Milvus
With over 45,000 GitHub stars and 100 million Docker pulls, Milvus is the most widely adopted open-source vector database, powering production AI systems at NVIDIA, Salesforce, eBay, Airbnb, and DoorDash. The distributed architecture separates compute and storage with stateless microservices on Kubernetes, horizontally scaling query nodes for read-heavy workloads and data nodes for write-heavy ingestion independently. Milvus 3.0 introduces lake-native retrieval that builds and serves indexes directly over vector data in object storage and open formats including Parquet, Lance, Iceberg, and Vortex without maintaining separate copies. Native hybrid search unifies lexical BM25 full-text retrieval and semantic vector search in a single engine with metadata filtering, eliminating the need for separate search infrastructure. Hardware-accelerated ANN indexing supports IVF, HNSW, DiskANN, and GPU-based indexes with BitQ 1-bit quantization cutting memory usage by 72 percent. SDKs for Python, Go, Node.js, and Java provide programmatic access, while Milvus Lite offers lightweight embedding for local development via pip install. Server-side aggregation, sorting, faceted search, StructArray for nested document structures, and ColBERT multi-vector scoring move ranking and result processing into the engine. The Path Index enables 100x faster JSON filtering with support for 100,000+ collections per cluster for multi-tenant deployments. Self-hosting deploys via Docker Standalone or Kubernetes with Helm charts using S3-compatible, GCS, or Azure Blob storage backends. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
ArchiveBox
Backed by 27,700+ GitHub stars and actively developed with the v0.9.x architectural overhaul introducing an event-driven plugin ecosystem, ArchiveBox delivers the open-source self-hosted web archiving platform that preserves websites, bookmarks, social posts, media, source code, and research material in durable formats before link rot, platform shutdowns, and censorship erase them permanently. Feed it URLs one at a time or schedule automated imports from browser history, RSS feeds, Pocket, Pinboard, Instapaper, Wallabag, Shaarli, JSON, CSV, HTML bookmark exports, and browser extension captures. Each snapshot stores redundant copies as original HTML, rendered single-file HTML via SingleFile, full-page PDF, screenshot PNG, WARC archive, article text via Readability, favicons, HTTP headers, media files via yt-dlp, git repository clones, and structured metadata in SQLite. The Docker Compose deployment bundles Chrome, wget, curl, yt-dlp, SingleFile, and Readability parsers with automatic dependency management and isolation. Interact through the self-hosted web UI with search, tagging, and admin controls, the comprehensive CLI for batch operations, the REST API for programmatic access, or the Python API for custom integrations. The new abx-plugins system enables community extractors with per-plugin configuration, while the append-only-log architecture provides resumable crawls and audit trails. S3, B2, and Google Cloud storage backends sync archives to remote storage via rclone. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Rivet
Stateful serverless actors that run indefinitely, sleep when idle, and persist state across restarts without external database round trips. Rivet provides a vendor-neutral alternative to Cloudflare Durable Objects, delivering long-running processes with co-located in-memory state and per-actor SQLite databases on any infrastructure you choose. The Rust engine comprises four packages: Pegboard for actor orchestration, Gasoline for durable execution, Guard for traffic routing via Envoy, and Epoxy implementing multi-region KV storage through EPaxos consensus. Each actor maintains instant-access in-memory state plus a dedicated SQLite database for relational queries, backed by RocksDB on single nodes or PostgreSQL with NATS pub/sub for multi-node clusters. RivetKit SDKs in TypeScript, Rust, and Python support built-in WebSocket connections, task queues, scheduling, and CRDT-based real-time collaboration. The v2.3 rewrite moved the core runtime from JavaScript to native Rust via WebAssembly, eliminating main-thread blocking across Node.js, Bun, Deno, and Cloudflare Workers. A built-in dashboard provides actor inspection with real-time Prometheus metrics. Deploys as a single Docker container on port 6420 with optional PostgreSQL for persistence. Available on RepoCloud with a dedicated VPS under the Apache 2.0 license.
