Dockhand
Dockhand is a Docker management platforms, offering a modern alternative to Portainer with free OIDC SSO and vulnerability scanning that competitors gate behind paid tiers. Real-time container management provides start, stop, restart, and remove operations with live resource monitoring across CPU, memory, and network usage on a dashboard with real-time metrics. The visual Docker Compose editor enables stack creation and modification with syntax highlighting, while Git integration deploys stacks directly from repositories with webhooks and auto-sync for GitOps workflows. Vulnerability scanning powered by Grype and Trivy analyzes container images against CVE databases, with configurable auto-update scheduling that can trigger updates based on vulnerability severity criteria. The Hawser Go agent enables management of remote Docker hosts in Standard mode for LAN environments or Edge mode using outbound WebSocket connections for hosts behind NAT, firewalls, or dynamic IPs without exposing inbound ports. Interactive terminal sessions provide shell access into running containers, while the file browser enables uploading, downloading, and editing files directly within containers. Image management includes registry browsing, pull operations, and layer inspection alongside network and volume administration. The security-focused architecture builds its own OS layer from scratch using Wolfi packages via apko with every package explicitly declared. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSL 1.1 licensed, converting to Apache 2.0 in 2029.
KitchenOwl
Your household's kitchen command center: shared grocery lists that sync in real-time across everyone's phones, a recipe book that imports from 500+ websites with one tap, a weekly meal planner that auto-generates shopping lists, and expense tracking that splits costs between roommates or family members. Native apps for Android, iOS, macOS, Windows, Linux, and web provide partial offline support so the list works even in store dead zones. The recipe-scrapers library with wild mode fallback handles imports from virtually any cooking site, extracting ingredients, steps, and images automatically — then converts recipe ingredients directly to shopping items with a single tap. Smart suggestions learn from your patterns over time, ordering items by your typical store route and recommending frequently purchased products. OpenID Connect authentication supports Google, Apple, Authelia, and custom providers. LLM-powered ingredient parsing uses configurable AI models for intelligent recipe text extraction. A Home Assistant integration enables voice-controlled list management via smart speakers. The REST API with a published Python client library allows third-party automation. Multi-language support covers 30+ languages through Weblate community translations. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
SolidInvoice
SolidInvoice ships a complete billing platform as a single FrankenPHP binary — no separate PHP installation, no web server configuration, just one executable that delivers quote-to-invoice conversion, automated recurring billing, Stripe and PayPal payment processing, multi-currency precision arithmetic, and eight render-ready PDF templates out of the box. Maintained since 2012 across 63 releases with 30 contributors, the Symfony 7 and PHP 8.4 backend provides quote creation with one-click conversion to invoices, recurring billing with configurable frequency schedules, and online payment processing through Payum supporting Stripe, PayPal, and additional gateways. Multi-currency support uses real Money objects for precision arithmetic, while multi-tax support handles invoice-level and line-item tax rates with automatic calculation. Client management stores contacts, multiple addresses with map integration, credit balances, and complete quote and invoice history per client. The redesigned Tabler-based UI features a dashboard with hero statistics, ChartJS revenue trend visualization, attention-required alerts for overdue and draft invoices, quick actions, and a recent activity timeline. A RESTful API enables integrations with external systems. Multi-channel notifications deliver alerts via email, SMS, and webhooks. Google OAuth and two-factor authentication secure access. Grid export and full company data export support backup and migration. Deploy using Docker, Homebrew, the standalone FrankenPHP binary, or from source. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Percona PMM
