Wanderer
Wanderer provides a privacy-first alternative to AllTrails and Komoot, giving outdoor enthusiasts complete ownership of their GPS data on a self-hosted server. The platform accepts uploads in GPX, KML, FIT, and TCX formats, automatically extracting distance, elevation gain and loss, duration, and speed statistics to build a searchable trail catalogue. The built-in route planner uses the Valhalla routing engine to calculate hiking, cycling, and walking routes directly on the map, while MapLibre GL renders smooth vector tiles from OpenStreetMap data with configurable tile sources and overlay layers. Each trail supports rich metadata including difficulty ratings, categories, waypoints with descriptions, photo galleries, and summit log entries that track completion dates with optional GPS data. Meilisearch powers instant full-text search across trail names, descriptions, and tags, complemented by map-based spatial filtering and advanced date, distance, and elevation filters. The ActivityPub integration follows the same federation protocol as Mastodon, allowing users to follow explorers on other Wanderer instances and see their public trails, comments, and summit logs in a unified feed without requiring cross-instance accounts. The WASM-based plugin system enables third-party extensions for custom integrations. The Docker Compose stack runs three containers — SvelteKit frontend on port 3000, PocketBase backend with embedded SQLite, and Meilisearch — with startup completing in under 90 seconds. On RepoCloud, deploy Wanderer on a dedicated VPS with root SSH access, persistent storage for your trail database and uploaded photos, and complete control over routing, geocoding, and tile server configurations, all under the AGPL v3 license.
Pocket ID
Backed by over 8,700 GitHub stars and OpenID Connect certification, Pocket ID delivers what enterprise identity platforms like Keycloak provide but without the configuration complexity — a passkey-only OIDC provider purpose-built for homelabs and small deployments. The core design decision is radical simplicity: no passwords exist in the system, only WebAuthn-based passkeys using hardware security keys, TouchID, FaceID, or device PINs, making phishing attacks structurally impossible rather than merely discouraged. The Go backend built on the Gin framework serves a compiled SvelteKit frontend as static assets, running as a single Docker container with SQLite as the default database and optional PostgreSQL for larger deployments. User management supports manual creation, signup links, and open registration, with group-based access control that restricts which OIDC clients each group can access and attaches custom claims for downstream role mapping. LDAP synchronization pulls users and groups from OpenLDAP or Active Directory, while SCIM support enables automated provisioning from compatible identity sources. Federated client credentials handle machine-to-machine authentication for service-to-service communication patterns. The audit system logs every authentication event with GeoIP enrichment, sends email notifications for sign-ins from unknown devices, and provides one-time login codes for accessing accounts from devices without passkey support. TLS with HTTP/2 is built in, PKCE adds code exchange protection, and OpenTelemetry provides tracing and metrics integration. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD 2-Clause licensed.
Shlink
With over 5,100 GitHub stars and eight years of active development since 2016, Shlink has become the definitive self-hosted URL shortener for teams that need unlimited links, full visitor analytics, and complete data ownership without per-link pricing or monthly caps. The PHP backend built on the Mezzio framework with Doctrine ORM serves redirects through any number of custom domains on a single instance, generating unique short codes or accepting custom slugs including multi-segment paths and emoji characters. Every click is tracked with anonymized visitor data including geolocation by country, city, and coordinates, browser and operating system identification, referrer source, and device type classification, all stored in your choice of MySQL, MariaDB, PostgreSQL, Microsoft SQL Server, or SQLite. Dynamic redirect rules route visitors to different destinations based on geolocation, device type, or browser language, enabling targeted campaigns from a single short URL. The REST API exposes every operation with OpenAPI documentation and an interactive sandbox at api-spec.shlink.io, while the CLI provides equivalent functionality for scripting and automation. The official progressive web app at app.shlink.io manages multiple Shlink instances from a single interface with URL creation, tag management, and detailed visit charts. Real-time event integration supports both Mercure and RabbitMQ for webhook-style notifications on new visits. Third-party imports migrate existing short URLs from Bitly and YOURLS with visit history preserved. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Reactive Resume
