NodeBB
Forum software rebuilt on the modern web stack: NodeBB runs the classic bulletin-board format - categories, threads, local accounts - in real time, on Node.js over MongoDB, Redis, or PostgreSQL. WebSockets stream new posts into open topics as they're written and deliver instant notifications for follows, likes, and subscriptions; built-in chat supports side-by-side private conversations. The headline of recent versions is core ActivityPub federation: your forum can follow, share, and converse with other NodeBB instances, Mastodon, Lemmy, and anything else that speaks the protocol, turning an isolated community into a fediverse node. Everything beyond the common core is a plugin - more than 500 plugins and themes install in one click from the admin panel, covering SSO providers, search backends like Elasticsearch and Solr, galleries, calendars, and more. The theming engine extends base templates with SCSS/CSS on Bootstrap 5, plus a drag-and-drop widget system and custom HTML/CSS/JS injection. Operators get a real-time analytics dashboard, human-readable SEO-friendly URLs with semantic markup, multilingual UI, and full read and write REST APIs for integration. Mobile-first rendering means the same install works everywhere. For communities that outgrew phpBB but don't want Discourse's weight, NodeBB is the natural middle.
OneDev
With over 15,100 GitHub stars and seven years of battle-tested production use, OneDev replaces entire DevOps toolchains — GitLab, Jenkins, Jira, Artifactory — with a single Java application that runs comfortably on a 1-core 2GB server for medium-sized projects. The platform unifies Git hosting with ANTLR-powered language-aware code search and symbol navigation, pull request workflows with configurable branch protection rules and required reviewers, and customizable issue tracking with scripted state transitions that automatically advance issues when code is committed, builds pass, or deployments complete. The GUI-based CI/CD editor creates pipelines without writing YAML, supporting typed parameters, matrix builds, job templates, cache management, and artifact publishing in a single visual interface. Jobs execute via Docker containers, bare metal shell, Kubernetes pods, or distributed agent pools, with web terminal access for live debugging and the ability to pause running jobs for inspection. Built-in package registries handle Docker images, npm packages, Maven artifacts, NuGet libraries, PyPI wheels, and RubyGems without external infrastructure. AI users can be assigned to issues and pull requests to autonomously implement features, review code, fix CI/CD failures, and resolve merge conflicts. The automated Kanban board supports rule-based card movement, time tracking, timesheets, and service desk ticket creation via email. Cluster deployment enables project replication across servers for high availability and horizontal distribution for scalability. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
CapRover
With over 15,000 GitHub stars and nearly nine years of active development, CapRover is the self-hosted PaaS that replaces Heroku's pricing with your own infrastructure while keeping the deploy-and-forget simplicity. The web dashboard manages application lifecycle from deploy through scaling — configure custom domains, environment variables, persistent volumes, instance counts, and nginx templates without touching config files or SSH. The CLI tool enables scriptable deployments with a single command from your terminal or CI/CD pipeline, while webhook-based deployment triggers automated builds from Git pushes. The one-click app marketplace provides over 100 pre-configured services including WordPress, Ghost, PostgreSQL, MySQL, MongoDB, Redis, Grafana, Portainer, and dozens more, each deployed as a Docker container with volumes and environment variables preconfigured. Automatic HTTPS provisions and renews Let's Encrypt certificates for every custom domain with one-click HTTP-to-HTTPS redirects. Under the hood, Docker Swarm orchestrates containers across multiple nodes for horizontal scaling and load balancing, while nginx handles routing with fully customizable EJS-generated configuration templates per application. Deployment supports four methods: CLI push, tarball upload through the web UI, Docker image reference, and Git repository connection. The build system supports Dockerfiles, captain-definition files with build packs, and direct Docker image pulls. NetData integration provides real-time server monitoring dashboards. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Cockpit
Cockpit puts Linux server administration in a web browser, rendering storage, networking, containers, and virtual machines as visual panels you click through instead of command-line syntax you memorize. It ships in every major Linux distribution and activates through systemd socket activation, consuming zero resources until someone connects on port 9090. What makes it different from other admin panels: every change through the web interface appears instantly at the command line, and every terminal change reflects in the browser in real time. No abstraction layer sits between the UI and the operating system, which means no configuration drift. Storage management covers disk partitioning, RAID arrays, LUKS encryption, LVM volumes, and NFS shares. Network configuration handles bonds, bridges, VLANs, and firewall zones through visual editors. Native Podman integration pulls images, creates containers, manages pods, and provides terminal access into running processes. KVM/libvirt support handles VM creation, cloning, snapshots, and live migration with console access. A built-in terminal provides shell access when the web interface is not enough, and the journal viewer filters systemd logs by severity and unit. Multi-server management connects additional hosts over SSH, presenting a unified dashboard across your entire infrastructure from one browser tab. Runs on a dedicated RepoCloud VPS with full root SSH access and browser serial console. LGPL licensed.
