PentaGI
Autonomous red team execution without manual script coordination is what PentaGI delivers through a multi-agent penetration testing platform engineered for automated security assessments. Security engineers configure testing scopes, target IP ranges, domain lists, and rules of engagement through an interactive web console with real-time execution graphs. Autonomous agent personas break down high-level assessment goals into discrete tactical phases, orchestrating network port discovery, service banner fingerprinting, web application crawling, and CVE verification. Specialized agents query integrated Graphiti knowledge graphs and local vulnerability repositories to synthesize attack paths, validate exploitability, and confirm finding veracity before issuing alerts. Operators monitor live agent terminal streams, inspect sandboxed tool executions, and adjust active LLM provider routes across OpenAI, Anthropic, or local Ollama endpoints. The template editor allows red teams to compose reusable testing playbooks with customizable security prompt chains, safety constraints, and automated remediation reporting. Audit logs capture full command histories, raw tool outputs, and LLM reasoning steps to generate compliance-ready technical documentation. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
FireFlyIII
With over 24,000 GitHub stars and active development since 2014, Firefly III is the self-hosted personal finance manager that gives you complete control over your financial data without ever contacting external servers. The double-entry bookkeeping system tracks every transaction with source and destination accounts, ensuring accurate balance calculations and audit trails across checking, savings, credit card, cash, and asset accounts. Budget management sets monthly spending limits by category with visual progress tracking and rollover support for unused allocations. Rule-based transaction automation applies categorization, tags, and budget assignments automatically based on configurable conditions matching description, amount, source, and destination patterns. Recurring transactions schedule regular bills, subscriptions, and income entries with automatic creation on configured dates. Piggy banks divide savings accounts into virtual sub-accounts for goal tracking with target amounts and deadlines. Financial reports include income versus expense summaries, budget performance charts, category breakdowns, tag reports, and net worth tracking with weekly, monthly, and yearly time ranges. Multi-currency support handles any currency with configurable exchange rates for international finance tracking. The REST JSON API covers nearly every feature for integration with external tools, import utilities, and the companion Firefly III Data Importer for bank statement processing. Two-factor authentication provides account security. Self-hosting deploys via Docker containers or directly on PHP 8.5+ with MySQL or PostgreSQL. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
GitLab
Used by over 100,000 organizations and ranked first in the Gartner Magic Quadrant for DevOps Platforms, GitLab is the open-core DevSecOps platform that delivers the complete software development lifecycle — from planning and source code management through CI/CD, security scanning, and monitoring — in a single self-managed application. The built-in CI/CD engine executes pipelines defined in YAML with parallel jobs, directed acyclic graph scheduling, multi-project pipelines, and auto-scaling runners on Docker, Kubernetes, or bare metal. Merge requests provide inline code review with approval rules, code owners, merge trains for serialized merging, and five merge strategies including fast-forward and semi-linear history. The integrated container registry stores Docker images alongside code, while the package registry supports npm, Maven, NuGet, PyPI, Conan, Go, and generic packages. Issue boards with epics, milestones, and labels enable agile planning, while the built-in wiki and GitLab Pages provide documentation hosting and static site publishing. Security scanning in the Community Edition includes basic SAST, secret detection, and container scanning running as pipeline jobs. The Omnibus installer bundles Rails, Puma, Gitaly, Workhorse, Nginx, PostgreSQL, Redis, Sidekiq, and Prometheus into a single package installable in minutes, while Docker and Helm chart options support containerized and Kubernetes deployments. GitLab Duo AI assists with code suggestions, merge request summaries, and vulnerability resolution. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Activepieces
Zapier's job, on your own server: Activepieces is an open-source workflow automation platform built to be exactly that replacement. Flows are built in a visual no-code editor with triggers, actions, loops, conditional branches, auto-retries, raw HTTP steps, and code steps that run JavaScript or TypeScript with full npm package support. Integrations are "pieces" - type-safe TypeScript npm packages with hot reloading for local development - and the catalog spans 600+ services, with the large majority contributed by the community. The platform is AI-first in two directions: native AI pieces call OpenAI, Anthropic, Google, and Azure models inside flows, and every piece automatically doubles as an MCP server, so assistants like Claude Desktop and Cursor can invoke your integrations and workflows through natural language. A built-in MCP server also exposes 30 tools for building flows, managing tables, and running tests agentically. Flows are fully versioned with draft and locked states. The core is MIT-licensed and runs on TypeScript with PostgreSQL and Redis.
