NanoClaw
NanoClaw delivers a radically simple alternative to OpenClaw — a single Node.js process and a handful of files that provide the same core functionality with true container-level security isolation. Agents execute inside Docker containers on Linux or Apple Containers on macOS, where even root access inside the sandbox cannot reach the host filesystem. The platform natively runs Claude Code via Anthropic's official Claude Agent SDK, with drop-in alternatives including OpenAI Codex, OpenRouter via OpenCode, Google, DeepSeek, and local open-weight models via Ollama — configurable per agent group. Multi-channel messaging connects WhatsApp, Telegram, Discord, Slack, Microsoft Teams, iMessage, Matrix, Google Chat, Webex, Linear, GitHub, WeChat, and email via Resend, installed on demand through skill commands. Each agent group receives its own CLAUDE.md memory file, isolated filesystem, container sandbox, and session state — a prompt injection in one group cannot exfiltrate data from another. The OneCLI Agent Vault handles credentials so agents never hold raw API keys, while approval-gated self-modification allows agents to request new packages or MCP servers that administrators must authorize. Scheduled tasks run recurring jobs inside containers with message delivery back to users. The setup script handles dependencies, authentication, and container configuration through Claude Code conversation. Deploy on any Docker-capable Linux server. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
OpenBot
Open source GrokBot, built by the team behind the AG-UI protocol. OpenBot is the open-source enterprise agent platform that gives every AI coworker its own sandboxed computer — a real Chromium browser with its own login sessions, a private filesystem, and only the MCP tools you explicitly grant. The centralized gateway evaluates CEL policy rules against tool name, intent, bot identity, page URL, element attributes, and file paths before any action executes, writing an immutable audit row for every call and outcome. Any agent that speaks AG-UI — LangGraph, Mastra, CrewAI, Pydantic AI, Google ADK, or hand-written endpoints — registers as a Bot and receives its own channel with persistent conversation history. The take-the-wheel system lets humans assume control when an agent encounters login walls or two-factor prompts, recording control transfers as structured audit events. Knowledge documents from Google Drive and OneDrive carry source-based permissions where deny principals always win and ambiguous mappings refuse retrieval entirely. The React and Vite frontend provides live screen viewing of each agent's browser, channel-based chat, admin settings, and component galleries. The Hono API server on port 3001 handles authentication, role-based access, tenant packaging, and credential management backed by PostgreSQL with pgvector. Deploy via Docker Compose with the included supervisor that manages per-bot computer containers. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Authelia
Authelia is the leading open-source SSO and multi-factor authentication server for self-hosted infrastructure. The Go backend compiles to a single binary or Docker container image, serving a TypeScript React web portal that handles first-factor username and password login, second-factor authentication via TOTP, WebAuthn FIDO2 security keys, passwordless passkeys, and Duo mobile push notifications, and an OpenID Connect 1.0 and OAuth 2.0 identity provider with device code flow, JWE encrypted ID tokens, custom claims policies, and network-scoped authorization criteria. The forward authentication model integrates with Nginx auth_request, Traefik ForwardAuth, HAProxy, Caddy, Envoy, SWAG, and Skipper reverse proxies, injecting Remote-User, Remote-Groups, and Remote-Email headers into authorized requests. Granular access control rules match subject, groups, request URI, HTTP method, and network to enforce one-factor and two-factor policies per route. The user backend supports LDAP with attribute mapping, connection pooling, and bind mode, or YAML file-based authentication with Argon2id hashed passwords. Session state stores in Redis for high availability across clustered deployments, while persistent data lives in SQLite, MySQL and MariaDB, or PostgreSQL. Brute force protection locks accounts after configurable failed attempts, and email-based identity verification handles password resets and device registration. Dark, light, and OLED themes with i18n localization customize the portal appearance. On RepoCloud, deploy Authelia on a dedicated VPS with Docker, root SSH access, and complete control over your authentication infrastructure, all under the Apache-2.0 license.
