Joplin
Notes on Windows, macOS, Linux, Android, iOS, and the terminal, synced through your own server: Joplin pairs its open-source clients with Joplin Server, the official self-hosted backend that replaces Dropbox, OneDrive, or Nextcloud as the synchronization target. Notes are Markdown with inline attachments (images, PDFs, audio), organized into hierarchical notebooks and sub-notebooks with cross-cutting tags, alongside to-do lists with reminders and alarms. End-to-end encryption is the headline feature: enabled in the clients, it encrypts sync payloads on-device before upload, so the server stores blobs it cannot read - genuine protection even if the host is compromised. The desktop app offers both Rich Text and Markdown editors, extended by a plugin ecosystem, custom themes, and an Extension API for writing your own scripts; a Web Clipper for Chrome and Firefox captures full pages or screenshots straight into notebooks. Joplin Server ships as a Docker image with SQLite for evaluation and PostgreSQL for production, offers a filesystem storage driver for large content, and includes multi-user support and note sharing - all free under AGPL-3.0 when self-hosted. Notes stay in an open format, so the exit path always exists.
Diaspora
Diaspora lets you run your own social network node that federates with thousands of others, creating a network with no central authority and no advertising engine mining your behavior. The defining feature is aspect-based sharing: organize contacts into groups like Family, Work, and Close Friends, then control exactly who sees each post with granularity that mainstream platforms have never matched. Hashtag-based discovery connects conversations across the entire federation regardless of which pod participants call home, building communities around topics rather than algorithmic engagement bait. The Ruby on Rails backend (now running on Puma with Sidekiq workers instead of the heavier Unicorn configuration) handles federation delivery, media processing, and notifications efficiently. Photo albums, video embedding, Markdown posts, mentions, reactions, and resharing provide familiar social primitives for rich communication. Cross-posting bridges to Twitter and Tumblr maintain your presence on legacy networks while your canonical data lives on your own infrastructure. With 13,700+ GitHub stars and 270+ contributors since its 2010 launch, Diaspora proved early that social media can work without surveillance capitalism. The Docker Compose deployment runs the application alongside PostgreSQL, Redis, Sidekiq workers, and Nginx, providing a production-ready pod for your community.
Agenta
Agenta delivers a comprehensive open-source LLMOps workspace that covers the full lifecycle of AI application development — from prompt engineering through production monitoring. The platform supports 15+ model providers including OpenAI, Anthropic, Google Gemini, Mistral, Groq, Together AI, Azure, AWS Bedrock, and self-hosted models via Ollama, enabling teams to switch between providers without code changes. The prompt playground allows side-by-side comparison of different configurations, while the evaluation system offers LLM-as-a-Judge assessment, 20+ pre-built evaluators covering semantic similarity, regex matching, and factual accuracy, plus custom Python evaluators for domain-specific requirements. Teams run evaluations through both the web UI for subject matter experts and the Evaluation SDK for programmatic CI/CD integration. The observability layer captures full trace visibility across complex agentic workflows, flagging quality issues like hallucinations and off-topic responses in real time. Human annotation workflows let domain experts review and annotate LLM outputs, feeding corrections back into the evaluation loop. The architecture supports Chain of Prompts, RAG pipelines, and multi-step agent workflows, integrating with frameworks like LangChain and LlamaIndex. Self-hosting deploys via Docker Compose with Traefik for routing, requiring only a clone, environment configuration, and a single docker compose command. On RepoCloud, deploy Agenta on a dedicated VPS with root SSH access, persistent storage for evaluation datasets and traces, and complete control over model provider credentials, all under the MIT license with no usage restrictions.
Keeper
Work, personal, business, and school calendars at different providers double-book because no one system sees your real availability - Keeper solves that multi-calendar collision problem. Its pull-compare-push sync engine aggregates events from Google Calendar, Outlook/Office 365, iCloud, FastMail, any CalDAV server, or read-only iCal/ICS feeds, and pushes blocking events to one or many destination calendars so time slots align everywhere. The design is deliberately content-agnostic - it syncs timeslots, not titles or descriptions, so a personal appointment shows as busy time on your work calendar without leaking details. Sync logic is clean: events Keeper creates carry a traceable UID suffix, deletions propagate, and orphaned entries are purged automatically. A token-authenticated aggregated iCal feed combines selected calendars into one subscribable URL for Apple Calendar or Thunderbird. An optional MCP server gives AI agents read-only calendar access over OAuth 2.1 - list calendars and query events by date range, with no write capability. Built with Next.js and Bun under AGPL-3.0, the standalone Docker image bundles web, API, cron, worker, Redis, and PostgreSQL in one container, and self-hosting unlocks every Pro feature - unlimited calendars and one-minute sync intervals - for free.