Dockge
Created by the developer behind Uptime Kuma and carrying over 23,000 GitHub stars, Dockge brings the same clean, reactive design philosophy to Docker Compose stack management with a web interface that makes Portainer's compose handling feel like editing YAML in a terminal over SSH. The interactive editor provides syntax highlighting, inline validation, and a live preview of your compose.yaml files while keeping every stack stored as a standard file on disk in /opt/stacks by default, meaning you can seamlessly switch between the web UI and the docker compose CLI without lock-in or proprietary database formats. Real-time WebSocket updates stream pull progress, container start/stop transitions, and build output directly to the browser with no polling delays. The built-in web terminal opens a shell session inside any running container for quick debugging, while the docker-run-to-compose converter transforms single-container run commands into proper compose.yaml definitions with one click. Multi-agent support introduced in version 1.4.0 connects multiple Docker hosts to a single Dockge dashboard, enabling centralized management of stacks distributed across different servers. Image update detection shows which stacks have newer versions available, and one-click updates pull the latest images and recreate containers without manual intervention. The stack is a single Docker container running on Node.js with Socket.IO for reactivity and stores no external database. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Nocobase
CRMs, project trackers, inventory tools - NocoBase is an open-source no-code/low-code platform for building business systems like these. Its architecture is data-model driven: you define collections and relationships first, then compose any number of interface blocks (tables, forms, kanban, charts) on top of the same model, so data structure is never coupled to a particular view. The core is a microkernel where every feature is a plugin, WordPress-style; you enable official plugins, install marketplace ones, or write your own as npm packages with server and client parts. Data sources include the main PostgreSQL or MySQL database, external databases, and third-party APIs - so you can build admin panels over existing production data instead of migrating it. Built-in infrastructure covers role-based permissions down to collection, record, and field level, workflow automation with approval steps and scheduled triggers, and audit logs; a one-click switch flips between usage and configuration modes. Because custom features live in isolated plugins with a documented lifecycle, core upgrades do not overwrite your customizations, and swapping UIs never requires data migrations since interfaces sit on independent models. Written in TypeScript on Node.js, Koa, and React under the AGPL license, it is light enough for one person to run and extend - and where no-code SaaS platforms charge per seat and per app, a self-hosted instance runs unlimited applications for unlimited users at hosting cost alone.
Argo CD
A CNCF Graduated project with over 23,700 GitHub stars and adoption by organizations including Intuit, Adobe, Capital One, and Red Hat, Argo CD has become the industry standard for GitOps-based Kubernetes deployments since its creation at Intuit in 2018, treating Git repositories as the single source of truth for application configurations and automatically reconciling live cluster state with declared desired state. The platform supports Helm charts including Helm 4, Kustomize overlays, Jsonnet, and plain Kubernetes YAML manifests, rendering templates and applying resources through configurable sync policies with automated or manual reconciliation, pruning of orphaned resources, and self-healing that reverts unauthorized cluster changes. ApplicationSets enable templated generation of applications across multiple clusters, environments, and Git repositories using generators for pull requests, Git directories, cluster lists, and merge strategies. The web UI provides a real-time application topology view with resource health status, sync state indicators, log streaming, and a network view supporting Gateway API and Ingress visualization. Version 3.5 introduced mTLS for internal component communication, graduated user impersonation and source hydrator to beta, added native ApplicationSet management with preview applications in the UI, and delivered source integrity validation. Multi-cluster management deploys applications across development, staging, and production environments from a single Argo CD instance with RBAC, SSO via OIDC and SAML, and audit logging. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Social Analyzer
Social Analyzer scans over 1,000 social media platforms in parallel to discover and correlate user profiles from a single username query, making it the most comprehensive OSINT reconnaissance tool of its kind. Three detection modes cover different accuracy and speed tradeoffs: fast HTTP library checks for rapid sweeps, Selenium WebDriver validation for JavaScript-heavy sites, and a special mode for stubborn edge cases. String analysis generates username permutations and combinations to catch related accounts with slight naming variations. Three interfaces serve different workflows: a Node.js web application on port 9005 with a browser-based GUI, a CLI for scripted batch operations, and Python plus Node.js APIs for embedding into automated investigation pipelines. The QeeqBox OSINT library extracts profile metadata, screenshots, titles, descriptions, and activity patterns, all visualized through Ixora-based force-directed graphs that map relationships between discovered accounts. Tesseract OCR analyzes profile images for additional detection vectors. Search results narrow by country codes, website categories, Alexa ranking thresholds, and confidence levels. Optional Google API and DuckDuckGo API integration adds search engine correlation alongside direct platform queries. Docker deployment bundles Node.js, Firefox ESR, Tesseract, and all dependencies into one container. Trusted by law enforcement and security researchers for digital forensics and identity verification. 23,000+ GitHub stars. AGPL-3.0 licensed.