Pythia
With over 400 GitHub stars and growing, Pythia transforms a local LLM into a self-calibrating geopolitical oracle that watches the entire planet and predicts what happens next — no API keys, no cloud, no cost. The Osiris-based Three.js globe frontend streams 30+ concurrent live feeds including GDELT geopolitics, armed conflict events, USGS earthquakes, NWS storm polygons, EONET disasters, FIRMS wildfires, Polymarket crowd odds, cryptocurrency and commodity prices, UNHCR displacement data, WHO disease outbreaks, and WFP food insecurity indicators. The FastAPI backend fuses these heterogeneous sources into a unified world brief, pipes it through Ollama, and generates located predictions across 24-hour, weekly, monthly, and yearly horizons — each carrying a probability, reasoning, and geocoordinates that fly the globe to the event. A council of four specialist swarm agents — Strategist, Economist, Naturalist, and Skeptic — re-scores every forecast, surfacing consensus, dissent, and splits through Brier-weighted voting where historically accurate personas earn louder votes. The engine maintains a persistent ledger graded by an LLM judge against archived world state, producing running Brier scores and calibration charts. Signal rules fire browser notifications and webhooks when conditions match, a morning brief digest summarizes overnight changes, and the agent API at port 8088 delivers the complete world view in a single JSON call compressed to approximately 50 tokens for AI agent consumption. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Kestra
With over 27,000 GitHub stars and an ecosystem of 1,900+ plugins covering every major cloud provider, database, and SaaS platform, Kestra is the orchestration engine that brings Infrastructure as Code principles to workflow automation — defining complex multi-step pipelines in readable YAML that execute across any language, runtime, or infrastructure boundary. The built-in VS Code-style editor provides syntax highlighting, auto-completion, real-time validation, and an AI Copilot that generates workflow YAML from natural language descriptions. Tasks execute in Python, Node.js, Go, R, Shell, SQL, or any Docker container, with event-driven triggers listening for file arrivals on SFTP and cloud storage, messages from Kafka, Redis, Pulsar, AMQP, MQTT, NATS, AWS SQS, Google Pub/Sub, and Azure Event Hubs in real time. The topology view visualizes workflow DAGs with execution state, duration, and output artifacts for each task node. Namespaces organize workflows into isolated environments with configurable secrets, while subflows enable modular composition with inputs, outputs, and conditional branching. Retry policies, timeouts, error handlers, and automatic backfills for missed schedules ensure reliability across production workloads. Git integration pushes workflows directly to branches from the UI with CI/CD pipeline support for automated deployment. The REST API enables programmatic workflow management, execution triggering, and resource provisioning. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Sourcebot
Point Sourcebot at your GitHub, GitLab, Bitbucket, Azure DevOps, Gerrit, or Gitea repositories and get regex, symbol, and filtered search results in under a second across thousands of repos and branches. Backed by Y Combinator with production deployments at NVIDIA, Shutterstock, SeatGeek, Arista, and Red Hat, the Zoekt-powered engine deploys as a single Docker container with zero external data transmission. Ask Sourcebot connects reasoning models like Claude Opus to your entire codebase, enabling natural language questions that return structured answers grounded with inline citations and navigable code snippets, backed by automatic tool calls that search code, follow references, and read files across all indexed repositories. Ask connectors extend this to Jira, Slack, Linear, and Confluence via MCP, pulling external context alongside code for debugging and documentation. IDE-level code navigation provides goto definition and find all references across repository boundaries without local cloning. The built-in file explorer renders any indexed file with syntax highlighting, breadcrumb navigation, and git blame showing per-line commit attribution. An analytics dashboard tracks daily, weekly, and monthly search activity. Permission syncing from GitHub and GitLab enforces access control lists so users only see repositories they are authorized to access. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Other licensed.
