831 applications
Cerbos screenshot thumbnail

Cerbos

Cerbos decouples authorization logic from application code entirely, evaluating human-readable YAML policies in under one millisecond through a stateless Policy Decision Point that requires no application state synchronization or cross-network fan-out. Its custom decision engine benchmarks up to 17x faster than OPA-based alternatives. Access control policies use conditions expressed in Google's Common Expression Language, supporting role-based, attribute-based, and policy-based access control patterns including derived roles, scoped policies, and permissions-aware data filtering that pushes authorization predicates directly into database queries. The PDP exposes both gRPC and HTTP APIs with SDKs for JavaScript, Python, Go, Java, .NET, Rust, PHP, and Ruby, making integration a single function call regardless of tech stack. GitOps-native workflows treat policies as code with Git versioning, CI validation through GitHub Actions, coverage reports, breaking-change detection, and audit logs of every authorization decision for ISO27001, SOC2, and HIPAA compliance. Deployment flexibility spans Kubernetes sidecars, standalone services, systemd daemons, AWS Lambda functions, and WebAssembly-embedded PDPs that run authorization logic directly in browsers, serverless architectures, and edge devices. The Admin API manages policy lifecycle operations programmatically, while the built-in Playground and REPL provide interactive testing environments for policy authoring and debugging. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.

Deploy
Freescout screenshot thumbnail

Freescout

Unlimited agents, unlimited tickets, unlimited mailboxes, forever, on a $4 VPS - FreeScout's pricing inversion is why it became the most popular self-hosted Help Scout alternative, a PHP/Laravel help desk and shared inbox developed from scratch over eight years. The inbox deliberately behaves like Gmail or Outlook, so new support agents need close to zero training. The email-support core is genuinely complete: seamless IMAP/SMTP integration including modern Microsoft Exchange authentication, collision detection that warns when two agents open the same conversation, canned responses, auto-replies, internal notes, open tracking, starring, forwarding, merging, and moving conversations between mailboxes, phone-call logging, push notifications, and an auto-refreshing conversation list - plus screenshot pasting straight from the clipboard into replies. It's 100% mobile-friendly, fully screen-reader accessible, and translated into 28 languages. Beyond the core, an ecosystem of 100+ modules (mostly one-time $12-20 purchases) adds knowledge base, workflows with Gmail-filter-style automation rules, satisfaction ratings, time tracking, tags, custom fields, LDAP, Slack, WhatsApp and Telegram channels, and an API with webhooks - pay only for what your team needs. Web installer and updater included. AGPL-licensed.

Deploy
BookOrbit screenshot thumbnail

BookOrbit

Consolidate your entire digital library into a self-hosted reading sanctuary with BookOrbit, an open-source media platform that organizes ebooks, audiobooks, comic archives, and research PDFs within a personal private cloud. Readers can enjoy multi-format media directly through responsive browser readers that support EPUB, CBZ, and M4B formats without external browser extensions. The platform synchronizes reading bookmarks, highlights, and completion statuses across web interfaces, Kobo ereaders, and KOReader devices. An automated metadata enrichment engine queries fourteen upstream bibliographic indexes, downloading cover artwork, chapter breakdowns, author biographies, and series taxonomies. The staging workspace allows librarians to inspect incoming files, review suggested metadata revisions, and embed updated tags directly into physical storage archives before shelving. Custom reading dashboards track annual book goals, calculate daily streaks, and plot reading habit radar charts. Multi-user configurations support distinct per-user collections, granular content permissions, and single sign-on authentication through OpenID Connect providers. Power users can export private OPDS feeds to external mobile reading applications or push books directly to connected Kindle hardware. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPL v3.0 licensed.

Deploy
Octobox screenshot thumbnail

Octobox

What Gmail did for email, Octobox does for GitHub notifications: an ephemeral, unmanageable stream becomes an inbox you can actually triage. GitHub marks notifications read the moment you glance at them and lets old ones vanish days later; heavy maintainers end up building elaborate Gmail filter systems just to cope. Octobox - a Ruby on Rails app over PostgreSQL - syncs your notifications into a persistent inbox with an explicit archived state: mark a thread done, and if the issue or PR sees new activity, it pops back automatically, so nothing silently falls through. Triage is keyboard-driven with Gmail-style shortcuts (j/k to navigate, e to archive, m to mute, s to star), and multi-select clears noisy repositories in bulk. Filtering is where it earns its keep: slice by repository, organization, type, action, state, reason, CI status, labels, author, assignee, or bot origin, combine prefix search filters, and pin favorite searches to the sidebar. The optional GitHub App enriches entries with live PR/CI status and labels so you can decide without clicking through. Auto-archive rules clear merged PRs and closed issues; muting and snoozing silence the rest. A REST API supports integrations. Self-hosting keeps your notification metadata - a map of everything you work on - on your own server.

