DockPanel
Created in March 2026 and rapidly gaining traction in self-hosting communities, DockPanel delivers the most feature-dense free server panel available — 811 API endpoints, 153 one-click Docker app templates across 14 categories, and full multi-server management, all running on three Rust binaries consuming under 50MB of combined RAM. The panel handles the complete server lifecycle: sites with automatic SSL via Let's Encrypt, MySQL and PostgreSQL databases in Docker containers, Git push-to-deploy using Nixpacks for automatic language detection without Dockerfiles, blue-green zero-downtime deployments with automatic rollback on failed health checks, DNS management, mail servers, monitoring dashboards, and encrypted backups to S3, SFTP, Backblaze B2, or Google Cloud Storage. Security receives production-grade attention with per-image CVE scanning that gates deployments, a built-in WAF, passkey authentication alongside Argon2 password hashing, HttpOnly JWT sessions with blacklist-on-logout, rate limiting on auth endpoints, and fail2ban integration — all verified through an 18-vulnerability pentest with zero remaining issues. Infrastructure as Code support exports your entire server configuration to YAML, and the developer CLI provides status, diagnose, and export commands for automation. GPU passthrough enables AI workload hosting, reseller accounts support white-label branding for agencies, and ARM64 compatibility covers Raspberry Pi and Oracle Cloud free-tier deployments. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Mission Control
With over 600 GitHub stars and a featured Show HN launch, Mission Control is the agent-first command center that replaces the chaos of manually shepherding AI agents with structured delegation, approval workflows, and autonomous execution. The Next.js 15 web UI delivers an Eisenhower priority matrix with drag-and-drop quadrants, a Kanban board tracking tasks through Not Started, In Progress, and Done columns, and a goal hierarchy with milestone progress bars — powered by shadcn/ui, Radix UI, and @dnd-kit. Six built-in agent roles — Researcher, Developer, Marketer, Business Analyst, Tester, and You — receive tasks through a token-optimized API compressing context by 92 percent to approximately 50 tokens versus 5,400 unfiltered. The autonomous daemon polls task queues on cron schedules, spawns Claude Code sessions via the official CLI, enforces concurrency limits, and auto-retries with loop detection that escalates to human decisions after three failures. Field Ops extends execution to 64 external services across 16 categories with working X, Ethereum with MetaMask signing, and Reddit adapters, protected by AES-256-GCM encrypted vault with scrypt key derivation, per-service and global spend limits, a circuit breaker, and three autonomy levels. All data lives in local JSON files with Zod validation and async-mutex locking ensuring safe concurrent writes, backed by 193 automated Vitest tests. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Chief-Onboarding
New hires fail from information overload and IT bottlenecks, not lack of goodwill - the observation behind ChiefOnboarding, a free, open-source employee onboarding platform (Django, Celery, PostgreSQL, Redis). Its answer is sequences - drag-and-drop timelines that drip-feed to-do items, resources, courses, forms, and badges to each new hire, triggered by dates or by completing a previous item, so nobody faces everything at once. Onboarding starts before day one: preboarding pages welcome hires early, and colleagues can leave personal messages that appear there. The account provisioning module creates the new hire's Slack, Google, Asana, and other accounts automatically on the scheduled day via a library of integrations plus custom webhooks - the IT ticket queue never gets involved. Everything works through two equivalent interfaces: a full web dashboard and a Slack bot, either usable standalone. Slack can even auto-create new hire accounts when someone joins the workspace and assign default sequences with zero manual action. Colleague tasks with comments and collaboration, a searchable people directory, scheduled introductions, and per-hire timezone awareness (no 3 a.m. notifications) round it out. No trackers, no phoning home - third-party credentials sit in encrypted fields on your server.
