Authelia
Authelia is the leading open-source SSO and multi-factor authentication server for self-hosted infrastructure. The Go backend compiles to a single binary or Docker container image, serving a TypeScript React web portal that handles first-factor username and password login, second-factor authentication via TOTP, WebAuthn FIDO2 security keys, passwordless passkeys, and Duo mobile push notifications, and an OpenID Connect 1.0 and OAuth 2.0 identity provider with device code flow, JWE encrypted ID tokens, custom claims policies, and network-scoped authorization criteria. The forward authentication model integrates with Nginx auth_request, Traefik ForwardAuth, HAProxy, Caddy, Envoy, SWAG, and Skipper reverse proxies, injecting Remote-User, Remote-Groups, and Remote-Email headers into authorized requests. Granular access control rules match subject, groups, request URI, HTTP method, and network to enforce one-factor and two-factor policies per route. The user backend supports LDAP with attribute mapping, connection pooling, and bind mode, or YAML file-based authentication with Argon2id hashed passwords. Session state stores in Redis for high availability across clustered deployments, while persistent data lives in SQLite, MySQL and MariaDB, or PostgreSQL. Brute force protection locks accounts after configurable failed attempts, and email-based identity verification handles password resets and device registration. Dark, light, and OLED themes with i18n localization customize the portal appearance. On RepoCloud, deploy Authelia on a dedicated VPS with Docker, root SSH access, and complete control over your authentication infrastructure, all under the Apache-2.0 license.
Neon
Neon reimagines PostgreSQL with a serverless architecture that decouples storage from compute, enabling instant copy-on-write database branching, autoscaling under load, and scale-to-zero when idle with sub-second cold starts. The lakebase architecture distributes durability across three layers: stateless compute nodes running unmodified PostgreSQL, safekeepers providing Paxos-based WAL quorum replication, and a pageserver that materializes pages on demand while offloading immutable history to S3-compatible object storage via MinIO or AWS S3. Copy-on-write branching creates full database clones as metadata operations without duplicating data, enabling developers to spin up isolated test environments, run parallel CI/CD pipelines, or recover from data loss through point-in-time restore across the configurable history window. Autoscaling dynamically adjusts CPU and memory based on live traffic without manual capacity planning, while scale-to-zero ensures costs drop to storage-only during idle periods. Neon maintains 100% PostgreSQL compatibility with broad extension support including PostGIS, pg_cron, pgvector, pg_stat_statements, and hundreds more, so existing applications connect with standard PostgreSQL drivers and ORMs unchanged. The API-first control plane enables programmatic provisioning, branch management, and multi-tenant fleet operations for platform builders and AI agent integrations. Acquired by Databricks in May 2025 and backed by over 22,800 GitHub stars. Deploys via Docker Compose with pageserver, safekeepers, storage broker, and compute nodes backed by MinIO object storage. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Homebox
With over 7,000 GitHub stars and active community maintenance through version 0.26.0 released in June 2026, Homebox fills the gap between inadequate spreadsheets and overcomplicated enterprise asset management by providing a purpose-built inventory system designed specifically for home users, families, and small groups. The Go backend with SQLite storage deploys as a single Docker container consuming under 50MB of RAM at idle, running on hardware as modest as a Raspberry Pi while the responsive web interface adapts seamlessly across desktops, tablets, and smartphones. The entity-based architecture introduced in v0.26 unifies items and locations into a shared structure supporting custom fields, attachments, entity types, and reusable templates for consistent data entry across inventory categories. QR code generation creates printable labels that scan with any smartphone camera to instantly display item details, photos, serial numbers, and associated documents. Warranty tracking records purchase dates, prices, and expiration dates while maintenance scheduling sends reminders for recurring service tasks. Location hierarchies organize items spatially with nested sub-locations, and flexible label tagging enables cross-cutting categorization beyond physical placement. Multi-user support shares collections with family members or roommates with OIDC single sign-on integration for Active Directory, Okta, and other identity providers. CSV import and export handles bulk operations, while the full REST API enables automation and third-party integrations. Collection-level ZIP export packages complete inventories with attachments for backup or migration. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Corteza
Salesforce's platform model, 100% open-source (Apache 2.0): Corteza is a Go/Vue.js low-code platform developed under a foundation, so there is no open-core bait to grow out of. The heart is Corteza Compose: namespaces contain applications, modules define record structures the way Salesforce objects do, and a drag-and-drop page builder assembles record pages, list pages, dashboards, and charts from configurable blocks. Automation comes from a visual, BPMN-style workflow engine plus JavaScript automation scripts, so cross-application business logic - approval chains, field updates, notifications - is configured rather than programmed. Granular role-based permissions reach down to individual modules, fields, and records, mirroring real organizational hierarchies. Corteza CRM ships as the flagship application built entirely on Compose: leads, accounts, opportunities, campaigns, and cases with a 360-degree customer view, covering most Salesforce standard objects - and because it is just a Compose app, adding or reshaping modules is configuration, not a fork. Everything is reachable over REST APIs, deliberately familiar tooling eases Salesforce admin migration, and a CLI can even generate synthetic records for load-testing what you build.
