Saltar al contenido
QuenchWorks

Hoja de ruta

Qué está publicado, qué sigue

195 bases de datos y herramientas están endurecidas y publicadas hoy. Debajo está lo que viene, primero las opciones limpias OSI. Cada entrada se compila desde el código fuente sobre Wolfi, se escanea hasta cero CVE corregibles, se firma y se fija por digest antes de pasar a disponible.

195/451
43% publicado
19543%
Publicado
22149%
En la hoja de ruta
358%
Bloqueadas

Disponible ahora

195

Analítico

1

Aplicaciones y productividad

13

Imagen base

1

Herramienta de compilación

7

CI/CD y registro

12

Caché

5

Coordinación

5

Coordinación y malla

3

Database

1

Bases de datos y motores

2

Developer tools / IDE

1

Documental

5

Puerta de enlace

9

Git

2

GitOps

2

Grafos

1

Identidad

6

Entorno de ejecución de lenguaje

13

Machine learning & AI

3

Medios y streaming

3

Mensajería

11

Métricas/Exportador

4

Almacenamiento de objetos

3

Observabilidad

18

PaaS

2

Registro

9

Relacional

7

Base de ejecución

4

Búsqueda

6

Búsqueda y vectores

1

Secretos

2

Secretos e identidad

2

Seguridad y cadena de suministro

13

Almacenamiento y plataforma

3

Series temporales

4

Vectorial

1

Columna ancha

2

Flujo de trabajo

8

Retenidas — compiladas, sin publicar

35

Se compilan y prueban limpias pero aún no alcanzan 0 CVE corregibles — la app o su base fija una dependencia por debajo de la versión que corrige un CVE conocido, así que la retenemos en lugar de publicar una imagen vulnerable. Cada una se vuelve a listar automáticamente en cuanto el upstream publica la corrección. Toca ¿por qué bloqueada? para ver la fijación exacta.

Aplicaciones y productividad

6
  • Apache Supersetbloqueada

    Plataforma de exploración de datos y paneles de inteligencia de negocio respaldada por una base de datos de metadatos y Redis.

    Aplicaciones y productividadApache-2.0
  • Flocibloqueada

    Emulador local de AWS autoalojado (Java), una alternativa a LocalStack Community tras su discontinuación en 2026. Los servicios en proceso (S3, DynamoDB, SQS, SNS, IAM) se ejecutan endurecidos como nonroot; los servicios respaldados por Docker (Lambda, RDS, ECS, EKS) necesitan el socket de Docker del host y root, por lo que quedan fuera del modelo endurecido.

    Aplicaciones y productividadMIT
  • Floci (full)bloqueada

    Opt-in, NON-hardened companion to the floci image: it runs as root and expects the host Docker socket mounted, which lets it emulate all 65 of Floci's AWS services including the 10 Docker-backed ones (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune).

    Aplicaciones y productividadMIT
  • Ghostbloqueada

    Plataforma de publicación y boletines en Node.js respaldada por MySQL o MariaDB.

    Aplicaciones y productividadMIT
  • Matomobloqueada

    Plataforma de analítica web respetuosa con la privacidad en PHP respaldada por MySQL o MariaDB.

    Aplicaciones y productividadGPL-3.0-only
  • Nextcloudbloqueada

    Suite autoalojada de sincronización, compartición y colaboración de archivos en PHP respaldada por PostgreSQL o MariaDB.

    Aplicaciones y productividadAGPL-3.0-only

CI/CD y registro

2
  • Gitnessbloqueada

    Alojamiento Git autoalojado con pipelines integrados, de Harness.

    CI/CD y registroApache-2.0
  • Jenkinsbloqueada

    Servidor de automatización extensible para integración y entrega continuas.

    CI/CD y registroMIT

Coordinación

1
  • Apache ZooKeeperbloqueada

    Centralized coordination service for distributed systems, providing configuration, naming, leader election, and synchronization primitives.

    CoordinaciónApache-2.0

Documental

1
  • FerretDBbloqueada

    MongoDB-compatible document database that translates the MongoDB wire protocol onto PostgreSQL via the DocumentDB extension.