OpenMetadata
OpenMetadata builds a unified knowledge graph connecting schemas, tables, columns, dashboards, pipelines, ML models, and data products into one searchable catalog accessible at port 8585. The ingestion framework ships 130+ connectors covering Snowflake, BigQuery, Redshift, Databricks, PostgreSQL, MySQL, Kafka, Airflow, dbt, Tableau, Looker, Power BI, Metabase, and Superset, automatically extracting metadata on configurable schedules. Column-level lineage traces data flow across transformations, joins, and aggregations, while built-in data quality testing executes profiling and validation rules as data contracts with automated alerting on failures. Governance features include role-based access control, PII auto-detection, glossary term propagation, and domain-based ownership assignment. The native MCP server and AI SDK expose semantic search, lineage queries, and governance metadata as tools any LLM agent can call, enabling AI systems to discover and reason about enterprise data with full trust context. The architecture requires only PostgreSQL or MySQL plus Elasticsearch, no Kafka, no graph database, and deploys via a single Docker Compose file. Created by the founders of Apache Hadoop, Apache Atlas, and Uber's Databook, the platform has earned over 14,700 GitHub stars and adoption by 3,000+ organizations. Apache 2.0 licensed.
Duplicati
Encrypted, incremental, compressed backups on storage you already have - Amazon S3, Backblaze B2, Google Drive, Azure, OneDrive, Dropbox, MEGA, Storj, WebDAV, SFTP, FTP, SMB, or a plain local disk - is what the MIT-licensed Duplicati has quietly done for years. Its security model is Trust No One: every block is encrypted with AES-256 (or a local GPG instance) before leaving the machine, and the passphrase never travels, so the storage provider holds only ciphertext. The block-based storage engine gives the best of both backup worlds: after one initial full backup, only changed data blocks upload - modify a tiny part of a huge file and only that part transfers - yet every backup version restores like a full backup in a single operation, with no incremental chains to replay. Deduplication and compression keep remote storage growth slow even across years of versions. A web interface manages everything: the built-in scheduler keeps backups current automatically, flexible filters select folders, file types, or custom patterns, retention policies prune old versions, and an integrated updater flags new releases. On compatible object-lock backends, immutable (WORM) storage protects backup data from ransomware that reaches the credentials. Runs on Windows, macOS, and Linux, free even for commercial use.
Botpress
Build, deploy, and monitor chatbots and LLM-powered agents on one open-source conversational AI platform: Botpress. Its Studio is a visual development environment: a drag-and-drop canvas arranges conversation logic with nodes for messages, questions, choices, and actions, while a built-in emulator simulates conversations for debugging before anything goes live. Agents ground their answers in a knowledge base assembled from uploaded documents, ingested websites, and past conversations via retrieval-augmented generation, and the LLM layer connects to multiple model providers - GPT-4, Claude, Mistral - with a configurable model strategy. An autonomous engine handles reasoning, tool orchestration, persistent memory across sessions, and sandboxed code execution, and custom code actions in TypeScript extend agents past prebuilt workflows. Over 100 integrations deploy the same bot to WhatsApp, Telegram, Slack, Microsoft Teams, and web chat, and connect it to HubSpot, Zendesk, Zapier, and arbitrary APIs and webhooks. Human handoff, conversation analytics, and quality monitoring cover production operation. Originating in 2017 from a Montreal team, the community edition is developed openly on GitHub.