OneDev
With over 15,100 GitHub stars and seven years of battle-tested production use, OneDev replaces entire DevOps toolchains — GitLab, Jenkins, Jira, Artifactory — with a single Java application that runs comfortably on a 1-core 2GB server for medium-sized projects. The platform unifies Git hosting with ANTLR-powered language-aware code search and symbol navigation, pull request workflows with configurable branch protection rules and required reviewers, and customizable issue tracking with scripted state transitions that automatically advance issues when code is committed, builds pass, or deployments complete. The GUI-based CI/CD editor creates pipelines without writing YAML, supporting typed parameters, matrix builds, job templates, cache management, and artifact publishing in a single visual interface. Jobs execute via Docker containers, bare metal shell, Kubernetes pods, or distributed agent pools, with web terminal access for live debugging and the ability to pause running jobs for inspection. Built-in package registries handle Docker images, npm packages, Maven artifacts, NuGet libraries, PyPI wheels, and RubyGems without external infrastructure. AI users can be assigned to issues and pull requests to autonomously implement features, review code, fix CI/CD failures, and resolve merge conflicts. The automated Kanban board supports rule-based card movement, time tracking, timesheets, and service desk ticket creation via email. Cluster deployment enables project replication across servers for high availability and horizontal distribution for scalability. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Pocket ID
Backed by over 8,700 GitHub stars and OpenID Connect certification, Pocket ID delivers what enterprise identity platforms like Keycloak provide but without the configuration complexity — a passkey-only OIDC provider purpose-built for homelabs and small deployments. The core design decision is radical simplicity: no passwords exist in the system, only WebAuthn-based passkeys using hardware security keys, TouchID, FaceID, or device PINs, making phishing attacks structurally impossible rather than merely discouraged. The Go backend built on the Gin framework serves a compiled SvelteKit frontend as static assets, running as a single Docker container with SQLite as the default database and optional PostgreSQL for larger deployments. User management supports manual creation, signup links, and open registration, with group-based access control that restricts which OIDC clients each group can access and attaches custom claims for downstream role mapping. LDAP synchronization pulls users and groups from OpenLDAP or Active Directory, while SCIM support enables automated provisioning from compatible identity sources. Federated client credentials handle machine-to-machine authentication for service-to-service communication patterns. The audit system logs every authentication event with GeoIP enrichment, sends email notifications for sign-ins from unknown devices, and provides one-time login codes for accessing accounts from devices without passkey support. TLS with HTTP/2 is built in, PKCE adds code exchange protection, and OpenTelemetry provides tracing and metrics integration. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD 2-Clause licensed.
ITFlow
Small MSPs waste thousands of dollars annually on overlapping subscriptions for documentation, ticketing, and billing tools that don't talk to each other. ITFlow replaces that fragmented stack with a unified platform where client contacts, locations, vendors, computer assets, software licenses, domains, SSL certificates, passwords, and documents all live under one roof. The AES-encrypted password vault stores credentials with organized access controls, and domain plus SSL certificate tracking generates automated renewal alerts before expiration disrupts client services. Ticketing supports creation, prioritization, assignment, and SLA tracking, with a client portal where customers submit tickets, view invoices, approve quotes, and access their own documentation independently. The accounting module covers the full lifecycle: quotes, recurring billing, expense tracking, Stripe payment processing, and financial dashboards showing revenue and outstanding balances at a glance. AI integration through Ollama, LocalAI, or ChatGPT accelerates documentation writing and ticket responses directly within the interface. The modular architecture lets you enable only what you need, sidestepping the bloat of enterprise PSA platforms designed for organizations ten times your size. With stable releases since 2025 and zero per-user licensing, ITFlow removes the escalating costs that make commercial PSA tools unsustainable for growing teams. The PHP application deploys with MariaDB and Nginx, ready for production in minutes.
