Nocobase
CRMs, project trackers, inventory tools - NocoBase is an open-source no-code/low-code platform for building business systems like these. Its architecture is data-model driven: you define collections and relationships first, then compose any number of interface blocks (tables, forms, kanban, charts) on top of the same model, so data structure is never coupled to a particular view. The core is a microkernel where every feature is a plugin, WordPress-style; you enable official plugins, install marketplace ones, or write your own as npm packages with server and client parts. Data sources include the main PostgreSQL or MySQL database, external databases, and third-party APIs - so you can build admin panels over existing production data instead of migrating it. Built-in infrastructure covers role-based permissions down to collection, record, and field level, workflow automation with approval steps and scheduled triggers, and audit logs; a one-click switch flips between usage and configuration modes. Because custom features live in isolated plugins with a documented lifecycle, core upgrades do not overwrite your customizations, and swapping UIs never requires data migrations since interfaces sit on independent models. Written in TypeScript on Node.js, Koa, and React under the AGPL license, it is light enough for one person to run and extend - and where no-code SaaS platforms charge per seat and per app, a self-hosted instance runs unlimited applications for unlimited users at hosting cost alone.
Apache Kafka
Used by over 80% of Fortune 100 companies including LinkedIn, Netflix, Uber, and Goldman Sachs, Apache Kafka processes trillions of messages per day as the world's most widely deployed distributed event streaming platform. Since version 4.0 released in March 2025, Kafka operates exclusively with KRaft consensus, replacing Apache ZooKeeper entirely with an internal Raft-based metadata quorum managed by controller nodes, reducing operational complexity and eliminating external coordination dependencies. Topics are organized as append-only partitioned commit logs with configurable replication factors across brokers, delivering network-limited throughput with end-to-end latencies as low as 2 milliseconds. Kafka Streams provides a client library for building stateful stream processing applications with exactly-once semantics, windowed aggregations, joins across streams and tables, and interactive queries against local state stores. Kafka Connect integrates with hundreds of systems including PostgreSQL, MySQL, Elasticsearch, Amazon S3, MongoDB, HDFS, and JMS through a standardized connector framework with distributed worker mode and automatic offset management. Share Groups introduced in version 4.2 deliver queue-style consumption semantics alongside traditional consumer groups, enabling Kafka to serve both pub-sub and point-to-point messaging patterns natively. The Schema Registry enforces Avro, Protobuf, and JSON Schema compatibility rules across producers and consumers, preventing schema evolution from breaking downstream applications. Tiered Storage offloads older log segments to object storage like S3 while maintaining transparent consumer access, dramatically reducing local broker storage costs for long-retention topics. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Restreamer
Point OBS or a hardware encoder at Restreamer's built-in RTMP or SRT ingest and it serves your website while rebroadcasting to YouTube Live, Twitch, Facebook, Vimeo, TikTok, LinkedIn, PeerTube, and anything else that accepts RTMP, SRT, or HLS - a complete self-hosted live-streaming server from datarhei. That multistreaming normally costs a monthly Restream.io subscription; here it's one FFmpeg process per destination on your own hardware. The web UI is genuinely approachable, with a wizard that walks beginners through camera setup, while professionals get the full surface: multiple audio/video inputs (USB, RTSP network cameras, virtual devices), codec and processing settings, separate audio muxing, and hardware acceleration via Nvidia CUDA, Intel VAAPI, or Raspberry Pi. Serving your own audience is first-class - a built-in Video.js player embeds in your site, a ready-made publication website streams without any embedding work, HLS chunk sizes are tunable, and automatic Let's Encrypt handles HTTPS. Viewer and bandwidth monitoring with limits keeps traffic costs predictable, and it's GDPR-friendly: no third-party provider, no audience data stored. A fully Swagger-documented REST API drives automation. SRT support keeps latency under a second.