With over 38,000 GitHub stars, nearly one million registered users, and over 1.3 million resumes created, Reactive Resume delivers a professional resume creation experience that rivals commercial platforms like Resume.io and Zety without collecting user data, showing advertisements, or imposing paywall restrictions. The real-time WYSIWYG editor renders changes instantly as users type, providing immediate visual feedback across all resume sections including work experience, education, skills, certifications, projects, and custom sections with typed extensions. Over fifteen professionally designed templates with full color customization, font selection, spacing adjustment, and icon style selectors ensure each resume reflects individual style preferences. The drag-and-drop system lets users move items between sections and pages freely across multi-column and full-width layouts. PDF generation produces pixel-perfect documents using a headless Chromium rendering pipeline, ensuring consistent output across all devices and print settings. Multi-language support covers over twenty languages with RTL script handling for Arabic and Hebrew. Authentication supports passkeys and multiple OAuth providers via Better Auth, while self-hosted deployment runs via Docker Compose with PostgreSQL and Browserless for PDF rendering. The import system accepts JSON Resume format, LinkedIn data exports, and PDF/DOCX files when AI integration is configured. AI-powered content suggestions using OpenAI, Google Gemini, Anthropic Claude, or local Ollama models help improve bullet points and professional summaries. A CSS editor with autocompletion allows fine-grained styling control. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Zammad
With 5,700+ GitHub stars and over a decade of active development since 2012, Zammad is the open-source helpdesk platform that unifies every customer communication channel — email, live chat, telephone, WhatsApp, Telegram, Facebook, SMS, and web forms — into a single ticket management interface backed by PostgreSQL, Elasticsearch, and Redis. Version 7.0 introduced native AI features including automated ticket categorization, priority assignment, and title rewriting via AI agents that plug into triggers, macros, and scheduler jobs, plus one-click AI ticket summaries and a writing assistant — all configurable with your choice of LLM provider: OpenAI, Anthropic, Mistral AI, Azure AI, Ollama for local models, or any custom OpenAI-compatible endpoint with full audit logging of every AI action. Define service level agreements with first response, update, and solution time tracking tied to business hours calendars, with automatic escalation notifications. The knowledge base provides multilingual FAQ management with internal and public visibility. Core workflows enable dynamic ticket masks with conditional field dependencies per group. Text modules let agents insert predefined responses via the double-colon shortcut, while macros execute multi-step actions with one click. Security includes two-factor authentication, S/MIME and PGP email encryption, and single sign-on via SAML or OpenID Connect. Integrations connect to GitHub, GitLab, Microsoft 365, LDAP with nested group support, and Exchange. Deploy via Docker Compose, Kubernetes with the official Helm chart, or DEB/RPM packages. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPLv3 licensed.
Vaultwarden
The Bitwarden server, reimplemented in Rust: Vaultwarden (formerly bitwarden_rs) is the unofficial lightweight edition. It speaks the same wire protocol as the official server, so every official Bitwarden client - browser extensions, iOS, Android, desktop, and the bw CLI - connects without modification, while the server itself runs as a single container against SQLite (or MySQL/MariaDB/PostgreSQL) instead of the official multi-container stack that wants gigabytes of RAM. Features Bitwarden gates behind paid tiers ship free: organizations with collections, groups, member roles, and policies; TOTP code storage; file attachments; Bitwarden Send; Emergency Access; event logs; and admin password reset. Two-factor options cover authenticator apps, email, FIDO2 WebAuthn, YubiKey, and Duo, and OIDC-based SSO landed natively in v1.35.0. Zero-knowledge encryption is unchanged - vault data is encrypted client-side and the master password never reaches the server. Attachments and Sends store on local disk or S3-compatible backends, an admin panel manages users and server settings, and backup is copying one data directory. Suited to individuals and teams up to roughly 50 users.
PeerTube
The fediverse's answer to YouTube comes from French non-profit Framasoft: PeerTube is a TypeScript/Angular video platform where hundreds of independently operated instances federate over ActivityPub into one network. Videos you publish are discoverable across the whole video fediverse, and viewers can follow your channels from Mastodon or any ActivityPub platform - or plain RSS - without needing an account on your instance. The namesake innovation attacks video hosting's core cost problem: alongside HLS delivery, an optional WebRTC-based P2P layer lets concurrent viewers' browsers share video segments with each other, so a video going viral distributes its own bandwidth demand instead of crushing your server; instance redundancy extends this by letting friendly instances cache each other's videos. Livestreaming is first-class - stream via OBS or any RTMP software, host permanent streams, enable replays, and interact through live chat. Creators get channels, playlists, analytics, built-in video editing (trim, watermark), and an embeddable player for any website. There are no ads, no data mining, and no recommendation algorithm engineered for watch-time - the project's explicit design stance. Admins control federation policy, P2P settings, and theming; a plugin system extends the rest. AGPL-licensed, 300+ contributors, in active development since 2015.
