AliasVault
Sign up for a new service and you face a familiar choice: hand over your real email and get spam-listed forever, or generate a throwaway alias that dies when you close the tab. AliasVault eliminates that trade-off by combining a password manager with a built-in email server, so every website gets a unique identity (random email, generated name, strong password) and incoming emails land directly in your encrypted vault rather than your primary inbox. Creating a new alias takes one click: the system generates a random address on your configured domain, a fake identity with name and birthdate, and a cryptographically strong password, all stored in a zero-knowledge encrypted vault that even the server administrator cannot read. Browser extensions for Chrome, Firefox, Edge, Safari, and Brave detect login forms and autofill credentials or prompt you to create a new alias on the spot. Native iOS and Android apps with biometric unlock provide mobile access to your vault and integrate with the operating system's autofill framework. The built-in TOTP authenticator generates time-based one-time codes without needing a separate app. Import existing credentials from other password managers through standard export formats, and export your vault data at any time for full portability. Self-hosting via Docker with your own email domain gives you complete control over where alias mail is received and stored, with no third-party dependencies. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Mission Control
With over 600 GitHub stars and a featured Show HN launch, Mission Control is the agent-first command center that replaces the chaos of manually shepherding AI agents with structured delegation, approval workflows, and autonomous execution. The Next.js 15 web UI delivers an Eisenhower priority matrix with drag-and-drop quadrants, a Kanban board tracking tasks through Not Started, In Progress, and Done columns, and a goal hierarchy with milestone progress bars — powered by shadcn/ui, Radix UI, and @dnd-kit. Six built-in agent roles — Researcher, Developer, Marketer, Business Analyst, Tester, and You — receive tasks through a token-optimized API compressing context by 92 percent to approximately 50 tokens versus 5,400 unfiltered. The autonomous daemon polls task queues on cron schedules, spawns Claude Code sessions via the official CLI, enforces concurrency limits, and auto-retries with loop detection that escalates to human decisions after three failures. Field Ops extends execution to 64 external services across 16 categories with working X, Ethereum with MetaMask signing, and Reddit adapters, protected by AES-256-GCM encrypted vault with scrypt key derivation, per-service and global spend limits, a circuit breaker, and three autonomy levels. All data lives in local JSON files with Zod validation and async-mutex locking ensuring safe concurrent writes, backed by 193 automated Vitest tests. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Duckle
Duckle compiles visual data integration pipelines into vectorized analytical SQL executed on an embedded columnar engine, eliminating the overhead and cloud egress costs of traditional ETL infrastructure. Engineers can construct data pipelines on a drag-and-drop canvas, connecting hundreds of data sources spanning relational databases, cloud object storage, streaming event buses, vector databases, and SaaS application programming interfaces. An interactive mapping editor enables complex joins between primary data inputs and lookup streams with typed transform expressions and live sample inspections. Built-in transformation blocks execute change data capture, slowly changing dimensions, aggregation rollups, and integrated dbt models with zero row-based metering or cloud egress fees. Teams schedule headless production executions through a dedicated web console equipped with role-based access management, execution audit trails, and automated failure alerts dispatched to webhook endpoints. Embedded Model Context Protocol capabilities allow AI coding assistants to validate schema configurations, inspect execution logs, and trigger batch workflows directly through conversational commands. Workspaces store entire pipeline definitions as individual files in version control, ensuring reproducible deployments across staging and production environments. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache-2.0 licensed.
Fireshare
The moment after ShadowPlay saves a great clip is what Fireshare was built for: your friends see it now, not after a YouTube upload, processing queue, and platform terms review. Drop videos into a watched folder and this Flask/React application generates a unique shareable URL for each one, complete with Open Graph metadata - so pasting the link into Discord, Twitter, or Slack produces a proper embed with title, description, and video thumbnail instead of a raw URL. Viewers need no account and no app. Visibility is per-file: public (browseable on your feed), private (unlisted, reachable only by direct link), or password protected. For game clips specifically, Fireshare organizes automatically - clips sort by game with cover art pulled from SteamGridDB, no manual tagging - while tags and full-library search cover everything else. Optional transcoding (CPU or GPU) creates lower-quality renditions so viewers on weak connections get automatic quality adaptation, and video cropping trims clips in place. The extras round out a genuinely finished tool: view counters, timestamped share links, a shuffle button, restrictable uploads, Discord notifications for new videos, an RSS feed of the public feed, mobile support, and LDAP for multi-user setups. No storage limits, no watermarks, no platform deciding what stays up. GPL-licensed.