AgentsView
Software developers running Claude Code, Cursor, Codex, and Aider use AgentsView to trace token expenditures, search full session transcripts, and analyze multi-agent concurrency timelines. Engineers can search through historical developer sessions to locate specific code modifications, prompt chains, or debugging rationales across extensive programming workflows. The real-time activity timeline visualizes concurrent agent operations, revealing peak execution windows, task run durations, and automated tool invocations. The usage analytics engine calculates financial costs and token volumes per model by applying live pricing tables while accounting for prompt caching read discounts. Developers inspect granular turn-by-turn session transcripts complete with raw model payloads, file difference diffs, executed shell commands, and syntax errors. The recall browser extracts key technical context from past programming sessions, organizing facts into an indexed reference knowledge corpus for reuse across future project tasks. Administrators can replicate SQLite session tables into DuckDB analytics files or PostgreSQL warehouses to query longitudinal metrics using SQL analytical tools or custom reporting scripts. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Octop
Modern engineering teams and busy households deploy Octop to run private, autonomous AI agents equipped with persistent memory workspaces, scheduled cron jobs, and direct browser automation. Users can orchestrate specialist agents tailored for software development, IT operations, content generation, and system diagnostics through an interactive React dashboard. The platform connects directly to Discord, Feishu, DingTalk, and WeCom, allowing team members to delegate complex tasks without leaving their everyday messaging apps. An integrated remote desktop and browser control engine lets agents navigate websites, capture screenshots, fill forms, and operate graphical software autonomously. Administrators can assign distinct MBTI personality profiles to agents, establish granular role-based permissions, configure scheduled cron workflows, and integrate custom Model Context Protocol servers for external tool access. Long-term memory persists across conversations through dedicated workspace files, ensuring contextual continuity whenever switching between underlying language models or team collaborators. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Omnigent
Open-sourced by the Databricks AI team under Apache 2.0 and reaching over 8,500 GitHub stars within two months of launch, Omnigent introduces the meta-harness concept: a common orchestration layer that sits above existing AI coding agents and makes them interoperable parts of a governed, collaborative system. The platform wraps Claude Code, Codex, Cursor, OpenCode, Hermes, Pi, and any custom agent defined in a simple YAML configuration file into sandboxed sessions with a uniform API, then exposes each session through the terminal, a web UI, a native desktop application, mobile interfaces, and a REST API. Built-in multi-agent workflows include Polly, a coding orchestrator that delegates tasks to parallel sub-agents in separate git worktrees and routes each diff to a reviewer from a different vendor, and Deep Research, which plans sub-queries, searches the live web through MCP servers, reads full pages, and cross-checks claims across independent sources. Contextual security policies go beyond static allow/deny rules by maintaining per-session state to enforce spend caps, model routing, approval gates for destructive actions, PII blocking, and repository-scoped write restrictions across server-wide, per-agent, and per-session levels. The OS sandbox restricts filesystem and network access while intercepting egress requests to inject credentials only on approved calls. Cloud sandbox providers including Modal, Daytona, E2B, CoreWeave, Kubernetes, and Databricks launch disposable execution environments per session. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
BookOrbit
Consolidate your entire digital library into a self-hosted reading sanctuary with BookOrbit, an open-source media platform that organizes ebooks, audiobooks, comic archives, and research PDFs within a personal private cloud. Readers can enjoy multi-format media directly through responsive browser readers that support EPUB, CBZ, and M4B formats without external browser extensions. The platform synchronizes reading bookmarks, highlights, and completion statuses across web interfaces, Kobo ereaders, and KOReader devices. An automated metadata enrichment engine queries fourteen upstream bibliographic indexes, downloading cover artwork, chapter breakdowns, author biographies, and series taxonomies. The staging workspace allows librarians to inspect incoming files, review suggested metadata revisions, and embed updated tags directly into physical storage archives before shelving. Custom reading dashboards track annual book goals, calculate daily streaks, and plot reading habit radar charts. Multi-user configurations support distinct per-user collections, granular content permissions, and single sign-on authentication through OpenID Connect providers. Power users can export private OPDS feeds to external mobile reading applications or push books directly to connected Kindle hardware. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GNU AGPL v3.0 licensed.