ExcaliDash
ExcaliDash adds persistent storage, access control, version history, and real-time collaboration to Excalidraw, transforming ephemeral whiteboarding sessions into a managed drawing library your team can rely on. The Node.js/Express backend with React/TypeScript frontend deploys via Docker Compose on port 6767, using Prisma ORM on SQLite for all drawings, users, and metadata. WebSocket-powered collaboration lets multiple users edit the same canvas simultaneously with live cursor presence. Drawing snapshots preserve every revision with visual preview and one-click restore to any previous state. Three authentication modes handle different deployment needs: local email/password for personal use, hybrid mode mixing native credentials with OIDC for gradual enterprise adoption, and enforced OIDC-only for organizations requiring SSO through providers like Authentik or Keycloak. Scoped sharing controls determine whether drawings stay private, shared internally with team members, or accessible via external links without authentication. Collections organize drawings through drag-and-drop grouping, full-text search locates any diagram instantly, and exports use the non-proprietary .excalidraw format ensuring complete data portability. 1,350+ stars since November 2025. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
WhoDB
With nearly 5,000 GitHub stars earned in under two years, WhoDB has rapidly emerged as the lightweight alternative to heavyweight database clients like DBeaver and DataGrip by delivering a sub-50MB binary that starts in under a second and connects to 18+ database systems from a single interface. The Go backend serves the React and TypeScript frontend with table virtualization for efficient rendering of large result sets, lazy loading, and query result streaming that keeps the interface responsive even when browsing tables with millions of rows. The Community Edition connects to PostgreSQL, CockroachDB, YugabyteDB, MySQL, MariaDB, TiDB, SQLite, DuckDB, MongoDB, FerretDB, Redis, Valkey, Dragonfly, Elasticsearch, OpenSearch, ClickHouse, QuestDB, and Memcached through a unified credential selector that switches between databases with minimal configuration. Interactive schema diagrams render entity-relationship graphs showing table structures, foreign keys, and column types for visual database exploration. The Jupyter-style query scratchpad provides SQL autocomplete, syntax highlighting, and multi-statement execution with paginated results. AI integration optionally connects to Ollama, OpenAI, Anthropic, LM Studio, or any OpenAI-compatible provider for natural language database queries — ask questions in plain English and receive generated SQL. Data management includes inline row editing, CSV export, and filtered data views. Docker deployment runs a single container exposing port 8080. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache-2.0 licensed.
Siftly
Siftly transforms your Twitter/X bookmarks from a chaotic pile of saved tweets into a searchable, AI-categorized knowledge base with an interactive visual mindmap. With over 2,700 GitHub stars since March 2026, the platform runs a four-stage enrichment pipeline on each bookmark: entity extraction mines hashtags, URLs, @mentions, and 100+ known tool domains without API calls; vision analysis generates 30-40 visual tags per image using the Anthropic SDK; semantic tagging produces 25-35 searchable descriptors; and categorization assigns one to three categories with confidence scores. Search combines SQLite FTS5 full-text indexing with Claude-based semantic reranking, narrowing candidates through keyword matching, category-intent detection, and deduplication before sending a bounded set for LLM relevance scoring, letting you find bookmarks by meaning rather than exact keywords. The interactive mindmap built on @xyflow/react renders your entire collection as a force-directed graph organized by category with expandable nodes, color-coded legends, and direct links to original tweets. Import bookmarks through a built-in bookmarklet or console script without browser extensions, then browse in grid or list view with filters for category, media type, and date range. Export as CSV, JSON, or category-grouped ZIP archives. Prisma 7 manages the local SQLite database with FTS5 built in, requiring zero external database setup. A bundled CLI provides JSON-output commands for stats, search, and category management. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Laranode
Built for self-hosted server deployments, Laranode transforms bare Linux installations into multi-tenant web hosting platforms with automated Let's Encrypt certificates and isolated PHP environments without recurring license fees. System administrators can provision isolated user accounts with dedicated document roots, configure custom domains, and deploy SSL certificates across all active websites in seconds. The integrated PHP manager enables per-site runtime isolation from legacy PHP 7.4 through cutting-edge PHP 8.5 releases, preventing version conflicts between separate production web applications. Operators can create MySQL databases, manage database users, inspect active connections, and adjust UFW firewall port access directly from the visual dashboard. An integrated browser-based file manager lets developers browse directories, edit configuration files, extract compressed archives, and modify file permissions without external FTP tools. Real-time telemetry monitors CPU utilization, memory consumption, disk capacity, and network traffic over customizable historical timeframes to catch bottlenecks early. Automated backup routines archive full accounts, individual websites, or specific databases to local storage, remote SFTP servers, or S3-compatible cloud object stores with point-in-time recovery verification. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Apprise-API