Backed by 1,080+ GitHub stars and maintained by Percona with the latest release v3.8.1 in June 2026, Percona Monitoring and Management delivers the open-source database observability platform that provides a single pane of glass across MySQL, PostgreSQL, MongoDB, Valkey, and Redis databases deployed on-premises, cloud, or hybrid environments. The Go-powered PMM Server collects metrics from lightweight PMM Client agents with minimal performance impact, storing time-series data in ClickHouse for fast querying across configurable retention periods. Query Analytics ranks every query by load across all database engines from one unified dashboard, drilling from fleet-level performance down to individual problematic queries with explain plans, per-query metrics, and anomaly detection. Real-time Query Analytics streams live MongoDB operations updated every 1-5 seconds for immediate troubleshooting of lock contention and long-running queries. Built-in Percona Advisors continuously scan connected databases for security gaps, misconfigurations, and performance problems, distilling decades of DBA expertise into automated actionable recommendations. Percona Alerting integrates with 15+ notification channels including Slack, PagerDuty, email, and webhooks to trigger on custom metric thresholds. Database-specific dashboards visualize InnoDB storage engine details, WiredTiger cache metrics, PostgreSQL tuple activity, replication lag, and cluster health with annotations for root-cause correlation. Deployment options include Docker single-container setup, Podman rootless execution, and Helm charts for Kubernetes with Ingress controller support and ConfigMap management. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Whiteboard
The drawing surface inside WebRTC conference tools like Meetzi and the LAMS online-learning platform is Whiteboard (by cracker0dks) - a lightweight Node.js collaborative sketchboard built to be embedded and customized, which also slots into Nextcloud via the External Sites app. Everyone opening the same whiteboardid URL parameter draws on the same board, with remote user cursors visible live, per-user undo/redo, and an indicator showing the smallest participating screen so nobody draws outside a colleague's view. Content handling goes beyond pen strokes: drag-and-drop or paste images and PDFs from any PC or browser, then resize, rotate, and draw over them on canvas or background; add text and sticky notes; hold Shift for angle-snapped lines and perfect squares. Every function has a keybinding - deliberately friendly to pen displays like Wacom and XP-Pen whose hardware buttons map to shortcuts. Boards save to image or JSON (with reload), export directly to Nextcloud via WebDAV, and persist across restarts with the file-database option. A REST API with bundled interactive docs allows full programmatic control, an optional access token locks down uploads, and YAML configuration tunes behavior and performance. MIT-licensed and reverse-proxy friendly.
Black Candy
With 4,300+ GitHub stars and native mobile apps on three platforms, Black Candy transforms any VPS into a private Spotify-style streaming service for your personal music collection. The Ruby on Rails 7 backend with Hotwire Turbo and Stimulus delivers a responsive single-page-feeling web player supporting album browsing, artist views, playlists, favorites, and queue management without full page reloads. Point it at a media directory containing MP3, FLAC, OGG, AAC, or WAV files and Black Candy indexes metadata, fetches album artwork from Discogs API, and begins streaming immediately with on-the-fly transcoding that adapts bitrate to client bandwidth. Multi-user support gives each account independent playlists, favorites, and listening history while sharing the same music library — ideal for families or shared households. Native iOS, Android, and F-Droid apps maintained as separate repositories provide offline caching, background playback, and server discovery for mobile listening. The admin panel manages user accounts, configures media paths, and sets Discogs API tokens for automatic cover art retrieval. Deployment requires one Docker command — `docker run -p 80:80 ghcr.io/blackcandy-org/blackcandy:latest` — with persistent storage volumes for the SQLite database and media directory. For larger deployments, switch to PostgreSQL via environment variables with dedicated database URLs for ActionCable, SolidQueue, and SolidCache. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Notifuse
Marketing campaigns and transactional mail from one open-source platform: Notifuse is a modern, self-hosted alternative to Mailchimp, Brevo, and Klaviyo without per-email or per-contact pricing. Built with Go and React on PostgreSQL, it separates concerns cleanly: a drag-and-drop visual builder composes responsive templates from MJML components with Liquid variables like {{ contact.first_name }} and per-template version history; campaigns add A/B testing across subject lines, content, and send times; and a REST transactional API serves application-triggered mail. Delivery routes through your choice of provider - Amazon SES, Mailgun, Postmark, SendGrid, SparkPost, Mailjet, or plain SMTP - with multi-provider failover. Contacts carry custom fields and a full activity timeline (messages, profile changes, webhook events), and real-time segmentation builds dynamic rules over properties, activity, and subscriptions. Event-driven automations create behavioral sequences, a notification center gives recipients self-service preference management, and an S3-compatible file manager handles images with CDN delivery. Multi-tenant workspaces with isolated databases and custom domains suit agencies. Open and click tracking report engagement in real time.