Eclaire
Built to consolidate fragmented digital life into a private personal cloud, Eclaire centralizes tasks, notes, documents, photos, and web bookmarks into a unified workspace powered by local artificial intelligence. Users can save web articles to generate clean Markdown copies and searchable PDF archives, automatically bypassing clutter and dead links. The integrated document ingestion engine extracts tabular data from spreadsheets, performs optical character recognition across uploaded receipts and handwritten images, and indexes multi-page PDF manuals for rapid full-text search. Conversational assistant panels allow operators to interrogate their accumulated library using natural language, asking for cross-document summaries, research timelines, or action items extracted from meeting transcripts. Background workers prioritize asynchronous indexing queues, categorizing image libraries with visual object tags and managing recurring task deadlines with automated Telegram alert notifications. External automation flows can interact directly with the unified storage layer via an OpenAI-compatible REST API, allowing mobile shortcuts and custom scripts to ingest bookmarks and dictate notes remotely. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
WYGIWYH
Track income, recurring expenses, and multi-currency assets with WYGIWYH, a self-hosted personal finance platform built on a strict cash-flow principle that preserves monthly savings while exposing spending patterns. Users can aggregate holdings across checking accounts, physical cash reserves, crypto wallets, and custom asset models with automatic foreign exchange rate calculations. The transaction engine executes automated adjustment rules to normalize merchant names, apply category tags, and calculate split costs on every purchase. Investors can schedule dollar-cost averaging portfolios to monitor accumulation performance and price averages over extended investment horizons. Interactive dashboards provide monthly breakdown grids, calendar views of pending recurring bills, and multi-year net worth trajectories. Financial analysts can export transaction journals to CSV, automate data synchronization through REST webhooks, or query accounts with AI agents via the Model Context Protocol. Customizable notification triggers alert account owners to payment due dates and anomalous spending spikes across monitored accounts. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPL v3.0 licensed.
Pipelock
Your AI coding agent has your API keys in its environment and unrestricted network access, which means one prompt injection away from sending those secrets anywhere. Pipelock closes that gap by sitting as a proxy between your agents and every outbound connection, scanning the actual content of HTTP, WebSocket, MCP, and Agent-to-Agent traffic before it leaves your server. An 11-layer scanner pipeline checks every request against 62 credential patterns covering AWS, GCP, Azure, GitHub, OpenAI, Anthropic, SSH keys, and database URLs, then inspects every response for prompt injection using 29 detection patterns with six-pass normalization that catches base64-encoded, leetspeak, and whitespace-obfuscated payloads. The MCP proxy wraps any Model Context Protocol server (stdio, HTTP, or WebSocket) with bidirectional scanning that detects tool description poisoning and mid-session rug-pull changes via SHA-256 fingerprinting. Every scanning decision produces a cryptographically signed action receipt that third parties can verify offline without trusting the agent or the vendor. The Operator Console provides a web dashboard for reviewing evidence scorecards, receipt timelines, agent sessions, enforcement decisions, and fleet posture at a glance. Cross-request taint tracking catches slow-drip exfiltration attempts that spread a secret across multiple calls. Canary tokens plant synthetic secrets that trip alerts the moment an agent tries to exfiltrate them. Pre-built Prometheus metrics and a Grafana dashboard provide real-time visibility into traffic volumes and block rates. Deploy on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
OpenCode Manager
OpenCode Manager is a mobile-first command center for AI coding agents. Install the PWA on your phone or tablet and you get real-time streaming chat, multi-repository Git operations, and scheduled automation right in your pocket. Git integration handles SSH-authenticated repo cloning, worktree management, unified diffs, and branch operations across all your projects in one dashboard. Chat with coding agents through Server-Sent Events streaming that supports slash commands, @-mentions for files, Plan and Build modes, and Mermaid diagram rendering for architecture discussions. Schedule reusable prompts to run against any repository on intervals or cron expressions, with each run tracking history and linking to sessions so you can pick up exactly where automation left off. MCP server configuration adds local and remote HTTP servers with OAuth support, plugging into the broader Model Context Protocol ecosystem. A dedicated assistant workspace provides an isolated AI environment with auto-provisioned skills for managing schedules, notifications, and settings. Multiple AI providers are supported including Anthropic, GitHub Copilot, and OpenAI-compatible services, each configurable with custom system prompts and granular tool permissions. Push notifications alert you to session events, agent questions, errors, and task completions across all managed repositories.
