HashiCorp Vault
With over 36,000 GitHub stars and adoption by organizations including Adobe, Shopify, and Roblox, HashiCorp Vault is the industry-standard platform for secrets management, encryption services, and privileged access control across hybrid and multi-cloud infrastructure. The key/value secrets engine stores arbitrary secrets with full versioning, soft-delete, and metadata tracking, while dynamic secrets engines generate on-demand, short-lived credentials for AWS, Azure, GCP, databases including PostgreSQL, MySQL, MongoDB, and MSSQL, and SSH access with automatic revocation after configurable lease periods. The PKI secrets engine dynamically issues X.509 certificates on demand with automatic rotation and ACME protocol support, eliminating manual certificate management workflows entirely. Encryption as a service through the transit secrets engine lets applications encrypt, decrypt, sign, verify, and generate HMACs without managing cryptographic keys directly, supporting AES-GCM-256, ChaCha20-Poly1305, RSA-2048/4096, ECDSA-P256/P384, and ED25519 algorithms. Authentication integrates with LDAP, OIDC/OAuth2, SAML, AppRole for machine-to-machine access, Kubernetes service accounts, AWS IAM, Azure Active Directory, and GitHub tokens. Fine-grained ACL policies use path-based rules with glob patterns and sentinel policies for programmatic enforcement. The integrated Raft storage backend provides high-availability clustering without external dependencies, while alternative backends include Consul, S3, DynamoDB, PostgreSQL, and MySQL. The built-in web UI provides a visual interface for browsing secrets, managing policies, configuring auth methods, and monitoring cluster health. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSL 1.1 licensed.
Focalboard
From the Mattermost team comes Focalboard, an open-source, MIT-licensed project board tool - a self-hosted alternative to Trello, Asana, and Notion databases, written in Go with a React frontend. Every board renders the same card data four ways: Kanban with drag-and-drop columns, a spreadsheet-style table, an image-forward gallery, and a calendar. Cards carry unlimited custom properties - dates, dropdowns, checkboxes, people, URLs - and boards can be grouped, filtered, and sorted by any property combination, with unlimited saved filtered views for quick access. Built-in templates cover the common workflows (meeting agendas, content calendars, project tasks, roadmaps, sprint planning), or you can build fully custom boards from scratch. Collaboration is real: card comments with @mentions, per-board permissions for teams or individuals, file attachments stored on your own infrastructure, and archiving with backup snapshots. Migration tooling imports existing boards from Trello (JSON export), Asana, and Notion, so switching does not mean starting over. It ships in 20+ languages and runs as a lightweight multi-user personal server. Worth knowing before deploying: Mattermost has shifted primary development to the integrated Mattermost Boards plugin, so the standalone edition is community-maintained - stable and functional, but evolving slowly. For teams wanting a free, private Trello without per-user fees, it remains a solid pick.
CockroachDB
With over 32,000 GitHub stars and adoption by DoorDash, Netflix, and Bose, CockroachDB is the distributed SQL database designed to survive disk failures, machine outages, rack losses, and entire datacenter failures while maintaining strongly-consistent ACID transactions with serializable isolation by default. The architecture layers SQL on a transactional key-value store using the Raft consensus protocol for synchronous replication, automatically splitting data into ranges that distribute and rebalance without manual sharding. PostgreSQL wire protocol compatibility means existing drivers, ORMs, and tools including psycopg2, pgx, ActiveRecord, Django ORM, GORM, Hibernate, and Prisma work without modification. Multi-region capabilities include configurable survival goals at region or zone level, table-level locality settings for pinning data to specific geographies for GDPR compliance, and follower reads for low-latency global queries. The built-in DB Console provides cluster overview dashboards, node maps showing geographical distribution, SQL activity pages tracking statement fingerprints, transaction latency percentiles, session details, and real-time metrics for queries per second, storage capacity, and replication status. Change data capture streams row-level changes to Apache Kafka, Google Cloud Pub/Sub, or webhook endpoints for event-driven architectures. Online schema changes execute ALTER TABLE without locking or downtime, and distributed backup supports full and incremental snapshots to S3, GCS, Azure Blob, and NFS. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. CockroachDB Software License (source-available).