Stalwart Mail
Stalwart replaces the traditional Postfix + Dovecot + SpamAssassin + calendar-server stack with one Rust binary that speaks every standard mail and collaboration protocol natively. JMAP, IMAP4rev2, POP3, SMTP, CalDAV, CardDAV, and WebDAV all run inside the same process — no glue scripts, no sidecar daemons, no version conflicts between components. The pluggable storage architecture lets operators choose RocksDB for single-node deployments, FoundationDB for distributed clusters, PostgreSQL, MySQL/MariaDB, or SQLite for the data store, S3/MinIO/Azure Blob for message blobs, and Elasticsearch or Meilisearch for full-text search, with Redis or the internal engine backing rate limiters and session state. Security features include S/MIME and OpenPGP encryption at rest, automated DKIM key generation with DNS publication, DANE and MTA-STS transport security, automatic ACME TLS provisioning, granular ACLs, rate limiting, and IP banning. The browser-based admin console manages accounts, domains, groups, mailing lists, SMTP queues, DMARC/TLS-RPT/ARF reports, and every configuration object without touching a config file, while the self-service portal at /account gives end users password reset and encryption key management. Multi-tenant support with per-tenant quotas enables hosting-platform deployments, and coordinator-less clustering via Zenoh or NATS scales horizontally by adding nodes. Deploy via Docker or the standalone binary. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL v3 licensed.
AppFlowy
With over 75,000 GitHub stars and native apps across macOS, Windows, Linux, iOS, and Android, AppFlowy is the most widely adopted open-source alternative to Notion — delivering the same block-based workspace model with full data sovereignty. The Flutter frontend renders natively on every platform while a Rust backend powered by Actix-web and Tokio handles CRDT-based real-time collaboration, ensuring sub-second sync across devices with conflict-free concurrent editing. Relational databases support grid, board, kanban, calendar, and gallery views over the same dataset, with two-way relations, rollups, advanced filters, sorts, and formula calculations that cover the majority of Notion's database workflows. The block editor supports 40+ content types including nested pages, toggles, callouts, code blocks with syntax highlighting, embeds, and slash-command insertion. AI integration connects to OpenAI, Anthropic, or local models via Ollama for writing assistance, summarization, and translation — all without sending data off-premises when using on-prem LLMs. Team spaces with workspace-level and per-page permissions, OAuth and SSO authentication through GoTrue, and S3-compatible object storage via MinIO provide enterprise-grade access control and file management. The self-hosted stack deploys through Docker Compose with PostgreSQL for metadata, Redis for caching and pub/sub, and a dedicated background worker for imports and email notifications. Offline-first architecture ensures the desktop app functions without connectivity, syncing changes when the connection resumes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Zitadel
Securing a SaaS product, running B2B onboarding, or replacing Auth0 and Keycloak with a stack they own - teams needing more than basic auth reach for ZITADEL, an open-source identity and access management platform built in Go. Its multi-tenancy model is the differentiator: a strict Instance, Organization, Project hierarchy isolates data and scopes policy at each level, with identity brokering (pre-built templates for Google, GitHub, Microsoft, Apple, plus generic OIDC, OAuth, SAML, and LDAP), domain discovery that routes users to the right organization by email domain, and delegated management so customers administer their own users and roles. Authentication covers OpenID Connect (certified, including device authorization and token exchange), SAML 2.0 as both IdP and SP, SCIM, FIDO2 passkeys for phishing-resistant passwordless login, and MFA via OTP, email, SMS, and U2F; machine-to-machine flows support JWT profile, PATs, and client credentials. The architecture is event-sourced - every mutation is an immutable event, yielding a complete audit trail - with relational projections for queries and no external session store, so it scales horizontally. API-first with gRPC and REST, extensible via Actions webhooks, and the same codebase self-hosted (Docker Compose or Helm on PostgreSQL) as in the cloud.