Snipe-IT
Trusted by thousands of organizations worldwide with over 14,700 GitHub stars, Snipe-IT has been the gold standard in open-source IT asset management since 2013. Built on Laravel 12 with PHP 8.2+, it provides a comprehensive web-based platform for tracking every physical and digital asset in your organization — from laptops and servers to software licenses, accessories, consumables, and components. The check-in/check-out system assigns assets to users with full audit trails, digital signature acceptance, and automated email notifications for checkouts, approaching deadlines, expiring warranties, and low inventory. License management handles multi-seat software with seat-by-seat tracking, compliance monitoring, and expiration alerts. Custom fields let you capture organization-specific metadata, while the advanced search engine supports logical operators including and/or conditions, exact matching with is:value, fuzzy exclusions with not:value, and null checks. SCIM 2.0 integration synchronizes users, groups, locations, companies, and managers from identity providers like Azure Entra ID and Okta. Enterprise authentication supports LDAP, Active Directory, Google Secure LDAP, and SAML 2.0 single sign-on. The reporting dashboard generates custom asset reports with saved templates, depreciation schedules, and audit logs. QR code labels enable instant mobile asset lookup via barcode scanners. The full-featured JSON REST API powers custom integrations, with community-built SDKs, MCP servers, and third-party mobile apps including SnipeMate and Snipe-Scan. Deploy via Docker Compose with MariaDB 11 in minutes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Languagetool
Grammar, punctuation, and style errors a dictionary lookup can't see: LanguageTool is open-source proofreading powered by a Java rule engine covering English, German, Spanish, French, Portuguese, Dutch, and 25+ other languages. Self-hosting the HTTP server is how you get Grammarly-class checking without sending every sentence you write to a third party - a real concern when the text being proofread is confidential email, legal drafts, or unreleased documentation. Your instance exposes the standard /v2/check API, so the official ecosystem plugs straight in: browser extensions for Chrome and Firefox accept a custom server URL, and integrations exist for VS Code, LibreOffice, Obsidian, Vim, Emacs, and many editors. Notably, self-hosting restores free browser-extension checking that the hosted service moved behind a premium subscription - your server, no character limits, no paywall. Detection quality is tunable: optional n-gram datasets (multi-gigabyte language models for en, de, es, fr, nl) teach the engine word-order and confusion-pair errors like there/their and brakes/breaks, and a fastText model improves automatic language identification. Everything runs offline once models are downloaded. The core is LGPL, the API is documented with Swagger, and rules are community- maintained and constantly expanding.
Zitadel
Securing a SaaS product, running B2B onboarding, or replacing Auth0 and Keycloak with a stack they own - teams needing more than basic auth reach for ZITADEL, an open-source identity and access management platform built in Go. Its multi-tenancy model is the differentiator: a strict Instance, Organization, Project hierarchy isolates data and scopes policy at each level, with identity brokering (pre-built templates for Google, GitHub, Microsoft, Apple, plus generic OIDC, OAuth, SAML, and LDAP), domain discovery that routes users to the right organization by email domain, and delegated management so customers administer their own users and roles. Authentication covers OpenID Connect (certified, including device authorization and token exchange), SAML 2.0 as both IdP and SP, SCIM, FIDO2 passkeys for phishing-resistant passwordless login, and MFA via OTP, email, SMS, and U2F; machine-to-machine flows support JWT profile, PATs, and client credentials. The architecture is event-sourced - every mutation is an immutable event, yielding a complete audit trail - with relational projections for queries and no external session store, so it scales horizontally. API-first with gRPC and REST, extensible via Actions webhooks, and the same codebase self-hosted (Docker Compose or Helm on PostgreSQL) as in the cloud.
BentoPDF
Merge, split, compress, convert, edit, annotate, redact, OCR, and sign PDFs - BentoPDF packs over 130 tools into a privacy-first toolkit that runs entirely in the browser through WebAssembly. Files are never uploaded - processing happens in browser memory on the user's machine and disappears when the tab closes, which makes the tool GDPR-clean by architecture and safe for financial, legal, and internal documents. The engine combines WASM builds of PyMuPDF, Ghostscript, and CoherentPDF; Tesseract handles OCR with searchable text-layer output; Office conversions cover Word, Excel, and PowerPoint; and digital signatures use X.509 certificates (PFX/PEM) with the private key staying on the client. Because there is no server-side processing, deployment is a static-file exercise: a single Docker container, or any static host. A dedicated self-hosted build strips the marketing pages while keeping every tool, and air-gapped deployments are first-class - an automated script bundles the WASM modules, OCR language data, and fonts for fully offline networks. No accounts, no limits, no watermarks; TypeScript and Vite under the hood.