MeterSphere
MeterSphere is the open-source continuous testing platform that brings test management, API testing, and AI-powered automation into a single self-hosted environment. The Spring Boot Java backend handles test execution with the JMeter engine while the Vue.js frontend delivers a responsive interface for managing test cases, plans, defects, and reports across projects. The built-in AI assistant leverages large language models to auto-generate functional test cases and API interface definitions, reducing manual test creation effort. Test management covers the complete lifecycle from writing and reviewing cases in list or mind-map views, through test plan creation with single plans and plan groups, to defect tracking with customizable templates and workflow rules. API testing combines Postman-like ease of use with JMeter-level flexibility, supporting interface debugging with server-side and local execution, API definition with visual request and response editors, interface mocking with configurable headers and body parameters, scenario automation with visual orchestration, and detailed test reports with automatic generation. The system-organization-project hierarchy supports up to 30 users in the community edition with role-based access control, file management, and configurable notification channels. MySQL stores application data, Kafka handles message queuing, MinIO provides S3-compatible object storage, and Redis manages caching. The plugin marketplace extends testing capabilities and enables DevOps pipeline integration. On RepoCloud, deploy MeterSphere on a dedicated VPS with Docker, root SSH access, and complete control over your testing infrastructure, all under the GPLv3 license.
Discourse
Created by Jeff Atwood, co-founder of Stack Overflow, and battle-tested for over a decade with 47,600+ GitHub stars, Discourse powers community forums for GitHub, Docker, Rust, Netlify, and thousands of organizations worldwide. The platform combines long-form threaded discussion with built-in real-time chat, enabling communities to move fluidly between asynchronous conversations and live interaction. Five automated trust levels progressively unlock permissions — posting links, editing wiki posts, flagging content, and moderating — based on reading time, post count, and community engagement, reducing spam and abuse without manual intervention. The Discourse AI plugin integrates with OpenAI, Anthropic, and self-hosted HuggingFace endpoints for automated topic summarization, sentiment analysis, semantic search, and AI-assisted content triage. Over 200 official and community plugins extend functionality with features like the Data Explorer for ad-hoc SQL queries against the forum database, polls, solved-topic marking, voting, calendar events, and custom user fields. SSO and OAuth support connects Google, Facebook, Apple, GitHub, and SAML identity providers, while reply-by-email and mailing list mode let users participate entirely through their inbox. The Ember.js single-page frontend delivers responsive performance across all devices with PWA support and web push notifications. Deployment uses Docker via the official discourse_docker launcher with automatic Let's Encrypt HTTPS, resource scaling based on server hardware, and support for single-container or multi-container configurations. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL v2.0 licensed.
Apache Answer
Graduated as an Apache Software Foundation Top-Level Project with over 15,500 GitHub stars and 100,000+ Docker Hub downloads, Apache Answer delivers the structured Q&A platform that Stack Overflow and Discourse popularized — fully self-hosted under Apache 2.0 with zero vendor lock-in. The Go backend with React frontend serves questions, answers, and knowledge articles with real-time Markdown preview using CommonMark syntax, inline @mentions to ping domain experts, and transparent revision history tracking every edit. Version 2.0 introduced AI workflows including an integrated AI assistant that helps draft and improve answers, a Model Context Protocol server for connecting AI agents to your knowledge base, API key management, and editor plugin support for extending the writing experience. Advanced search filters by tags, usernames, scores, and date ranges, while real-time suggestions surface relevant existing questions as users type to reduce duplicates. The reputation system rewards quality contributions with configurable privilege thresholds, and admin/moderator/user roles control access across the platform. A plugin architecture enables community-built extensions for third-party OAuth login, caching backends, search engines, and storage providers. Theming supports custom layouts, dark mode, and responsive design across devices, with content available in 15+ languages translated by the community. Bulk user import, email domain restrictions, and content access controls secure the platform for enterprise deployment. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Dolibarr
With 7,400+ GitHub stars, 280+ contributors, and 99 releases spanning 15 years of active development since 2011, Dolibarr is the modular ERP and CRM platform that scales from freelancers tracking invoices to manufacturing companies managing full production workflows — all within a single PHP application requiring only a web server and database. Enable exactly the modules your business needs: CRM with leads, proposals, and online contract signing; invoicing with customer and supplier management, credit notes, and SEPA direct debit; double-entry accounting with bank reconciliation and margin analysis; stock and warehouse management with barcode scanning, batch and lot tracking, and product variants; bill of materials and manufacturing orders with workstation scheduling; HR with employee records, leave management, expense reports, recruitment pipelines, and timesheets; project and task management with shared iCal calendars; and a ticket system with integrated knowledge base for customer support. TakePOS provides a touch-optimized point-of-sale interface for retail shops, bars, and restaurants with floor and table management, QR code self-ordering, automatic stock decrements, and Stripe terminal integration. Payment processors connect via PayPal, Stripe, and Paybox. The marketplace offers over 1,000 third-party add-ons, and the low-code Module Builder enables custom extensions without programming. Deploy via the official Docker image with MariaDB, DEB and RPM packages for Linux, or manual installation on any PHP-capable server. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
osTicket
With nearly 3,900 GitHub stars, over 1,800 forks, and continuous development since 2013 culminating in the v1.18.4 release in June 2026, osTicket remains one of the most deployed open-source help desk systems worldwide, trusted by organizations from small businesses to universities and government agencies. The PHP backend on Apache or IIS with MySQL stores every ticket, response, and attachment while the web interface provides separate agent and customer portal views with role-based access control across departments, teams, and individual agents. Customers submit tickets through web forms, email piping, or phone-entry by agents, and configurable ticket filters automatically route incoming requests to the correct department, assign agents or teams, set priority levels, apply SLA plans, and trigger canned responses based on matching criteria including custom field values. Agent collision avoidance locks tickets during response composition to prevent duplicate replies, while SLA plans with business hour schedules track due dates and escalate overdue tickets automatically. Custom forms and fields let organizations capture structured data specific to each help topic — from IT asset tags to billing account numbers — with configurable required and internal-only visibility. The advanced search system with saved queries and CSV export enables reporting across all ticket metadata and custom fields. The customer portal provides ticket tracking, profile management, and knowledge base access. OAuth2 plugin support enables modern email authentication with Microsoft 365 and Google. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-2.0 licensed.
