Standard Notes
Standard Notes keeps your notes, files, and tags encrypted on your device before anything touches the network, meaning the server stores only ciphertext it cannot read. Cross-platform sync across desktop, mobile, and web delivers fast, conflict-free updates on unlimited devices with the same zero-knowledge guarantee that only your password can decrypt your content. The V2 server architecture condenses everything into four Docker containers consuming roughly 570MB RAM total (down from 13 containers and 1.7GB in the legacy setup), with startup under one minute. Revision history automatically preserves every version of every note, so recovering deleted text or reverting to a previous state never depends on manual backups. A nested tag system organizes thousands of notes with hierarchical categorization that goes well beyond flat folder structures, while search operates entirely on client-side decrypted content. File attachments of any type encrypt and sync alongside notes with identical end-to-end protection. Multiple editor options span plain text, Markdown with preview, and rich formatting to fit different writing workflows. Two-factor authentication via TOTP with email backup codes adds a second barrier beyond your password. An optional separate container serves the web frontend, providing browser access to your encrypted vault without depending on standardnotes.com infrastructure. With 5,500+ GitHub stars and active development, the project continues expanding editor plugins and sync improvements.
Mayan EDMS
Mayan EDMS stores, classifies, and retrieves millions of documents with automatic OCR, workflow automation, and audit-ready access controls that organizations have relied on for over a decade. Tesseract integration extracts searchable text from scanned PDFs and images in over 100 languages, transforming paper archives into instantly queryable digital collections without manual data entry. The workflow engine routes documents through approval chains using configurable state machines that trigger notifications, enforce retention policies, and maintain complete audit trails for regulatory compliance. Version tracking preserves every revision with full diff capabilities, while GnuPG digital signatures provide cryptographic proof of authenticity and tamper detection for sensitive records. Role-based permissions combined with object-level ACLs and LDAP integration ensure documents remain visible only to authorized users, down to individual file granularity. Full-text search powered by Whoosh or ElasticSearch handles advanced queries across massive document stores with faceted filtering and relevance ranking. The Django REST Framework API enables programmatic upload, metadata extraction, and workflow triggering from external systems. Beyond simple folder hierarchies, metadata schemas, document types, tags, and cabinet structures provide multi-dimensional classification tailored to how your organization actually works. Background processing through Celery handles OCR, conversion, and preview generation asynchronously, keeping the web interface responsive under heavy ingest loads.
Komodo
Komodo puts every server, container, and deployment pipeline behind a single dashboard where you build, ship, and monitor Docker workloads across unlimited hosts. Lightweight stateless agents install on each connected server and report CPU, memory, and disk metrics back to the Rust-powered core, giving you real-time visibility without heavyweight monitoring stacks. Docker Compose stacks deploy directly from the UI or link to Git repositories with webhook-triggered automatic redeploys on push. A built-in CI pipeline compiles versioned Docker images from source, with optional AWS spot instances for burst build capacity. For orchestration at scale, Docker Swarm management handles node configuration, service deployment, and multi-node stack orchestration from the same control plane. Browser terminal sessions open persistent named shells on servers and inside containers, complete with shared team access and scriptable Actions that chain executions into multi-stage procedures. Infrastructure-as-code support defines all resources declaratively in TOML files within a Git repository, keeping production state version-controlled and auditable. Granular role-based access control with user groups, per-resource permissions, and OAuth through GitHub and Google keeps teams operating within defined boundaries. A full OpenAPI specification, dedicated CLI, and typesafe client libraries for Rust and TypeScript make programmatic integration straightforward. With 12,000+ stars and active development, the community continues expanding multi-architecture builds and Swarm tooling.
2FAuth
2FAuth generates TOTP, HOTP, and Steam Guard codes from any web browser, freeing your two-factor authentication from dependence on a single smartphone or app. Lose your phone, switch devices, or sit at a desktop computer, and your 2FA codes remain accessible through the web interface. The Laravel and Vue.js application stores account secrets in an encrypted SQLite database that backs up as a single file. Adding accounts works through camera-based QR scanning or manual secret key entry for services that only provide text codes. Group organization with drag-and-drop sorting keeps large collections navigable, categorized however you prefer. WebAuthn authentication with FIDO2 hardware keys protects vault access with phishing-resistant passwordless login, meaning the tool that secures your accounts is itself secured by the strongest available method. Automatic screen lock triggers after configurable idle time, and OTP obfuscation dots out generated codes until you tap to reveal them, preventing shoulder surfing in shared spaces. The REST API enables browser extensions and external applications to request codes programmatically. Import compatibility with Google Authenticator, Aegis, and 2FAS ensures painless migration without re-enrolling every account from scratch. PWA installation places 2FAuth on your device home screen for native-app-like instant access. Runs on a dedicated RepoCloud VPS with guaranteed resources and full root SSH access. AGPL-3.0 licensed.