Pipelock
Your AI coding agent has your API keys in its environment and unrestricted network access, which means one prompt injection away from sending those secrets anywhere. Pipelock closes that gap by sitting as a proxy between your agents and every outbound connection, scanning the actual content of HTTP, WebSocket, MCP, and Agent-to-Agent traffic before it leaves your server. An 11-layer scanner pipeline checks every request against 62 credential patterns covering AWS, GCP, Azure, GitHub, OpenAI, Anthropic, SSH keys, and database URLs, then inspects every response for prompt injection using 29 detection patterns with six-pass normalization that catches base64-encoded, leetspeak, and whitespace-obfuscated payloads. The MCP proxy wraps any Model Context Protocol server (stdio, HTTP, or WebSocket) with bidirectional scanning that detects tool description poisoning and mid-session rug-pull changes via SHA-256 fingerprinting. Every scanning decision produces a cryptographically signed action receipt that third parties can verify offline without trusting the agent or the vendor. The Operator Console provides a web dashboard for reviewing evidence scorecards, receipt timelines, agent sessions, enforcement decisions, and fleet posture at a glance. Cross-request taint tracking catches slow-drip exfiltration attempts that spread a secret across multiple calls. Canary tokens plant synthetic secrets that trip alerts the moment an agent tries to exfiltrate them. Pre-built Prometheus metrics and a Grafana dashboard provide real-time visibility into traffic volumes and block rates. Deploy on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Sage Wiki
Sage Wiki turns a pile of unstructured documents into a fully interlinked, searchable wiki by running them through a five-pass LLM compiler pipeline. Inspired by Andrej Karpathy's vision of LLM-compiled knowledge bases, the pipeline processes source files through diff detection, summarization, concept extraction, image captioning, and cross-reference discovery, with parallel LLM calls and checkpoint/resume for vaults scaling to 100,000+ documents. The typed ontology graph stores entities and relations with BFS traversal, configurable relation types, multilingual synonyms, and a promotion/demotion lifecycle backed by grounding verification and consensus scoring. Multi-format ingestion handles Markdown, PDF, Word, Excel, PowerPoint, EPUB, email, CSV, images, and code files without manual tagging. LLM provider support spans Anthropic, OpenAI, Gemini, Ollama, and any OpenAI-compatible API, with per-pass model routing enabling cost optimization by assigning cheaper models to simpler tasks. The built-in MCP server exposes 17 tools over SSE transport for integration with Claude, Cursor, and any MCP-compatible agent, while native Obsidian vault overlay ensures existing note workflows remain undisrupted. Team deployment supports Git-synced shared wikis, centralized server access, and hub federation across multiple projects. Ships as a single Go binary with Docker Compose multi-arch images serving the web UI on port 3333. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Apprise-API
One REST call, 130+ notification services: Apprise API wraps the well-known Apprise library in a lightweight Django/Gunicorn microservice, so "send an alert" works the same whether it goes to Slack, Discord, Telegram, Teams, email, SMS, Pushover, or PagerDuty - each addressed by a simple URL scheme. It solves the credential-sprawl problem cleanly: instead of embedding provider tokens in every app, cron job, and CI pipeline, you centralize them here and everything else just POSTs a body and title. Two modes cover every workflow. Stateless calls to /notify carry target URLs in the payload (or fall back to a default set via APPRISE_STATELESS_URLS); stateful mode stores named configurations server-side under keys, so /notify/{KEY} fans out to everything registered - with tag-based routing (comma for OR, space for AND) selecting which endpoints fire per message. Messages take info, success, warning, or failure types in text, Markdown, or HTML, with attachments up to a configurable size. A built-in web UI manages and tests configurations, APPRISE_CONFIG_LOCK makes the store read-only, service allow/deny lists restrict which schemes work, webhook remapping adapts third-party payloads, and a Prometheus /metrics endpoint watches the gateway itself.