Documenso
With over 14,000 GitHub stars and a mission to become the world's most trusted document-signing tool, Documenso delivers a beautifully designed electronic signature platform that organizations can self-host for complete data sovereignty. The signing workflow handles everything from simple one-party signatures to complex multi-recipient documents with configurable roles including signers, approvers, viewers, and CC recipients, each with distinct permissions and notification flows. Document templates enable reusable signing packages with pre-configured fields and recipient patterns, eliminating repetitive setup for contracts, NDAs, and onboarding documents that teams process regularly. The PAdES-standard implementation ensures digital signatures are legally compliant and cryptographically verifiable, with complete audit trails documenting every action from document creation through final signature. Direct link signing allows recipients to access documents without email, enabling embedded signing experiences within existing applications and websites. The REST API provides programmatic document creation, recipient management, and webhook notifications for integrating signature workflows into CRM systems, HR platforms, and custom business applications. Team management features organize users into groups with role-based permissions, custom branding per team, and centralized billing for organizations with multiple signing workflows. SSO integration supports standard authentication providers for enterprise identity management. The TypeScript codebase built on Next.js and Prisma with PostgreSQL makes customization and contribution accessible to modern web developers. Zapier integration connects Documenso to thousands of third-party applications for automated document routing. Deploy on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
CrowdSec
With over 14,000 GitHub stars and a growing global network of security deployments, CrowdSec turns every attack on any participating server into protection for the entire community. The security engine operates as a combined IDS/IPS and WAF, analyzing log sources from Nginx, Apache, SSH, WordPress, and over 50 other services to detect brute force attacks, port scans, web vulnerability exploitation, and credential stuffing in real time. When one server detects a new threat, the attacker's IP is shared through the community blocklist, proactively protecting thousands of other installations before the attacker can reach them. The built-in WAF powered by Coraza v3 inspects HTTP requests at the application layer, validates against OpenAPI schemas, and applies custom rules with flexible AND/OR condition mixing for precise threat detection. Bot detection serves challenge pages with client fingerprinting to distinguish legitimate traffic from automated scrapers and scanners. Remediation components block malicious IPs at multiple infrastructure layers including iptables, nftables, Nginx, HAProxy, Cloudflare, and AWS Security Groups through the detect-here-remedy-there architecture. The scenario-based detection system ships with default rules for common attack patterns and supports custom scenarios written in YAML with an expressive filter language. A centralized console provides real-time visualization of alerts, threat intelligence analysis, and management of multiple distributed security engines. GDPR compliant by design, all log analysis happens locally and raw logs never leave your infrastructure. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Lemmy
Powering over 496 instances with more than 35,000 monthly active users and 26,500 communities, Lemmy has established itself as the leading open-source, federated link aggregation platform in the Fediverse. Built entirely in Rust for memory-safe, high-performance server operation, Lemmy enables anyone to run their own Reddit-style community that automatically connects with every other Lemmy instance — and compatible ActivityPub platforms like Mastodon, PieFed, and Kbin — through standardized federation protocols. Users create and subscribe to topic-based communities, submit posts containing text, links, or images, engage through threaded comment discussions, and shape content visibility through upvote/downvote mechanisms. Instance administrators retain full control over moderation policy, federation allowlists and blocklists, site appearance, and user registration settings, while community moderators can sticky posts, lock threads, ban users, and maintain public moderation logs for transparency. The platform supports private messaging between users, email notifications, RSS and Atom feed generation for every community, comprehensive internationalization with dozens of language packs, custom emoji support, and both light and dark themes through a clean mobile-responsive interface. Deployment is straightforward with official Docker Compose configurations and Ansible playbooks, backed by a PostgreSQL database with pict-rs for image hosting. Lemmy's Rust backend consistently benchmarks among the most efficient Fediverse server implementations, enabling small VPS instances to serve thousands of users. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Logto
With over 14,000 GitHub stars, 1 million managed identities on Logto Cloud, and continuous releases through version 1.42.0 in July 2026, Logto has emerged as the most credible open-source alternative to Auth0, Clerk, and AWS Cognito by packaging OIDC, OAuth 2.1, enterprise SSO, multi-tenancy, and RBAC into a single MPL-2.0 codebase that self-hosts for free with no per-MAU pricing surprises. Every Logto tenant operates as a fully compliant OpenID Provider supporting PKCE-only public clients, DPoP token binding, and RFC 9068 JWT access tokens. Pre-built sign-in flows handle email, phone, social login via Google, Facebook, Azure AD, and dozens of connectors, passkey authentication, and multi-factor verification through TOTP and WebAuthn. Organizations enable first-class multi-tenancy where users belong to multiple tenants with per-organization RBAC scopes on API resources. Enterprise SSO connects to Okta, Entra ID, and any SAML or OIDC identity provider. SDKs for over 30 frameworks including React, Next.js, Angular, Vue, Flutter, Go, and Python integrate authentication into SPAs, web apps, mobile apps, APIs, machine-to-machine, and CLI tools. The admin console provides user management, audit logs, webhook event subscriptions, and custom domain configuration. Personal Access Tokens and token exchange support AI agent architectures and MCP server authentication. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MPL-2.0 licensed.