SnappyMail
SnappyMail is a fast, privacy-respecting webmail client that connects to any existing IMAP and SMTP server, booting in under a second with a JavaScript payload of just 138 KB under Brotli compression (down from RainLoop's 8 MB fork origin). No database is required: all configuration and user data persists as flat files in a single volume, making Docker deployment trivially simple with the roughly 30 MB image consuming approximately 50 MB of RAM. Built-in PGP encryption supports three backends: OpenPGP.js v5 with ECDSA and EDDSA key generation, GnuPG integration, and Mailvelope browser extension compatibility, eliminating the need for separate encryption plugins. The integrated Sieve script editor enables users to create mail filtering rules, vacation auto-responders, and forwarding conditions directly within the web interface when connected to ManageSieve-capable servers on port 4190. Multi-domain administration allows a single instance to serve users across multiple IMAP servers with per-domain authentication routing. The admin panel manages extensions, security settings, branding customization, and domain configuration. GDPR-friendly by design, it removes all social media integrations, Gravatar lookups, and external tracking present in RainLoop. Dark mode strips background and font colors from email messages. The modified Squire HTML editor replaces CKEditor for composing rich-text messages. Scores 99% on Lighthouse performance. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Mox
Mox offers a complete mail server stack in a single Go binary requiring no external dependencies. The quickstart command configures a working mail server with SMTP, IMAP4, webmail, and full DNS authentication in under ten minutes. SMTP handling includes a delivery server on port 25, a submission server for authenticated clients, and a queue with automatic retries and DKIM signing. IMAP4rev2 implementation provides full mailbox synchronization with CONDSTORE and QRESYNC for efficient offline clients, NOTIFY for multi-mailbox monitoring, MULTISEARCH across mailboxes, and TLS client certificate authentication via the EXTERNAL SASL mechanism. The built-in webmail provides browser-based reading and composing with message threading, attachments, and HTML rendering without requiring a separate web client. Email authentication implements SPF validation, DKIM signing and verification with automatic key rotation, DMARC policy enforcement with aggregate and failure reporting, DANE with DNSSEC-protected TLSA records, and MTA-STS for certificate verification. Junk filtering combines reputation-based sender scoring with Bayesian content analysis trained per account. The web administration interface manages domains, accounts, DNS records, TLS certificates, delivery queue, and real-time log viewing. Internationalized email addresses with EAI and IDNA support handle non-ASCII domains and mailboxes. Account autoconfiguration publishes settings for Thunderbird autoconfig and Outlook autodiscover. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
ChatChat
One clean interface in front of Anthropic, OpenAI, Google Gemini, Cohere, and more: Chat Chat is a Next.js front door to the major AI providers, ending the juggling of separate subscriptions, tabs, and UIs per model. Bring your own API keys, pick a provider and model per conversation, and switch between them as the task demands: Claude for long-form reasoning, GPT for code, Gemini for multimodal work - the interface stays identical. Beyond configured presets, custom providers plug in with their own API endpoints and keys, which covers OpenAI-compatible gateways and local inference servers. The design splits into two dedicated modes: a chat interface for conversational work with customizable system prompts, and a search interface that pairs AI processing with query handling for research-style questions. The stack is modern and hackable - Next.js 14, Tailwind CSS, shadcn/ui on Radix primitives, Jotai for state - with full internationalization including English, Chinese, and Japanese. Self-hosting means your conversation history and API keys live on your instance rather than a third-party wrapper service, and pay-per-token API pricing typically beats stacking multiple monthly chat subscriptions. AGPL-licensed and deliberately simple to deploy: one container, environment variables for keys, done.
Authorizer
Your users belong in your own database - Authorizer, an open-source authentication and authorization server shipping as a single Go binary, keeps them there. It connects to 13+ backends - PostgreSQL, MySQL, SQLite, SQL Server, MariaDB, MongoDB, Cassandra, ScyllaDB, ArangoDB, DynamoDB, Couchbase, YugabyteDB, PlanetScale, and CockroachDB - so identity data lives beside the application it protects instead of in an auth vendor's cloud. The server is fully OAuth 2.0 and OpenID Connect compliant, including authorization code flow with PKCE, a JWKS endpoint, token revocation, and nine JWT signing algorithms. Login options cover email/password, magic links, TOTP multi-factor, SMS OTP via Twilio, and social providers including Google, GitHub, Apple, Microsoft, and Discord. Authorization goes beyond roles: an embedded OpenFGA engine provides Zanzibar-style relationship-based permission checks in process. APIs are exposed over GraphQL, REST, and gRPC, with SDKs for JavaScript, React, Go, and Python, plus themeable built-in login pages and an admin dashboard. Apache 2.0 licensed.
