Mail-in-a-Box
Mail-in-a-Box turns a single Ubuntu server into a fully functional email system with one setup command, installing and configuring Postfix for SMTP, Dovecot for IMAP, Roundcube for webmail, and Z-Push for Exchange ActiveSync push notifications in an automated sequence that would take days to replicate manually. The DNS server auto-configures the full suite of email authentication records: SPF, DKIM, DMARC, DNSSEC with DANE TLSA, MTA-STS, and SSHFP. Getting all of these right is what separates email that lands in inboxes from email that lands in spam, and most manual installations never achieve the complete set. Nextcloud integration adds CardDAV contact sync and CalDAV calendar sharing across devices. Let's Encrypt certificates provision and renew automatically for every hosted domain. The web control panel manages users, aliases, custom DNS records, and automated backups, protected by TOTP two-factor authentication. Daily health checks verify that services run correctly, ports remain open, TLS certificates stay valid, and DNS records resolve properly, alerting you before delivery problems develop. Multiple domains and users operate from one installation with internationalized domain name support. Built-in HTTPS static site hosting uses the TLS infrastructure already in place. Runs on a dedicated RepoCloud VPS with guaranteed resources, root SSH, and browser serial console for complete email sovereignty. CC0 public domain licensed.
InsForge
With 12,600 GitHub stars and 52 releases in under a year of development, InsForge is the fastest-growing open-source backend platform purpose-built for AI coding agents — giving Claude, Cursor, and any MCP-compatible tool direct access to database, authentication, storage, compute, and AI model infrastructure through a single self-hosted stack. The native MCP server exposes every InsForge operation as callable tools, letting coding agents autonomously create database tables, manage user authentication, upload files, deploy edge functions, and ship complete full-stack applications without human intervention. The Model Gateway provides an OpenAI-compatible API that routes requests across multiple LLM providers (OpenAI, Anthropic, Google, and open-source models) with unified billing, rate limiting, and fallback logic. PostgreSQL with pgvector handles both relational data and vector embeddings for RAG pipelines, while S3-compatible storage manages file uploads and static assets. Edge Functions run serverless TypeScript code on Deno with sub-millisecond cold starts for API endpoints, webhooks, and scheduled tasks. The authentication system provides user management, OAuth2 flows, sessions, and magic links with JWT token handling built in. Site Deployment builds and serves frontend applications with automatic SSL and custom domain configuration. The CLI paired with Agent Skills enables terminal-based workflows where agents invoke InsForge operations directly from the command line. Deploy via Docker with PostgreSQL as the only required external dependency. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache-2.0 licensed.
Neon
Neon reimagines PostgreSQL with a serverless architecture that decouples storage from compute, enabling instant copy-on-write database branching, autoscaling under load, and scale-to-zero when idle with sub-second cold starts. The lakebase architecture distributes durability across three layers: stateless compute nodes running unmodified PostgreSQL, safekeepers providing Paxos-based WAL quorum replication, and a pageserver that materializes pages on demand while offloading immutable history to S3-compatible object storage via MinIO or AWS S3. Copy-on-write branching creates full database clones as metadata operations without duplicating data, enabling developers to spin up isolated test environments, run parallel CI/CD pipelines, or recover from data loss through point-in-time restore across the configurable history window. Autoscaling dynamically adjusts CPU and memory based on live traffic without manual capacity planning, while scale-to-zero ensures costs drop to storage-only during idle periods. Neon maintains 100% PostgreSQL compatibility with broad extension support including PostGIS, pg_cron, pgvector, pg_stat_statements, and hundreds more, so existing applications connect with standard PostgreSQL drivers and ORMs unchanged. The API-first control plane enables programmatic provisioning, branch management, and multi-tenant fleet operations for platform builders and AI agent integrations. Acquired by Databricks in May 2025 and backed by over 22,800 GitHub stars. Deploys via Docker Compose with pageserver, safekeepers, storage broker, and compute nodes backed by MinIO object storage. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
BookOrbit
Consolidate your entire digital library into a self-hosted reading sanctuary with BookOrbit, an open-source media platform that organizes ebooks, audiobooks, comic archives, and research PDFs within a personal private cloud. Readers can enjoy multi-format media directly through responsive browser readers that support EPUB, CBZ, and M4B formats without external browser extensions. The platform synchronizes reading bookmarks, highlights, and completion statuses across web interfaces, Kobo ereaders, and KOReader devices. An automated metadata enrichment engine queries fourteen upstream bibliographic indexes, downloading cover artwork, chapter breakdowns, author biographies, and series taxonomies. The staging workspace allows librarians to inspect incoming files, review suggested metadata revisions, and embed updated tags directly into physical storage archives before shelving. Custom reading dashboards track annual book goals, calculate daily streaks, and plot reading habit radar charts. Multi-user configurations support distinct per-user collections, granular content permissions, and single sign-on authentication through OpenID Connect providers. Power users can export private OPDS feeds to external mobile reading applications or push books directly to connected Kindle hardware. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPL v3.0 licensed.