QwenPaw
Designed as a unified personal AI workstation, QwenPaw operates as an autonomous digital copilot that coordinates scheduled automations, interactive coding sessions, and multi-channel team communication across everyday messaging apps. Users can dispatch long-running research tasks, process office documents including PDF, Excel, and Word files, and execute browser-based data collection without manual intervention. The built-in web console and terminal interface provide full visibility into agent reasoning, allowing operators to inspect intermediate thinking steps, review proposed file edits, and approve sensitive tool calls. Through direct connectors for Discord, Telegram, DingTalk, Lark, and WeChat, teams can trigger specialized skills or query shared workspaces directly from their existing group channels. A self-evolving personal memory system continuously indexes chat interactions and local resources into editable Markdown files, ensuring knowledge persists across restarts and task delegations. Built-in guardrails including a sandboxed execution runtime, tool access policies, and automated skill scanners protect underlying host files from unauthorized modifications during autonomous scripting runs. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Baby Buddy
Baby Buddy is a private self-hosted child care tracker that centralizes feeding sessions, sleep cycles, diaper changes, and developmental health milestones into a collaborative dashboard for parents and caregivers. Caregivers can start quick timers on mobile devices to measure nursing intervals, bottle feedings, naps, and tummy time sessions with single-tap precision. The dashboard automatically calculates daily averages, feeding amounts, and awake windows to help families establish consistent daily sleep and feeding routines. Parents can track diaper changes by recording wetness, stool consistency, and color anomalies to spot digestive health changes early. Physical measurements including weight, height, and head circumference plot directly against World Health Organization growth curves to visualize percentile progression between pediatric visits. Multi-child profiles allow families with twins or multiple young children to switch contexts instantly and monitor individual growth timelines. Granular user permissions let parents invite nannies, babysitters, and relatives with restricted logging permissions while keeping administrative settings private. The built-in REST API and webhook system enable physical smart button clicks and home automation routines to log events instantly without opening a browser. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD-2-Clause licensed.
BTCPay Server
BTCPay Server processes Bitcoin payments with zero transaction fees, zero monthly costs, and zero third-party custody of your funds. Payments settle directly from customer to your wallet through a full Bitcoin node that provides cryptographic proof of receipt without trusting any intermediary. Lightning Network integration through LND, Core Lightning, or Eclair enables sub-second confirmation at sub-cent fees, with Ride The Lightning providing web-based node management within BTCPay itself. The Point of Sale app creates storefronts with product catalogs, tipping, and QR code displays for physical retail, events, or web embeds. Hardware wallet support through BTCPay Vault connects Ledger, Trezor, and ColdCard for transaction signing, keeping private keys in cold storage while running a hot payment interface. Multi-tenant architecture allows multiple stores on one instance, each with isolated wallets, Lightning nodes, and user permissions. The Greenfield REST API exposes every function programmatically for headless operation, automated invoicing, and custom integrations. E-commerce connectors for WooCommerce, Shopify, Magento, and PrestaShop plug in alongside Zapier for workflow automation. Optional Tor hidden services expose the instance as an onion address for censorship resistance. The official Docker Compose stack handles Nginx reverse proxy, Let's Encrypt TLS, and optional Tor configuration on a dedicated RepoCloud VPS with guaranteed CPU, RAM, and SSD. MIT licensed.