    DocumentalApache-2.0

Grafos

1
  • Neo4jbloqueada

    Graph database for highly connected data, queried with Cypher for traversals and relationship-heavy workloads.

    GrafosGPL-3.0-only

Identidad

3
  • Autheliabloqueada

    Pasarela de autenticación y 2FA para proxies inversos.

    IdentidadApache-2.0
  • Keycloakbloqueada

    Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.

    IdentidadApache-2.0
  • ZITADELbloqueada

    Cloud-native identity and access management (IAM) with OIDC/OAuth2/SAML, multi-tenancy, and a built-in admin console.

    IdentidadAGPL-3.0-only

Mensajería

3
  • Apache Kafkabloqueada

    Distributed event-streaming platform for high-throughput, durable, replayable publish-subscribe pipelines and stream processing.

    MensajeríaApache-2.0
  • Apache Pulsarbloqueada

    Cloud-native distributed messaging and streaming platform with multi-tenancy, geo-replication, and tiered storage that separates compute from storage.

    MensajeríaApache-2.0
  • Mattermostbloqueada

    Plataforma de chat de equipo autoalojada; el servidor Team Edition es Apache-2.0 y funciona sobre PostgreSQL.

    MensajeríaAGPL-3.0-only

Observabilidad

9
  • Apache JMeterbloqueada

    Herramienta de pruebas de carga y rendimiento para endpoints web y de servicios.

    ObservabilidadApache-2.0
  • Apache SkyWalkingbloqueada

    APM: trazabilidad distribuida, métricas y análisis de topología de servicios.

    ObservabilidadApache-2.0
  • Grafanabloqueada

    Dashboards and visualization for metrics, logs, and traces across many data sources.

    ObservabilidadAGPL-3.0-only
  • Grafana Alloybloqueada

    Distribución de colector basada en OpenTelemetry para métricas, logs, trazas y perfiles.

    ObservabilidadApache-2.0
  • Graylogbloqueada

    Gestión y análisis centralizado de logs. De código disponible, no OSI.

    ObservabilidadSSPL-1.0
  • metrics-serverbloqueada

    Kubernetes resource-metrics API for HPA and kubectl top.

    ObservabilidadApache-2.0
  • OpenSearch Dashboardsbloqueada

    Interfaz de visualización y paneles para OpenSearch.

    ObservabilidadApache-2.0
  • Telegrafbloqueada

    Agente de recopilación de métricas basado en plugins del ecosistema InfluxData.

    ObservabilidadMIT
  • Thanosbloqueada

    Almacenamiento a largo plazo y consulta global para Prometheus.

    ObservabilidadApache-2.0

PaaS

1
  • Coolify Helperbloqueada

    Coolify helper image carrying the build and deploy toolchain (buildpacks, git, ssh) that runs on target hosts to execute deployments. [blocked: upstream CVEs / ES9 unsupported]

    PaaSApache-2.0 AND AGPL-3.0-or-later

Relacional

1
  • CockroachDBbloqueada

    Distributed SQL database with PostgreSQL wire compatibility and automatic horizontal scaling and survivability.

    RelacionalBUSL-1.1

Búsqueda

3
  • Apache Solrbloqueada

    Enterprise search platform built on Apache Lucene, offering full-text search, faceting, and indexing over large document collections.

    BúsquedaApache-2.0
  • Elasticsearchbloqueada

    Distributed search and analytics engine.

    BúsquedaSSPL-1.0
  • OpenSearchbloqueada

    Search and analytics suite with a Kibana-style dashboards UI.

    BúsquedaApache-2.0

Secretos e identidad

2
  • Ory Hydrabloqueada

    Proveedor de OAuth 2.0 y OpenID Connect respaldado por una base de datos relacional.

    Secretos e identidadApache-2.0
  • Ory Kratosbloqueada

    Servidor de identidad y gestión de usuarios para inicio de sesión, registro y MFA.

    Secretos e identidadApache-2.0

Seguridad y cadena de suministro

1
  • Grypebloqueada

    Escáner de vulnerabilidades para imágenes de contenedor y SBOMs.