Castopod
Every podcast you publish through Castopod automatically becomes a Fediverse social account that Mastodon, Pleroma, and Pixelfed users can follow, boost, and comment on from their own timelines. This ActivityPub integration transforms podcast distribution from a one-way broadcast into a two-way conversation where listeners interact with episodes through the social platforms they already use. Beyond federation, the platform manages the complete lifecycle: upload an episode, and auto-generated RSS feeds distribute it to Apple Podcasts, Spotify, Deezer, Podcast Addict, and every compatible directory. IABv2-compliant analytics measure downloads, geographic distribution, and listening apps while maintaining GDPR, CCPA, and LGPD compliance through anonymized data collection. Podcasting 2.0 namespace support unlocks chapters with images, SRT/VTT transcripts, location tags, and person credits that modern podcast apps surface to listeners. Video episodes publish alongside audio, and auto-generated clips feed social media sharing workflows. Monetization tools span Value4Value micropayments, premium subscriptions, funding links, and cookieless advertising. Multi-user roles operate per-podcast: contributors, editors, and admins each work within defined permission boundaries. The PHP application runs behind nginx with MariaDB and Redis on a RepoCloud VPS with dedicated CPU, RAM, and SSD. AGPL-3.0 licensed.
Glean
Information overload is the default state of the modern internet, and Glean exists to tame it by pulling every blog, newsletter, and news source you follow into a single, organized reading experience with an interface that prioritizes clarity over clutter. Subscribe to RSS and Atom feeds, import your existing subscriptions via OPML, and organize everything into multi-level folders with a flexible tagging system that lets you slice your reading list by topic, priority, or mood. A three-pane layout presents your feed list, article summaries, and full content side by side, with one-click actions for marking articles as read, saving them for later, bookmarking favorites, or archiving what you have already processed. Background workers fetch new articles every 15 minutes so your feeds stay current without manual refreshes. The preference learning engine (backed by Milvus vector embeddings) scores incoming articles against your reading history and surfaces a personalized Smart Feed of content you are most likely to care about, reducing the time spent scrolling past irrelevant posts. A built-in MCP server lets AI assistants like Claude Desktop search and interact with your feed library directly. The admin dashboard on a separate port provides user management, system monitoring, and configuration controls for multi-user deployments. Bookmark external URLs from any browser with the Chrome extension, or access your feeds on mobile through the Progressive Web App. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
ClassicPress
WordPress without Gutenberg: ClassicPress, the community-led fork, keeps the TinyMCE classic editor as the default and strips the block editor and Full Site Editing out of core entirely. The result is roughly half WordPress's size - obsolete libraries like jQueryUI, Thickbox, and Flash support are gone, replaced by native HTML5 elements and modern alternatives like SortableJS - which translates to a measurably faster admin and a leaner attack surface. Forked from WordPress 6.2, it remains compatible with the vast plugin and theme ecosystem targeting that lineage (anything not requiring blocks generally works, helped by a blocks-compatibility mode), and the PHP-first WordPress API developers have used for over a decade works unchanged - no React required to extend your CMS. The fork adds its own improvements: built-in media categories and tags with bulk editing, revision management that lets you prune database bloat, native HTML5 dialogs for accessible touch-friendly menus, and recent releases bring APCu object-cache support, vanilla-JS core widgets, and performant translations. Governance is democratic and community-driven rather than corporate. For content sites, business sites, and blogs where the classic editing workflow is the feature, ClassicPress is stability as a philosophy.
Taiga
Winner of the 2015 Most Valued Agile Tool award and cited as a top project management platform by Opensource.com with over 2,100 GitHub stars on the Docker deployment repository alone, Taiga has served an estimated 20 million users worldwide with over 2 million Docker pulls since its creation in 2014 by Kaleidos. The platform delivers a complete agile project management experience through Scrum boards with backlog prioritization, sprint planning, story point estimation configurable per role, burndown charts at both project and sprint levels, and velocity tracking with a project doom-line indicator. Kanban boards offer customizable workflow columns with swimlanes, WIP limits, zoom controls, and the ability to switch between Scrum and Kanban at any point without losing data. The issue tracker supports custom types, priorities, and severities with the ability to promote issues directly to user stories. Team collaboration features include threaded comments, file attachments, email notifications, mentions, a built-in wiki for project documentation, and a team performance dashboard with the Iocane health metric for tracking team sustainability. The platform integrates with GitHub, GitLab, and Bitbucket for version control linking, provides importers for migrating from Trello and Jira, and exposes a REST API for custom integrations. Available in over 20 languages with custom fields, tags, roles, and permissions. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MPL-2.0 licensed.
