Running an ERP system for a business in Kenya often comes with significant friction: complex server management, manual KRA eTIMS tax compliance, fragmented M-Pesa payment reconciliations, and identity management headaches.
At JengaStack, our mission is to eliminate this complexity. We've built a managed SaaS platform that automates Odoo 19 hosting, localized tax compliance, payment gateways and enterprise security.
🎯 The Problem
Kenyan SMEs and growing enterprises face three primary operational hurdles when adopting ERP systems:
- Local Statutory Compliance: Setting up KRA eTIMS tax categories, PIN validation and compliant invoice formatting in standard open-source ERPs is tedious and error-prone.
- Payment Disconnect: Integrating local payment gateways like M-Pesa (Daraja) usually requires custom, unmaintained modules.
- Infrastructure Overhead: Self-hosting Odoo requires managing PostgreSQL databases, reverse proxies, SSL certificates, backup schedules, and monitoring.
⚙️ How JengaStack Solves It
We engineered a multi-tenant platform powered by a Django + HTMX dashboard orchestrating isolated Odoo 19 tenant stacks.
1. Automated Kenyan Statutory Provisioning
When a new tenant signs up, JengaStack automatically provisions an isolated Odoo environment pre-configured with:
-
Currency & Locale: Activated KES (
KSh) withAfrica/Nairobitimezone andDD/MM/YYYYformatting. -
Kenyan Chart of Accounts: Pre-loaded
l10n_kepackage. - KRA Tax Categories: Out-of-the-box support for 16% Standard VAT (Code A), 0% Zero-Rated (Code B), Exempt (Code C), 8% Fuel Tax, Withholding Tax (WHT) and WHVAT.
- Localized Layouts: Pre-formatted A4 statutory invoice and quote layouts featuring KRA PIN fields.
2. Native M-Pesa Integration
Through our custom jenga_mpesa module, tenants accept M-Pesa STK push and C2B payments directly at checkout or via invoice payment links. Transactions automatically reconcile into Odoo’s general ledger in real time.
3. Enterprise Identity & Security (Authentik SSO)
We integrated Authentik OIDC using standard PKCE Authorization Code Flows (RFC 7636). Users sign in once via Jenga ID to access their management dashboard and Odoo workspace seamlessly without handling insecure credentials.
4. Robust Cloud Infrastructure (Azure + Traefik + PgBouncer)
Our multi-VPS production architecture on Azure separates controller services from tenant worker nodes:
- Edge Proxy: Traefik dynamically routes domain requests and handles automatic TLS certificates.
- Database Scaling: PgBouncer provides connection pooling for high concurrency.
- Continuous Monitoring: Alertmanager integrated with Telegram and Grafana ensures instant notification on infrastructure state.
-
Two-Lane Email Architecture: System notifications leverage Brevo SMTP (
noreply@jengastack.app), while customer communications direct to Zoho Mail support.
Key Technical & Product Highlights Featured:
• Mission: Managed Odoo Hosting & Automated Compliance for Kenya.
• Localization: KRA eTIMS (16%, 0%, Exempt, 8% Fuel, WHT, WHVAT), l10n_ke, KES (KSh), EAT
timezone (Africa/Nairobi).
• Payments: Native M-Pesa (Daraja) integration.
• Security: Authentik OIDC with PKCE authorization flow (RFC 7636).
• Stack: Django, HTMX, Odoo 19, Traefik, PgBouncer, Tailscale, Komodo, Azure.
🚀 What's Next?
We are rolling out early access for Kenyan businesses, accounting firms, and IT integrators who want hassle-free ERP deployment.
- 🌐 **Website:** https://jengastack.app
- 📖 **Documentation:** https://docs.jengastack.app
Have questions about our architecture or want a demo? Reach out to support@jengastack.app or connect with us on LinkedIn!
──────
Top comments (0)