Documenso
With over 14,000 GitHub stars and a mission to become the world's most trusted document-signing tool, Documenso delivers a beautifully designed electronic signature platform that organizations can self-host for complete data sovereignty. The signing workflow handles everything from simple one-party signatures to complex multi-recipient documents with configurable roles including signers, approvers, viewers, and CC recipients, each with distinct permissions and notification flows. Document templates enable reusable signing packages with pre-configured fields and recipient patterns, eliminating repetitive setup for contracts, NDAs, and onboarding documents that teams process regularly. The PAdES-standard implementation ensures digital signatures are legally compliant and cryptographically verifiable, with complete audit trails documenting every action from document creation through final signature. Direct link signing allows recipients to access documents without email, enabling embedded signing experiences within existing applications and websites. The REST API provides programmatic document creation, recipient management, and webhook notifications for integrating signature workflows into CRM systems, HR platforms, and custom business applications. Team management features organize users into groups with role-based permissions, custom branding per team, and centralized billing for organizations with multiple signing workflows. SSO integration supports standard authentication providers for enterprise identity management. The TypeScript codebase built on Next.js and Prisma with PostgreSQL makes customization and contribution accessible to modern web developers. Zapier integration connects Documenso to thousands of third-party applications for automated document routing. Deploy on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Jaeger
Created by Uber Technologies and graduated as the seventh CNCF top-level project in October 2019 with over 23,000 GitHub stars, Jaeger has become one of the most widely deployed open-source distributed tracing platforms, processing billions of spans per day in production environments at organizations including Uber, Red Hat, and Shopify. Version 2 rebuilt the platform on the OpenTelemetry Collector framework, inheriting its extensible pipeline architecture while implementing Jaeger-specific features as extensions and components, enabling seamless integration with the OpenTelemetry ecosystem through native OTLP protocol support. The platform stores traces in Cassandra 4.0+, Elasticsearch 7.x/8.x, OpenSearch 1.0+, ClickHouse, or the embedded Badger database for development setups. Three sampling strategies control trace volume: head-based sampling with constant, probabilistic, and rate-limiting modes, tail-based sampling using the OpenTelemetry Collector processor that evaluates complete traces before storage decisions, and adaptive sampling that dynamically adjusts probabilities based on observed traffic patterns. Service Performance Monitoring computes RED metrics directly from spans, displaying request rates, error rates, and latency percentiles in the Monitor tab with drill-down from aggregate service views to individual traces. The web UI provides trace search with multi-field filtering, trace detail views with span timeline visualization, trace comparison across services, and dependency graphs mapping service relationships from actual traffic. Deployment options range from a single all-in-one binary for development to distributed collector-ingester-query configurations with Kafka intermediate buffering for production scale. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
OpenFGA
OpenFGA answers the question 'can this user perform this action on this resource?' in single-digit milliseconds, implementing Google's Zanzibar paper as a production-ready authorization engine adopted by Auth0, Grafana Labs, Canonical, Docker, Agicap, and Read.AI. The server exposes both gRPC and HTTP APIs for authorization queries including Check, ListObjects, ListUsers, Expand, and the high-throughput BatchCheck endpoint that deduplicates and processes multiple authorization decisions in a single request. Authorization models combine relationship-based access control with role-based and attribute-based patterns through a purpose-built DSL that supports contextual tuples, conditional relationship tuples with CEL expressions, and time-based filtering via the ReadChanges API. Storage backends include PostgreSQL 14+, MySQL 8, and SQLite in beta, with an in-memory adapter for development and testing. Official SDKs for Java, .NET, Node.js, Go, and Python provide type-safe client integration, while a Terraform provider enables infrastructure-as-code management of authorization stores and models. The built-in browser playground at port 3000 lets developers visually model authorization schemas, write relationship tuples, and test access control queries interactively before deployment. OpenTelemetry instrumentation integrates with existing monitoring infrastructure, and Helm charts simplify Kubernetes deployment. A VS Code extension provides syntax highlighting and validation for FGA model files, and GitHub Actions automate model testing in CI/CD pipelines. A CNCF incubating project with transparent governance. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