Seatsurfing
Seatsurfing brings desk booking, room reservations, and parking management to interactive floor plans across multiple office locations, solving the coordination headache of hybrid work. The Go backend serves two React/TypeScript frontends through a single Docker container on port 8080: a Booking UI built as an installable Progressive Web App for mobile and desktop reservations, and an Admin UI for floor plan configuration, capacity enforcement, and analytics. Interactive floor plans accept uploaded office layouts where administrators visually place bookable spaces with per-space metadata and availability rules. Multi-location support handles organizations with distributed offices across multiple buildings and cities. The buddy system displays which colleagues have bookings on a given day, enabling team coordination without manual communication. Capacity management enforces occupancy limits per area with automatic denial when thresholds are reached. SSO integration supports OIDC and OAuth2 providers including Microsoft Azure AD, Keycloak, and Authentik for enterprise identity federation. Microsoft Teams and Confluence integrations embed booking directly into collaboration tools employees already use daily. The REST API enables automation and custom integrations, while the analytics dashboard tracks utilization rates, peak hours, and booking patterns. Docker Compose deployment requires only a PostgreSQL database with multi-architecture images supporting amd64 and arm64. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
Traggo
With over 1,600 GitHub stars and a design philosophy that fundamentally rethinks how time tracking should work, Traggo abandons the traditional project-task hierarchy that forces your work into rigid categories and instead lets you tag time spans with arbitrary key-value pairs — project:website, type:coding, client:acme, billable:yes — enabling cross-dimensional analysis that conventional trackers cannot replicate. The Go backend compiles into a single binary that runs alongside a SQLite database and embedded web UI in under 10MB total, consuming approximately 50MB of RAM at runtime and starting in seconds on even the smallest VPS. Tags are the fundamental data model: create any tag key with any set of values, then apply multiple tags to each time span simultaneously to track by project, client, task type, energy level, or any other dimension your workflow demands. Customizable dashboards render pie charts, bar charts, and line graphs from tag-aggregated data, letting you visualize time distribution across any combination of dimensions over configurable date ranges. The calendar view displays time spans as colored blocks across days and weeks, while the list view provides chronological entry browsing with inline editing. Multiple themes including light and dark modes adapt the interface to personal preference, and simple user management with role-based access supports small team deployments. Docker deployment runs a single container exposing port 3030 with multi-architecture support for amd64, arm64, and arm v7. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.
Eclaire
Built to consolidate fragmented digital life into a private personal cloud, Eclaire centralizes tasks, notes, documents, photos, and web bookmarks into a unified workspace powered by local artificial intelligence. Users can save web articles to generate clean Markdown copies and searchable PDF archives, automatically bypassing clutter and dead links. The integrated document ingestion engine extracts tabular data from spreadsheets, performs optical character recognition across uploaded receipts and handwritten images, and indexes multi-page PDF manuals for rapid full-text search. Conversational assistant panels allow operators to interrogate their accumulated library using natural language, asking for cross-document summaries, research timelines, or action items extracted from meeting transcripts. Background workers prioritize asynchronous indexing queues, categorizing image libraries with visual object tags and managing recurring task deadlines with automated Telegram alert notifications. External automation flows can interact directly with the unified storage layer via an OpenAI-compatible REST API, allowing mobile shortcuts and custom scripts to ingest bookmarks and dictate notes remotely. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
mCaptcha
The CAPTCHA bargain - annoy your users and feed their behavior to Google - gets replaced with economics by mCaptcha. Instead of image puzzles, it uses SHA256 proof-of-work: every visitor's browser silently solves a small computational challenge (via a WebAssembly library) before submitting a form. Humans never notice the milliseconds; bots hammering your site must burn more compute sending requests than your server spends answering them, which makes attacks more expensive than defense - the property that also makes mCaptcha genuine DoS protection, not just bot filtering. Written in Rust, the system is fully automated: difficulty scales with traffic, so challenges stay trivial in normal conditions and harden under attack. The privacy and accessibility wins are structural rather than promised: no tracking, no profiling, no user-pattern data collection, and no visual puzzles that exclude users with visual or cognitive impairments - the design was published in Communications of the ACM. Rate limiting is IP-independent, so users behind NATs, VPNs, or Tor get the same experience instead of endless challenge loops, and proofs resist replay attacks, neutering captcha farms. Migration is deliberately easy: the API is compatible with reCAPTCHA and hCaptcha, making it a drop-in replacement. AGPL-licensed core with proprietary-friendly client libraries.