Kubero
With over 4,300 GitHub stars and a v3 release adding built-in user management, team views, and multi-language support, Kubero has established itself as the most feature-complete open-source Heroku alternative running natively on Kubernetes. The platform operates as a Kubernetes operator with two containers — kubero-ui and the operator — storing all state in etcd without an external database. Developers push code via Git integration with GitHub, GitLab, Bitea, or Gitea, and Kubero automatically builds using Buildpacks, Nixpacks, Runpacks, or Dockerfiles, then deploys to the configured domain with SSL via cert-manager. CI/CD pipelines support up to four staging environments — review, test, staging, and production — with per-stage environment variable isolation and ephemeral review apps that spin up on pull request open and tear down on close. The template catalog includes over 170 pre-configured applications like WordPress, Grafana, and PostgreSQL deployable in one click, while managed add-ons provide highly available PostgreSQL, Redis, MySQL, Kafka, CouchDB, Elasticsearch, and MongoDB alongside your applications. Security features include Trivy vulnerability scanning, GitHub and OAuth2 single sign-on, basic auth, and a role-based permission system with API tokens. The NestJS backend with Vue.js and Vuetify frontend provides application metrics, real-time logs, a built-in web console for container access, scheduled cronjob management, and deployment notifications via Discord, Slack, or webhooks. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
Tau
Tau delivers a complete self-hosted cloud platform where Git is the control plane and WebAssembly is the runtime. The Go binary deploys as interconnected nodes that form a P2P network using libp2p for automatic service discovery, eliminating Kubernetes entirely. Serverless functions compile to WebAssembly for secure multi-tenant execution with automatic horizontal scaling — write in Go, Rust, AssemblyScript, or C and deploy by pushing to Git. Branch-based environments map Git branches to isolated deployments, so staging and production run identical infrastructure from different refs. Static website hosting serves frontends with global distribution and automatic content-addressed deduplication via IPFS-derived storage. The built-in K/V database provides distributed storage with automatic replication across nodes, while object storage handles file management with content addressing. Pub/Sub messaging enables real-time communication between functions and external services including WebSocket support. Spore Drive automates multi-host deployment and rolling updates from a single command across bare metal or VMs running Ubuntu. The Dream CLI provides a complete local development environment that mirrors production exactly — same services, same routing, same deployment flow. Zero-configuration HTTPS provisions TLS certificates automatically for custom domains. The web console at console.taubyte.com provides visual project management, or use the tau CLI for Git-native workflows. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD-3-Clause licensed.
Cerbos
Cerbos decouples authorization logic from application code entirely, evaluating human-readable YAML policies in under one millisecond through a stateless Policy Decision Point that requires no application state synchronization or cross-network fan-out. Its custom decision engine benchmarks up to 17x faster than OPA-based alternatives. Access control policies use conditions expressed in Google's Common Expression Language, supporting role-based, attribute-based, and policy-based access control patterns including derived roles, scoped policies, and permissions-aware data filtering that pushes authorization predicates directly into database queries. The PDP exposes both gRPC and HTTP APIs with SDKs for JavaScript, Python, Go, Java, .NET, Rust, PHP, and Ruby, making integration a single function call regardless of tech stack. GitOps-native workflows treat policies as code with Git versioning, CI validation through GitHub Actions, coverage reports, breaking-change detection, and audit logs of every authorization decision for ISO27001, SOC2, and HIPAA compliance. Deployment flexibility spans Kubernetes sidecars, standalone services, systemd daemons, AWS Lambda functions, and WebAssembly-embedded PDPs that run authorization logic directly in browsers, serverless architectures, and edge devices. The Admin API manages policy lifecycle operations programmatically, while the built-in Playground and REPL provide interactive testing environments for policy authoring and debugging. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Mstream
"The easiest music streaming server available" is mStream's own billing, and the claim holds up: a lightweight Node.js app that turns a folder of audio files into a private streaming service in minutes, no external database required. Its filesystem-based design is the clever part - the API mirrors your folder structure, so you can browse and play music immediately, before any library scan finishes, and your organization on disk is your organization in the app. It streams flac, mp3, wav, ogg, opus, aac, and m4a, which matters to the audiophile crowd: FLAC plays uncompressed, bit-perfect, with gapless playback for live albums and continuous mixes. The web player runs anywhere a browser does and packs personality - a Milkdrop-style visualizer (Butterchurn), playlist sharing via links, and drag-and-drop uploads straight through the file explorer. Native iOS and Android apps add the feature streaming subscriptions can't match: sync your collection to your phone for true offline playback of music you own. Multi-user support assigns separate directories and permissions per account. Resource usage is famously light - mStream is tested on multi-terabyte libraries and runs happily on a Raspberry Pi, so a small RepoCloud instance serves a lifetime's collection. GPL-licensed, with zero listening-habit telemetry.