Graylog
Trusted by over 60,000 organizations worldwide with more than 8,100 GitHub stars since 2010, Graylog has established itself as one of the fastest paths from raw log data to operational visibility, delivering centralized log management, security analytics, and compliance auditing through a purpose-built web interface with sub-second search at scale. The platform ingests logs from virtually any source via syslog, GELF, Beats, raw TCP/UDP, HTTP, CEF, IPFIX, and Netflow protocols, processing each message through configurable pipelines that parse fields, apply transformations, enrich events with GeoIP data from MaxMind or IPinfo lookup tables, and route messages to appropriate streams based on content rules. OpenSearch handles full-text indexing and storage with dynamic shard sizing that automatically calculates appropriate sizes from available node memory, while MongoDB stores configuration metadata including user accounts, roles, dashboards, alert rules, and pipeline definitions. The alerting system integrates with Slack, PagerDuty, and email with customizable notification templates and Replay Search links for immediate investigation context. Version 7.0 introduced MCP server integration for connecting preferred LLMs to perform AI-assisted log analysis and automation, while version 7.1 added Sigma detection rule import from private GitHub, GitLab, and Bitbucket repositories for detection-as-code workflows. The Sidecar agent management system centrally configures and deploys Filebeat, Winlogbeat, and nxlog collectors across infrastructure from the Graylog web interface. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. SSPL licensed.
Payload CMS
Backed by 44,000 GitHub stars and now part of Figma, Payload is the first headless CMS that installs natively into your Next.js application's /app directory rather than running as a separate service. The code-first architecture uses TypeScript config files to define collections, globals, and field schemas — from which Payload auto-generates database tables with migrations, a fully customizable React admin panel, REST and GraphQL endpoints, and type-safe Node.js local APIs you can call directly in React Server Components. The Lexical-based rich text editor supports block-based layout building, inline media embeds, and nested field structures, while the built-in localization engine handles unlimited locales with field-level translations. Authentication ships out of the box with HTTP-only cookie sessions, CSRF protection, role-based access control definable at the document, field, and operation level, and support for OAuth providers. Version history tracks every document change with full draft and publish workflows, and Live Preview renders content edits in real-time using server components. The job queue system manages background tasks and multi-step workflows deployable via Vercel Cron or standalone workers. Database flexibility spans PostgreSQL, MongoDB, and SQLite through swappable adapters, and the plugin ecosystem includes official modules for SEO, form builders, redirects, nested documents, and search alongside hundreds of community extensions. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
HashiCorp Consul
With nearly 30,000 GitHub stars and deployment across organizations including Criteo, Pandora, and Barclays, HashiCorp Consul is the industry-standard platform for service discovery, service mesh, and distributed configuration across dynamic multi-cloud and multi-datacenter infrastructure. Services register themselves and become discoverable via a built-in DNS interface on port 8600 or an HTTP API on port 8500, with health checks ensuring only healthy instances receive traffic through automatic catalog deregistration and service-level circuit breaking. The service mesh capabilities use Envoy sidecar proxies with Transparent Proxy mode to establish automatic mTLS encryption for all service-to-service communication, while identity-based intentions define fine-grained authorization rules controlling which services can communicate. The integrated API Gateway manages north-south traffic into the mesh with configurable routing rules, TLS termination, and header-based matching policies. Consul's distributed key-value store provides hierarchical configuration storage accessible via CLI, HTTP API, and the built-in web UI, with blocking queries enabling watch-based configuration updates without polling. Multi-datacenter federation connects Consul clusters across regions through WAN gossip and RPC forwarding, enabling cross-datacenter service discovery and failover with configurable prepared queries. The Raft consensus protocol provides strong consistency for the service catalog and KV store, with anti-entropy mechanisms ensuring agent state converges with the server catalog. Consul integrates natively with Kubernetes via Helm charts with automatic sidecar injection, Nomad for workload orchestration, Vault for secrets management, and Terraform for infrastructure provisioning. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BUSL 1.1 licensed.