PRISM
PRISM consolidates passive reconnaissance, credential leak detection, and network asset mapping into a unified operational dashboard to replace fragmented command-line security tools. Analysts can launch simultaneous multi-source investigations against domains, internet protocol addresses, email mailboxes, phone numbers, and online handles to uncover domain registrations, open network ports, cryptographic certificates, and historical web archives. The platform interrogates threat feeds and leak repositories to expose credential leaks, dark web mirrors, and email routing anomalies with automated SMTP mailbox verification. Cross-platform identity engines crawl thousands of social networks and public registries to correlate aliases, discover leaked commit identities, and trace digital footprints across the web. Discovered assets render into interactive entity relationship graphs alongside geographic internet protocol maps to help investigators visualize infrastructure clusters and ownership links. An automated operational security calculator evaluates exposure vulnerabilities across identity, web, and infrastructure vectors, producing an aggregated risk score with granular hardening recommendations. Scheduled watchlists continually monitor target infrastructure, dispatching webhook notifications to chat channels whenever new subdomains, ports, or credential leaks appear. Investigators can export comprehensive audit dossiers as self-contained HTML files, styled PDF documents, or structured spreadsheets. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
MintHCM
The first AI-enabled open-source Human Capital Management system built for the agentic era — not a legacy HRMS with AI features bolted on, but a platform architected from the ground up with native MCP, A2A, and WebMCP protocols enabling any LLM client to query employee records, create calendar entries, and orchestrate multi-step HR workflows. Built on the battle-tested SuiteCRM/SugarCRM CE foundation and extended with 17 dedicated HR modules — recruitment pipeline with candidate scoring, onboarding checklists, competency matrices, employment history tracking, leave management with accrual policies, time and attendance, resource booking, travel and expense reporting, workplace management, performance evaluations, job description builder, employer branding campaigns, offboarding workflows, and a configurable analytics engine — all controlled through granular role-based permissions. The integrated LangGraph-powered AI agent operates with human-in-the-loop confirmation before mutating data, while the MCP server layer exposes structured HR operations to Claude Desktop, GitHub Copilot, and any MCP-compatible client. Native REST API enables integration with SAP, Workday, and custom applications. Mobile apps for iOS and Android provide field access to employee data and approvals. Runs on Apache2 with PHP 8.2, MySQL 8.0 or MariaDB, and ElasticSearch 7.10+ for full-text search and list indexing. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL v3 licensed.
Laranode
Built for self-hosted server deployments, Laranode transforms bare Linux installations into multi-tenant web hosting platforms with automated Let's Encrypt certificates and isolated PHP environments without recurring license fees. System administrators can provision isolated user accounts with dedicated document roots, configure custom domains, and deploy SSL certificates across all active websites in seconds. The integrated PHP manager enables per-site runtime isolation from legacy PHP 7.4 through cutting-edge PHP 8.5 releases, preventing version conflicts between separate production web applications. Operators can create MySQL databases, manage database users, inspect active connections, and adjust UFW firewall port access directly from the visual dashboard. An integrated browser-based file manager lets developers browse directories, edit configuration files, extract compressed archives, and modify file permissions without external FTP tools. Real-time telemetry monitors CPU utilization, memory consumption, disk capacity, and network traffic over customizable historical timeframes to catch bottlenecks early. Automated backup routines archive full accounts, individual websites, or specific databases to local storage, remote SFTP servers, or S3-compatible cloud object stores with point-in-time recovery verification. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
CodeX Docs
Writing docs should feel like editing a modern document, not wrangling Markdown files - CodeX Docs delivers that on Editor.js, the block-styled editor its CodeX team builds and thousands of products use. Content is composed from clean blocks (headings, lists, code, images, embeds) with a UI that reads well on both desktop and mobile, and pages render statically with human-readable, SEO-friendly URLs. Structure is free-form: pages nest to any depth, so a flat FAQ and a deep product manual coexist in one instance, and the UI tunes to fit - collapse sections, hide the sidebar. The operational footprint is deliberately tiny. No database is required: the default driver persists to a local folder, with MongoDB available when you want it, and the whole app configures through one YAML file (overridable with APP_CONFIG_ environment variables) covering title, start page, auth password, and JWT secret. Editing mode sits behind password authentication. Thoughtful extras are wired in: readers can report misprints straight to your Telegram or Slack, Hawk error tracking catches frontend and backend exceptions, and Yandex Metrica analytics is a one-line config. A ready-made Helm chart covers Kubernetes. Written in TypeScript.