Excalidraw
Half the architecture sketches on the internet trace back to Excalidraw - the MIT-licensed virtual whiteboard whose hand-drawn aesthetic made technical diagramming feel approachable, at roughly 85,000 GitHub stars. The infinite canvas offers rectangles, ellipses, diamonds, arrows with smart binding and labels, free-draw, text, images, and an eraser, with full undo/redo, zoom, dark mode, and keyboard-first ergonomics. Community shape libraries add thousands of pre-built elements - AWS architecture icons, flowchart stencils, UI wireframe kits - and everything exports to PNG, SVG, the clipboard, or the open .excalidraw JSON format that keeps drawings diffable and portable. Live collaboration works on a share-a-link model with live cursors and a laser pointer for presenting, and it is end-to-end encrypted by design: the room key travels in the URL hash, which never reaches the server, so the WebSocket relay only ever sees ciphertext. The architecture is remarkably light - the app is a static bundle served by Nginx, drawings persist locally in the browser, and the stateless excalidraw-room relay handles multiplayer - so a self-hosted deployment gives unlimited boards and collaborators with near-zero resource cost, replacing per-editor whiteboard subscriptions.
Rotki
Crypto portfolio tracking that inverts the SaaS model: rotki runs on your own machine, needs no email or account for the free tier, and keeps every wallet address, balance, transaction, and tax event in a local SQLCipher database encrypted with 256-bit AES. By default nothing passes through rotki-operated servers - a design choice that matters when cloud portfolio trackers concentrate exactly the identity-linked holdings data attackers want. Centralized exchanges (Kraken, Binance, Coinbase, Bitstamp, and more) connect through read-only API keys that can see but never withdraw; blockchain accounts cover Ethereum and its L2s, Bitcoin, Solana, Polkadot, and Kusama, with ENS resolution and your choice of RPC endpoint or your own node. rotki decodes on-chain transactions into readable events across major DeFi protocols - Aave, Uniswap, Compound, Curve, Lido - and generates profit-and- loss reports for tax season with customizable accounting settings, including FIFO, LIFO, and HIFO cost-basis methods, plus CSV imports for defunct exchanges. Optional premium sync is zero-knowledge, encrypting the database on-device before upload. AGPLv3-licensed and multiplatform, with a Docker package for server deployment.
LightDash
With 5,600+ GitHub stars and deep dbt integration, Lightdash is the open-source Agentic BI platform that treats analytics like software — defining metrics, dimensions, joins, permissions, and caching in a governed context layer that powers dashboards, AI agents, data apps, embedded analytics, and MCP server endpoints simultaneously. The dbt Write-Back feature lets business users create custom metrics and models in the UI, then automatically generates pull requests in GitHub or GitLab so every change flows through code review and CI validation before reaching production. Context-specific AI analysts automatically select relevant models and metrics, build queries, and present insights in plain English, while row-level security, user attributes, and customer-facing permissions ensure data governance at every layer. The platform connects to BigQuery, Snowflake, Redshift, Databricks, PostgreSQL, Trino, and ClickHouse through warehouse adapters, with the TypeScript monorepo built on React, Mantine, Vite, and TanStack Query on the frontend plus Node.js, Express, Knex, and PostgreSQL on the backend. Data teams build analytics with coding agents, preview changes from the CLI, validate in CI pipelines, and review charts and dashboards in pull requests — making the entire analytics lifecycle version-controlled and reproducible. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Erxes
Replacing HubSpot, Zendesk, Intercom, and Linear with a single self-hosted platform, erxes delivers an Experience Operating System trusted by over 4,000 GitHub stars and built on a modern Nx-powered monorepo architecture. The core ships with six foundational modules — My Inbox for omnichannel conversations across email, web chat, voice, and Discord; Contacts for unified customer profiles; Products for catalog management; Segments for behavioral targeting; Automation for visual workflow builders; and Documents for template generation. Beyond the core, a plugin marketplace activates Frontline for ticket management and omnichannel support queues, Sales for deal pipelines and lead scoring, Operations for project boards with cycle management, Content for headless CMS and knowledge bases, and Team for employee directories, time clocks, and internal chat. The technical stack combines GraphQL Federation with Apollo Server v4 and tRPC v11 microservices on Node.js, React 18 micro-frontends via Rspack Module Federation with TailwindCSS 4, MongoDB with Mongoose for persistence, Redis for caching, BullMQ for job queues, and Elasticsearch for full-text search. Deployment supports Docker Compose orchestration with automatic service discovery across all plugin containers. The Global Profile architecture enables agencies to manage multiple client brands under a single login with separated data stores. iOS and Android SDKs embed the messenger widget directly into mobile applications. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPLv3 licensed.