CodeX Docs
Writing docs should feel like editing a modern document, not wrangling Markdown files - CodeX Docs delivers that on Editor.js, the block-styled editor its CodeX team builds and thousands of products use. Content is composed from clean blocks (headings, lists, code, images, embeds) with a UI that reads well on both desktop and mobile, and pages render statically with human-readable, SEO-friendly URLs. Structure is free-form: pages nest to any depth, so a flat FAQ and a deep product manual coexist in one instance, and the UI tunes to fit - collapse sections, hide the sidebar. The operational footprint is deliberately tiny. No database is required: the default driver persists to a local folder, with MongoDB available when you want it, and the whole app configures through one YAML file (overridable with APP_CONFIG_ environment variables) covering title, start page, auth password, and JWT secret. Editing mode sits behind password authentication. Thoughtful extras are wired in: readers can report misprints straight to your Telegram or Slack, Hawk error tracking catches frontend and backend exceptions, and Yandex Metrica analytics is a one-line config. A ready-made Helm chart covers Kubernetes. Written in TypeScript.
Whiteboard
The drawing surface inside WebRTC conference tools like Meetzi and the LAMS online-learning platform is Whiteboard (by cracker0dks) - a lightweight Node.js collaborative sketchboard built to be embedded and customized, which also slots into Nextcloud via the External Sites app. Everyone opening the same whiteboardid URL parameter draws on the same board, with remote user cursors visible live, per-user undo/redo, and an indicator showing the smallest participating screen so nobody draws outside a colleague's view. Content handling goes beyond pen strokes: drag-and-drop or paste images and PDFs from any PC or browser, then resize, rotate, and draw over them on canvas or background; add text and sticky notes; hold Shift for angle-snapped lines and perfect squares. Every function has a keybinding - deliberately friendly to pen displays like Wacom and XP-Pen whose hardware buttons map to shortcuts. Boards save to image or JSON (with reload), export directly to Nextcloud via WebDAV, and persist across restarts with the file-database option. A REST API with bundled interactive docs allows full programmatic control, an optional access token locks down uploads, and YAML configuration tunes behavior and performance. MIT-licensed and reverse-proxy friendly.
Mayan EDMS
Mayan EDMS stores, classifies, and retrieves millions of documents with automatic OCR, workflow automation, and audit-ready access controls that organizations have relied on for over a decade. Tesseract integration extracts searchable text from scanned PDFs and images in over 100 languages, transforming paper archives into instantly queryable digital collections without manual data entry. The workflow engine routes documents through approval chains using configurable state machines that trigger notifications, enforce retention policies, and maintain complete audit trails for regulatory compliance. Version tracking preserves every revision with full diff capabilities, while GnuPG digital signatures provide cryptographic proof of authenticity and tamper detection for sensitive records. Role-based permissions combined with object-level ACLs and LDAP integration ensure documents remain visible only to authorized users, down to individual file granularity. Full-text search powered by Whoosh or ElasticSearch handles advanced queries across massive document stores with faceted filtering and relevance ranking. The Django REST Framework API enables programmatic upload, metadata extraction, and workflow triggering from external systems. Beyond simple folder hierarchies, metadata schemas, document types, tags, and cabinet structures provide multi-dimensional classification tailored to how your organization actually works. Background processing through Celery handles OCR, conversion, and preview generation asynchronously, keeping the web interface responsive under heavy ingest loads.