LibreTranslate
Machine translation with no Google, no Azure, no per-character billing, and no text leaving your infrastructure: LibreTranslate is a free, open-source translation API that runs entirely on your own server. The engine underneath is Argos Translate, which runs OpenNMT neural models with SentencePiece tokenization and Stanza sentence-boundary detection, all offline. Models install as portable .argosmodel packages covering dozens of languages - English, Spanish, French, German, Chinese, Japanese, Russian, Arabic, Hindi, Portuguese, and many more - and Argos handles automatic pivoting: with es-to-en and en-to-fr installed, it chains them to translate es-to-fr without a direct model. The API is a straightforward HTTP POST to /translate with source and target language codes, returning JSON - simple enough that the ecosystem has clients in every major language and integrations across tools like Weblate and Mastodon. Beyond plain text it translates HTML while preserving markup and handles whole file uploads (documents in, translated documents out), plus automatic language detection when the source is unknown. A clean bundled web UI serves interactive translation for end users, and optional API keys with rate limits control access. AGPL-licensed and trainable with custom models, it is the standard answer when translation must be private, unmetered, and self-contained - GDPR-sensitive text never touches a third party.
Haven
Haven gives your community a private chat server with voice calls, screen sharing, and end-to-end encrypted direct messages where friends join via invite link in their browser without installing apps or creating third-party accounts. Real-time messaging supports image uploads via paste and drag-drop, emoji reactions, replies, threads, typing indicators, @mentions with autocomplete, and inline GIF search through Tenor or GIPHY. Peer-to-peer WebRTC voice chat includes per-user volume sliders, mute and deafen controls, talking indicators, and screen sharing with picture-in-picture mode. Direct messages use ECDH P-256 key exchange with AES-256-GCM symmetric encryption where private keys never leave the browser, ensuring not even the server operator can read them. Twenty-plus visual themes with stackable effects including CRT scanlines, Matrix Rain, Cyberpunk Text Scramble, Snowfall, and Campfire Embers let users personalize the experience with configurable intensity sliders. Rich Presence integration shows what members are playing or listening to via Last.fm, Steam, and Spotify. A built-in bot API supports webhooks and custom slash commands, while Discord history import preserves channels, threads, forums, reactions, pins, and avatars. The Node.js server deploys via Docker Compose or a single batch file that auto-handles dependencies, SSL certificates, and configuration. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Harbor
The first container registry to reach CNCF graduated status with over 29,000 GitHub stars since VMware open-sourced it in 2016, Harbor transforms the basic Docker Distribution into a hardened enterprise registry with vulnerability scanning, supply chain signing, multi-datacenter replication, and project-level access control out of the box. Trivy scans every pushed image against the NVD, GitHub Advisory Database, and distribution-specific vulnerability feeds, with scan-on-push policies that block deployment of images exceeding configurable severity thresholds. Artifact signing through Cosign keyless signatures and Notation enforces content trust policies ensuring only cryptographically verified images reach production clusters. Policy-based replication synchronizes images and Helm charts between Harbor instances across multiple datacenters using repository, tag, and label filters with automatic retry and bandwidth throttling — enabling hybrid-cloud and disaster-recovery topologies. The RBAC model isolates projects with per-project quotas, robot accounts for CI/CD automation, webhook notifications, and audit logging that tracks every pull, push, delete, and configuration change. LDAP, Active Directory, and OIDC authentication integrate with existing identity providers, while the proxy cache transparently caches images from Docker Hub, Quay, and other upstream registries to reduce pull latency and rate-limit exposure. The RESTful API with embedded Swagger UI, tag retention policies, garbage collection scheduling, and immutable artifact rules complete the lifecycle management. Deploy via Docker Compose or Helm Chart on Kubernetes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
