Craftplan: a self-hosted ERP for artisanal D2C makers
Self-hosted software for managing artisanal D2C micro-businesses
At a glance
- What is it?
- Craftplan is an AGPL-3.0 Elixir and Phoenix application that bundles catalog, BOM, inventory, production, purchasing and CRM for small-batch manufacturers. Here is what the repository actually documents, and where it stops.
- Who is it for?
- Adopt Craftplan if you run a small-batch food, beverage or craft operation and you are willing to run PostgreSQL and an S3-compatible store yourself; a docker compose up -d against the published compose file is the whole install. Do not adopt it if you need multi-currency accounting, a mobile client, or an ERP whose documentation covers upgrades and rollback, because the README documents none of those.
- Can I use it commercially?
- Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 3 days ago.
- What is it written in?
- Mainly Elixir, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Craftplan solves for a one-person production kitchen
A small food or craft producer usually ends up with a spreadsheet for recipes, a second spreadsheet for stock, an invoicing tool, and a notebook for orders. Craftplan's stated goal is to collapse that into one platform: catalog management, inventory control, order processing, production planning, purchasing and CRM, so a maker does not pay for several separate subscriptions. The audience is narrow and the README is explicit about it. This is an ERP for small-scale artisanal manufacturers and craft businesses, not a generic system adapted downward. That distinction shows up in the feature list. Allergen and nutritional fact tracking is a first-class field, which matters if you sell packaged food and need to produce nutrition labels. Bills of Materials are versioned, with older versions read-only and automatic cost rollups across nested BOMs, which is the shape of a recipe that changes between batches. Labor steps carry time and cost. If your business is a Shopify store reselling someone else's goods, most of this is dead weight.
Ash Framework, LiveView and the BOM cost rollup
The stack is Elixir, Phoenix LiveView, PostgreSQL, Tailwind, and the Ash Framework. Ash is the part that determines how the application behaves at the edges: resources, policies and actions are declared rather than hand-written, which is why the README can claim policy-based authorization on all resources and JSON:API plus GraphQL endpoints from the same definitions. In practice, a product points at a versioned Bill of Materials; that BOM references nested BOMs and raw materials; the cost rollup walks the tree and produces a cost figure. Editing creates a new version and freezes the old one, so historical batch costs stay reproducible. Production batches then consume materials automatically and store a cost snapshot at the moment of production, which is the mechanism that keeps a price change in a supplier's material from silently rewriting last month's margin. Inventory tracks lots for traceability and records movements as consume, receive or adjust. Purchasing receives goods into stock and creates lots. Orders allocate line items to production batches, and the calendar-based scheduling feeds an iCal subscription URL that covers order deliveries and batch schedules. The API keys and email provider credentials are encrypted at rest, with CLOAK_KEY in .env.example being the AES key behind that.
Installing Craftplan with Docker Compose
The README says you do not need to clone the repository. You download two files, copy the environment template, fill in the secrets, and start the stack. The compose file pulls ghcr.io/puemos/craftplan:latest and starts Craftplan, PostgreSQL 16 and MinIO, with migrations running automatically. The web interface is then reachable at http://localhost:4000.
curl -O https://raw.githubusercontent.com/puemos/craftplan/main/docker-compose.yml
curl -O https://raw.githubusercontent.com/puemos/craftplan/main/.env.example
cp .env.example .env # Fill in the required secrets (see .env.example)
docker compose up -dFour values in .env.example are marked required and the file gives the exact commands to produce three of them. SECRET_KEY_BASE and TOKEN_SIGNING_SECRET are both 48 random bytes, base64-encoded; CLOAK_KEY is 32 bytes; POSTGRES_PASSWORD is the password for the bundled database container.
openssl rand -base64 48 # SECRET_KEY_BASE
openssl rand -base64 48 # TOKEN_SIGNING_SECRET
openssl rand -base64 32 # CLOAK_KEYThe compose file also sets HOST and PORT, defaulting to localhost and 4000, and wires the application to MinIO using AWS_S3_SCHEME, AWS_S3_HOST, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_S3_BUCKET. Those MinIO credentials default to minioadmin, which is fine for a first run on a laptop and wrong for anything reachable from the internet. After the containers come up, the first real task is a CSV bulk import of products, materials and customers, since the README lists CSV import as the supported path for getting existing data in. The self-hosting guide linked from the README covers single-container mode, Railway deployment and reverse proxy setup.