Authentik
With over 24,000 GitHub stars and a rapidly growing community of self-hosters, authentik delivers enterprise-grade identity management that replaces commercial solutions like Okta and Auth0 with a fully self-hosted platform requiring no per-user licensing fees. The platform serves as a unified identity provider supporting SAML 2.0, OAuth 2.0 and OpenID Connect, LDAP for legacy application compatibility, SCIM 2.0 for automated user provisioning, and RADIUS for network device authentication. The visual flow designer enables administrators to create custom authentication workflows combining password verification, multi-factor authentication with TOTP, WebAuthn, and SMS codes, email verification, captcha challenges, and conditional logic based on user attributes or device context. The forward-auth and reverse proxy integration works seamlessly with Traefik, Nginx, Caddy, and Envoy to protect applications that lack built-in authentication. User enrollment flows support self-registration with configurable approval workflows, invitation links, and automatic group assignment. The LDAP outpost exposes user and group data to legacy applications requiring LDAP bind authentication, while the SCIM provider automates user lifecycle management with downstream applications. Multi-tenancy support through brands allows a single authentik instance to serve multiple organizations with independent domains, branding, and authentication policies. The admin interface provides comprehensive user management, group hierarchy, application catalog, event logging with GeoIP enrichment, and system health monitoring. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Licensed under a source-available license with an open-source community edition.
CrowdSec
With over 14,000 GitHub stars and a growing global network of security deployments, CrowdSec turns every attack on any participating server into protection for the entire community. The security engine operates as a combined IDS/IPS and WAF, analyzing log sources from Nginx, Apache, SSH, WordPress, and over 50 other services to detect brute force attacks, port scans, web vulnerability exploitation, and credential stuffing in real time. When one server detects a new threat, the attacker's IP is shared through the community blocklist, proactively protecting thousands of other installations before the attacker can reach them. The built-in WAF powered by Coraza v3 inspects HTTP requests at the application layer, validates against OpenAPI schemas, and applies custom rules with flexible AND/OR condition mixing for precise threat detection. Bot detection serves challenge pages with client fingerprinting to distinguish legitimate traffic from automated scrapers and scanners. Remediation components block malicious IPs at multiple infrastructure layers including iptables, nftables, Nginx, HAProxy, Cloudflare, and AWS Security Groups through the detect-here-remedy-there architecture. The scenario-based detection system ships with default rules for common attack patterns and supports custom scenarios written in YAML with an expressive filter language. A centralized console provides real-time visualization of alerts, threat intelligence analysis, and management of multiple distributed security engines. GDPR compliant by design, all log analysis happens locally and raw logs never leave your infrastructure. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
CyberChef
GCHQ open-sourced its "Cyber Swiss Army Knife", and CyberChef became the web app security analysts, incident responders, and CTF players reach for when data needs decoding, decrypting, or dissecting. Its interface is four panes: paste or drag input (files up to 2GB), search a categorized library of hundreds of operations, drag them into a recipe with arguments, and read the output. Operations span Base64, hex, and XOR encoding; AES, DES, and Blowfish encryption; classical ciphers from Caesar to Railfence; hashes and checksums; compression; regex and string extraction of IPs, domains, and URLs; timestamp conversion; and parsers for IPv6, X.509 certificates, and more. Recipes chain arbitrarily - convert from a hexdump then decompress, decrypt AES pulling the IV from the cipher stream, or let the Magic operation auto-detect several layers of nested encoding. Auto Bake re-runs the recipe live as input or arguments change, Step executes one operation at a time for debugging, and flow control (forks, subsections, registers) applies different operations to different parts of the data. Recipes save to files or share as URLs encoding the full pipeline. Crucially, CyberChef is entirely client-side JavaScript - nothing uploads anywhere - and self-hosting guarantees an unmodified copy inside your own network, where malware artifacts belong.
HashiCorp Vault
With over 36,000 GitHub stars and adoption by organizations including Adobe, Shopify, and Roblox, HashiCorp Vault is the industry-standard platform for secrets management, encryption services, and privileged access control across hybrid and multi-cloud infrastructure. The key/value secrets engine stores arbitrary secrets with full versioning, soft-delete, and metadata tracking, while dynamic secrets engines generate on-demand, short-lived credentials for AWS, Azure, GCP, databases including PostgreSQL, MySQL, MongoDB, and MSSQL, and SSH access with automatic revocation after configurable lease periods. The PKI secrets engine dynamically issues X.509 certificates on demand with automatic rotation and ACME protocol support, eliminating manual certificate management workflows entirely. Encryption as a service through the transit secrets engine lets applications encrypt, decrypt, sign, verify, and generate HMACs without managing cryptographic keys directly, supporting AES-GCM-256, ChaCha20-Poly1305, RSA-2048/4096, ECDSA-P256/P384, and ED25519 algorithms. Authentication integrates with LDAP, OIDC/OAuth2, SAML, AppRole for machine-to-machine access, Kubernetes service accounts, AWS IAM, Azure Active Directory, and GitHub tokens. Fine-grained ACL policies use path-based rules with glob patterns and sentinel policies for programmatic enforcement. The integrated Raft storage backend provides high-availability clustering without external dependencies, while alternative backends include Consul, S3, DynamoDB, PostgreSQL, and MySQL. The built-in web UI provides a visual interface for browsing secrets, managing policies, configuring auth methods, and monitoring cluster health. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSL 1.1 licensed.