Krayin CRM
Krayin CRM gives sales teams a visual Kanban pipeline where leads flow through configurable stages — new, contacted, qualified, proposal, won, lost — with deal values tracked per stage, drag-and-drop transitions, and AI-powered document import that extracts contact details from uploaded PDFs, DOCs, and images without manual data entry. Built on Laravel 12 with a Vue.js frontend and MySQL database, the platform delivers complete customer lifecycle management through a two-stage contact model separating unqualified Leads from qualified Persons linked to Organizations, with a unified timeline displaying associated activities, notes, emails, and deals. The activity module schedules calls, meetings, and tasks on a drag-and-drop calendar with reminders and team assignment. A built-in product catalog supports line-item quoting with pricing and quantities. Email integration connects via SMTP, IMAP, and SendGrid parsing, linked to leads and contacts automatically. Workflow automation triggers actions on conditions and pushes events to external systems via webhooks. The dashboard visualizes pipeline performance, top customers, top products, and email engagement with pie charts and trend widgets. Custom attributes add text, number, date, boolean, and dropdown fields to any entity. Role-based ACLs manage team permissions per module. Extensions add multi-tenant SaaS, WhatsApp lead generation, and VoIP calling. Deploy via Docker Compose. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Prefect
With 23,600 GitHub stars, 13 million monthly PyPI downloads, and 425+ contributors automating over 200 million data tasks monthly for Fortune 50 companies like Progressive Insurance and disruptors like Cash App, Prefect is the most widely deployed open-source workflow orchestration framework for Python — turning any script into a resilient production pipeline with a single @flow decorator while eliminating rigid DAG structures entirely. The durable execution engine persists task results and automatically resumes from failures without replaying expensive upstream work, guaranteeing exactly-once execution for any Python function. Event-driven automation triggers workflows from webhooks, cloud events, or state changes through a real-time event bus that detects what happens or fails to happen across your entire data platform. Work pools decouple workflow code from infrastructure, enabling seamless switching between Docker, Kubernetes, AWS ECS, Azure Container Instances, GCP Cloud Run, and serverless environments without modifying pipeline logic. Native Ray and Dask task runners extend execution across clusters for compute-intensive workloads. The self-hosted server provides a monitoring dashboard with flow run timelines, task state visualization, scheduling, and automation configuration. The third-generation engine reduces overhead by over 90 percent compared to Prefect 2, supporting batch, event-driven, interactive, and background task workflows. Deploy via Docker Compose with PostgreSQL, Redis, server, background services, and worker containers, or use official Helm charts for production Kubernetes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache-2.0 licensed.
Node-RED
Wire nodes together in a browser, deploy in one click, and real-time data flows from sources through transformations to outputs: Node-RED is the OpenJS Foundation's flow-based programming tool for event-driven applications. Born at IBM as a proof-of-concept for manipulating MQTT topic mappings, it has become the lingua franca of IoT and automation glue - home automation, industrial control, edge data collection - with a community library of over 5,000 contributed nodes and flows covering protocols, devices, and services. Where visual wiring runs out, JavaScript function nodes written in a rich in-editor code editor take over, and every flow serializes to importable, exportable JSON that shares cleanly and version-controls sensibly. Version 5.0 (2026) delivered the largest editor overhaul in the project's history: a rethought layout with Explorer and Information panels in a split sidebar, a native dark theme with theme variants, improved accessibility, and refreshed node appearance. The runtime is lightweight Node.js, exploiting the event-driven non-blocking model so the same flows run on a Raspberry Pi at the network edge or a cloud VM. Apache-2.0 licensed with 240+ contributors, it pairs naturally with dashboard nodes for live charts and controls.