Kandev
Kandev provides a command center for orchestrating AI coding agents across parallel workstreams. The Go backend paired with a Next.js frontend delivers kanban boards with drag-and-drop columns, pipeline workflow definitions with per-step agent handoffs, and an IDE-like review workspace combining file editor, file tree, terminal, browser preview, and unified git diffs. Multi-provider support connects Claude Code, GitHub Copilot, Codex, Qoder, Grok, and custom agents through configurable profiles with per-agent prompts, runtimes, and review gates. Tasks execute in isolated git worktrees with multi-repository support, letting agents work on separate branches simultaneously while changes surface in a consolidated review interface. Native integrations with GitHub, GitLab, Jira, Linear, Sentry, and Slack pull external issues into the kanban and link tasks to pull requests. Kandev exposes streamable HTTP and SSE MCP endpoints, enabling external clients — Cursor, Claude Desktop, Augment — to create tasks and read workspace context programmatically. Workflow definitions export as portable YAML for sharing across installations. Agentic workflows chain multi-step pipelines mixing different models per step — Opus for architecture, Sonnet for implementation, with human review gates between stages. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Temps
Consolidate application hosting, web analytics, error tracking, and performance monitoring into Temps, an open-source developer platform that replaces disparate SaaS subscriptions with a single compiled Rust binary. Engineering teams deploy full-stack web applications, background daemons, and microservices directly from Git repositories with automated TLS certificate provisioning powered by an embedded Cloudflare Pingora reverse proxy. The centralized web console unifies real-time visitor analytics, conversion funnels, and rrweb-powered session replay recordings without third-party tracking scripts. Integrated error monitoring ingests runtime exceptions with full stack traces and source map resolution, while continuous health checks evaluate container CPU utilization, memory thresholds, and network throughput across custom alerting rules. Developers manage infrastructure through an extensive command line interface containing over 440 operations across 69 command groups, or deploy drop-in skill files that allow AI coding assistants like Claude Code and Codex to provision preview environments autonomously. The platform also provides serverless key-value storage, S3-compatible blob buckets, and native transactional email routing with custom DKIM validation. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
DAC
Your dashboards deserve version control, code review, and reproducible builds, just like the rest of your stack. DAC lets you define interactive data dashboards in YAML or TSX, validate them in CI, and serve them from a single Go binary that embeds a full React frontend. Choose from 21 chart types including line, bar, area, pie, scatter, bubble, funnel, sankey, heatmap, calendar, sparkline, waterfall, gauge, treemap, radar, and candlestick, plus metric cards, data tables, text blocks, and image widgets. The built-in semantic layer lets you define metrics and dimensions once in reusable model files, then reference them from any widget while DAC generates the SQL automatically. Connect to Postgres, MySQL, Snowflake, BigQuery, Redshift, Databricks, and DuckDB through standard Bruin connection configs. Interactive filters with date pickers, dropdowns, multiselects, and search inputs inject values via Jinja templating and re-execute only affected widgets. Live reload via Server-Sent Events refreshes connected browsers instantly when you save a file. Export dashboards as self-contained static HTML with baked-in query results for S3, GitHub Pages, or offline sharing, and render slide decks via the Google Slides export command. On RepoCloud, deploy DAC on a dedicated VPS with root SSH access and persistent storage for your dashboard definitions and database connections under the AGPL-3.0 license.
GoRaven
GoRaven transforms AI chat from a question-answer window into a full engineering workstation where agents read files, write code, run shell commands, query databases via MCP tools, and deliver structured results — orchestrating across OpenAI, Claude, DeepSeek, Gemini, Qwen, GLM, and Ollama with task-based routing that allocates the right model for each job based on cost and capability. Built on a Go backend using the Freedom framework with Iris HTTP and a React/TypeScript frontend powered by Vite and Tailwind CSS, each user operates in an isolated workspace with team-shared project areas and centrally managed model quotas. The skill marketplace packages prompts, scripts, and workflows as reusable installable units with automatic dependency resolution and centralized versioning. MCP toolchain integration connects agents to internal APIs, databases, private services, and CLI tools so they query data, invoke services, and trigger actions directly. RAG-powered knowledge bases ingest policies, documentation, and business data for real-time retrieval during planning, coding, and Q&A with source attribution. Long-running task support decomposes complex work through a main agent coordinating sub-agents that execute in parallel across sessions. Plugin hooks inject custom logic at conversation start and end, tool calls, and SSE event streams without forking core code. The operations dashboard tracks usage metrics, model consumption, and team activity. Supports SQLite, MySQL, or PostgreSQL with Redis or local memory caching. Deploy with a single Docker command. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.