DataHub
DataHub maps your entire data ecosystem into a searchable, governed catalog where every table, pipeline, dashboard, and metric is discoverable and traceable from source to consumer. Originally built at LinkedIn to manage metadata at hyperscale and proven to handle 10 million+ assets and billions of relationships in production, the platform is now trusted by 3,000+ organizations including Netflix, Visa, Slack, and Pinterest. The Spring Java backend (GMS) exposes both GraphQL and OpenAPI REST endpoints, while the React frontend delivers an intuitive interface for searching, browsing, and governing data assets. The Python-based ingestion framework provides 80+ production-grade connectors extracting deep metadata from Snowflake, BigQuery, Redshift, Databricks, dbt, Airflow, Spark, Kafka, Looker, Tableau, Power BI, Superset, PostgreSQL, MySQL, Hive, Glue, S3, Iceberg, and Unity Catalog through pull-based scheduled crawls and push-based emission via Python and Java SDKs. Automatic table-level and column-level lineage detection uses SQL parsing with 97-99% accuracy, tracing data flows from ingestion pipelines through warehouses to BI dashboards. Real-time metadata streaming via Kafka keeps the catalog continuously synchronized as schemas evolve and pipelines execute. The governance layer provides business glossary management, tag propagation along lineage graphs, domain-based organization, and fine-grained access control policies. DataHub Actions triggers automated responses to metadata changes, enabling notifications, quality checks, and downstream workflows. Elasticsearch powers full-text search with faceted filtering across entities. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Invio
Create an invoice, share a secure link, get paid — that's the entire workflow, no client portals or account registrations required. Invio distills billing into its absolute minimum viable surface while still producing legally compliant EU electronic invoices in Factur-X/ZUGFeRD 2.2 BASIC, UBL 2.1, and Italian FatturaPA formats, all embedded as XML attachments inside WeasyPrint-rendered PDFs. The Deno 2 backend uses Hono v4 for HTTP routing with SQLite persistence, while the SvelteKit 2 frontend styled with Tailwind CSS v4 and DaisyUI v5 delivers a responsive interface that stays out of your way. The team access system includes a permission matrix, TOTP-based two-factor authentication, and OIDC integration with configurable auto-provisioning — drop it into existing identity infrastructure without manual user management. Preset products let you build invoices from reusable catalog items. A change history log tracks every modification for audit purposes. Rate limiting protects the API behind reverse proxies. The entire stack ships as a single multi-stage Docker image containing Deno, Bun, Node, WeasyPrint, and all required font packages — zero external service dependencies beyond the container itself. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Unlicense licensed.
Plausible
Built as a direct rejection of the adtech model, Plausible is the best-known privacy-first web analytics tool - lightweight, cookie-free, and open-source. It sets no cookies and stores no personal data: unique visitors are counted via a hash of IP plus User-Agent that rotates every 24 hours and is never stored raw, so no consent banner is required and GDPR compliance is structural rather than contractual. The tracking script is under 1 KB - orders of magnitude lighter than GA - and the dashboard is a deliberate contrast to GA4's sprawl: one fast-loading page with visitors, sources, top pages, countries, devices, and UTM breakdowns, filterable by any dimension. Custom events and goals track signups and clicks, Google Search Console integration pulls in search queries, scheduled email reports keep stakeholders updated, and the Stats API (v2) plus CSV export feed data anywhere. This is the AGPL-licensed Community Edition, the same Elixir codebase that powers Plausible's cloud service, running as three containers: the web app, PostgreSQL for accounts, and ClickHouse for event storage - which means self-hosters get direct SQL access to raw analytics data the cloud version never exposes. Traffic data stays entirely on your server, with no visitor caps or per-pageview pricing.