Talkyard
Talkyard combines five discussion formats in one platform: StackOverflow-style Q&A with accepted answers, Reddit-like upvote sorting for ideas, threaded forums, real-time chat channels, and embeddable blog comments. Running separate tools for each conversation type fragments community knowledge across disconnected systems, but Talkyard keeps it all searchable in one place. Question askers mark accepted answers, and community voting surfaces the best solutions for future visitors. Idea topics sort by upvotes for crowdsourced feedback prioritization and product decisions. Chat channels handle real-time day-to-day conversation, while forum threads preserve important discussions that need to remain findable months later. The embedding capability goes beyond blog comments: entire Talkyard forums can live inside iframes on your existing website with automatic deep-linking and iframe auto-resizing, adding community discussion to any page without rebuilding your site. Docker Compose containers run with dropped capabilities, no-new-privileges enforcement, non-root processes, health checks, and automatic log rotation. Multi-site hosting serves multiple communities from one installation with isolated databases and separate domains. Automated upgrades pull new images and restart services without intervention. ElasticSearch indexes every discussion format for instant full-text search. The Scala backend with TypeScript frontend stores data in PostgreSQL with automatic Let's Encrypt HTTPS. Runs on a RepoCloud VPS with guaranteed CPU, RAM, SSD, root SSH, and browser console. AGPL licensed.
BTCPay Server
BTCPay Server processes Bitcoin payments with zero transaction fees, zero monthly costs, and zero third-party custody of your funds. Payments settle directly from customer to your wallet through a full Bitcoin node that provides cryptographic proof of receipt without trusting any intermediary. Lightning Network integration through LND, Core Lightning, or Eclair enables sub-second confirmation at sub-cent fees, with Ride The Lightning providing web-based node management within BTCPay itself. The Point of Sale app creates storefronts with product catalogs, tipping, and QR code displays for physical retail, events, or web embeds. Hardware wallet support through BTCPay Vault connects Ledger, Trezor, and ColdCard for transaction signing, keeping private keys in cold storage while running a hot payment interface. Multi-tenant architecture allows multiple stores on one instance, each with isolated wallets, Lightning nodes, and user permissions. The Greenfield REST API exposes every function programmatically for headless operation, automated invoicing, and custom integrations. E-commerce connectors for WooCommerce, Shopify, Magento, and PrestaShop plug in alongside Zapier for workflow automation. Optional Tor hidden services expose the instance as an onion address for censorship resistance. The official Docker Compose stack handles Nginx reverse proxy, Let's Encrypt TLS, and optional Tor configuration on a dedicated RepoCloud VPS with guaranteed CPU, RAM, and SSD. MIT licensed.
Mail-in-a-Box
Mail-in-a-Box turns a single Ubuntu server into a fully functional email system with one setup command, installing and configuring Postfix for SMTP, Dovecot for IMAP, Roundcube for webmail, and Z-Push for Exchange ActiveSync push notifications in an automated sequence that would take days to replicate manually. The DNS server auto-configures the full suite of email authentication records: SPF, DKIM, DMARC, DNSSEC with DANE TLSA, MTA-STS, and SSHFP. Getting all of these right is what separates email that lands in inboxes from email that lands in spam, and most manual installations never achieve the complete set. Nextcloud integration adds CardDAV contact sync and CalDAV calendar sharing across devices. Let's Encrypt certificates provision and renew automatically for every hosted domain. The web control panel manages users, aliases, custom DNS records, and automated backups, protected by TOTP two-factor authentication. Daily health checks verify that services run correctly, ports remain open, TLS certificates stay valid, and DNS records resolve properly, alerting you before delivery problems develop. Multiple domains and users operate from one installation with internationalized domain name support. Built-in HTTPS static site hosting uses the TLS infrastructure already in place. Runs on a dedicated RepoCloud VPS with guaranteed resources, root SSH, and browser serial console for complete email sovereignty. CC0 public domain licensed.