EverShelf
That yogurt hiding behind the ketchup expired three weeks ago, and the flour you bought "just in case" has been sitting in the pantry since last winter. EverShelf replaces mental guesswork with a structured inventory system that tracks every item across pantry, fridge, freezer, and custom locations with precise quantities, expiry dates, and consumption patterns. Scan barcodes with your phone camera to add products instantly, or let the Gemini AI identify items from a photo and estimate shelf life based on storage location. The dashboard surfaces expired items and upcoming expirations with color-coded urgency badges, while anomaly detection flags suspicious quantities and consumption predictions that deviate from your history. Opened products get reduced shelf-life calculations; vacuum-sealed items get extended dates automatically. The recipe engine generates context-aware meal suggestions from your current inventory, prioritizing ingredients approaching expiry so nothing goes to waste; each recipe includes step-by-step cooking mode with text-to-speech narration and timer integration. A smart shopping list auto-populates when stock hits zero and syncs bidirectionally with the Bring! app, with AI-estimated prices per item and consumption forecasts showing when you will need to restock. For Home Assistant users, a native HACS integration provides 22 sensors, expiry calendars, bidirectional todo-list sync, and voice assistant support for adding items hands-free. A dedicated Kiosk mode optimizes the interface for wall-mounted tablets with BLE scale integration. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Docmost
Confluence and Notion both want your team's documentation in their cloud; Docmost, an open-source collaborative wiki platform, keeps it on your server. The centerpiece is a Notion-style block editor with CRDT-based real-time collaboration: multiple people edit the same page simultaneously and changes merge without conflicts or overwrites. Content lives in spaces - per team, project, or department - with nested page trees, role-based permissions, groups, inline comments, page history with restore, and full-text search across everything. The editor covers tables, code blocks, callouts, KaTeX math, and file attachments, and diagramming is built in rather than bolted on: Mermaid, Draw.io, and Excalidraw all render inside pages, alongside embeds for Airtable, Loom, Miro, and more. Migration paths include Notion, Markdown, HTML, and ZIP archive imports (Confluence, PDF, and DOCX importers ship in the Enterprise edition, along with SSO via SAML/OIDC/LDAP and MFA). The stack is TypeScript with PostgreSQL and Redis, deploys via Docker Compose, runs in air-gapped environments with no external dependencies, and is translated into 10+ languages. The AGPL-3.0 community edition carries no per-seat fees; the project has passed 20,000 GitHub stars since its 2024 launch.
Grist
With over 11,200 GitHub stars and adoption by France's sovereign digital workspace LaSuite serving 20,000+ government users, Grist is the relational spreadsheet that ends the false choice between fragile Excel files and expensive custom database development — storing all data in portable SQLite files while providing true relational structure where VLOOKUPs become actual linked records that update instantly across entire documents. Python-powered formulas replace complex Excel syntax with clear, readable logic using the full Python standard library, while familiar Excel functions remain available for users who prefer them. Granular access rules control permissions at row, column, table, and cell levels — not just entire sheets — enabling multi-department documents where each team sees only their authorized data. The flexible layout system combines spreadsheets, card views, charts, calendars, and custom widgets on configurable dashboard pages that transform raw data into operational interfaces. Real-time collaboration lets multiple users edit simultaneously with automatic snapshot history capturing every change for full audit trails and point-in-time recovery. AI formula assistance connects to OpenAI, Llama, or any OpenAI-compatible endpoint via OpenRouter to generate formulas from natural language descriptions. The REST API and webhooks enable integration with n8n, Zapier, and custom automation, while incremental imports keep external data sources synchronized. Deployable via Docker with OIDC, SAML, and SCIM authentication support. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Blinko
With over 10,800 GitHub stars earned in under two years, Blinko has emerged as the privacy-first answer to cloud-dependent note-taking tools by combining instant thought capture with AI-powered retrieval that actually understands what you wrote rather than just matching keywords. The core engine uses Retrieval-Augmented Generation to build vector embeddings of every note in your PostgreSQL database, enabling natural language queries like "what were my thoughts on the database migration last Tuesday" to surface relevant content through semantic understanding rather than exact string matching. AI integration supports both cloud providers — OpenAI, MiniMax, and compatible endpoints — and fully local inference through Ollama running models like Llama 3.2 on your own hardware, ensuring your notes never leave your network when privacy demands it. Built on Next.js with a React frontend, the web interface presents notes as cards with full Markdown support including code blocks, LaTeX, and rich formatting, with a clean input bar for capturing fleeting thoughts in seconds. The Tauri-based desktop and mobile clients extend access to macOS, Windows, Linux, and Android with native performance characteristics. Notes are stored as plain text in PostgreSQL with vector indexes that update incrementally as new content arrives, and the embedding index can be rebuilt on demand when switching between AI providers. Multiple users can share a single instance with individual accounts, and data exports to standard formats. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