3X-UI
3X-UI is the most popular open-source Xray management panel, providing a full-featured web interface for deploying and monitoring proxy and VPN protocols on Linux servers. The Go backend manages Xray-core instances supporting VLESS, VMess, Trojan, Shadowsocks, WireGuard, Hysteria2, HTTP, SOCKS, Dokodemo-door, and TUN inbounds across TCP, mKCP, WebSocket, gRPC, HTTPUpgrade, and XHTTP transports secured with TLS, XTLS Vision, and REALITY. The Clients page tracks each user with individual traffic quotas, expiration dates, concurrent connection limits, and live online status indicators, while one-click share links, QR codes, and a built-in subscription server distribute configurations in multiple output formats. The multi-node architecture manages and scales deployments across multiple servers from a single panel instance. The Panel Settings page configures listen address, port, URI path, session duration, trusted proxy CIDRs, authentication, and Telegram bot integration for remote monitoring and management alerts. Outbound routing supports WARP, NordVPN, custom rules, load balancers, and proxy chaining. Xray Configs provides template-level control over the core configuration, while the API Docs page exposes a complete RESTful API with in-panel Swagger documentation. Data persists in SQLite by default or PostgreSQL for larger deployments, with database export and import from the panel. Fail2ban integration enforces per-client IP limits. On RepoCloud, deploy 3X-UI on a dedicated VPS with Docker, root SSH access, and complete control over your proxy infrastructure, all under the GPL-3.0 license.
Sencho
With over 430 GitHub stars and designed for DevOps engineers, platform teams, and homelab operators, Sencho is the self-hosted Docker Compose control plane that gives you a real operational cockpit without abandoning file-on-disk compose workflows. The web dashboard provides live CPU, memory, and disk sparklines per container, one-click start/stop/restart controls, and a Monaco-powered YAML editor with syntax highlighting, inline diff, and one-click rollback. Compose files remain the source of truth on the host filesystem. Multi-node management connects remote Sencho instances via authenticated HTTP and WebSocket proxy using long-lived API tokens, with no SSH access or exposed Docker sockets required. The Pilot Agent establishes an outbound-only WebSocket tunnel for nodes behind NAT, CGNAT, or strict firewalls. Blueprints define compose intent once and deploy it across label-targeted nodes, with drift detection keeping the fleet aligned. Fleet Federation provides cordon and pin controls for maintenance windows, while Fleet Actions execute bulk deploy, stop, and restart operations by stack label across the entire infrastructure. The security suite includes Trivy vulnerability scanning, deploy enforcement policies, SARIF and SBOM export, and Fleet Sync to replicate scan policies across replicas. Additional capabilities include 199+ one-click app templates, Git source integration, atomic deploys with auto-rollback, auto-heal, scheduled operations, webhooks, and custom S3 off-site backups to MinIO, R2, B2, or AWS. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Bulwark Webmail
Transforming your Stalwart Mail Server into an all-in-one private communication hub, Bulwark Webmail delivers fast web-based email, collaborative calendars, shared contacts, and cloud files in a single unified interface. Users can manage multiple email accounts from an integrated inbox with conversational message threading, nested organizational tags, scheduled delivery, and instant full-text search across thousands of archived messages. The rich text composer provides markdown shortcuts, inline image embedding, reusable canned response templates, and automated draft synchronization. Team members can coordinate schedules across day, week, month, and agenda calendar views with drag-to-reschedule adjustments, interactive iMIP meeting invitations, and external CalDAV calendar subscriptions. The integrated address book organizes individual contacts into custom groups with full vCard import and export support, while the files module lets users browse server storage, preview incoming attachments, and upload documents directly through the browser. Built-in security safeguards enforce multi-factor authentication, cryptographic S/MIME signatures, client-side encryption at rest, and automated HTML luminance remapping to keep dark emails legible. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL v3 licensed.