Maintenant
Maintenant replaces three to five separate monitoring tools with a single Go binary that consolidates container discovery, endpoint monitoring, SSL tracking, resource metrics, and public status pages without requiring any external database. The embedded Vue 3 frontend serves on port 8080 immediately after deployment, auto-discovering Docker containers and Kubernetes pods through direct socket and API access without configuration. HTTP and TCP endpoint monitoring validates availability with configurable intervals, while TLS certificate tracking alerts before expiration across all monitored domains. Resource metrics collect CPU, RAM, network throughput, and disk usage per container with real-time Server-Sent Events streaming to the dashboard. Heartbeat and cron monitoring accepts pings from external scheduled jobs, triggering alerts on missed check-ins via webhook callbacks and Discord notifications. The built-in alert engine supports escalation rules and notification batching. Public status pages expose component health to end users without authentication, customizable per monitored service. Network security insights analyze exposed ports, container privilege levels, and host configuration to produce a posture score. Update intelligence scans OCI registries to detect available container image updates with digest comparison. The REST API with SSE broker enables automation, and the integrated MCP server provides tooling for AI assistant integration. SQLite in WAL mode stores all data with zero operational overhead. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
OmniRoute
OmniRoute is an AI gateway, aggregating 338 LLM providers including OpenAI, Anthropic Claude, Google Gemini, DeepSeek, Kimi, MiniMax, and GLM into a single OpenAI-compatible endpoint at localhost:20128. The gateway catalogs over 1,200 models across 90 free-tier providers and 40 free-forever providers, automatically rotating through tier-1, tier-2, and tier-3 fallback chains when any provider exhausts its quota or returns errors. RTK plus Caveman stacked token compression reduces eligible context by 15 to 95 percent before forwarding requests, cutting API costs dramatically without degrading output quality. OmniRoute exposes its full routing engine through a built-in MCP server with 104 tools across 31 scopes over stdio, HTTP, and SSE transports, plus an A2A protocol server with six autonomous agent skills and JSON-RPC 2.0 streaming. The gateway integrates directly with Claude Code, Cursor, GitHub Copilot, Codex CLI, OpenCode, and Cline through standard base-URL configuration. Seventeen routing strategies include latency-optimized, cost-minimized, and auto-scoring modes that evaluate candidates on success rate, context fit, model fitness, quota state, and circuit-breaker health. The Next.js dashboard provides real-time provider status, usage analytics, combo chain configuration, and model catalog browsing via a responsive PWA. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Kopia
Engineers who have outgrown Duplicati or rsync scripts tend to appreciate Kopia's design: encrypted, compressed, content-deduplicated snapshots in Go, stored in a repository on any storage you control - S3, Google Cloud Storage, Azure Blob, Backblaze B2, SFTP, WebDAV, or a plain filesystem. Encryption is mandatory and end-to-end: every block is encrypted client-side with AES-256-GCM or ChaCha20-Poly1305 using keys derived from your repository password, and even file names never leave the machine in plaintext. Blocks are packed into 20-40 MB blobs with random names, so the storage provider learns nothing about content or structure. Deduplication is automatic and content-based - identical data across files, snapshots, and even multiple machines backing up to the same repository is stored once. Policies govern everything per-directory: compression choice, retention (hourly through annual), scheduling, and ignore rules. Incremental snapshots are point-in-time records you can mount and browse like a filesystem. This deployment runs the Kopia repository server with its web UI, centralizing backups from multiple client machines over an authenticated API - each client connects with the server URL and certificate fingerprint, and users only see their own snapshots. Error correction, high-latency-tolerant caching, and both CLI and GUI round it out.
2FAuth
2FAuth generates TOTP, HOTP, and Steam Guard codes from any web browser, freeing your two-factor authentication from dependence on a single smartphone or app. Lose your phone, switch devices, or sit at a desktop computer, and your 2FA codes remain accessible through the web interface. The Laravel and Vue.js application stores account secrets in an encrypted SQLite database that backs up as a single file. Adding accounts works through camera-based QR scanning or manual secret key entry for services that only provide text codes. Group organization with drag-and-drop sorting keeps large collections navigable, categorized however you prefer. WebAuthn authentication with FIDO2 hardware keys protects vault access with phishing-resistant passwordless login, meaning the tool that secures your accounts is itself secured by the strongest available method. Automatic screen lock triggers after configurable idle time, and OTP obfuscation dots out generated codes until you tap to reveal them, preventing shoulder surfing in shared spaces. The REST API enables browser extensions and external applications to request codes programmatically. Import compatibility with Google Authenticator, Aegis, and 2FAS ensures painless migration without re-enrolling every account from scratch. PWA installation places 2FAuth on your device home screen for native-app-like instant access. Runs on a dedicated RepoCloud VPS with guaranteed resources and full root SSH access. AGPL-3.0 licensed.
