Redmine is a tracker first
Redmine is a web application for issues organised into projects. Its long-lived strengths are configurable trackers, statuses, custom fields, roles, wikis, files, time entries and repository links. That makes it a credible home for engineering defects, internal requests and project coordination where the issue record needs to outlive a chat thread.
Use Redmine when teams can agree on a modest common vocabulary and want to operate the application themselves. Do not treat it as a blank canvas for every process in the company. A heavily customised instance can become difficult to upgrade, especially where plugins alter views, permissions or workflows.
Model work before installing plugins
Start with the objects people will use: projects, trackers, statuses, priorities, versions and user roles. A tracker answers what sort of record this is; a status answers where it is in a workflow. Keep those concepts separate. For example, Bug and Change request can be trackers, while New, In progress and Resolved are statuses.
Write one transition map per workflow. Include who may change status, who can edit a closed issue, and what happens if a reporter replies after closure. An administrator can make almost any configuration work in a demo. The harder test is whether an ordinary project member can file, find and update an issue without asking what each field means.
Choose a deployment shape with recovery in mind
The runtime, database, uploaded files and mail path are a single service from the user’s point of view.
| Component | Why it matters | What to test |
|---|---|---|
| Redmine application | Runs the Rails application and serves project data. | The configured public host and HTTPS scheme survive a restart and a reverse-proxy hop. |
| Database | Holds users, projects, issues, journals, settings and permissions. | A backup restores into an isolated instance and a sample issue history is intact. |
| File storage | Holds uploaded files and attachments outside the database. | Restored issues can open their expected attachments with normal user permissions. |
| Mail service | Sends invitations, password reset and issue notifications. | A non-administrator can receive a reset message and an assignment notification. |
| Reverse proxy and TLS | Provides the public boundary and client-facing transport security. | Direct application ports are not public and generated links use the intended URL. |
Put boundaries into roles and projects
Redmine permission decisions are easier to review when they match real responsibilities.
Project membership
Decide who can see each project before importing issues. Private projects, subprojects and cross-project visibility can surprise teams if default roles are too broad.
Tracker permissions
Allow people to create and edit the records they own. Keep workflow administration, user management and global configuration separate from routine issue work.
Custom fields
Add a field only when it changes a decision, report or hand-off. Each required field increases the chance that people enter filler merely to save an issue.
Repository connections
If repository integration is used, document its credentials, expected references and failure path. Repository browsing is useful; it should not become a hidden dependency for issue creation.
Treat plugins as part of the product
State the user problem, the plugin maintainer, the supported Redmine versions and the removal plan. If a feature can be handled with built-in configuration, prefer the built-in route.
Build a staging copy with the production database schema and plugin list. Review compatibility, run migrations according to the upstream instructions, then test issue creation, permissions, mail and attachments.
Check logs, background processing where configured, outgoing mail and representative project views. Keep a record of the release, plugins and any migration steps for the next maintenance window.
Protect access and project records
Use HTTPS for all user traffic and protect administrative paths with least-privilege accounts. Decide how Redmine accounts are created, disabled and reviewed. If external authentication is configured, test group and role mapping with a temporary account before assigning it to a live project. An identity integration can authenticate a person correctly while still giving them the wrong project access.
Keep application secrets and database credentials outside source control. Restrict direct database access, restrict backup access, and review attachment handling. A project tracker often contains incident notes, design files or customer references. Its data classification should reflect what teams put into it, not merely the fact that it is called project management.
Move issues without losing their meaning
Inventory the source system by project rather than treating every record alike. Decide which projects are active, which are archives, which comments and attachments must move, and whether original identifiers need to stay searchable. Map source status values to the target workflow before the import. A direct copy of old labels can create a board nobody understands.
Run a pilot with one active project. Ask its owner to check open issues, resolved issues, authors, timestamps, watchers, files and links. Freeze or redirect new work only for that project at cutover. Leave the source readable until the agreed checks pass and publish a clear answer to the question users will ask: where do I create the next issue?
What the operating team owns
A Redmine instance ages through configuration changes as much as software releases. Keep the operational record close to the system.
Configuration record
- List trackers, workflows, roles, required fields and project templates.
- Record why each global setting or plugin exists.
- Review defaults after major team or policy changes.
Backup and restore
- Back up database data and attachments together.
- Protect backup copies with the same care as production project data.
- Restore into an isolated environment on a schedule you can sustain.
User support
- Provide a route for access requests and wrongly assigned roles.
- Document mail-notification troubleshooting.
- Name the person who approves workflow changes.
Upgrade record
- Keep the runtime, database and plugin versions together.
- Test the configured plugin set before each production upgrade.
- Record the restore point and rollback decision for the change.
Practical Redmine questions
Should every department get its own tracker names?
Usually no. Start with a shared set such as Bug, Feature and Task only when those words carry the same meaning for the people who report and resolve them. Add a local tracker when it supports a real permission or workflow distinction.
Can we test an upgrade only in production?
That makes plugin and migration failures user-facing. Test the intended Redmine version, runtime and plugin list against representative data in a separate environment, then schedule production work with a rollback decision.
What is a complete backup?
For Redmine, it includes the database and uploaded files, plus the configuration and procedure needed to restore the public URL, mail settings and integrations. A database dump alone is not enough for a file-heavy project.
Who should approve a workflow change?
The owner of the affected process should approve it, while the Redmine administrator checks its technical impact. A small change to a status transition can alter what reporters, managers and external collaborators are able to do.
What makes the work larger
The effort depends less on installing Redmine than on the existing process and data. Multiple departments with separate workflows, a wide permission model, old records with many attachments, custom plugins, identity integration and stringent recovery expectations all add design and testing work. Be explicit about those drivers when you set the rollout scope.
Name an application owner, a database or platform owner, a workflow owner and a support contact. One person can hold more than one role, especially at first. The point is that a user with a stuck issue knows who can fix the process and who can fix the service.