xyOps
With 4,500+ GitHub stars and version 1.0.92 released August 2026, xyOps delivers a complete operations platform that unifies workflow automation, job scheduling, server monitoring, alerting, and incident response in one self-hosted system. The platform uses a distributed architecture where a central conductor coordinates lightweight xySat satellite agents running on Linux, macOS, or Windows worker nodes via persistent WebSocket connections. The visual workflow builder lets you chain events, triggers, actions, and monitors into multi-step pipelines with conditional logic, fan-out/fan-in parallelism, multiplex controllers for fleet-wide execution, and configurable resource limits. QuickMon provides per-second CPU, memory, disk, and network visibility streamed live to the web UI, while user-defined monitor plugins sample metrics every minute with time-series storage at hourly, daily, monthly, and yearly resolutions. Alert triggers evaluate expressions against live data and fire notifications via email, webhook, or custom actions, with full server snapshots attached showing every running process, network connection, and resource utilization at the moment of detection. Failed jobs and alerts automatically create tickets with linked logs, metrics history, and context for end-to-end incident tracking. The plugin marketplace supports extensions written in any language, and the Docker plugin enables container-based job execution. Deploy via Docker with persistent volumes on port 5522 for the web UI and 5523 for API access, running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD-3-Clause licensed.
Calibre-Web
With over 17,700 GitHub stars and continuous development since 2015, Calibre-Web has become the definitive self-hosted digital library solution for book enthusiasts who want beautiful web access to their Calibre collections. The responsive Bootstrap 3 interface delivers instant browsing, searching, and filtering across titles, authors, tags, series, book formats, and languages, with custom shelves for organizing personal reading collections. In-browser reading supports EPUB, PDF, TXT, CBR, CBT, CBZ, and DJVU formats with a configurable EPUB reader featuring multiple themes and page location tracking, while one-click email delivery sends books directly to Kindle, Kobo, and other E-Readers without leaving the interface. Native Kobo sync lets Kobo device owners synchronize their entire Calibre library wirelessly, maintaining reading progress and bookmarks across devices. Metadata management includes editing capabilities with automatic metadata downloading from Google Books, Amazon, and other configurable sources, plus eBook format conversion through Calibre binaries for on-the-fly EPUB, MOBI, AZW3, and PDF conversion. User management provides fine-grained per-user permissions controlling download access, upload rights, editing capabilities, and content visibility based on categories or Custom Column values. Authentication supports local accounts, LDAP directory integration, Google and GitHub OAuth, proxy authentication, and Magic Link login for easy E-Reader access. The OPDS catalog feed enables any compliant E-Reader app to browse and download from the library. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
Stalwart Mail
Stalwart replaces the traditional Postfix + Dovecot + SpamAssassin + calendar-server stack with one Rust binary that speaks every standard mail and collaboration protocol natively. JMAP, IMAP4rev2, POP3, SMTP, CalDAV, CardDAV, and WebDAV all run inside the same process — no glue scripts, no sidecar daemons, no version conflicts between components. The pluggable storage architecture lets operators choose RocksDB for single-node deployments, FoundationDB for distributed clusters, PostgreSQL, MySQL/MariaDB, or SQLite for the data store, S3/MinIO/Azure Blob for message blobs, and Elasticsearch or Meilisearch for full-text search, with Redis or the internal engine backing rate limiters and session state. Security features include S/MIME and OpenPGP encryption at rest, automated DKIM key generation with DNS publication, DANE and MTA-STS transport security, automatic ACME TLS provisioning, granular ACLs, rate limiting, and IP banning. The browser-based admin console manages accounts, domains, groups, mailing lists, SMTP queues, DMARC/TLS-RPT/ARF reports, and every configuration object without touching a config file, while the self-service portal at /account gives end users password reset and encryption key management. Multi-tenant support with per-tenant quotas enables hosting-platform deployments, and coordinator-less clustering via Zenoh or NATS scales horizontally by adding nodes. Deploy via Docker or the standalone binary. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL v3 licensed.