Castopod
Every podcast you publish through Castopod automatically becomes a Fediverse social account that Mastodon, Pleroma, and Pixelfed users can follow, boost, and comment on from their own timelines. This ActivityPub integration transforms podcast distribution from a one-way broadcast into a two-way conversation where listeners interact with episodes through the social platforms they already use. Beyond federation, the platform manages the complete lifecycle: upload an episode, and auto-generated RSS feeds distribute it to Apple Podcasts, Spotify, Deezer, Podcast Addict, and every compatible directory. IABv2-compliant analytics measure downloads, geographic distribution, and listening apps while maintaining GDPR, CCPA, and LGPD compliance through anonymized data collection. Podcasting 2.0 namespace support unlocks chapters with images, SRT/VTT transcripts, location tags, and person credits that modern podcast apps surface to listeners. Video episodes publish alongside audio, and auto-generated clips feed social media sharing workflows. Monetization tools span Value4Value micropayments, premium subscriptions, funding links, and cookieless advertising. Multi-user roles operate per-podcast: contributors, editors, and admins each work within defined permission boundaries. The PHP application runs behind nginx with MariaDB and Redis on a RepoCloud VPS with dedicated CPU, RAM, and SSD. AGPL-3.0 licensed.
Websurfx
Websurfx aggregates results from multiple search engines into one private, ad-free interface that never tracks your queries. Written in Rust, the backend provides memory safety against buffer overflows and data races at the language level while handling concurrent requests across upstream providers like DuckDuckGo and Searx. A built-in re-ranking algorithm scores and merges results by relevance, producing a unified page that draws from many sources while appearing as one coherent search. Safe-search filtering operates across four levels from unrestricted to complete content blocking, with regex-based filter lists for parental controls in schools and organizations. Upstream requests route through configurable proxy chains or Tor, preventing search providers from correlating your queries with a specific IP address. Four Docker image variants target different caching strategies: hybrid Redis plus in-memory for maximum throughput, Redis-only, in-memory-only, or zero-persistence for environments where cached queries must never touch disk. The Lua configuration file controls engine selection, request timeouts, rate limiting thresholds, and production-mode delays that throttle upstream traffic to prevent abuse. Quick-result widgets handle calculations, currency conversions, and unit transformations inline without external redirects. Image search capabilities serve visual discovery for designers and researchers who need media results without surveillance. Runs on a RepoCloud VPS with dedicated resources and full root access. AGPL-3.0 licensed.
Wallos
Track every recurring payment you have, from streaming services to SaaS tools, and get AI-powered recommendations on where to cut costs. Wallos manages subscriptions with automatic due date reminders delivered through email, Discord, Telegram, Pushover, Gotify, or custom webhooks so renewal charges never catch you off guard. Multi-currency support handles international subscriptions while the Fixer API converts everything to your primary currency for unified budget visibility. The statistics dashboard breaks down monthly and yearly spending by customizable categories, revealing consumption patterns and highlighting savings opportunities. AI analysis via ChatGPT, Gemini, or a locally-hosted Ollama instance reviews your subscription portfolio and suggests alternatives or consolidation strategies. Logo search automatically fetches brand imagery so your subscription list stays visually organized without manual uploads. Authentication supports OIDC with OAuth for enterprise environments, and the mobile-responsive interface works on any device with customizable themes and multi-language support. The PHP 8.3 application with SQLite backend runs from a single Docker container (bellamy/wallos image) with two persistent volumes for database and logos on port 8282. Deploy on RepoCloud with a dedicated VPS, keeping all financial data private under the GPL-3.0 license.
Rivet
Stateful serverless actors that run indefinitely, sleep when idle, and persist state across restarts without external database round trips. Rivet provides a vendor-neutral alternative to Cloudflare Durable Objects, delivering long-running processes with co-located in-memory state and per-actor SQLite databases on any infrastructure you choose. The Rust engine comprises four packages: Pegboard for actor orchestration, Gasoline for durable execution, Guard for traffic routing via Envoy, and Epoxy implementing multi-region KV storage through EPaxos consensus. Each actor maintains instant-access in-memory state plus a dedicated SQLite database for relational queries, backed by RocksDB on single nodes or PostgreSQL with NATS pub/sub for multi-node clusters. RivetKit SDKs in TypeScript, Rust, and Python support built-in WebSocket connections, task queues, scheduling, and CRDT-based real-time collaboration. The v2.3 rewrite moved the core runtime from JavaScript to native Rust via WebAssembly, eliminating main-thread blocking across Node.js, Bun, Deno, and Cloudflare Workers. A built-in dashboard provides actor inspection with real-time Prometheus metrics. Deploys as a single Docker container on port 6420 with optional PostgreSQL for persistence. Available on RepoCloud with a dedicated VPS under the Apache 2.0 license.