LinkAce
Preventing silent link rot across research libraries, LinkAce captures, indexes, and permanently archives web discoveries into searchable multi-user collections with automated Wayback Machine snapshots. Curators bookmark articles, documentation, tools, and media using custom browser bookmarklets or quick-add input fields that automatically scrape page titles and metadata descriptions. The built-in link monitor continuously checks saved endpoints for HTTP status anomalies, alerting curators whenever destinations move, throw server errors, or vanish from the live internet. For long-term preservation, the system dispatches automated backup requests to the Internet Archive Wayback Machine to capture historical copies of critical research material. Curators organize their library using nested lists and granular tag hierarchies, switching seamlessly between compact tables, detailed reading feeds, and visual card layouts. Teams and households can create separate user accounts to collaborate on shared collections, delegating read-only or editing privileges per list. The platform also generates individualized RSS feeds for public or private bookmark streams, synchronizes external data through a tokenized REST API, and dispatches automated database dumps to AWS S3 storage buckets. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
PipesHub
Unify fragmented corporate knowledge across chat channels, documents, and cloud drives with PipesHub, an open-source workplace context platform providing permission-aware search and verifiable answers for teams and autonomous agents. Employees can query enterprise knowledge bases through a conversational interface that retrieves relevant information across Google Workspace, Microsoft 365, Slack, Confluence, Jira, and GitHub while strictly respecting individual user access permissions. Knowledge workers can verify every answer through clickable citation blocks that trace claims directly back to source documents, spreadsheet rows, or chat messages. Teams can assemble custom AI agents visually using a drag-and-drop builder, combining retrieval collections with interactive toolsets to automate multi-step operations like drafting customer responses or creating issue tickets. Autonomous agents connect via Model Context Protocol to inspect shared company knowledge and perform external actions across connected SaaS tools. Organizations can index scanned PDFs, slide decks, markdown pages, and spreadsheets with OCR and document parsing, maintaining synchronized records through automated schedules. Administrators can inspect synchronized records, monitor query history, and manage connector credentials across all integrated business applications. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache License 2.0 licensed.
CaddyUI
Providing an intuitive control plane for modern reverse proxy infrastructure, CaddyUI enables system administrators to manage proxy hosts, automated TLS certificates, and traffic routing without hand-editing configuration files. Operators can create and adjust reverse proxy destinations, URL path rewrites, custom headers, and redirection rules using structured forms that validate against the proxy engine before saving. The platform coordinates automatic ACME certificate requests and renewals, displaying live certificate expiration timelines, validation stages, and internal self-signed certificate authority options for local network services. Fleet management tools synchronize proxy rules across multiple distributed server instances, preventing configuration drift across staging and production clusters. Automated post-deployment health checks verify upstream endpoint availability, HTTP status codes, and latency thresholds, instantly rolling back to the previous configuration if an expectation fails. An integrated observability suite delivers real-time visitor traffic analytics, geographic maps, HTTP response code breakdowns, and single-click client IP blocking to counter malicious probing attempts. Administrators can schedule automated database backups, configure multi-user access with role permissions, and integrate CrowdSec threat intelligence to protect backends. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
LiveKit
With over 20,000 GitHub stars and adoption by companies building everything from telehealth platforms to AI voice agents, LiveKit is the most widely deployed open-source real-time communication server available. The Go-based Selective Forwarding Unit handles hundreds of concurrent participants per node with adaptive bitrate streaming, simulcast layers, SVC codec support for VP9 and AV1, and end-to-end encryption. Client SDKs span JavaScript, Swift, Kotlin, Flutter, React Native, Rust, Python, Unity, and ESP32 embedded devices, while server-side APIs cover Node.js, Go, Ruby, Java, Python, Rust, PHP, and .NET. The Agents framework enables building AI-powered voice and video applications — real-time speech-to-text, LLM-driven conversations, and computer vision pipelines — running as server-side participants in any room. Egress records sessions to S3-compatible storage or streams to RTMP endpoints, while Ingress pulls external feeds from OBS via RTMP, WHIP, or SRT into LiveKit rooms. The SIP bridge connects traditional telephony to WebRTC rooms for hybrid conferencing. JWT-based authentication, webhook notifications, room-level moderation APIs, and selective subscription give operators granular control. Deploy as a single binary for development, Docker Compose for production single-node, or Kubernetes with the official Helm chart for distributed multi-region clusters using Redis for state coordination. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Multica
Reaching 45,000 GitHub stars within seven months of launch, Multica is the fastest-growing open-source platform for managing AI coding agents as first-class teammates — assign an issue to Claude Code, Codex, Cursor, Copilot, Kimi, or any of 21 supported agent CLIs and it picks up the work, comments progress in real time via WebSocket, raises blockers, and hands the result back for human review before anything merges. The Go backend (Chi router, sqlc-generated type-safe queries, gorilla/websocket) connects to PostgreSQL 17 with pgvector for semantic search across workspace history, while the Next.js 16 App Router frontend delivers workspace dashboards showing per-agent token spend, execution time, daily cost charts, and runtime status across unlimited connected machines. Agent Skills provide reusable methods, reference material, and supporting files that compound across runs — a persistent knowledge layer that makes each subsequent task faster and more accurate. Squads let a leader agent select the right specialist for subtasks, creating multi-agent workflows without manual orchestration. Review gates ensure no AI-generated code ships to main without explicit human approval. Self-host via Docker Compose or Kubernetes with full Git integration across GitHub, GitLab, Gitea, and Forgejo including self-hosted instances. The CLI and REST API make every surface scriptable, and Autopilot automations trigger agent runs from events. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed with additional conditions.