Nhost
Backed by 9,200 GitHub stars and venture funding led by Nauta Capital, Nhost is the open-source Firebase alternative that replaces Google's proprietary document store with a relational PostgreSQL foundation from day one. The Hasura integration auto-generates a real-time GraphQL API with subscriptions, role-based permissions, and remote schemas from your PostgreSQL tables, while event triggers and cron triggers automate backend workflows without custom infrastructure. Authentication supports email and password, magic links, phone OTP via SMS, social OAuth providers including Google and GitHub, WebAuthn for passwordless login with Face ID, fingerprints, and YubiKeys, plus two-factor authentication. Since the Q1 2026 release, Nhost Auth also functions as a full OAuth2 and OpenID Connect provider, allowing your Nhost project to issue tokens to third-party applications the same way GitHub or Google do. The S3-compatible storage service handles file uploads with automatic image optimization, virus scanning, and presigned URLs for secure direct downloads. Node.js serverless functions deploy JavaScript and TypeScript backend logic without managing servers, while the Nhost CLI spins up the complete local stack via Docker for development with automatic database migration tracking and Hasura metadata management. The MCP server integration exposes project documentation and data schemas to AI assistants for intelligent query building. SDKs cover JavaScript, TypeScript, React, Vue, Next.js, and Dart for Flutter. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Radarr
The movie half of the *arr stack: Radarr is a .NET collection manager that automates acquiring films for Usenet and BitTorrent users the way Sonarr does for TV. Add a movie once and Radarr handles the rest: it monitors indexers and RSS feeds, grabs a matching release the moment one appears, sends it to SABnzbd, NZBGet, qBittorrent, Deluge, Transmission, rTorrent, or another connected download client, then imports, sorts, and renames the file into your library structure. Quality profiles are the control surface - define allowed resolutions and a cutoff, and Radarr keeps upgrading files automatically, replacing a DVD rip when a Blu-ray release lands. Custom formats go further, scoring releases by codec, HDR metadata, release group, streaming source, or arbitrary regex so the copy you want always wins the pick. Failed downloads retry with another release automatically; a manual search shows every candidate and explains why one was skipped. Release parsing recognizes director's cuts, special editions, AKA titles, and hardcoded subs. Plex and Kodi integration handles notifications, library refreshes, and metadata like posters, trailers, and subtitles, and a calendar view tracks upcoming releases. It pairs naturally with Jellyseerr for request management and shares its API conventions with the whole *arr ecosystem.
Laranode
Built for self-hosted server deployments, Laranode transforms bare Linux installations into multi-tenant web hosting platforms with automated Let's Encrypt certificates and isolated PHP environments without recurring license fees. System administrators can provision isolated user accounts with dedicated document roots, configure custom domains, and deploy SSL certificates across all active websites in seconds. The integrated PHP manager enables per-site runtime isolation from legacy PHP 7.4 through cutting-edge PHP 8.5 releases, preventing version conflicts between separate production web applications. Operators can create MySQL databases, manage database users, inspect active connections, and adjust UFW firewall port access directly from the visual dashboard. An integrated browser-based file manager lets developers browse directories, edit configuration files, extract compressed archives, and modify file permissions without external FTP tools. Real-time telemetry monitors CPU utilization, memory consumption, disk capacity, and network traffic over customizable historical timeframes to catch bottlenecks early. Automated backup routines archive full accounts, individual websites, or specific databases to local storage, remote SFTP servers, or S3-compatible cloud object stores with point-in-time recovery verification. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Mox
Mox offers a complete mail server stack in a single Go binary requiring no external dependencies. The quickstart command configures a working mail server with SMTP, IMAP4, webmail, and full DNS authentication in under ten minutes. SMTP handling includes a delivery server on port 25, a submission server for authenticated clients, and a queue with automatic retries and DKIM signing. IMAP4rev2 implementation provides full mailbox synchronization with CONDSTORE and QRESYNC for efficient offline clients, NOTIFY for multi-mailbox monitoring, MULTISEARCH across mailboxes, and TLS client certificate authentication via the EXTERNAL SASL mechanism. The built-in webmail provides browser-based reading and composing with message threading, attachments, and HTML rendering without requiring a separate web client. Email authentication implements SPF validation, DKIM signing and verification with automatic key rotation, DMARC policy enforcement with aggregate and failure reporting, DANE with DNSSEC-protected TLSA records, and MTA-STS for certificate verification. Junk filtering combines reputation-based sender scoring with Bayesian content analysis trained per account. The web administration interface manages domains, accounts, DNS records, TLS certificates, delivery queue, and real-time log viewing. Internationalized email addresses with EAI and IDNA support handle non-ASCII domains and mailboxes. Account autoconfiguration publishes settings for Thunderbird autoconfig and Outlook autodiscover. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Kima