BookLore
BookLore centralizes personal electronic book, audiobook, and comic collections into an organized private media server equipped with automated metadata scrapers and e-reader synchronization. Users can drop EPUB, PDF, CBZ, and MOBI files into a watched BookDrop directory to trigger automated format parsing, background cover retrieval, and staged queue imports. Integrated metadata scrapers query Google Books, Open Library, Goodreads, and Amazon to automatically fill synopsis summaries, author records, publishing dates, and review scores. Dynamic Magic Shelves categorize volumes through custom rule-based filters, author collections, and full-text search indexes across your complete literature catalog. The browser-based reader renders documents with adjustable typography, night modes, audio playback controls, text annotations, and persistent bookmarking. Hardware e-readers and mobile devices connect through native Kobo Store emulation APIs, bidirectional KOReader progress synchronization, and OPDS catalog feeds. Multi-tenant permissions provide each household member with private reading statistics, personalized shelves, email book delivery, and direct send-to-Kindle dispatch. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPLv3 licensed.
Yaade
Yet Another API Development Environment delivers a self-hosted alternative to Postman designed from the ground up for teams that need secure, collaborative API development without sending sensitive credentials through third-party cloud services. The multi-user system manages team members with role-based permissions and supports external authentication through OAuth2 and OIDC providers, while all data persists in an H2 file-based database that survives container and server restarts. REST and WebSocket request testing includes environment variable substitution, request chaining, and Markdown documentation for each endpoint. The JavaScript scripting engine runs request and response scripts for automated testing and data extraction, with cron job scheduling and API-triggered execution for continuous integration workflows. Collections import directly from OpenAPI specifications and Postman exports, while outbound export generates request code in multiple languages and frameworks. The browser extension proxy for Chrome and Firefox routes requests through the user's browser to bypass CORS restrictions when testing localhost and internal APIs, with an alternative server-side proxy for headless environments. Single-file data import and export simplifies backup and migration between instances. The React and Vite frontend ships with dark mode enabled by default. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Grimoire
Grimoire captures, extracts, and indexes the content behind your bookmarks so you can search what pages actually say, not just their titles and URLs. The ingestion pipeline accepts links from the web UI, REST API, MCP server, browser bookmarklet, or bulk import, then fetches each page and extracts readable content using specialized parsers for GitHub repos, GitHub issues, StackOverflow threads, YouTube transcripts, PDFs, and standard web articles. Everything stores locally in SQLite with file-based content archives. Search operates in three modes: FTS5 keyword matching for exact terms, semantic embedding search for meaning-based retrieval using vector similarity, or a hybrid ranking mode combining both. Optional AI providers including OpenAI, Ollama, Anthropic, DeepSeek, and any OpenAI-compatible endpoint generate automatic tags, summaries, and embeddings without being required for core functionality. The interface built with React 18, Vite, TypeScript, Tailwind CSS, and Radix UI supports categories, nested tags, notes, archive and trash states, read-later flags, and multi-user isolated spaces. A single Bun-powered Hono process serves both the compiled frontend and the REST API on port 3210, requiring only one Docker container and a SQLite volume. Backup and restore export bookmarks, content, settings, and metadata as portable ZIP archives. Nearly 3,000 GitHub stars reflect growing adoption among developers and researchers. Running on a VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.