Levelrail is a self-hosted deployment platform where a node agent talks directly to Docker's Engine API instead of SSHing in, turning Linux machines into a private cloud with git deploys, TLS, logs, metrics, rollback and managed databases.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONTailscale is an open-source mesh VPN built on WireGuard, providing a daemon and CLI to create secure private networks across Linux, Windows, macOS, FreeBSD and OpenBSD.
3X-UI is an open-source web control panel for managing Xray-core servers, supporting many proxy and VPN protocols with per-client traffic accounting, multi-node management, subscriptions, bots and a REST API.
Quietport is a self-hosted, encrypted file sync system for Mac, Windows, and Linux. It uses a private WireGuard mesh and rclone for end-to-end encrypted sharing without accounts, where the server stores only ciphertext.
Headscale is an open-source, self-hosted implementation of the Tailscale control server, letting self-hosters run a single private WireGuard-based tailnet for personal or small-organization use.
tailscaled-rs is an experimental, independent Rust daemon that implements the Tailscale control protocol to join WireGuard-based mesh networks. It provides a persistent background service with CLI management, state persistence, and local API access, serving as a community-driven alternative to the official client.
pktc is a compiler that translates packet description trees into Linux tunnel device configurations. Write what you expect on the wire and it emits iproute2 commands.
Firezone is a secure remote access platform built on WireGuard, offering blazing-fast encrypted connectivity with identity-based policies, device attestation, and detailed audit logs for accessing private applications and infrastructure.
Self-hosted PaaS that orchestrates multi-node deployments over a private WireGuard mesh with K3s: deploy apps, managed databases and Compose stacks while worker nodes stay dark to the public internet.
Portlyn is a self-hosted identity-aware reverse proxy with a built-in WireGuard tunnel, combining routing, TLS, per-route authentication, and observability in a single Go binary for homelabs and small teams.
Xray-core is an open-source network proxy platform from Project X, originating from the XTLS protocol. It supports VLESS, XTLS, REALITY and related transports, with install scripts, Docker images, web panels and many GUI clients across platforms.
vpnonly routes selected macOS apps through a WireGuard VPN tunnel while keeping all other traffic on the normal connection. It uses macOS PF firewall group matching to split-tunnel applications without kernel extensions or Network Extension entitlements.