OpenStock
OpenStock delivers a production-ready financial market terminal that unifies real-time equity pricing, technical analysis, and multi-asset watchlists into a personal self-hosted dashboard. Investors can monitor equities across thirty international exchanges, inspect live candlestick charts powered by TradingView, and evaluate technical momentum oscillators without paying recurring platform subscriptions. The global command palette accessible via keyboard shortcuts enables instantaneous ticker discovery across global exchange symbols and economic sectors. Users can organize individual stock watchlists in MongoDB, configure automated price threshold alerts triggered every fifteen seconds, and review cross-platform sentiment scores synthesized from Reddit, X, and financial news feeds. The built-in automation engine schedules weekly digest reports and event-driven notifications dispatched directly to your inbox through Nodemailer transports. Responsive market heatmaps and top-mover widgets surface daily sector performance before the opening bell rings. Deployable via Docker Compose with dedicated MongoDB persistence, the platform scales across multi-key Finnhub rate limits effortlessly. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Duplicati
Encrypted, incremental, compressed backups on storage you already have - Amazon S3, Backblaze B2, Google Drive, Azure, OneDrive, Dropbox, MEGA, Storj, WebDAV, SFTP, FTP, SMB, or a plain local disk - is what the MIT-licensed Duplicati has quietly done for years. Its security model is Trust No One: every block is encrypted with AES-256 (or a local GPG instance) before leaving the machine, and the passphrase never travels, so the storage provider holds only ciphertext. The block-based storage engine gives the best of both backup worlds: after one initial full backup, only changed data blocks upload - modify a tiny part of a huge file and only that part transfers - yet every backup version restores like a full backup in a single operation, with no incremental chains to replay. Deduplication and compression keep remote storage growth slow even across years of versions. A web interface manages everything: the built-in scheduler keeps backups current automatically, flexible filters select folders, file types, or custom patterns, retention policies prune old versions, and an integrated updater flags new releases. On compatible object-lock backends, immutable (WORM) storage protects backup data from ransomware that reaches the credentials. Runs on Windows, macOS, and Linux, free even for commercial use.
BTCPay Server
BTCPay Server processes Bitcoin payments with zero transaction fees, zero monthly costs, and zero third-party custody of your funds. Payments settle directly from customer to your wallet through a full Bitcoin node that provides cryptographic proof of receipt without trusting any intermediary. Lightning Network integration through LND, Core Lightning, or Eclair enables sub-second confirmation at sub-cent fees, with Ride The Lightning providing web-based node management within BTCPay itself. The Point of Sale app creates storefronts with product catalogs, tipping, and QR code displays for physical retail, events, or web embeds. Hardware wallet support through BTCPay Vault connects Ledger, Trezor, and ColdCard for transaction signing, keeping private keys in cold storage while running a hot payment interface. Multi-tenant architecture allows multiple stores on one instance, each with isolated wallets, Lightning nodes, and user permissions. The Greenfield REST API exposes every function programmatically for headless operation, automated invoicing, and custom integrations. E-commerce connectors for WooCommerce, Shopify, Magento, and PrestaShop plug in alongside Zapier for workflow automation. Optional Tor hidden services expose the instance as an onion address for censorship resistance. The official Docker Compose stack handles Nginx reverse proxy, Let's Encrypt TLS, and optional Tor configuration on a dedicated RepoCloud VPS with guaranteed CPU, RAM, and SSD. MIT licensed.