Wagtail
Backed by over 20,000 GitHub stars, 800 contributors, and organizations like Google, NASA, and the NHS, Wagtail is the Django-powered content management system that gives editors creative freedom through StreamField while keeping developers in full control of data structure and front-end rendering. StreamField lets editors compose pages from a custom library of content blocks — rich text, images, embedded videos, tables, code snippets, and developer-defined custom types — without compromising the underlying data model or breaking responsive layouts. The built-in JSON API supports headless deployments with versioned endpoints for pages, images, and documents, enabling decoupled front-ends in Next.js, Nuxt.js, or any framework that consumes REST. Editorial workflows provide configurable approval chains where content moves through draft, review, and publish states with commenting, task assignment, and email notifications built into the admin interface. Integrated search connects to Elasticsearch for full-text indexing with faceted filtering, or falls back to PostgreSQL and SQLite backends with fuzzy matching support added in v7.4. Multi-site management serves multiple domains from a single Wagtail installation with independent page trees, while the internationalization framework handles content translation with locale-aware URL routing. Image management includes focal point detection, responsive renditions, and automatic format conversion. The platform supports Django 5.2 and 6.0 with Python 3.10 through 3.14 and PostgreSQL, MySQL, MariaDB, or SQLite databases. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD-3-Clause licensed.
Maintenant
Maintenant replaces three to five separate monitoring tools with a single Go binary that consolidates container discovery, endpoint monitoring, SSL tracking, resource metrics, and public status pages without requiring any external database. The embedded Vue 3 frontend serves on port 8080 immediately after deployment, auto-discovering Docker containers and Kubernetes pods through direct socket and API access without configuration. HTTP and TCP endpoint monitoring validates availability with configurable intervals, while TLS certificate tracking alerts before expiration across all monitored domains. Resource metrics collect CPU, RAM, network throughput, and disk usage per container with real-time Server-Sent Events streaming to the dashboard. Heartbeat and cron monitoring accepts pings from external scheduled jobs, triggering alerts on missed check-ins via webhook callbacks and Discord notifications. The built-in alert engine supports escalation rules and notification batching. Public status pages expose component health to end users without authentication, customizable per monitored service. Network security insights analyze exposed ports, container privilege levels, and host configuration to produce a posture score. Update intelligence scans OCI registries to detect available container image updates with digest comparison. The REST API with SSE broker enables automation, and the integrated MCP server provides tooling for AI assistant integration. SQLite in WAL mode stores all data with zero operational overhead. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
GLPI
GLPI combines helpdesk ticketing, hardware inventory, license compliance, CMDB, and project management in a single PHP application with over 6,200 GitHub stars and 500,000+ Docker pulls, offering a unified ITSM platform that replaces ServiceNow, Freshservice, and ManageEngine without per-agent pricing. The ITIL-aligned service desk handles incidents, problems, changes, and service requests with configurable SLA management, approval workflows, satisfaction surveys, and business rules that automate ticket routing, escalation, and categorization. Native dynamic inventory through the GLPI Agent discovers Windows, Linux, and macOS endpoints with deep hardware profiling, while network discovery scans switches, printers, and infrastructure devices automatically. Software and license management tracks per-user and per-core license allocations with compliance reporting, expiration alerts, and financial cost tracking across the asset lifecycle from purchase through depreciation to disposal. Data center infrastructure management provides rack visualization with U-level positioning, PDU tracking, and connection mapping. The integrated forms editor builds custom request portals for end-users, while the self-service portal lets users submit tickets, browse the service catalog, and reserve assets. Webhooks trigger external HTTP calls on events, and the High-Level REST API v2 exposes every resource for automation. A plugin marketplace offers 90+ extensions for monitoring integration, advanced reporting, and authentication. Deploy via Docker with the glpi/glpi image alongside MySQL. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPLv3 licensed.