PeerDB
Replicate PostgreSQL to data warehouses 10x faster than conventional CDC tools, proven across 400+ companies including AutoNation and LC Waikiki collectively moving 200 TB monthly. The architecture pairs a Rust-based Nexus query layer implementing the PGWire protocol with Go-based Flow workers orchestrated by Temporal. Because Nexus speaks native Postgres wire protocol, any client tool (pgAdmin, psql, Grafana, Tableau, Flyway) can manage replication through standard SQL commands like CREATE MIRROR. Three streaming modes serve different needs: log-based CDC via logical replication slots, cursor-based streaming through timestamp or integer columns, and XMIN-based capture for tables lacking logical replication. Parallel initial load achieves consistent snapshots through transaction snapshotting and CTID range scans, reducing 100+ GB migrations from days to minutes. Native TOAST column handling processes large JSONB payloads and IoT data efficiently without row expansion penalties. Destinations include ClickHouse, Snowflake, BigQuery, Kafka, Azure Event Hubs, Google PubSub, S3, and PostgreSQL with in-flight SQL transformations. Schema change propagation, partitioned table support, and slot growth alerts ensure production reliability. Docker Compose bundles Temporal, catalog Postgres, Flow API, workers, and the Next.js monitoring UI. Deployable on RepoCloud with dedicated VPS resources under AGPL-3.0.
Tailchat
Think of it as a team messaging platform where every feature beyond core chat is a plugin you can install or remove, inspired by VS Code's extension model but applied to real-time communication. The Moleculer microservice backend scales horizontally across nodes while Socket.io delivers instant message synchronization with text, images, files, mentions, reactions, and rich Markdown formatting. Available plugins provide LiveKit video conferencing, collaborative drawing boards, task management panels, end-to-end encryption, custom themes, and third-party push notification reception without touching core code. Groups use a two-level space system with customizable panel layouts arranged through drag-and-drop, while role-based access control enforces fine-grained permissions across the organization. The Open Platform exposes OAuth for single sign-on across connected applications and a Bot API enabling bidirectional message processing between Tailchat and external services via HTTP requests. Multi-platform clients cover web, Electron desktop with screenshot capabilities, and mobile apps with native push. Docker Compose deployment bundles MongoDB for persistence, Redis for caching and transport, and MinIO for S3-compatible file storage. Deploy on RepoCloud with a dedicated VPS for persistent team infrastructure under the Apache 2.0 license.
ChartDB
Paste one SQL query result into a browser and get an interactive entity-relationship diagram instantly, with no installations, no credentials, and no account required. ChartDB's "Smart Query" runs a single statement in your existing database client that exports table definitions, relationships, indexes, and column types as JSON metadata, meaning the application never touches your database passwords. The canvas renders draggable entities with cardinality markers, collapsible grouping areas, and sticky notes for documentation. AI-powered DDL export generates migration scripts between dialect pairs like PostgreSQL to MySQL or SQLite to CockroachDB, analyzing your schema to produce target-specific DDL with correct type mappings and constraint translations. Import paths cover Smart Query JSON, raw DDL scripts, and DBML files from tools like dbdiagram.io. The AI layer connects to OpenAI or any compatible inference server including local vLLM instances running models like Qwen2.5-32B. Database coverage includes PostgreSQL (with Supabase and Timescale extensions), MySQL, SQL Server, MariaDB, SQLite (with Cloudflare D1), CockroachDB, ClickHouse, and Oracle. Exports to SVG with inline styles or SQL DDL in any target dialect. Ships as a React/Vite frontend behind Nginx in Docker, deployable on RepoCloud with dedicated VPS resources under the AGPL-3.0 license.