Streaming personal music collections with neural discovery and intelligent playlist curation is what Kima accomplishes as a modern self-hosted audio server that replaces Spotify and Apple Music. Listeners organize their FLAC, MP3, and AAC audio files into responsive grid layouts that scale up to eight columns on ultra-wide displays while automatically fetching album covers, artist biographies, and synchronized line-by-line lyrics. The built-in Vibe System utilizes CLAP neural network audio embeddings to map an entire music collection across two-dimensional clusters and three-dimensional interactive galaxy views, enabling users to explore acoustic relationships or queue smooth sonic paths between distant tracks. Music fans can import playlists directly from Spotify, Deezer, and YouTube using deterministic ISRC matching, while automated Made For You mixes generate era-specific playlists, workout stations, and discovery queues based on individual listening habits. Integrated podcast search pulls subscriptions from iTunes with automatic episode tracking across devices, while native Audiobookshelf connectors synchronize spoken-word chapter positions and playback progress directly into the unified web player. OpenSubsonic API endpoints allow mobile users to stream libraries through native clients like Symfonium and DSub using scoped authentication tokens, while administrators manage multi-user accounts with time-based two-factor authentication. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
Rivet
Stateful serverless actors that run indefinitely, sleep when idle, and persist state across restarts without external database round trips. Rivet provides a vendor-neutral alternative to Cloudflare Durable Objects, delivering long-running processes with co-located in-memory state and per-actor SQLite databases on any infrastructure you choose. The Rust engine comprises four packages: Pegboard for actor orchestration, Gasoline for durable execution, Guard for traffic routing via Envoy, and Epoxy implementing multi-region KV storage through EPaxos consensus. Each actor maintains instant-access in-memory state plus a dedicated SQLite database for relational queries, backed by RocksDB on single nodes or PostgreSQL with NATS pub/sub for multi-node clusters. RivetKit SDKs in TypeScript, Rust, and Python support built-in WebSocket connections, task queues, scheduling, and CRDT-based real-time collaboration. The v2.3 rewrite moved the core runtime from JavaScript to native Rust via WebAssembly, eliminating main-thread blocking across Node.js, Bun, Deno, and Cloudflare Workers. A built-in dashboard provides actor inspection with real-time Prometheus metrics. Deploys as a single Docker container on port 6420 with optional PostgreSQL for persistence. Available on RepoCloud with a dedicated VPS under the Apache 2.0 license.
BillionMail
With over 15,000 GitHub stars accumulated since its February 2025 launch, BillionMail delivers the rare combination of a production mail transfer agent and a full email marketing suite in a single self-hosted package — eliminating the monthly per-subscriber fees charged by Mailchimp, SendGrid, and similar platforms. The Go-based architecture bundles Postfix for SMTP transmission, Dovecot for IMAP and POP3 mailbox access, Rspamd for intelligent spam filtering and greylisting, and RoundCube for browser-based webmail, all orchestrated through Docker Compose with PostgreSQL for persistent storage and Redis for queue management and caching. The marketing engine supports unlimited subscriber lists with tag-based segmentation, scheduled campaign sends, A/B subject line testing, and both HTML and drag-and-drop visual template editors for crafting responsive emails without coding. Real-time analytics dashboards track sent volume, deliverability rate, open rate, click-through rate, and bounce reasons, while the platform provides step-by-step DNS record configuration wizards for SPF, DKIM, and DMARC to maximize inbox placement. A transactional email API exposes REST endpoints for single and batch sending, enabling integration with CRM systems, e-commerce platforms, and custom applications. Auto-provisioned free SSL certificates, Fail2ban brute-force protection, and privacy-first architecture with zero third-party tracking ensure secure operation. The platform installs in under eight minutes via a single shell script and supports SMTP on port 25, SMTPS on 465, submission on 587, IMAP on 143/993, and POP3 on 110/995. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPLv3 licensed.
Wizarr
Getting non-technical friends and family onto a media server is its most tedious chore - Wizarr solves it. Instead of manually creating accounts, dictating server addresses, and explaining which app to install, you send one invite link. When the recipient clicks it, Wizarr creates their account on your server automatically - Plex, Jellyfin, Emby, Audiobookshelf, Komga, Kavita, and Romm are all supported - then walks them through a mobile-first, app-like onboarding wizard: download the right client, sign in, and learn how to request movies through your Overseerr or Ombi instance, with an optional Discord server invite along the way. Invitations are genuinely manageable: set expiration dates, usage limits, passphrases, library-scoped access tiers, and time-limited memberships that end access automatically. The wizard itself is fully customizable - Markdown-based steps managed from the admin UI, organized into pre-invite and post-invite phases (terms of service before joining, app setup after), reorderable bundles assignable to specific invitation types, and combined flows for invites spanning multiple servers. Multi-server and multi-admin support manages several backends from one dashboard, SSO support is plug-and-play, and a REST API with OpenAPI/Swagger documentation covers automation. A Flask/HTMX app in a single Docker container.