    Seguridad y cadena de suministroApache-2.0

Flujo de trabajo y datos

1
  • n8nbloqueada

    Automatización de flujos de trabajo fair-code con IA nativa. De código disponible, no OSI.

    Flujo de trabajo y datosSustainable Use License

En la hoja de ruta

221

Candidatos, no compromisos. próximo = las apuestas más sólidas a corto plazo; luego siguen planificado y explorando. Los elementos marcados como precaución son de código disponible (no OSI) y solo se publicarían con una nota de licencia visible y la alternativa limpia señalada. (Las apps que compilan pero aún no llegan a 0 CVE corregibles están en Retenidas, arriba.) Cada tarjeta también muestra cómo se publicará: imagen + chart para un servicio desplegable, osolo imagen para una utilidad base/CLI/sidecar (como busybox).

Secretos e identidad

12
  • Dependency-Trackplanificado

    Plataforma de análisis de SBOM y de vulnerabilidades de componentes respaldada por una base de datos relacional.

    imagen + chartApache-2.0
  • EJBCAplanificado

    Autoridad certificadora de PKI empresarial (Community Edition) respaldada por una base de datos relacional.

    imagen + chartLGPL-2.1-or-later
  • OPA Gatekeeperplanificado

    OPA policy admission controller for Kubernetes.

    imagen + chartApache-2.0
  • OpenLDAPplanificado

    Servidor de directorio LDAP para autenticación centralizada y datos de usuario.

    imagen + chartOLDAP-2.8
  • Pinnipedplanificado

    Autenticación para clústeres de Kubernetes que federa proveedores de identidad externos.

    imagen + chartApache-2.0
  • Sealed Secretsplanificado

    Cifra los Secrets de Kubernetes para que puedan almacenarse de forma segura en Git.

    imagen + chartApache-2.0
  • Secrets Store CSI Driverplanificado

    CSI driver that mounts secrets from external stores (Vault, cloud KMS) as volumes.

    imagen + chartApache-2.0
  • SPIREplanificado

    Runtime de SPIFFE para emitir identidades de carga de trabajo en toda una flota.

    imagen + chartApache-2.0
  • Teleportplanificado

    Plano de acceso que proporciona acceso basado en identidad a SSH, Kubernetes y bases de datos. La edición community es AGPL-3.0.

    imagen + chartAGPL-3.0-onlyagpl
  • Vaultplanificado

    HashiCorp Vault. De código disponible, no OSI.

    alt. limpia: OpenBao (MPL-2.0) — the open fork, already shipped.

    imagen + chartBUSL-1.1precaución
  • Polaris (Fairwinds)explorando

    Kubernetes configuration best-practice validation.

    imagen + chartApache-2.0
  • SATOSAexplorando

    Proxy that translates between SAML and OIDC.

    imagen + chartApache-2.0

Puertas de enlace y proxies

14
  • Apache APISIXplanificado

    Pasarela de API dinámica sobre Nginx + LuaJIT: recarga plugins y configuración en caliente desde etcd, sin dependencia de una base de datos relacional. Una alternativa de alto rendimiento a Kong.

    imagen + chartApache-2.0
  • Contourplanificado

    Controlador de ingress de Kubernetes basado en Envoy.

    imagen + chartApache-2.0
  • Envoy Gatewayplanificado

    Implementación CNCF de la Gateway API de Kubernetes sobre Envoy: recursos estándar de K8s en lugar de CRDs propios del proveedor. La alternativa a Kong centrada en Kubernetes.

    imagen + chartApache-2.0
  • Gloo Edgeplanificado

    Pasarela basada en Envoy para microservicios, monolitos y serverless, con sólido soporte multiprotocolo: HTTP, gRPC, WebSockets y FaaS.

    imagen + chartApache-2.0
  • Jettyplanificado

    Lightweight Eclipse Jetty servlet server.

    imagen + chartApache-2.0
  • Kong Gatewayplanificado

    Pasarela de API sobre nginx/OpenResty. Open-core (la pasarela OSS es Apache-2.0; muchas funciones están restringidas al nivel empresarial) y depende de PostgreSQL. APISIX y Tyk son alternativas más ligeras y totalmente abiertas.