OpenPanel
Known as the open-source Mixpanel alternative that respects user privacy, OpenPanel delivers a unified web and product analytics platform combining Mixpanel's behavioral analysis with the simplicity of Plausible and full data ownership through self-hosting. Cookieless tracking eliminates consent banners entirely while still capturing events, page views, sessions, user journeys, funnels, retention cohorts, and custom properties with full GDPR compliance by design. The 2.3 KB async script loads without blocking page rendering, and 16 official SDKs cover Next.js, React, Vue, Astro, Remix, Nuxt, Angular, Svelte, React Native, Swift, Kotlin, Python, PHP, Laravel, Express, and REST API for custom integrations. Real-time dashboards display live visitor counts, active sessions, and event streams as they happen. Custom chart builders create tailored visualizations from any tracked event with breakdowns by property, time period, and user segment. Session replay reconstructs individual user journeys showing every page visited, event triggered, and interaction recorded. Funnel analysis identifies conversion drop-offs with step-by-step breakdown and property filtering. Retention analysis measures how often users return with customizable time windows and cohort comparisons. A/B testing and variant tracking enable experiment measurement directly within the platform. Event notifications alert when specific events occur or thresholds are crossed. The self-hosted deployment uses Docker Compose with ClickHouse for high-speed analytical queries, PostgreSQL for metadata, and Redis for real-time processing — deployable on any VPS or Kubernetes cluster. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Wakapi
Its author, a student and WakaTime fan, didn't want to pay $9/month for data about his own keystrokes - so Wakapi was born, a self-hosted, WakaTime-compatible backend for coding statistics. The compatibility is the killer design decision: the official WakaTime plugins for VS Code, JetBrains IDEs, Vim, and dozens of other editors work unmodified - just point the plugin's API URL at your Wakapi instance with your personal key, and heartbeats flow to your server instead of a third party's. Duration inference matches WakaTime's own algorithm, with a configurable timeout (10 minutes by default). From that stream Wakapi builds statistics and plots across projects, languages, editors, hosts, and operating systems, plus the fun extras: public leaderboards (optionally login-gated, with configurable aggregation windows), badges for GitHub readmes, and weekly email reports. A REST API serves your data programmatically, Prometheus export feeds your existing Grafana, and a WakaTime relay mode can mirror heartbeats to both services during migration - with one-click import of historical WakaTime data. Written in Go, it is lightning fast and light enough for the smallest instance, storing to SQLite, PostgreSQL, or MySQL, with configurable data retention for GDPR peace of mind. Deliberately smaller than WakaTime, deliberately yours.
SonarQube Community
Trusted by over seven million developers worldwide with 310+ contributors and more than 10,600 GitHub stars since 2011, SonarQube has become the industry standard for automated code review and continuous code quality inspection. The platform performs deep static analysis across Java, JavaScript, TypeScript, Python, C#, C++, PHP, Kotlin, Go, Ruby, Swift, and 30+ additional languages, detecting bugs that cause runtime failures, security vulnerabilities exploitable by attackers, security hotspots requiring manual review, code smells degrading maintainability, and code duplications increasing technical debt. Quality Gates define pass-fail thresholds on metrics like coverage, duplications, reliability rating, and security rating, failing CI/CD pipelines when new code introduces issues below organizational standards. Pull request analysis decorates GitHub, GitLab, Bitbucket, and Azure DevOps merge requests with inline issue annotations and overall quality summaries before merging. Built-in quality profiles provide curated rule sets per language following the Sonar Way methodology, with dedicated profiles for AI-generated code that target patterns commonly introduced by agentic coding workflows. Infrastructure-as-Code analysis covers Terraform, Kubernetes, Docker, Ansible, CloudFormation, and Helm charts with supply-chain security rules for CI/CD pipelines. The companion IDE plugin delivers real-time analysis with quick-fix guidance directly in VS Code, IntelliJ, and Eclipse. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. LGPL-3.0 licensed.