Opengeni
Enterprises requiring production-grade governance for long-running autonomous AI operations can rely on OpenGeni, a self-hosted orchestration platform with human-in-the-loop approvals, Connected Machine execution, and comprehensive audit replays. Operators can configure durable multi-turn workflows that execute continuously toward specified goals without premature termination, automatically pausing when human verification, structured multiple-choice decisions, or critical credential approvals are required. Teams can assign execution workloads across ephemeral cloud sandboxes or route them straight to enrolled Connected Machines to run commands directly against local code repositories without exposing inbound network ports. The integrated web console lets developers inspect live Server-Sent Event activity streams, replay complete turn histories from audit logs, inspect generated artifacts, and cancel or steer in-flight agent tasks on demand. Platform administrators can enforce fine-grained access policies through GitHub App repository bindings, broker temporary role-scoped secrets, and maintain a shared organizational knowledge base where agents propose findings for human review before vector indexing. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache-2.0 licensed.
Pelican Panel
Pelican Panel is an open-source game server management platform that enables gaming communities and hosting providers to deploy, configure, and operate multiplayer servers for titles like Minecraft, Palworld, and Counter-Strike within secure, containerized environments. Administrators can provision dedicated game servers in seconds using modular configuration eggs, allocating precise CPU cores, memory thresholds, and disk quotas to prevent resource contention across noisy neighbors. Players and server operators access an interactive web console featuring live terminal output, instant power state toggles, and direct command execution over secure WebSockets. An integrated file browser enables operators to upload server modifications, edit configuration scripts with syntax highlighting, and decompress archives without opening an external terminal. Built-in scheduling pipelines automate recurring tasks such as world backups, daily server restarts, and mod updates based on custom cron expressions. Multi-tenant permission controls allow guild leaders to invite co-administrators and grant granular privileges for restarting daemons, reviewing console logs, or managing database credentials without exposing the host system. Operators can also provision external SFTP endpoints, attach secondary IP allocations, and trigger webhook alerts whenever container health anomalies occur. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Gitea
With over 57,000 GitHub stars and deployment across thousands of organizations worldwide, Gitea is the most popular self-hosted Git service, delivering a complete software development platform in a single Go binary that runs on as little as 512MB of RAM. The platform provides full repository management with pull requests featuring inline code review, branch protection rules, merge strategies including squash, rebase, and merge commit, and automated status checks through Gitea Actions. The built-in CI/CD system uses the same YAML workflow syntax as GitHub Actions and can directly reuse over 20,000 existing Actions plugins, allowing teams to migrate from GitHub with minimal pipeline rewrites using the open-source act_runner executor. The integrated package registry supports over 20 formats including npm, PyPI, Maven, NuGet, Cargo, Helm, Composer, Conda, RubyGems, Pub, and an OCI-compatible Container registry for Docker images with no additional configuration required. Project management features include issue tracking with labels, milestones, dependencies, and time tracking, alongside kanban project boards for visual workflow management. Gitea supports LFS for large file storage, built-in wiki pages per repository, webhook integrations with Slack, Discord, Telegram, Microsoft Teams, and custom HTTP endpoints, and OAuth2 authentication with LDAP, SAML, and PAM backend support. Repository mirroring enables bidirectional synchronization with GitHub, GitLab, and Bitbucket, while the comprehensive REST and GraphQL APIs power external integrations and the official tea CLI tool. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Friendica
Friendica connects to more federation protocols than any other single platform: ActivityPub reaches Mastodon, Pleroma, Misskey, Lemmy, Pixelfed, and PeerTube; the Diaspora protocol bridges that network; and OStatus provides legacy compatibility. But protocol reach is just the foundation. Where most fediverse platforms stop at microblogging, Friendica offers long-form posts, photo albums, event calendars with RSVP, group discussions, and rich multimedia content. BlueSky and Tumblr connectors extend your reach into non-federated networks, while RSS import pulls content from any blog or news source into your timeline. Privacy controls let you scope each post to specific contacts, groups, or public visibility with per-post granularity rather than account-wide settings. Multiple themes customize the interface from Facebook-like layouts to minimal designs, and Fedilab provides native mobile access. Under the hood, the PHP application with MariaDB runs as either an Apache or FPM Docker image with Redis caching and background cron workers handling federation delivery, media processing, and notification dispatch. One of the oldest fediverse projects (1,650+ stars, 160+ contributors since 2010), Friendica has weathered every protocol evolution and platform migration the decentralized web has thrown at it, making it one of the most battle-tested social networking platforms available.