    imagen + chartApache-2.0
  • KrakenDplanificado

    Stateless high-performance API gateway.

    imagen + chartApache-2.0
  • NGINX Unitplanificado

    Polyglot application server from the nginx team.

    imagen + chartApache-2.0
  • OpenRestyplanificado

    nginx + LuaJIT platform for scriptable web apps and gateways.

    imagen + chartBSD-2-Clause
  • Squidplanificado

    Proxy HTTP de caché y reenvío.

    imagen + chartGPL-2.0-or-lateragpl
  • Varnishplanificado

    Proxy inverso de caché HTTP y acelerador web.

    imagen + chartBSD-2-Clause
  • WildFlyplanificado

    JBoss Jakarta EE application server.

    imagen + chartLGPL-2.1
  • Apache TomEEexplorando

    Tomcat plus the Jakarta EE stack.

    imagen + chartApache-2.0
  • Emissary-ingressexplorando

    Envoy-based Kubernetes API gateway / ingress.

    imagen + chartApache-2.0

Puerta de enlace de IA

2
  • Bifrostplanificado

    Pasarela de IA de alto rendimiento en Go: acceso unificado, balanceo de carga y conmutación por error entre más de 20 proveedores de LLM con una sobrecarga casi nula. Una alternativa abierta a los plugins de pasarela de IA añadidos.

    imagen + chartApache-2.0
  • LiteLLMplanificado

    Proxy ligero en Python que expone una única API compatible con OpenAI para llamar, monitorizar y mapear costes de más de 100 proveedores de LLM.

    imagen + chartMIT

Observabilidad

15
  • Fluentdplanificado

    Capa unificada de logging para recopilar, parsear y enrutar logs.

    imagen + chartApache-2.0
  • Kibanaplanificado

    Visualización y paneles para Elasticsearch. La distribución por defecto es Elastic-2.0, no OSI.

    alt. limpia: OpenSearch Dashboards (Apache-2.0) over OpenSearch, both open.

    imagen + chartElastic-2.0precaución
  • Logstashplanificado

    Pipeline de procesamiento de logs y eventos del lado del servidor. La distribución por defecto es Elastic-2.0, no OSI.

    alt. limpia: Vector (MPL-2.0) or Fluentd (Apache-2.0), both open pipelines.

    imagen + chartElastic-2.0precaución
  • mongodb-exporterplanificado

    Prometheus exporter for MongoDB metrics.

    imagen + chartApache-2.0
  • mysqld-exporterplanificado

    Prometheus exporter for MySQL/MariaDB metrics.

    imagen + chartApache-2.0
  • Netdataplanificado

    Real-time per-second infrastructure monitoring agent.

    imagen + chartGPL-3.0agpl
  • OpenCostplanificado

    Kubernetes cost monitoring and allocation (CNCF).

    imagen + chartApache-2.0
  • OpenTelemetry Operatorplanificado

    Operator that manages OpenTelemetry Collector instances and auto-instrumentation.

    imagen + chartApache-2.0
  • Percona PMMplanificado

    Percona Monitoring and Management — deep MySQL/PostgreSQL/MongoDB observability (query analytics) built on Prometheus, Grafana and VictoriaMetrics. AGPL, OSI-approved.

    imagen + chartAGPL-3.0
  • Promtailplanificado

    Loki's agent for shipping pod and file logs.

    imagen + chartApache-2.0
  • Uptime Kumaplanificado

    Self-hosted uptime and status-page monitor.

    imagen + chartMIT
  • Zabbixplanificado

    Plataforma de monitorización de infraestructura y red; la versión 7 y posteriores son AGPL-3.0.

    imagen + chartAGPL-3.0-onlyagpl
  • Zipkinplanificado

    Sistema de trazabilidad distribuida para recopilar y consultar datos de tiempos.

    imagen + chartApache-2.0
  • Cortexexplorando

    Horizontally scalable, multi-tenant Prometheus storage.

    imagen + chartApache-2.0
  • kafka-exporterexplorando

    Prometheus exporter for Kafka lag and topic metrics.