One REST call, 130+ notification services: Apprise API wraps the well-known Apprise library in a lightweight Django/Gunicorn microservice, so "send an alert" works the same whether it goes to Slack, Discord, Telegram, Teams, email, SMS, Pushover, or PagerDuty - each addressed by a simple URL scheme. It solves the credential-sprawl problem cleanly: instead of embedding provider tokens in every app, cron job, and CI pipeline, you centralize them here and everything else just POSTs a body and title. Two modes cover every workflow. Stateless calls to /notify carry target URLs in the payload (or fall back to a default set via APPRISE_STATELESS_URLS); stateful mode stores named configurations server-side under keys, so /notify/{KEY} fans out to everything registered - with tag-based routing (comma for OR, space for AND) selecting which endpoints fire per message. Messages take info, success, warning, or failure types in text, Markdown, or HTML, with attachments up to a configurable size. A built-in web UI manages and tests configurations, APPRISE_CONFIG_LOCK makes the store read-only, service allow/deny lists restrict which schemes work, webhook remapping adapts third-party payloads, and a Prometheus /metrics endpoint watches the gateway itself.
BillionMail
With over 15,000 GitHub stars accumulated since its February 2025 launch, BillionMail delivers the rare combination of a production mail transfer agent and a full email marketing suite in a single self-hosted package — eliminating the monthly per-subscriber fees charged by Mailchimp, SendGrid, and similar platforms. The Go-based architecture bundles Postfix for SMTP transmission, Dovecot for IMAP and POP3 mailbox access, Rspamd for intelligent spam filtering and greylisting, and RoundCube for browser-based webmail, all orchestrated through Docker Compose with PostgreSQL for persistent storage and Redis for queue management and caching. The marketing engine supports unlimited subscriber lists with tag-based segmentation, scheduled campaign sends, A/B subject line testing, and both HTML and drag-and-drop visual template editors for crafting responsive emails without coding. Real-time analytics dashboards track sent volume, deliverability rate, open rate, click-through rate, and bounce reasons, while the platform provides step-by-step DNS record configuration wizards for SPF, DKIM, and DMARC to maximize inbox placement. A transactional email API exposes REST endpoints for single and batch sending, enabling integration with CRM systems, e-commerce platforms, and custom applications. Auto-provisioned free SSL certificates, Fail2ban brute-force protection, and privacy-first architecture with zero third-party tracking ensure secure operation. The platform installs in under eight minutes via a single shell script and supports SMTP on port 25, SMTPS on 465, submission on 587, IMAP on 143/993, and POP3 on 110/995. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPLv3 licensed.
SOGo
SOGo adds shared calendars, address books, and a modern webmail interface to your existing Dovecot, Postfix, or Cyrus mail setup, turning familiar infrastructure into a full Exchange competitor. Rather than replacing your IMAP and SMTP servers, SOGo layers collaboration on top of them, becoming the missing link between raw mail delivery and what users actually expect from a workplace communication platform. The ActiveSync implementation synchronizes email, contacts, calendars, and tasks natively with iPhones, Android devices, and Windows without requiring users to manually configure CalDAV endpoints. CalDAV and CardDAV compliance ensures Apple Calendar, Thunderbird (via the official SOGo Connector extension), GNOME Evolution, and Android via DAVx5 all connect without plugins or workarounds. The web interface uses AngularJS Material design with responsive layouts, offering folder management, drag-and-drop calendar scheduling, contact groups, resource booking, and delegation. Shared calendars support free-busy lookups, iMIP event invitations, and per-user ACL permissions for fine-grained access across organizational units. Built on Objective-C with the GNUstep foundation, SOGo delivers exceptional performance: hundreds of concurrent ActiveSync connections from mobile devices alongside webmail and calendar traffic with sub-second response times. With 2,095+ stars and 116 releases, the project has proven its stability in production environments supporting thousands of users. The Docker deployment runs alongside PostgreSQL and memcached.