Deploy
Kvrocks screenshot thumbnail

Kvrocks

Every Redis client you already use connects to Kvrocks without a single code change, but instead of holding your entire dataset in RAM, data lives on SSD through RocksDB, turning terabytes of memory cost into pennies of disk. An Apache Software Foundation top-level project, Kvrocks supports strings, hashes, lists, sets, sorted sets, streams, bitmaps, JSON documents, TimeSeries data points, Bloom filters, Cuckoo filters, and HyperLogLog structures, all persisted to disk with in-memory caching for hot data access. Asynchronous replication using binlog similar to MySQL provides data durability across replicas, while Redis Sentinel integration enables automatic failover when master or replica nodes fail. The proxyless centralized cluster architecture distributes data across shards while remaining fully compatible with standard Redis cluster SDKs and clients. Token-based namespaces provide multi-tenant isolation with authentication per namespace, going beyond Redis SELECT's numbered database model. RocksDB's LSM-tree storage engine provides efficient compression through configurable compaction strategies, reducing disk footprint dramatically while maintaining sub-millisecond reads for cached keys. Migration tooling includes RedisShake for Redis-to-Kvrocks live migration and kvrocks2redis for reverse migration, enabling gradual adoption without service interruption. The kvrocks_exporter exposes Prometheus-compatible metrics for monitoring, and OpenTelemetry integration provides distributed tracing. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.

Deploy
Wakapi screenshot thumbnail

Wakapi

Its author, a student and WakaTime fan, didn't want to pay $9/month for data about his own keystrokes - so Wakapi was born, a self-hosted, WakaTime-compatible backend for coding statistics. The compatibility is the killer design decision: the official WakaTime plugins for VS Code, JetBrains IDEs, Vim, and dozens of other editors work unmodified - just point the plugin's API URL at your Wakapi instance with your personal key, and heartbeats flow to your server instead of a third party's. Duration inference matches WakaTime's own algorithm, with a configurable timeout (10 minutes by default). From that stream Wakapi builds statistics and plots across projects, languages, editors, hosts, and operating systems, plus the fun extras: public leaderboards (optionally login-gated, with configurable aggregation windows), badges for GitHub readmes, and weekly email reports. A REST API serves your data programmatically, Prometheus export feeds your existing Grafana, and a WakaTime relay mode can mirror heartbeats to both services during migration - with one-click import of historical WakaTime data. Written in Go, it is lightning fast and light enough for the smallest instance, storing to SQLite, PostgreSQL, or MySQL, with configurable data retention for GDPR peace of mind. Deliberately smaller than WakaTime, deliberately yours.

Deploy
Kubero screenshot thumbnail

Kubero

With over 4,300 GitHub stars and a v3 release adding built-in user management, team views, and multi-language support, Kubero has established itself as the most feature-complete open-source Heroku alternative running natively on Kubernetes. The platform operates as a Kubernetes operator with two containers — kubero-ui and the operator — storing all state in etcd without an external database. Developers push code via Git integration with GitHub, GitLab, Bitea, or Gitea, and Kubero automatically builds using Buildpacks, Nixpacks, Runpacks, or Dockerfiles, then deploys to the configured domain with SSL via cert-manager. CI/CD pipelines support up to four staging environments — review, test, staging, and production — with per-stage environment variable isolation and ephemeral review apps that spin up on pull request open and tear down on close. The template catalog includes over 170 pre-configured applications like WordPress, Grafana, and PostgreSQL deployable in one click, while managed add-ons provide highly available PostgreSQL, Redis, MySQL, Kafka, CouchDB, Elasticsearch, and MongoDB alongside your applications. Security features include Trivy vulnerability scanning, GitHub and OAuth2 single sign-on, basic auth, and a role-based permission system with API tokens. The NestJS backend with Vue.js and Vuetify frontend provides application metrics, real-time logs, a built-in web console for container access, scheduled cronjob management, and deployment notifications via Discord, Slack, or webhooks. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.