    imagen + chartApache-2.0

Búsqueda y vectores

1
  • Milvusplanificado

    Base de datos vectorial escalable para cargas de trabajo de IA.

    imagen + chartApache-2.0

Flujo de trabajo y datos

17
  • Ansibleplanificado

    Agentless IT automation and configuration management.

    imagen + chartGPL-3.0agpl
  • Apache Druidplanificado

    Base de datos de analítica en tiempo real para consultas OLAP de alta concurrencia.

    imagen + chartApache-2.0
  • Apache Flinkplanificado

    Procesamiento de flujos con estado.

    imagen + chartApache-2.0
  • Apache NiFiplanificado

    Automatización visual de flujos de datos para enrutar, transformar y mediar datos.

    imagen + chartApache-2.0
  • Apache Pinotplanificado

    Almacén de datos OLAP distribuido en tiempo real para analítica de baja latencia.

    imagen + chartApache-2.0
  • Apache Sparkplanificado

    Motor unificado de analítica por lotes y en streaming.

    imagen + chartApache-2.0
  • Camundaplanificado

    Automatización de procesos y orquestación BPMN, incluido el motor Zeebe.

    imagen + chartApache-2.0
  • Dagsterplanificado

    Orquestador de datos para pipelines de ML y analítica.

    imagen + chartApache-2.0
  • Prefectplanificado

    Servidor de orquestación de flujos de trabajo nativo de Python para pipelines de datos.

    imagen + chartApache-2.0
  • Trinoplanificado

    Motor de consultas SQL distribuido para analítica federada entre fuentes de datos.

    imagen + chartApache-2.0
  • Unleashplanificado

    Servidor de gestión de feature flags y toggles respaldado por PostgreSQL.

    imagen + chartApache-2.0
  • WireMockplanificado

    HTTP API mock server for testing.

    imagen + chartApache-2.0
  • Apache Camel Kexplorando

    Kubernetes-native integration framework.

    imagen + chartApache-2.0
  • Apache Polarisexplorando

    Open REST catalog for Apache Iceberg tables.

    imagen + chartApache-2.0
  • Apache Tikaexplorando

    Content and metadata extraction toolkit.

    imagen + chartApache-2.0
  • Cubeexplorando

    Semantic layer and analytics API over your data.

    imagen + chartApache-2.0
  • Hyperledger Fabricexplorando

    Permissioned enterprise blockchain platform.

    imagen + chartApache-2.0

Mensajería y streaming

7
  • AKHQplanificado

    Web UI to manage and browse Kafka — the console the messaging-stack needs.

    imagen + chartApache-2.0
  • Apache ActiveMQplanificado

    Broker de mensajes JMS en Java, incluido el motor de nueva generación Artemis.

    imagen + chartApache-2.0
  • Apicurio Registryplanificado

    API and schema registry for Kafka, Avro, and Protobuf.

    imagen + chartApache-2.0
  • Karapaceplanificado

    Registro de esquemas y proxy REST abierto para Kafka; una alternativa con licencia Apache al schema-registry de Confluent Community.

    imagen + chartApache-2.0
  • Redpandaplanificado

    Streaming compatible con Kafka. De código disponible, no OSI.

    alt. limpia: Kafka or Pulsar (Apache-2.0), both already shipped.

    imagen + chartBSL-1.1precaución
  • Strimziplanificado

    Kubernetes operator for running and managing Kafka.

    imagen + chartApache-2.0
  • Apache Stormexplorando

    Distributed real-time stream processing.

    imagen + chartApache-2.0

Coordinación y malla

13
  • Calicoplanificado

    eBPF/iptables CNI for networking and network policy.

    imagen + chartApache-2.0
  • Ciliumplanificado

    Redes, seguridad y observabilidad basadas en eBPF para Kubernetes.

    imagen + chartApache-2.0
  • Consulplanificado

    Descubrimiento de servicios y malla. De código disponible, no OSI.

    alt. limpia: etcd (Apache-2.0) for KV/coordination, already shipped.