LeafWiki
Engineering teams and technical writers maintain operational runbooks, system documentation, and knowledge bases using LeafWiki, an open-source self-hosted wiki that stores page contents directly as human-readable Markdown files on the local filesystem. Authors can compose documentation through a dual-pane editor equipped with live HTML preview, keyboard navigation, autocomplete for internal links, and native rendering for Mermaid diagrams, KaTeX mathematical formulas, and collapsible callout containers. The navigational tree organizes complex documentation into explicit directory hierarchies and custom drag-and-drop page sequences tracked in lightweight configuration files rather than arbitrary alphabetical lists. An integrated SQLite engine indexes page content and custom taxonomy tags for fast full-text searches, automatic incoming backlink tracking, and automated broken link detection. System operators can deploy the single-binary application without external database servers or runtime dependencies, backing up the entire repository by copying the data directory. Administrators can provision granular user roles, configure reverse proxy header authentication for single sign-on gateways, and manage read-only API access keys for automated documentation scripts and continuous integration pipelines. Public viewers can browse technical notes without authentication or switch between dark and light high-contrast themes. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Suite Docs
An open-source alternative to Notion and Google Docs developed jointly by France's DINUM and Germany's ZenDiS that prioritizes data sovereignty, real-time collaboration, and structured knowledge management. The Yjs-powered CRDT engine provides live cursors, presence indicators, and inline comments enabling teams to edit simultaneously without conflicts, while BlockNote.js renders a clean block-based editing experience with rich text formatting, Markdown shortcuts, and drag-and-drop content organization. Hierarchical sub-documents create wiki-style knowledge bases where documentation nests naturally into navigable structures, and a dedicated slide mode transforms any document into a presentation without separate tooling. The document API separates content from metadata with distinct endpoints for formatted content, raw content streams, and document properties. Optional AI integration connects to configurable language models for writing assistance, summarization, and content generation directly within the editor. Access control supports granular permissions per document with team sharing, public links, and invitation flows. DOCX import brings existing documents into the platform while maintaining formatting fidelity. The Django backend serves a REST API with PostgreSQL storage, Redis caching, and S3-compatible media handling. Deploy via Docker Compose, Kubernetes with the official Helm chart, Nix, or YunoHost on your own infrastructure. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
OpenPost
OpenPost is an open-source content creation and publishing suite that unifies multi-platform social scheduling, graphic design, and video editing into a single self-hosted control center. Creators can compose one primary announcement and tailor bespoke copy, media attachments, and thread structures across sixteen distinct networks including Bluesky, Mastodon, X, Threads, LinkedIn, YouTube, and Discord. The integrated browser canvas lets you design multi-slide carousels with custom typography, layer ordering, and automated background removal without juggling external design software. A built-in multitrack video suite allows you to trim footage, render subtitle captions, insert transitions, and slice clips directly by highlighting spoken words in generated transcripts. Social managers can organize campaigns through an interactive visual calendar, stagger deliveries across automated queues, and monitor unified comment streams to answer incoming audience inquiries directly from a single inbox. Teams can organize multiple independent client brands into partitioned workspaces with role-based permissions, automated repost policies, and programmable scheduling webhooks via native REST and Model Context Protocol endpoints. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
KeeWeb
Your KeePass vaults, opened from any browser: KeeWeb reads, edits, and creates standard KDBX files, so it works with the same databases as KeePass and KeePassXC without conversion or lock-in. Self-hosting the web app gives you a password manager reachable from any modern browser, including mobile, with no client installation and no third-party cloud in the loop. All KDBX cryptography runs client-side; the server just serves the static app. Open multiple vault files simultaneously and search them all from one box, with advanced options covering specific fields, password history, and regular expressions. Vaults load from local files, your own server (WebDAV), or Dropbox, Google Drive, and OneDrive, with automatic sync - and files are cached for offline use, so a dropped connection never locks you out; changes resync once you're back online. Day-to-day niceties include a configurable password generator, protected fields that stay masked and are held in memory more defensively, entry history, tags with easy input, drag-and-drop attachments, and per-entry icons with favicon fetching. The optional KeeWeb Connect extension (Chrome, Firefox, Edge, Safari) autofills credentials using the keepassxc-protocol. MIT-licensed with matching desktop apps for macOS, Windows, and Linux.