Stalwart
With 14,000 GitHub stars and 81 releases since March 2023, Stalwart is the most protocol-complete open-source mail server available — delivering JMAP, IMAP4rev2, IMAP4rev1, POP3, SMTP, CalDAV, CardDAV, and WebDAV from a single Rust binary that compiles to a memory-safe, zero-garbage-collection executable with predictable latency under load. The SMTP server implements DMARC, DKIMv2, DKIMv1, SPF, and ARC for complete message authentication with automatic DKIM key rotation, while transport security enforces DANE, MTA-STS, and SMTP TLS reporting to prevent downgrade attacks. Built-in spam filtering with statistical classifiers, DNS blocklists, and collaborative reputation databases eliminates the need for external Rspamd or SpamAssassin deployments. Encryption at rest protects stored messages with S/MIME or OpenPGP, and automatic TLS certificate provisioning via ACME supports TLS-ALPN-01, DNS-01, and HTTP-01 challenges without manual certificate management. The ManageSieve server enables server-side email filtering rules, while full-text search indexes message bodies and attachments for instant retrieval. Pluggable storage backends support RocksDB for embedded deployments, PostgreSQL, MySQL, and S3-compatible object storage for distributed architectures. LDAP and SQL-based authentication integrate with existing directory services, and the web administration panel manages domains, accounts, quotas, and DKIM keys. Security audited with memory safety guaranteed by Rust's ownership model. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Stalwart Mail
Stalwart replaces the traditional Postfix + Dovecot + SpamAssassin + calendar-server stack with one Rust binary that speaks every standard mail and collaboration protocol natively. JMAP, IMAP4rev2, POP3, SMTP, CalDAV, CardDAV, and WebDAV all run inside the same process — no glue scripts, no sidecar daemons, no version conflicts between components. The pluggable storage architecture lets operators choose RocksDB for single-node deployments, FoundationDB for distributed clusters, PostgreSQL, MySQL/MariaDB, or SQLite for the data store, S3/MinIO/Azure Blob for message blobs, and Elasticsearch or Meilisearch for full-text search, with Redis or the internal engine backing rate limiters and session state. Security features include S/MIME and OpenPGP encryption at rest, automated DKIM key generation with DNS publication, DANE and MTA-STS transport security, automatic ACME TLS provisioning, granular ACLs, rate limiting, and IP banning. The browser-based admin console manages accounts, domains, groups, mailing lists, SMTP queues, DMARC/TLS-RPT/ARF reports, and every configuration object without touching a config file, while the self-service portal at /account gives end users password reset and encryption key management. Multi-tenant support with per-tenant quotas enables hosting-platform deployments, and coordinator-less clustering via Zenoh or NATS scales horizontally by adding nodes. Deploy via Docker or the standalone binary. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL v3 licensed.
Gollum
Every wiki page lives as a plain-text file in a standard Git repository, giving you full version history, branching, merging, and the freedom to edit with any text editor or IDE alongside the web interface. Originally built by GitHub's founders as the engine behind GitHub's own wiki feature, Gollum supports Markdown, AsciiDoc, reStructuredText, Org-mode, Textile, MediaWiki, Creole, and Pod markup formats with live preview rendering as you type. PlantUML and Mermaid diagrams render inline for architecture documentation, MathJax handles mathematical notation, and BibTeX integration via Pandoc provides academic citation management. YAML frontmatter controls per-page sidebars, headers, footers, and table of contents generation. CriticMarkup annotations enable editorial review workflows with tracked insertions, deletions, substitutions, and comments. Macros extend pages with dynamic content injection, file includes, and navigation helpers. The wiki maintains compatibility with GitHub and GitLab wiki repositories, so teams can clone existing platform wikis for local editing and offline access. The official Docker image at gollumwiki/gollum exposes port 4567 with volume-mounted repositories, requiring roughly 170 MB of container storage and minimal RAM. Authentication integrates via OmniAuth supporting GitHub, GitLab, Google, and other OAuth providers. Over 14,300 stars on GitHub since 2009. MIT licensed.