    imagen + chartBUSL-1.1precaución
  • Istioplanificado

    Malla de servicios construida sobre Envoy: gestión de tráfico, mTLS y observabilidad. A escala de plataforma, una oleada de varias imágenes (plano de control istiod más sidecars y pasarelas de Envoy) en lugar de una sola imagen.

    imagen + chartApache-2.0
  • Linkerdplanificado

    Malla de servicios ligera.

    imagen + chartApache-2.0
  • MetalLBplanificado

    Implementación de balanceador de carga para clústeres de Kubernetes en bare-metal.

    imagen + chartApache-2.0
  • Nomadplanificado

    Planificador de cargas de trabajo. De código disponible, no OSI.

    imagen + chartBUSL-1.1precaución
  • PowerDNSplanificado

    Servidor DNS autoritativo y recursor con backends de base de datos.

    imagen + chartGPL-2.0-onlyagpl
  • Unboundplanificado

    Resolutor DNS validador, recursivo y con caché.

    imagen + chartBSD-3-Clause
  • BIND 9explorando

    Authoritative and recursive DNS server.

    imagen + chartMPL-2.0
  • FRRoutingexplorando

    Internet routing protocol suite (BGP, OSPF, etc.).

    imagen + chartGPL-2.0
  • kube-vipexplorando

    Virtual IP and load balancer for the control plane and services.

    imagen + chartApache-2.0
  • Tailscaleexplorando

    WireGuard-based mesh VPN with a Kubernetes operator.

    imagen + chartBSD-3-Clause

Bases de datos y motores

23
  • Apache Kvrocksplanificado

    Base de datos clave-valor con protocolo de Redis persistida sobre RocksDB.

    imagen + chartApache-2.0
  • Apache Nessieplanificado

    Catálogo transaccional y versionado para tablas de data lakehouse.

    imagen + chartApache-2.0
  • ArangoDBplanificado

    Base de datos multimodelo para documentos, grafos y clave-valor (Community Edition).

    imagen + chartApache-2.0
  • CloudNativePGplanificado

    Kubernetes operator for PostgreSQL HA: streaming replication, automated failover, and backups/PITR to object storage, all via CRDs. CNCF project; the modern operator behind the pg-ha-stack.

    imagen + chartApache-2.0
  • CrateDBplanificado

    Distributed SQL database for time-series and search.

    imagen + chartApache-2.0
  • Flywayplanificado

    Versioned SQL database migrations.

    imagen + chartApache-2.0
  • Hasura GraphQL Engineplanificado

    API GraphQL instantánea sobre PostgreSQL y otras bases de datos.

    imagen + chartApache-2.0
  • JanusGraphplanificado

    Base de datos de grafos distribuida sobre backends de almacenamiento intercambiables.

    imagen + chartApache-2.0
  • KeyDBplanificado

    Fork multihilo de Redis; con licencia BSD y compatible con el protocolo de Redis.

    imagen + chartBSD-3-Clause
  • Liquibaseplanificado

    Database schema change and migration management.

    imagen + chartApache-2.0
  • MariaDB Operatorplanificado

    Kubernetes operator for MariaDB/MySQL: provisioning, Galera multi-primary HA, replication, backups, and user/grant management via CRDs.

    imagen + chartMIT
  • MongoDB Community Operatorplanificado

    MongoDB Community Kubernetes Operator: replica-set HA, automated failover, and TLS via CRDs. The operator is Apache-2.0; note the MongoDB server it deploys is SSPL (not OSI).

    imagen + chartApache-2.0
  • Percona XtraDB Cluster Operatorplanificado

    Operator for Percona XtraDB Cluster (MySQL): synchronous multi-primary HA via Galera, with automated backups and point-in-time recovery.

    imagen + chartApache-2.0
  • Pgpool-IIplanificado

    Middleware de pooling de conexiones, balanceo de carga y replicación para PostgreSQL.

    imagen + chartBSD-3-Clause
  • pgvectorplanificado

    PostgreSQL with the pgvector extension for vector similarity search.

    imagen + chartPostgreSQL
  • ProxySQLplanificado

    Proxy de alto rendimiento para MySQL/MariaDB.

    imagen + chartGPL-3.0agpl
  • RethinkDBplanificado

    Realtime document database with live queries.