Agentic SOC Platform
Agentic SOC Platform compresses hours of manual security analysis into seconds by deploying specialized AI agents that autonomously triage, investigate, and enrich security alerts. The Python/Django backend processes SIEM webhooks through Redis Streams into a modular pipeline where LangGraph-orchestrated agents extract IOCs, correlate signals, and generate Cases with severity, confidence, impact, priority, and structured verdicts. The built-in SIRP provides full case management with Alerts, Artifacts, Enrichments, Tickets, and a Knowledge base that accumulates institutional memory for both human analysts and LLM agents. Native Splunk and Elasticsearch/Kibana integrations deliver unified log search through a standardized interface so agents and analysts share identical security context. The playbook engine combines traditional SOAR automation with AI-powered investigation — launching threat hunting agents, knowledge extraction, threat intelligence enrichment, and CMDB lookups from a single orchestration layer. MCP Plugin support exposes ASP capabilities to Claude Code, Codex, and OpenCode, enabling external AI agents to operate cases, search logs, query threat intelligence, and write custom modules directly. Python Modules adapt new alert sources while Playbooks orchestrate LLM analysis and automated response actions, scaling the platform with your security scenarios. Deploy via Docker Compose with all data staying inside your network. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Artalk
Artalk embeds a full commenting system into any webpage with three lines of JavaScript, packing multi-site management, social login, spam filtering, and Markdown rendering into a client that weighs roughly 40KB. One server instance manages comments for unlimited websites with complete data isolation between sites, eliminating the need for separate deployments per project. The framework-agnostic Vanilla JS client renders a complete comment interface with Markdown support, LaTeX mathematical formula rendering, image uploads, emoji packs compatible with OwO format, and automatic dark mode detection. An integrated admin dashboard accessible through the comment box provides comment moderation queues, IP banning, comment pinning, page-level statistics, and content management without direct database access. Social login authenticates commenters through GitHub, Google, Twitter, Discord, and additional OAuth providers, while captcha protection spans four backends: image captcha, Cloudflare Turnstile, Google reCAPTCHA, and hCaptcha. Spam filtering layers include Akismet integration, keyword block lists, and cloud moderation services that catch unwanted content before publication. Email notifications support SMTP, Aliyun DM, and Sendmail transports with customizable templates, and multi-channel push notifications extend to Telegram, Bark, and other messaging platforms. The OpenAPI-documented HTTP API enables programmatic comment management. Database flexibility covers SQLite, MySQL, PostgreSQL, and SQL Server. A plugin marketplace offers community extensions for custom behavior. Continuously maintained for over 8 years. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Flatnotes
A web interface for a folder of Markdown files - Flatnotes is exactly that, and the discipline of that design is why people love it. Every note is a plain .md file in a single flat directory: no database, no proprietary format, no hierarchy to maintain, no export step if you ever leave. Edit notes in the browser or open the same files in VS Code or Obsidian, sync them with Syncthing or rsync while the app is running - the Whoosh-powered search index synchronizes incrementally, so external edits just show up. The interface is a clean Vue.js app with both WYSIWYG and raw Markdown editing modes (TOAST UI Editor), instant full-text search behind the "/" shortcut with partial-match support, wikilinks for cross-note references, and automatic tag extraction from #hashtags in note bodies. Light and dark themes and a mobile-responsive layout make it pleasant everywhere. Authentication is flexible for a personal tool: none, read-only, username/password, or TOTP two-factor. A documented REST API covers create/read/update/delete for automation. The operational story is the quiet selling point - the only state is the notes folder and a rebuildable index, so backup is copying a directory. For a personal notepad that respects your data, Flatnotes nails minimal.