Deploy
Black Candy screenshot thumbnail

Black Candy

With 4,300+ GitHub stars and native mobile apps on three platforms, Black Candy transforms any VPS into a private Spotify-style streaming service for your personal music collection. The Ruby on Rails 7 backend with Hotwire Turbo and Stimulus delivers a responsive single-page-feeling web player supporting album browsing, artist views, playlists, favorites, and queue management without full page reloads. Point it at a media directory containing MP3, FLAC, OGG, AAC, or WAV files and Black Candy indexes metadata, fetches album artwork from Discogs API, and begins streaming immediately with on-the-fly transcoding that adapts bitrate to client bandwidth. Multi-user support gives each account independent playlists, favorites, and listening history while sharing the same music library — ideal for families or shared households. Native iOS, Android, and F-Droid apps maintained as separate repositories provide offline caching, background playback, and server discovery for mobile listening. The admin panel manages user accounts, configures media paths, and sets Discogs API tokens for automatic cover art retrieval. Deployment requires one Docker command — `docker run -p 80:80 ghcr.io/blackcandy-org/blackcandy:latest` — with persistent storage volumes for the SQLite database and media directory. For larger deployments, switch to PostgreSQL via environment variables with dedicated database URLs for ActionCable, SolidQueue, and SolidCache. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

Deploy
Grimmory screenshot thumbnail

Grimmory

Consolidate fragmented collections of digital novels, graphic novels, manga, and audiobooks into Grimmory, an open-source media library server that combines automated file sorting with rich in-browser reading environments. The server indexes diverse media formats including EPUB, MOBI, AZW3, FB2, PDF, CBZ, CBR, CB7, M4B, and MP3 files across isolated storage directories. Readers explore literature through specialized browser viewports that provide customizable typography, CFI highlight annotations, two-page comic spreads with right-to-left manga modes, and chapter-based audiobook playback with sleep timers. Automated BookDrop watch folders ingest incoming files, retrieving book covers, author biographies, and community ratings from Google Books, Open Library, and Amazon APIs. Dynamic Magic Shelves organize catalogs automatically using nested boolean rule trees that filter books by page counts, genres, release dates, or narrator identities without server reload overhead. External e-readers access media catalogs through standard OPDS feeds or native Kobo and KOReader synchronization endpoints that match documents by binary content hashes. Built-in email delivery sends formatted books directly to Kindle devices with a single click, while OpenID Connect authentication enforces granular multi-user library permissions. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPLv3 licensed.

Deploy
Anakin screenshot thumbnail

Anakin

Backed by Y Combinator and powering scraping infrastructure across 195 countries, Anakin delivers a production-grade web scraping API purpose-built for AI agents and RAG pipelines that need clean, structured data from sites that actively block conventional scrapers. The single Go binary server handles JavaScript-heavy SPAs through its Camoufox anti-detect browser service with automatic fingerprint rotation, while the HTTP-first handler chain tries lightweight extraction before escalating to full browser rendering — keeping response times under 2 seconds for static pages. The built-in React 19 dashboard provides visual scraping with live results, job tracking with status filters, domain configuration management with handler chain CRUD, and proxy performance monitoring via Thompson Sampling scoring. Structured JSON extraction leverages Gemini AI to transform raw HTML into typed schemas without manual selector maintenance. SDKs span Python, TypeScript, Go, .NET, Java, and Ruby, while the MCP server exposes all 21 tools directly to Claude, Cursor, Windsurf, and any Model Context Protocol-compatible agent. The hosted platform extends the open-source engine with AI web search returning full page content with citations, multi-source agentic research across 20+ sources per query, Wire pre-built actions covering 944 websites with 5,201 structured endpoints, persistent browser sessions for authenticated scraping, and website change monitoring with scheduled alerts. Deploy via Docker Compose with three containers or run the binary directly with optional PostgreSQL persistence. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.

Deploy
EasyAppointments screenshot thumbnail

EasyAppointments

Service businesses get a booking page without per-booking commissions or monthly SaaS fees from Easy!Appointments, the self-hosted appointment scheduler. Customers pick a service, provider, and open time slot from a clean web form; the system enforces working plans, breaks, and booking rules you define per provider, then confirms by email to both sides. The structure fits real service organizations: multiple providers with individual schedules, multiple service types with their own durations and prices, and admin/secretary roles for front-desk management. Two-way Google Calendar synchronization keeps each provider's external calendar authoritative - book in Easy!Appointments and it appears in Google Calendar, block time in Google and the slot disappears from the booking form. Version 1.6 adds SMS notifications and payment support, and a REST API opens the scheduling data to custom integrations. Built on PHP (CodeIgniter) with MySQL, it installs in a single folder and can share a database with your existing site; a WordPress plugin embeds the booking form directly in pages or posts. The interface ships in dozens of languages with time-zone handling throughout. GPL-3.0 licensed and free for commercial use - a helpdesk, clinic, salon, or consultancy runs its whole booking workflow on its own server.