Navidrome
Spotify economics without the subscription or catalog gaps: Navidrome, the reference self-hosted music server, streams your own FLAC, MP3, and ALAC collection from a single Go binary with a React/Material UI web player. Its Subsonic/OpenSubsonic API compatibility is the superpower: 50+ existing clients work out of the box, from Symfonium and DSub on Android to Feishin and Sonixd on desktop, plus Android Auto, CarPlay, and Android TV apps. Transcoding is server-managed and FFmpeg-backed - FLAC direct-plays at home and downsamples to MP3, AAC, or Opus over mobile bandwidth, with the OpenSubsonic transcoding extension letting clients declare capabilities and receive per-track direct-play or transcode decisions automatically. Multi-user support gives every account its own play counts, favorites, ratings, and playlists, and multi-library support scopes different collections to different users. The feature list covers serious listening: Last.fm and ListenBrainz scrobbling, artist bios and images, embedded and external lyrics, audiobook bookmarks, saved play queues that resume on another device, internet radio, jukebox mode, and M3U playlist auto-import kept in sync with your folder. Resource usage is famously low - it runs happily on a Raspberry Pi and scales to six-figure track counts.
Ntfy
ntfy sends push notifications to your phone or desktop with a single curl command: publish a message to any topic and every subscriber receives it instantly, no signup or API key required. Over 31,000 GitHub stars and 106 releases since 2021 back a server supporting five priority levels mapped to distinct notification sounds and vibration patterns, emoji tags for visual classification, click actions that open URLs when tapped, and up to three action buttons per notification for view, HTTP callback, broadcast, or clipboard copy operations. File attachments push images from surveillance cameras, documents, or any binary payload directly to mobile devices. Subscriptions work through JSON streams, Server-Sent Events, WebSockets, or raw text, with server-side filtering by priority, tags, and message ID. Authentication enforces topic-level access control through Basic Auth, Bearer tokens, or query parameters, with a built-in user and ACL management system. UnifiedPush compatibility lets ntfy serve as a push distributor for Mastodon, Matrix, and other federated services. Web Push via VAPID keys delivers browser notifications without the mobile app. The server ships as a single statically linked Go binary or Docker image supporting amd64, armv7, and arm64 architectures, consuming 30-50 MB RAM at idle with SQLite-backed message caching. Integrations include Grafana, Prometheus Alertmanager, Uptime Kuma, Home Assistant, and Ansible Semaphore. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 / GPLv2 dual-licensed.
Archon
Stop hoping your AI coding assistant remembers to plan before it codes, test after it implements, and review before it ships. Archon wraps Claude Code, OpenAI Codex, and other AI agents inside structured YAML workflows that enforce the same development process every single time. Define your pipeline as a directed acyclic graph of nodes (AI tasks, shell scripts, approval gates, loops) and Archon handles the orchestration: resolving dependencies, running independent nodes in parallel, passing artifacts between steps, and isolating every run in its own git worktree so five bug fixes can proceed simultaneously without conflicts. Ship with 17 pre-built workflows covering everything from "idea to merged PR" to automated conflict resolution, or author your own by committing YAML files to your repository's .archon/workflows/ directory. The web dashboard, launched with archon serve, provides a conversation interface with real-time streaming, a visual drag-and-drop workflow builder for creating DAG pipelines, step-by-step progress monitoring for every run, and a unified sidebar aggregating conversations from CLI, Slack, Telegram, and GitHub into one view. An NLP router parses natural language requests and automatically selects the right workflow. Structured JSON output schemas let you enforce typed responses from AI nodes, with validation and auto-repair for providers that lack native schema support. Every workflow file is version-controlled, portable, and reviewable in pull requests, so your entire team runs identical processes from day one. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Listmonk
Seven million emails from a single binary peaking at 57 MB of RAM: listmonk is a high-performance newsletter and mailing list manager in Go with PostgreSQL as its only dependency - no Redis, no worker processes, no message broker. The project's own production benchmark sent 7+ million emails with the binary peaking around 57 MB of RAM, and throughput exceeds 100K emails per hour on modest hardware. Campaigns run through a multi-threaded, multi-SMTP queue with round-robin delivery, per-server concurrency, retries, and sliding-window rate limiting across providers like Amazon SES, SendGrid, Mailgun, or your own Postfix relay. Subscribers carry custom JSON attributes and are segmented with raw SQL queries, so any audience Postgres can express, listmonk can target. Templates use Go template syntax with 100+ functions for dynamic per-subscriber content, and the Vue dashboard reports opens, clicks, bounces, and unsubscribes with automated bounce processing. A REST API handles transactional email and programmatic control, a built-in media library hosts campaign assets, and CSV or API import migrates lists from hosted platforms. The economics are the headline: where Mailchimp pricing scales with list size, listmonk plus Amazon SES sends the same volume for hosting cost plus roughly $0.10 per thousand emails - commonly a 95% reduction - and your email list, a core business asset, stays on your own infrastructure. AGPLv3-licensed; bring your own SMTP provider for delivery.
