with Docker already present. The command runs the image in the background, restarts the container unless you stop it, publishes both ports, and mounts a host directory for persistence.
docker run -d \
--name cordys-crm \
--restart unless-stopped \
-p 8081:8081 \
-p 8082:8082 \
-v ~/cordys:/opt/cordys \
1panel/cordys-crmAfter it returns, the README says the first login is at http://<your server IP>:8081/ with the username admin and the password CordysCRM. Those are documented defaults, which means they are also public knowledge. Change the password before you expose the port beyond localhost, and think about whether 8081 should be reachable from the open internet at all on day one.
If your environment has no outbound network access, the README points to an offline installation package instead, and if you already run 1Panel, it points to the 1Panel app store as a third path. Those two routes are described in the online documentation rather than in the README itself, so the exact steps are not reproduced here.
Where Cordys CRM Is the Wrong Choice
The licence is the first real constraint, and it is not a formality. The README states the repository follows the FIT2CLOUD Open Source License, which it describes as essentially GPLv3 with additional restrictions. Two restrictions are spelled out: you may not replace or modify the Cordys CRM logo and copyright information, and any derivative work must comply with GPLv3's open source obligations. The repository metadata reports the licence as NOASSERTION, which is GitHub's way of saying it could not classify the file automatically. If your organisation has a policy against copyleft, or a white-label requirement that involves swapping the product mark, this project fails that policy regardless of how good the software is. The README does not address trademark use beyond the logo clause, and it does not discuss commercial licensing alternatives.
The second constraint is operational. There is no managed upgrade path described in the README. Releases are frequent (v1.9.0, v1.9.1 and v1.9.2 all landed within roughly three weeks), which is good for fixes and bad for anyone who wants to upgrade twice a year. The README does not document rollback, does not describe a migration procedure between major versions, and does not state a supported upgrade window. You are pulling a new image tag and hoping the schema migrations in the Spring Boot backend are forward-compatible with the data in ~/cordys. Test that on a copy of the volume first.
The third is scope. A CRM is not just contacts and deals. If your sales process depends on territory management, complex forecasting hierarchies, or a partner channel module, check the roadmap entries against your requirements list before you spend a weekend on the install. The roadmap is a list of what has shipped, not a commitment about what comes next.
Cordys CRM Versus SuiteCRM and EspoCRM
The obvious comparison is with the long-running self-hosted CRMs. SuiteCRM is a SugarCRM fork written in PHP, and EspoCRM is a lighter PHP application with a REST API and a well-known entity manager. Both have been deployed privately for years and both carry licences that are easier for a legal team to classify than the FIT2CLOUD Open Source License.
The difference in approach is where the intelligence lives. SuiteCRM and EspoCRM are record systems with APIs; anything AI-shaped is something you bolt on yourself, usually by pointing an external tool at their REST endpoints. Cordys ships the AI surface as a first-class part of the product: a documented CRM Skills interface with its own repository, an MCP Server opened in v1.2.0, and a named integration with MaxKB. If your plan is to have an assistant read and write CRM records, Cordys has already drawn that path, and the PHP alternatives have not.
The difference in reporting is similar. Cordys fuses DataEase, so BI is inside the product rather than a separate warehouse project. With SuiteCRM or EspoCRM you would typically export to a BI tool and model the data yourself.
The cost of that integration is coupling. A CRM that depends on DataEase for its analytics and on a skills interface for its AI features inherits those projects' release cycles. The README does not describe how tightly DataEase is embedded or whether it can be disabled, and it does not say what happens to the skills interface if the assistant side changes. That is the price of getting the integration for free.
Maintenance Cost, Licence Implications and What to Watch
The repository is not archived, and the last push was on 2026-09-20. Release cadence is high: v1.9.0 on 2026-08-28, v1.9.1 on 2026-09-11, v1.9.2 on 2026-09-17. For an operator, a three-week release rhythm means you should decide on a pinning policy before you deploy, not after. Pulling 1panel/cordys-crm without a tag gets you whatever was pushed most recently.
The maintenance surface is four things: the container, MySQL inside it, Redis inside it, and the ~/cordys volume. Backups are a copy of that directory plus a consistent database dump. The README does not describe a backup procedure, so the mechanism is on you.
On licence, the practical points are the two the README states: keep the logo and copyright intact, and keep derivative works under GPLv3. If you plan to embed Cordys in a product you sell, or to offer it as a hosted service, read the LICENSE file in the repository rather than the README summary, and get your own legal review. Nothing here is legal advice, and the README's own characterisation of the licence as "essentially GPLv3 with some additional restrictions" is a summary, not the terms.
One more thing worth checking before you commit: the repository carries an AGENTS.md file and a .codex directory at its root, alongside BUILD.md and a Maven wrapper. That suggests the project expects contributors to build from source and to work with coding agents. If you intend to fork and modify, that is a good sign. If you only intend to run the image, it changes nothing.
Editorial conclusion
Adopt Cordys CRM if you want a CRM you host yourself, you are comfortable with Docker on Linux, and you accept the FIT2CLOUD Open Source License terms, which forbid replacing the Cordys logo and copyright notices and require derivative works to stay under GPLv3. Do not adopt it if you need a mature partner and commission module set, if your procurement team requires an OSI-standard licence with no branding clause, or if you cannot run MySQL and Redis alongside the app. Before committing, verify three things: that the 8081 and 8082 ports are free on your host, that the default admin password has been changed after first login, and that the repository's LICENSE file matches what your legal reviewers expect, since the repository metadata reports the licence as NOASSERTION rather than a recognised identifier.
Frequently asked questions
How do I install Cordys CRM?
The README gives a single docker run command that starts the container in the background, publishes ports 8081 and 8082, and mounts ~/cordys on the host to /opt/cordys inside the container. It assumes a Linux server with Docker already installed. The README also mentions installing through the 1Panel app store or from an offline package for environments without network access.
What are the default login credentials for Cordys CRM?
The README states that after installation you open http://<your server IP>:8081/ and log in with the username admin and the password CordysCRM. Because those defaults are published, change the password before exposing the port beyond your own network.
What licence does Cordys CRM use?
The README says the repository follows the FIT2CLOUD Open Source License, which it describes as essentially GPLv3 with additional restrictions. Two restrictions are named: you cannot replace or modify the Cordys CRM logo and copyright information, and derivative works must comply with GPLv3. The repository metadata reports the licence as NOASSERTION, so check the LICENSE file directly.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/1panel-dev-cordyscrm)