Deploy
Macro screenshot thumbnail

Macro

Macro merges email, team chat, collaborative documents, task management, CRM, and video calls into one keyboard-driven application where AI agents operate across the entire workspace with shared team memory, replacing the Slack plus Notion plus Linear plus Superhuman plus HubSpot stack with a single deployment. The email module provides a multi-account unified inbox with keyboard shortcuts, shared team inboxes, and Gmail integration. Team messaging offers channels and direct messages designed for technical discussions with threaded conversations. The task system draws from Linear with board and list views tightly integrated with channels, email threads, and AI agents. Real-time collaborative documents use CRDT synchronization via Loro for conflict-free editing with Markdown-native formatting and @mention linking. A 2D canvas board embeds @links to tasks, files, and emails for visual project planning. AI agents access unified team-level memory spanning all workspace modules, taking autonomous actions across email, chat, tasks, and documents through MCP-compatible tool interfaces. Video calls include recording, transcription, and automatic logging to team memory. The CRM module tracks customers and contacts with custom properties, email synchronization, and data enrichment. Eighty-plus Rust microservices on the Axum framework handle backend operations while a SolidJS static SPA delivers the frontend with instant search and real-time collaboration. Docker Compose deployment provisions the complete service stack with PostgreSQL, Redis, OpenSearch, and FusionAuth authentication. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.

Deploy
Briefer screenshot thumbnail

Briefer

Backed by Y Combinator with 4,300 GitHub stars and growing rapidly since its September 2024 launch, Briefer delivers the first truly unified notebook-and-dashboard platform that eliminates the fragmented workflow of juggling Jupyter for analysis, Tableau for visualization, and Notion for documentation — combining all three in a single Notion-like workspace where SQL query results automatically become Python DataFrames accessible in subsequent code blocks. The built-in AI analyst understands your database schema and notebook context to generate SQL queries, write Python transformations, create visualizations, and fix errors on demand using configurable OpenAI or private LLM backends. Connect directly to PostgreSQL, MySQL, BigQuery, Redshift, Snowflake, and Amazon Athena as data sources, or upload CSV files for immediate analysis. Native point-and-click visualizations produce charts, tables, and dashboards without writing code, while interactive data apps use inputs, dropdowns, and date pickers to create parameterized reports for non-technical stakeholders. Scheduled execution runs notebooks and dashboards periodically with results delivered via Slack integration or public shareable links. Write-back queries modify production data directly from notebooks for ad-hoc pipeline testing. The architecture runs as three Docker containers — web frontend, API server, and optional AI service — backed by PostgreSQL and a Jupyter server for Python execution, deployable via single Docker command, Docker Compose, or Helm charts for Kubernetes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPLv3 licensed.

Deploy
Archestra screenshot thumbnail

Archestra

Archestra delivers the enterprise AI infrastructure layer that organizations need when managing multiple LLM providers, MCP servers, and AI agents across teams becomes unmanageable. The LLM gateway routes requests across Anthropic, OpenAI, Azure, Bedrock, and DeepSeek with virtual API keys, per-team cost limits, and dynamic model routing — giving every developer one token for Claude Code, Cursor, or Codex while finance tracks spend per department. The MCP gateway authenticates tool calls with OAuth 2.1 and On-Behalf-Of tokens so each tool executes as the calling user, not a shared service account, eliminating credential sprawl. The private MCP registry lets teams publish custom tool servers with approval flows promoting servers from dev through staging to production, each environment maintaining its own credentials and network egress policies. The Kubernetes operator manages MCP server lifecycle — deploying containers, scaling, health-checking, and routing gateway traffic to local servers automatically. The agent runtime supports scheduled triggers, email and webhook invocations, sub-agent delegation, reusable skills, and sandboxed code execution with a K8s-native filesystem. Deterministic guardrails including Dual-LLM verification and Lethal Trifecta protections prevent dangerous tool calls before execution. Built-in OpenTelemetry traces and Prometheus metrics provide full observability without additional tooling. Docker deployment exposes the Admin UI on port 3000 and API on port 9000 with a single command. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.