Saleor
Backed by 23,000+ GitHub stars and trusted by global brands processing millions of orders, Saleor delivers the open-source headless commerce API that replaces monolithic ecommerce platforms with a composable, GraphQL-native architecture where APIs are the only way to interact with the system. The core engine built on Python and Django handles catalog management, order processing, payment orchestration, inventory tracking, and fulfillment workflows while remaining completely decoupled from any frontend technology. Native multichannel support enables per-channel control of pricing, currencies, warehouses, product availability, and payment methods, managing Instagram, Amazon, regional websites, and retail POS from a single backend. The extensibility layer provides 160+ webhooks spanning synchronous payment callbacks, asynchronous event notifications via Google Cloud Pub/Sub and AWS SQS, and subscription queries that shape webhook payloads to deliver only the data your services need. Dashboard UI Extensions offer 45+ mount points for embedding custom interfaces via iframes without forking, while the Apps system allows building payment gateways, PIM integrations, loyalty programs, and discount logic in any language. The React-based administration dashboard provides product management, order processing, customer segmentation, and analytics with multi-language and multi-currency support. OIDC integration connects existing identity providers for single sign-on across the merchant organization. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD 3-Clause licensed.
Jaeger
Created by Uber Technologies and graduated as the seventh CNCF top-level project in October 2019 with over 23,000 GitHub stars, Jaeger has become one of the most widely deployed open-source distributed tracing platforms, processing billions of spans per day in production environments at organizations including Uber, Red Hat, and Shopify. Version 2 rebuilt the platform on the OpenTelemetry Collector framework, inheriting its extensible pipeline architecture while implementing Jaeger-specific features as extensions and components, enabling seamless integration with the OpenTelemetry ecosystem through native OTLP protocol support. The platform stores traces in Cassandra 4.0+, Elasticsearch 7.x/8.x, OpenSearch 1.0+, ClickHouse, or the embedded Badger database for development setups. Three sampling strategies control trace volume: head-based sampling with constant, probabilistic, and rate-limiting modes, tail-based sampling using the OpenTelemetry Collector processor that evaluates complete traces before storage decisions, and adaptive sampling that dynamically adjusts probabilities based on observed traffic patterns. Service Performance Monitoring computes RED metrics directly from spans, displaying request rates, error rates, and latency percentiles in the Monitor tab with drill-down from aggregate service views to individual traces. The web UI provides trace search with multi-field filtering, trace detail views with span timeline visualization, trace comparison across services, and dependency graphs mapping service relationships from actual traffic. Deployment options range from a single all-in-one binary for development to distributed collector-ingester-query configurations with Kafka intermediate buffering for production scale. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Temporal
Powering mission-critical infrastructure at OpenAI, Cursor, Replit, Lovable, Retool, and Snap with over 22,000 GitHub stars, Temporal is the durable execution platform that originated from Uber's Cadence project — built by the creators of AWS SQS, AWS SWF, and Azure Durable Functions with nine years of production-proven reliability. The workflow-as-code model lets developers write business logic in Go, Java, Python, TypeScript, .NET, PHP, or Ruby using native SDKs, while the Temporal Server automatically persists state at every step, replays from failures, retries activities with configurable backoff policies, and manages task queues without developers writing reconciliation logic. Workflows support signals for external event injection, timers for scheduled delays, child workflows for decomposition, and queries for real-time state inspection — all backed by deterministic replay over an event-sourced history that guarantees exactly-once semantics. The Web UI provides visual workflow execution inspection with event timelines, pending activity monitoring, namespace management, and worker health dashboards. Persistence supports PostgreSQL, MySQL, or Apache Cassandra for horizontal scalability, with Elasticsearch or OpenSearch for advanced workflow visibility queries. Multi-cluster replication enables global failover across data centers. The self-hosted stack deploys via Docker Compose with the auto-setup image, PostgreSQL, Web UI, and admin tools — operational within 30 minutes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.