Tailscale
With over 34,000 GitHub stars and backing from a well-funded engineering team, Tailscale has fundamentally simplified how developers and system administrators think about secure networking. The client daemon establishes WireGuard tunnels directly between devices using sophisticated NAT traversal techniques, achieving direct peer-to-peer connections in the vast majority of network configurations without requiring port forwarding, firewall rules, or VPN concentrators. When direct connections prove impossible due to restrictive network environments, DERP relay servers provide encrypted fallback paths. MagicDNS assigns human-readable hostnames to every device on the network, eliminating the need to remember IP addresses across a tailnet. Subnet routing allows nodes to advertise access to entire local networks, enabling remote access to office resources, home labs, or cloud VPCs through a single gateway node. Exit node functionality routes all internet traffic through a designated device for privacy protection or geographic flexibility. Access control lists define granular policies for which devices and users can communicate with which services, enforced cryptographically at the network layer. The authentication layer integrates with identity providers including Google, Microsoft, GitHub, Apple, and OIDC-compliant systems for single sign-on access. Taildrop enables direct encrypted file transfers between devices without cloud intermediaries. The tailscale CLI provides complete network management from the terminal including status monitoring, route advertisement, and node configuration. Running Tailscale on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console provides a permanent, always-on node in your mesh network. BSD-3-Clause licensed with an active open-source community.
Duplicati
Encrypted, incremental, compressed backups on storage you already have - Amazon S3, Backblaze B2, Google Drive, Azure, OneDrive, Dropbox, MEGA, Storj, WebDAV, SFTP, FTP, SMB, or a plain local disk - is what the MIT-licensed Duplicati has quietly done for years. Its security model is Trust No One: every block is encrypted with AES-256 (or a local GPG instance) before leaving the machine, and the passphrase never travels, so the storage provider holds only ciphertext. The block-based storage engine gives the best of both backup worlds: after one initial full backup, only changed data blocks upload - modify a tiny part of a huge file and only that part transfers - yet every backup version restores like a full backup in a single operation, with no incremental chains to replay. Deduplication and compression keep remote storage growth slow even across years of versions. A web interface manages everything: the built-in scheduler keeps backups current automatically, flexible filters select folders, file types, or custom patterns, retention policies prune old versions, and an integrated updater flags new releases. On compatible object-lock backends, immutable (WORM) storage protects backup data from ransomware that reaches the credentials. Runs on Windows, macOS, and Linux, free even for commercial use.
mCaptcha
The CAPTCHA bargain - annoy your users and feed their behavior to Google - gets replaced with economics by mCaptcha. Instead of image puzzles, it uses SHA256 proof-of-work: every visitor's browser silently solves a small computational challenge (via a WebAssembly library) before submitting a form. Humans never notice the milliseconds; bots hammering your site must burn more compute sending requests than your server spends answering them, which makes attacks more expensive than defense - the property that also makes mCaptcha genuine DoS protection, not just bot filtering. Written in Rust, the system is fully automated: difficulty scales with traffic, so challenges stay trivial in normal conditions and harden under attack. The privacy and accessibility wins are structural rather than promised: no tracking, no profiling, no user-pattern data collection, and no visual puzzles that exclude users with visual or cognitive impairments - the design was published in Communications of the ACM. Rate limiting is IP-independent, so users behind NATs, VPNs, or Tor get the same experience instead of endless challenge loops, and proofs resist replay attacks, neutering captcha farms. Migration is deliberately easy: the API is compatible with reCAPTCHA and hCaptcha, making it a drop-in replacement. AGPL-licensed core with proprietary-friendly client libraries.
3X-UI
3X-UI is the most popular open-source Xray management panel, providing a full-featured web interface for deploying and monitoring proxy and VPN protocols on Linux servers. The Go backend manages Xray-core instances supporting VLESS, VMess, Trojan, Shadowsocks, WireGuard, Hysteria2, HTTP, SOCKS, Dokodemo-door, and TUN inbounds across TCP, mKCP, WebSocket, gRPC, HTTPUpgrade, and XHTTP transports secured with TLS, XTLS Vision, and REALITY. The Clients page tracks each user with individual traffic quotas, expiration dates, concurrent connection limits, and live online status indicators, while one-click share links, QR codes, and a built-in subscription server distribute configurations in multiple output formats. The multi-node architecture manages and scales deployments across multiple servers from a single panel instance. The Panel Settings page configures listen address, port, URI path, session duration, trusted proxy CIDRs, authentication, and Telegram bot integration for remote monitoring and management alerts. Outbound routing supports WARP, NordVPN, custom rules, load balancers, and proxy chaining. Xray Configs provides template-level control over the core configuration, while the API Docs page exposes a complete RESTful API with in-panel Swagger documentation. Data persists in SQLite by default or PostgreSQL for larger deployments, with database export and import from the panel. Fail2ban integration enforces per-client IP limits. On RepoCloud, deploy 3X-UI on a dedicated VPS with Docker, root SSH access, and complete control over your proxy infrastructure, all under the GPL-3.0 license.