Deploy
Bazarr screenshot thumbnail

Bazarr

Subtitles are the one chore Sonarr and Radarr leave behind - Bazarr finishes the *arr media stack by automating them. It connects to both via their APIs and mirrors their libraries - it doesn't scan disk itself, it manages exactly what your *arr apps index. For every monitored episode and movie it checks existing internal and external subtitles against your language profiles, then hunts missing ones across dozens of providers - OpenSubtitles.com, Podnapisi, Addic7ed, Subscene, and many regional sources - covering 184 subtitle languages including forced/foreign-dialogue tracks. Matching is smarter than filename guessing: releases are compared by release group and source, some providers support exact file-hash matching, and every downloaded subtitle gets a percentage score. Set a minimum score per Sonarr/Radarr connection and Bazarr rejects weak matches; enable upgrades and it replaces previously downloaded subtitles when better ones surface. Out-of-sync files get fixed too - automatic subtitle synchronization realigns timing after download, triggered only below a configurable score threshold so good subs aren't touched. Per-show and per-movie language configuration, download history, manual on-demand search, and adaptive searching that throttles provider API calls round it out, all behind a clean Sonarr-style web UI written in Python. If your library serves multilingual viewers, this removes the last manual step.

Deploy
Seanime screenshot thumbnail

Seanime

Seanime turns your server into a dedicated anime and manga command center, combining local library management, torrent streaming, an integrated manga reader, and AniList progress tracking in a single self-hosted web application. Point it at your media folders and the smart scanner automatically identifies and matches your anime files to AniList entries without requiring strict naming conventions or folder hierarchies. Stream episodes directly from torrents through qBittorrent, Transmission, Torbox, Real-Debrid, AllDebrid, or Premiumize; the built-in player starts playback before the download finishes, so there is no waiting for full transfers. The manga reader pulls chapters from community extension sources and tracks your reading progress across series automatically. An in-app extension marketplace lets you install third-party providers for streaming, manga, and torrent sources, all written in JavaScript and managed through a visual interface. Seanime Tenji, the companion mobile app for iOS and Android, connects to your server for on-the-go library browsing, content streaming, and offline downloads. Auto-download rules grab new episodes of airing series the moment torrents appear. The transcoding engine handles on-the-fly conversion for browser playback on any device, while direct play passes through compatible formats at full quality. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.

Deploy
Octop screenshot thumbnail

Octop

Modern engineering teams and busy households deploy Octop to run private, autonomous AI agents equipped with persistent memory workspaces, scheduled cron jobs, and direct browser automation. Users can orchestrate specialist agents tailored for software development, IT operations, content generation, and system diagnostics through an interactive React dashboard. The platform connects directly to Discord, Feishu, DingTalk, and WeCom, allowing team members to delegate complex tasks without leaving their everyday messaging apps. An integrated remote desktop and browser control engine lets agents navigate websites, capture screenshots, fill forms, and operate graphical software autonomously. Administrators can assign distinct MBTI personality profiles to agents, establish granular role-based permissions, configure scheduled cron workflows, and integrate custom Model Context Protocol servers for external tool access. Long-term memory persists across conversations through dedicated workspace files, ensuring contextual continuity whenever switching between underlying language models or team collaborators. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

Deploy
2FAuth screenshot thumbnail

2FAuth

2FAuth generates TOTP, HOTP, and Steam Guard codes from any web browser, freeing your two-factor authentication from dependence on a single smartphone or app. Lose your phone, switch devices, or sit at a desktop computer, and your 2FA codes remain accessible through the web interface. The Laravel and Vue.js application stores account secrets in an encrypted SQLite database that backs up as a single file. Adding accounts works through camera-based QR scanning or manual secret key entry for services that only provide text codes. Group organization with drag-and-drop sorting keeps large collections navigable, categorized however you prefer. WebAuthn authentication with FIDO2 hardware keys protects vault access with phishing-resistant passwordless login, meaning the tool that secures your accounts is itself secured by the strongest available method. Automatic screen lock triggers after configurable idle time, and OTP obfuscation dots out generated codes until you tap to reveal them, preventing shoulder surfing in shared spaces. The REST API enables browser extensions and external applications to request codes programmatically. Import compatibility with Google Authenticator, Aegis, and 2FAS ensures painless migration without re-enrolling every account from scratch. PWA installation places 2FAuth on your device home screen for native-app-like instant access. Runs on a dedicated RepoCloud VPS with guaranteed resources and full root SSH access. AGPL-3.0 licensed.

Deploy