LibreTranslate
Machine translation with no Google, no Azure, no per-character billing, and no text leaving your infrastructure: LibreTranslate is a free, open-source translation API that runs entirely on your own server. The engine underneath is Argos Translate, which runs OpenNMT neural models with SentencePiece tokenization and Stanza sentence-boundary detection, all offline. Models install as portable .argosmodel packages covering dozens of languages - English, Spanish, French, German, Chinese, Japanese, Russian, Arabic, Hindi, Portuguese, and many more - and Argos handles automatic pivoting: with es-to-en and en-to-fr installed, it chains them to translate es-to-fr without a direct model. The API is a straightforward HTTP POST to /translate with source and target language codes, returning JSON - simple enough that the ecosystem has clients in every major language and integrations across tools like Weblate and Mastodon. Beyond plain text it translates HTML while preserving markup and handles whole file uploads (documents in, translated documents out), plus automatic language detection when the source is unknown. A clean bundled web UI serves interactive translation for end users, and optional API keys with rate limits control access. AGPL-licensed and trainable with custom models, it is the standard answer when translation must be private, unmetered, and self-contained - GDPR-sensitive text never touches a third party.
AnythingMCP
Connecting autonomous AI assistants to internal enterprise databases and legacy systems is streamlined by AnythingMCP, a visual Model Context Protocol gateway with automated knowledge graph generation and granular access controls. Engineers can import OpenAPI specifications, Postman collections, SOAP WSDL files, or raw database credentials to generate standardized Model Context Protocol tools in minutes without writing custom code. The built-in knowledge graph automatically maps entity relationships across disparate databases and software platforms, teaching agents how to correlate customer records in CRM tools with live order histories in enterprise resource planning software. System administrators can enforce fine-grained access policies by restricting tool execution permissions to specific roles and scoping database operations to read-only queries with strict row limits. An interactive web console provides real-time tool inspection, payload testing, request tracing, and comprehensive audit logs that capture every upstream invocation with full parameter visibility. Enterprise teams can integrate identity providers through OAuth2, SAML single sign-on, and SCIM automated user provisioning while protecting sensitive credentials using AES-256-GCM encryption at rest. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPLv3 licensed.
Apache Superset
Powering data analytics at companies like Airbnb, Twitter, and Lyft where it originated, Apache Superset has become the leading open-source business intelligence platform with over 65,000 GitHub stars and an Apache Software Foundation top-level project designation. The platform ships with over forty visualization types out of the box including geographic maps, time-series charts, pivot tables, heatmaps, treemaps, and Sankey diagrams, all rendered with Apache ECharts for publication-quality output. Its SQL Lab provides a full-featured IDE experience with syntax highlighting, autocomplete, query history, and result caching for interactive data exploration. Superset connects natively to PostgreSQL, MySQL, ClickHouse, Trino, Presto, BigQuery, Snowflake, Apache Druid, Apache Hive, and dozens more databases through SQLAlchemy connectors, with support for custom database drivers via Python plugins. The semantic layer allows data teams to define calculated columns, metrics, and virtual datasets that business users can query without writing SQL. Role-based access control with row-level security enables fine-grained data governance, while the embedded analytics SDK lets you integrate dashboards directly into external applications via iframes with SSO pass-through. The caching layer supports Redis and Memcached for query result caching, and the asynchronous query execution engine powered by Celery handles long-running queries without blocking the UI. Alerts and reports can be scheduled via email or Slack with PNG or CSV attachments generated from any chart or dashboard. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.