Harbor
The first container registry to reach CNCF graduated status with over 29,000 GitHub stars since VMware open-sourced it in 2016, Harbor transforms the basic Docker Distribution into a hardened enterprise registry with vulnerability scanning, supply chain signing, multi-datacenter replication, and project-level access control out of the box. Trivy scans every pushed image against the NVD, GitHub Advisory Database, and distribution-specific vulnerability feeds, with scan-on-push policies that block deployment of images exceeding configurable severity thresholds. Artifact signing through Cosign keyless signatures and Notation enforces content trust policies ensuring only cryptographically verified images reach production clusters. Policy-based replication synchronizes images and Helm charts between Harbor instances across multiple datacenters using repository, tag, and label filters with automatic retry and bandwidth throttling — enabling hybrid-cloud and disaster-recovery topologies. The RBAC model isolates projects with per-project quotas, robot accounts for CI/CD automation, webhook notifications, and audit logging that tracks every pull, push, delete, and configuration change. LDAP, Active Directory, and OIDC authentication integrate with existing identity providers, while the proxy cache transparently caches images from Docker Hub, Quay, and other upstream registries to reduce pull latency and rate-limit exposure. The RESTful API with embedded Swagger UI, tag retention policies, garbage collection scheduling, and immutable artifact rules complete the lifecycle management. Deploy via Docker Compose or Helm Chart on Kubernetes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Vaultwarden
The Bitwarden server, reimplemented in Rust: Vaultwarden (formerly bitwarden_rs) is the unofficial lightweight edition. It speaks the same wire protocol as the official server, so every official Bitwarden client - browser extensions, iOS, Android, desktop, and the bw CLI - connects without modification, while the server itself runs as a single container against SQLite (or MySQL/MariaDB/PostgreSQL) instead of the official multi-container stack that wants gigabytes of RAM. Features Bitwarden gates behind paid tiers ship free: organizations with collections, groups, member roles, and policies; TOTP code storage; file attachments; Bitwarden Send; Emergency Access; event logs; and admin password reset. Two-factor options cover authenticator apps, email, FIDO2 WebAuthn, YubiKey, and Duo, and OIDC-based SSO landed natively in v1.35.0. Zero-knowledge encryption is unchanged - vault data is encrypted client-side and the master password never reaches the server. Attachments and Sends store on local disk or S3-compatible backends, an admin panel manages users and server settings, and backup is copying one data directory. Suited to individuals and teams up to roughly 50 users.
2FAuth
2FAuth generates TOTP, HOTP, and Steam Guard codes from any web browser, freeing your two-factor authentication from dependence on a single smartphone or app. Lose your phone, switch devices, or sit at a desktop computer, and your 2FA codes remain accessible through the web interface. The Laravel and Vue.js application stores account secrets in an encrypted SQLite database that backs up as a single file. Adding accounts works through camera-based QR scanning or manual secret key entry for services that only provide text codes. Group organization with drag-and-drop sorting keeps large collections navigable, categorized however you prefer. WebAuthn authentication with FIDO2 hardware keys protects vault access with phishing-resistant passwordless login, meaning the tool that secures your accounts is itself secured by the strongest available method. Automatic screen lock triggers after configurable idle time, and OTP obfuscation dots out generated codes until you tap to reveal them, preventing shoulder surfing in shared spaces. The REST API enables browser extensions and external applications to request codes programmatically. Import compatibility with Google Authenticator, Aegis, and 2FAS ensures painless migration without re-enrolling every account from scratch. PWA installation places 2FAuth on your device home screen for native-app-like instant access. Runs on a dedicated RepoCloud VPS with guaranteed resources and full root SSH access. AGPL-3.0 licensed.