GoatCounter
GoatCounter delivers meaningful web traffic insights — pageviews, referrers, browsers, screen sizes, country-level geolocation — without setting a single cookie, without collecting personal data, and without forcing GDPR consent banners on your visitors. Written entirely in Go and distributed as a single compiled binary consuming roughly 25MB of RAM, it adds just 3.5KB to your pages via the tracking script, with a JavaScript-free tracking pixel alternative for sites that avoid scripts entirely, plus backend middleware integration and log file import for server-side collection. The dashboard displays pageview counts per path with hourly resolution, referrer sources grouped by domain with full URL on hover, browser and OS version breakdowns, screen size distributions, and country-level location data derived from IP addresses that are immediately discarded after geolocation. Campaign tracking supports UTM parameters and custom data attributes. A public stats option exposes your dashboard at a shareable URL for build-in-public transparency. SQLite serves as the default database requiring zero administration, while PostgreSQL handles higher-traffic deployments with multi-site setups. Built-in ACME and TLS certificate management eliminates reverse proxy requirements for HTTPS — no Nginx or Caddy needed. The REST API provides programmatic access to all analytics data. Deploy as a single binary, via Docker with the official arp242/goatcounter image, or through native packages. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. EUPL-1.2 licensed.
Forem
With 22,700 GitHub stars, 4,100+ forks, and proven scale powering dev.to — one of the largest developer communities serving millions of monthly users — Forem provides a complete community platform for building engaged audiences around shared interests, whether for developer documentation, customer communities, fan bases, or professional networks. The Rails backend with Preact frontend delivers article publishing with a rich Markdown editor, threaded discussions, user profiles with portfolio links, tag-based content organization, podcast hosting, classified listings for jobs and events, and social interactions including reactions, bookmarks, and following. AI-powered semantic search using PostgreSQL pgvector embeddings surfaces relevant content across articles and concepts, while scheduled automations enable community bots to create automated roundups, republish curated content, and trigger time-based moderation actions. Score-based content ranking replaces simple reaction counts with nuanced algorithms that resist gaming. The admin dashboard provides user management, content moderation, community settings, analytics, and organization controls. OAuth integration supports GitHub, Twitter, Apple, and configurable OIDC providers for frictionless sign-up. Dynamic open-graph image generation creates branded social cards automatically. Deploy with Kamal 2 to any cloud provider or bare metal server with PostgreSQL and Redis. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPLv3 licensed.
Agenta
Agenta delivers a comprehensive open-source LLMOps workspace that covers the full lifecycle of AI application development — from prompt engineering through production monitoring. The platform supports 15+ model providers including OpenAI, Anthropic, Google Gemini, Mistral, Groq, Together AI, Azure, AWS Bedrock, and self-hosted models via Ollama, enabling teams to switch between providers without code changes. The prompt playground allows side-by-side comparison of different configurations, while the evaluation system offers LLM-as-a-Judge assessment, 20+ pre-built evaluators covering semantic similarity, regex matching, and factual accuracy, plus custom Python evaluators for domain-specific requirements. Teams run evaluations through both the web UI for subject matter experts and the Evaluation SDK for programmatic CI/CD integration. The observability layer captures full trace visibility across complex agentic workflows, flagging quality issues like hallucinations and off-topic responses in real time. Human annotation workflows let domain experts review and annotate LLM outputs, feeding corrections back into the evaluation loop. The architecture supports Chain of Prompts, RAG pipelines, and multi-step agent workflows, integrating with frameworks like LangChain and LlamaIndex. Self-hosting deploys via Docker Compose with Traefik for routing, requiring only a clone, environment configuration, and a single docker compose command. On RepoCloud, deploy Agenta on a dedicated VPS with root SSH access, persistent storage for evaluation datasets and traces, and complete control over model provider credentials, all under the MIT license with no usage restrictions.