Sourcebot
Point Sourcebot at your GitHub, GitLab, Bitbucket, Azure DevOps, Gerrit, or Gitea repositories and get regex, symbol, and filtered search results in under a second across thousands of repos and branches. Backed by Y Combinator with production deployments at NVIDIA, Shutterstock, SeatGeek, Arista, and Red Hat, the Zoekt-powered engine deploys as a single Docker container with zero external data transmission. Ask Sourcebot connects reasoning models like Claude Opus to your entire codebase, enabling natural language questions that return structured answers grounded with inline citations and navigable code snippets, backed by automatic tool calls that search code, follow references, and read files across all indexed repositories. Ask connectors extend this to Jira, Slack, Linear, and Confluence via MCP, pulling external context alongside code for debugging and documentation. IDE-level code navigation provides goto definition and find all references across repository boundaries without local cloning. The built-in file explorer renders any indexed file with syntax highlighting, breadcrumb navigation, and git blame showing per-line commit attribution. An analytics dashboard tracks daily, weekly, and monthly search activity. Permission syncing from GitHub and GitLab enforces access control lists so users only see repositories they are authorized to access. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Other licensed.
BitRouter
BitRouter is a context-aware LLM router that learns which model delivers the cheapest successful outcome per workflow step, cutting agent costs by up to 80% while maintaining 96% quality versus all-frontier baselines. Point any agent runtime at http://localhost:4356 with a one-line OPENAI_BASE_URL change and BitRouter routes to OpenAI, Anthropic, Google, Groq, DeepSeek, Mistral, Moonshot, MiniMax, Nvidia, and any OpenAI-compatible endpoint simultaneously, normalizing authentication, streaming, and cross-protocol translation between wire formats. The act-observe-evaluate-learn loop traces every hop with cost, tokens, and latency attribution, scores each decision against a versioned policy-lock.yaml, then tightens routes automatically with no LLM judge in the path. Native MCP gateway auto-discovers tools from connected servers and makes them routable and governed alongside model calls. Agent Client Protocol integration enables the TUI to manage Claude Code, Codex, OpenCode, OpenClaw, Gemini, and Copilot sessions in real time with inline tool-call approval and live streaming. Built-in guardrails inspect, redact, or block risky content before requests leave your network. Virtual keys scope API access per agent or user without exposing upstream credentials. Per-agent spend caps and loop guards contain runaway cost automatically. Multi-account failover reroutes mid-run so rate limits never re-pay completed work. Ships as a single Rust binary via npm or Cargo. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Inference Gateway
Inference Gateway puts a single OpenAI-compatible API endpoint in front of OpenAI, Anthropic, Groq, Cohere, Ollama, DeepSeek, Google, Mistral, MiniMax, Moonshot, Nvidia, and llama.cpp, so your application code never changes when you switch models or providers. The Go binary starts on port 8080 and normalizes authentication, streaming protocols, and response formats across all backends transparently. Native Model Context Protocol support auto-discovers tools from connected MCP servers and injects them into LLM requests without client-side management, enabling server-side tool execution across any provider that supports function calling. Agent-to-Agent protocol integration allows distributed agent communication through a declarative Agent Definition Language that generates production-ready Go or Rust servers from a single YAML manifest. The dedicated Kubernetes Operator manages Gateway, Agent, MCP, and Orchestrator custom resources with automatic HPA scaling, OIDC authentication, and service discovery that rebuilds MCP configurations when the discovered server set changes. Prometheus metrics and OpenTelemetry tracing provide full request-level observability across the entire inference pipeline. Middleware controls enable per-request provider selection, model routing, and fallback strategies. Official SDKs in Go, Python, TypeScript, and Rust provide typed client interfaces with streaming support. Docker Compose deployment requires only environment variables for API keys. A CNCF Sandbox applicant. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Seatsurfing
Seatsurfing brings desk booking, room reservations, and parking management to interactive floor plans across multiple office locations, solving the coordination headache of hybrid work. The Go backend serves two React/TypeScript frontends through a single Docker container on port 8080: a Booking UI built as an installable Progressive Web App for mobile and desktop reservations, and an Admin UI for floor plan configuration, capacity enforcement, and analytics. Interactive floor plans accept uploaded office layouts where administrators visually place bookable spaces with per-space metadata and availability rules. Multi-location support handles organizations with distributed offices across multiple buildings and cities. The buddy system displays which colleagues have bookings on a given day, enabling team coordination without manual communication. Capacity management enforces occupancy limits per area with automatic denial when thresholds are reached. SSO integration supports OIDC and OAuth2 providers including Microsoft Azure AD, Keycloak, and Authentik for enterprise identity federation. Microsoft Teams and Confluence integrations embed booking directly into collaboration tools employees already use daily. The REST API enables automation and custom integrations, while the analytics dashboard tracks utilization rates, peak hours, and booking patterns. Docker Compose deployment requires only a PostgreSQL database with multi-architecture images supporting amd64 and arm64. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-3.0 licensed.