Pocket ID
Backed by over 8,700 GitHub stars and OpenID Connect certification, Pocket ID delivers what enterprise identity platforms like Keycloak provide but without the configuration complexity — a passkey-only OIDC provider purpose-built for homelabs and small deployments. The core design decision is radical simplicity: no passwords exist in the system, only WebAuthn-based passkeys using hardware security keys, TouchID, FaceID, or device PINs, making phishing attacks structurally impossible rather than merely discouraged. The Go backend built on the Gin framework serves a compiled SvelteKit frontend as static assets, running as a single Docker container with SQLite as the default database and optional PostgreSQL for larger deployments. User management supports manual creation, signup links, and open registration, with group-based access control that restricts which OIDC clients each group can access and attaches custom claims for downstream role mapping. LDAP synchronization pulls users and groups from OpenLDAP or Active Directory, while SCIM support enables automated provisioning from compatible identity sources. Federated client credentials handle machine-to-machine authentication for service-to-service communication patterns. The audit system logs every authentication event with GeoIP enrichment, sends email notifications for sign-ins from unknown devices, and provides one-time login codes for accessing accounts from devices without passkey support. TLS with HTTP/2 is built in, PKCE adds code exchange protection, and OpenTelemetry provides tracing and metrics integration. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD 2-Clause licensed.
SonarQube Community
Trusted by over seven million developers worldwide with 310+ contributors and more than 10,600 GitHub stars since 2011, SonarQube has become the industry standard for automated code review and continuous code quality inspection. The platform performs deep static analysis across Java, JavaScript, TypeScript, Python, C#, C++, PHP, Kotlin, Go, Ruby, Swift, and 30+ additional languages, detecting bugs that cause runtime failures, security vulnerabilities exploitable by attackers, security hotspots requiring manual review, code smells degrading maintainability, and code duplications increasing technical debt. Quality Gates define pass-fail thresholds on metrics like coverage, duplications, reliability rating, and security rating, failing CI/CD pipelines when new code introduces issues below organizational standards. Pull request analysis decorates GitHub, GitLab, Bitbucket, and Azure DevOps merge requests with inline issue annotations and overall quality summaries before merging. Built-in quality profiles provide curated rule sets per language following the Sonar Way methodology, with dedicated profiles for AI-generated code that target patterns commonly introduced by agentic coding workflows. Infrastructure-as-Code analysis covers Terraform, Kubernetes, Docker, Ansible, CloudFormation, and Helm charts with supply-chain security rules for CI/CD pipelines. The companion IDE plugin delivers real-time analysis with quick-fix guidance directly in VS Code, IntelliJ, and Eclipse. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. LGPL-3.0 licensed.
Kopia
Engineers who have outgrown Duplicati or rsync scripts tend to appreciate Kopia's design: encrypted, compressed, content-deduplicated snapshots in Go, stored in a repository on any storage you control - S3, Google Cloud Storage, Azure Blob, Backblaze B2, SFTP, WebDAV, or a plain filesystem. Encryption is mandatory and end-to-end: every block is encrypted client-side with AES-256-GCM or ChaCha20-Poly1305 using keys derived from your repository password, and even file names never leave the machine in plaintext. Blocks are packed into 20-40 MB blobs with random names, so the storage provider learns nothing about content or structure. Deduplication is automatic and content-based - identical data across files, snapshots, and even multiple machines backing up to the same repository is stored once. Policies govern everything per-directory: compression choice, retention (hourly through annual), scheduling, and ignore rules. Incremental snapshots are point-in-time records you can mount and browse like a filesystem. This deployment runs the Kopia repository server with its web UI, centralizing backups from multiple client machines over an authenticated API - each client connects with the server URL and certificate fingerprint, and users only see their own snapshots. Error correction, high-latency-tolerant caching, and both CLI and GUI round it out.
Element
Matrix's flagship client, built by the protocol's creators: Element brings the decentralized open standard for real-time communication to web, desktop, iOS, and Android. Paired with a Matrix homeserver, it delivers Slack-quality team messaging where you own every message, file, encryption key, and byte of metadata. End-to-end encryption is on by default, built on Olm and Megolm - the Double Ratchet algorithm family Signal popularized, extended for large-room scalability and publicly audited by NCC Group. Messages encrypt per-device with cross-signed device verification, so even a compromised server yields nothing readable. Federation is the defining capability: like email, users on different homeservers converse seamlessly, and 30+ bridges connect Matrix rooms to Slack, Discord, WhatsApp, and Telegram, so moving to sovereign infrastructure doesn't sever contact with anyone. Rooms support threads, reactions, file sharing, and voice and video calls via Element Call. The result is digital sovereignty chosen by governments and enterprises across Europe: your data sits on your server in your jurisdiction, portable to any other Matrix host because the protocol is an open standard. Apache-2.0 licensed, with no per-user fees at any scale.