Kodus AI
Kodus AI automates pull request code review with inline AI comments across GitHub, GitLab, Bitbucket, and Azure DevOps, supporting any LLM provider at cost with zero token markup. The multi-service TypeScript architecture deploys via Docker Compose, running an API server, background worker, webhooks service, and React dashboard backed by PostgreSQL with pgvector, MongoDB, and RabbitMQ. Integration covers both cloud platforms and their enterprise flavors (GitHub Enterprise Server, GitLab Self-Managed, Bitbucket Data Center) using standard OAuth flows and webhook signing to keep the review loop entirely inside your network. The platform is model-agnostic with Bring Your Own Key support for Claude, GPT, Gemini, Llama, and any OpenAI-compatible endpoint including locally-hosted models. Custom review rules combine your team's coding standards with requirements pulled from Jira, Linear, and Notion, automatically checking every PR against documented specifications. The CLI enables local reviews against working trees, staged diffs, branches, or specific commits, integrating into CI/CD pipelines as pre-merge gates. Source code is never stored and never used for model training, with all data encrypted in transit and at rest. 1,270+ stars and 129+ releases since March 2025. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Bambuddy
Command and automate your entire fleet of 3D printers without relying on proprietary cloud services using Bambuddy, a self-hosted management hub that delivers local network control, print scheduling, and job archiving for Bambu Lab hardware. Print shop operators can route slicing output directly from Bambu Studio or Orca Slicer through virtual printer proxies that emulate physical machines while automatically cataloging print files in a searchable 3D repository. The automated dispatch engine assigns queued gcode files to available printers based on required nozzle temperatures, build plate dimensions, and matched multi-color filament slots. Users can inspect live camera streams across multiple printing beds simultaneously, verify empty build plates before dispatching new jobs, and generate stabilized timelapse videos with custom music. Integrated smart plug connectors automatically cut power to idle machines when print cycles finish and trigger push notifications to Discord or mobile devices if thermal anomalies or mechanical pauses occur. Farm managers can schedule maintenance alerts based on cumulative motor runtime, track spool inventory levels across storage locations, and synchronize printing configurations across duplicate hardware setups. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPL v3.0 licensed.
PodFetch
Podcast enthusiasts and homelab archivers automate digital episode preservation and stream personal audio feeds using PodFetch, an open-source self-hosted podcast manager that combines scheduled RSS downloads, Podcasting 2.0 transcript indexing, and browser playback into a modern listening platform. Listeners can subscribe to international podcast channels through direct feed URLs, Apple Podcasts directory searches, or bulk OPML subscription imports, configuring background polling timers to download new releases automatically upon publication. The integrated audio player supports variable speed playback, episode bookmarks, listening histories, and fullscreen visualization modes directly inside responsive desktop and mobile browser sessions. Advanced search capabilities leverage Podcasting 2.0 synchronized transcripts and automated speech-to-text generation via OpenAI-compatible Whisper APIs, allowing collectors to run full-text keyword searches across every spoken phrase in their audio archive. Built-in GPodder API synchronization maintains subscription lists and playback positions across popular smartphone apps like AntennaPod and native companion clients without relying on commercial cloud accounts. Server operators can assign multi-user accounts with private favorites lists, export customized RSS aggregation streams, and route storage paths between fast solid-state drives and large secondary mechanical hard disks. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache-2.0 licensed.
Akaunting
Akaunting is an online accounting software for small businesses and freelancers. The double-entry accounting engine provides a full Chart of Accounts, journal entries, and balance sheet reporting, eliminating the manual errors inherent in single-entry systems. Unlimited invoice creation with customizable templates, automatic payment reminders, and client portal access lets businesses present professional documents and accept payments through PayPal, Stripe, and other gateway integrations. Expense tracking captures operational costs with category-based organization, receipt scanning, and vendor bill management with overdue payment alerts. Bank Feeds auto-syncs transactions from connected bank accounts and matches them against invoices and bills for streamlined reconciliation. The dashboard displays receivables, payables, cash flow summaries, profit and loss charts, expenses by category, and account balances at a glance with configurable date ranges. Quotes and estimates convert directly into invoices upon client approval, while recurring invoices and bills automate periodic billing without manual intervention. The modular architecture built on Laravel with the Akaunting Module package enables an App Store where developers publish extensions for payroll, inventory, projects, and CRM functionality. Multi-company support manages separate books from a single installation with per-company user roles. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSL licensed.