Where Craftplan stops: upgrades, backups and small-team limits
The compose file pins the image to the latest tag, and the README does not document rollback, a migration downgrade path, or a tested upgrade sequence between releases. Given that v0.7.0, v0.6.4 and v0.6.3 all landed within two days of each other in early September 2026, that gap matters more than it would for a project with a slow release cadence: you are tracking a moving image. There is no backup or restore documentation in the README either, and the state lives in two places, the postgres_data volume and the MinIO bucket, so a naive pg_dump alone will not capture product photos. Access control is two roles, admin and staff, with policy-based authorization underneath. There is no mention of multi-currency, tax filing, payroll, or a mobile application. The calendar feed is read-only, an .ics subscription, so it is not a two-way sync with Google Calendar. And the whole thing assumes you can operate PostgreSQL and an S3-compatible object store; if that is not true, a hosted inventory tool will cost less than your time.
Craftplan versus a generic open source ERP
The obvious comparison is Odoo Community, the general-purpose open source ERP that covers manufacturing, inventory, sales and accounting in one codebase. The difference is not feature count, it is the shape of the data model. Odoo models manufacturing as work centers, routings and MRP runs, which is the right vocabulary for a factory and an awkward one for someone who makes forty jars of jam a week. Craftplan inverts that: the versioned BOM with nested cost rollup and the allergen and nutritional fields are the center of the model, and financial accounting is simply absent from the feature list. That is a real trade-off, not a marketing one. If you need double-entry bookkeeping, VAT handling or a purchase-to-pay ledger inside the same system, Craftplan will not replace your accountant's tool, and Odoo or ERPNext will. If you need a nutrition label and a per-batch cost snapshot for a product whose recipe changes seasonally, the generic ERPs make you model that yourself.
Licence and the cost of running Craftplan yourself
Craftplan is licensed under AGPL-3.0, and the README points at the LICENSE file. For a maker running it on their own server for their own business, the practical effect is that you receive the source and can modify it. The clause that catches people is the network one: if you modify Craftplan and let other users interact with it over a network, the AGPL's source-availability expectation applies to your modified version. That is a summary of the licence's intent, not legal advice; read the LICENSE file and talk to a lawyer if you plan to offer a modified Craftplan as a service. The upgrade cost is the other half. Releases arrive frequently, the compose file tracks latest, and there is no documented rollback, so the honest position is that you should read the release notes for each version before pulling, and take a database and object-store snapshot you know how to restore, because the project does not tell you how.
Editorial conclusion
Adopt Craftplan if you run a small-batch food, beverage or craft operation and you are willing to run PostgreSQL and an S3-compatible store yourself; a docker compose up -d against the published compose file is the whole install. Do not adopt it if you need multi-currency accounting, a mobile client, or an ERP whose documentation covers upgrades and rollback, because the README documents none of those. Before you commit, verify three things on your own hardware: that the four required secrets in .env.example validate at boot, that your chosen email provider is one of the six listed, and that your backup routine captures both the postgres_data volume and the MinIO bucket, since the README describes neither backup nor restore.
Frequently asked questions
What is Craftplan and who is it for?
It is an open source ERP for small-scale artisanal manufacturers and craft businesses, covering catalog, BOM, inventory, orders, production, purchasing and CRM in one self-hosted platform. The README frames it for makers who want to avoid paying for several separate tools.
How do I install Craftplan?
The README gives a Docker Compose install that does not require cloning the repository: download docker-compose.yml and .env.example, copy the example to .env, fill in the required secrets, and run docker compose up -d. That starts Craftplan with PostgreSQL and MinIO, and the app is available at http://localhost:4000.
Which secrets does Craftplan require before it starts?
.env.example marks SECRET_KEY_BASE, TOKEN_SIGNING_SECRET, CLOAK_KEY and POSTGRES_PASSWORD as required, and gives openssl commands to generate the first three. CLOAK_KEY is the 32-byte AES key used to encrypt API keys and email credentials at rest.
Does Craftplan support an API?
The README lists JSON:API and GraphQL endpoints for programmatic access, with API key authentication and encrypted storage of those keys, plus CORS configuration. The documentation links to a separate API reference page.
How is Craftplan licensed?
It is licensed under AGPL-3.0, per the README and the LICENSE file in the repository. The AGPL's network clause is the part to read carefully if you intend to run a modified version for other users.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/puemos-craftplan)