    imagen + chartApache-2.0
  • SurrealDBplanificado

    Base de datos multimodelo. De código disponible, no OSI.

    imagen + chartBUSL-1.1precaución
  • Vitessplanificado

    Sharding horizontal para MySQL.

    imagen + chartApache-2.0
  • Aerospikeexplorando

    Real-time key-value database; community edition is AGPL.

    imagen + chartAGPL-3.0agpl
  • Couchbaseexplorando

    Distributed document database. Source-available, not OSI.

    alt. limpia: CouchDB (Apache-2.0), already shipped.

    imagen + chartBSL-1.1precaución
  • OrientDBexplorando

    Multi-model graph and document database.

    imagen + chartApache-2.0
  • Tiny RDMexplorando

    Modern Redis/Valkey desktop GUI (Wails/Go+Vue). A desktop client, not a deployable server, so it falls outside the hardened in-cluster image model — a web Redis UI (e.g. redis-commander) would be the cache-stack UI instead.

    imagen + chartGPL-3.0agpl

Almacenamiento y plataforma

9
  • Apache Ozoneplanificado

    Almacén de objetos distribuido escalable (S3 + HDFS).

    imagen + chartApache-2.0
  • Dokployplanificado

    PaaS autoalojable sobre Docker Swarm. Open-core: la mayor parte es Apache-2.0, las partes /proprietary son de código disponible (DSAL-1.0). No encaja en el catálogo endurecido: requiere root, el socket de Docker y un Swarm inicializado, por lo que no puede ejecutarse como nonroot ni en modo de solo lectura.

    alt. limpia: Coolify (Apache-2.0), already shipped.

    imagen + chartApache-2.0 + DSAL-1.0precaución
  • Kuboplanificado

    Implementación de referencia de IPFS para almacenamiento distribuido direccionado por contenido.

    imagen + chartMIT
  • Longhornplanificado

    Almacenamiento de bloques distribuido para Kubernetes con snapshots y copias de seguridad.

    imagen + chartApache-2.0
  • MinIOplanificado

    S3-compatible object storage; relicensed to AGPL-3.0.

    alt. limpia: SeaweedFS / Garage / RustFS (Apache-2.0), all already shipped.

    imagen + chartAGPL-3.0agpl
  • SonarQubeplanificado

    Inspección continua de calidad y seguridad del código.

    imagen + chartLGPL-3.0
  • Woodpecker CIplanificado

    Motor de CI sencillo y nativo de contenedores.

    imagen + chartApache-2.0
  • Rookexplorando

    Ceph storage orchestrator for Kubernetes (block/object/file).

    imagen + chartApache-2.0
  • Versity Gatewayexplorando

    S3-compatible gateway fronting any storage backend.

    imagen + chartApache-2.0

Aplicaciones y productividad

24
  • Appsmithplanificado

    Constructor low-code de herramientas internas y paneles de administración respaldado por PostgreSQL y Redis.

    imagen + chartApache-2.0
  • Discourseplanificado

    Plataforma de debate y foros en Ruby respaldada por PostgreSQL y Redis.

    imagen + chartGPL-2.0-or-lateragpl
  • Gotenbergplanificado

    API sin estado de conversión de HTML y Office a PDF.

    imagen + chartMIT
  • Gristplanificado

    Self-hosted spreadsheet-database hybrid, an Airtable alternative.

    imagen + chartApache-2.0
  • Homepageplanificado

    Panel autoalojado de servicios y marcadores con integraciones de widgets.

    imagen + chartGPL-3.0-onlyagpl
  • Joomlaplanificado

    CMS en PHP respaldado por MySQL o MariaDB.

    imagen + chartGPL-2.0-or-lateragpl
  • Mastodonplanificado

    Servidor de red social federada (Ruby más Node) respaldado por PostgreSQL y Redis.

    imagen + chartAGPL-3.0-onlyagpl
  • MediaWikiplanificado

    The wiki engine behind Wikipedia, backed by MySQL or MariaDB.

    imagen + chartGPL-2.0-or-later
  • Metabaseplanificado

    Friendly self-service BI and analytics dashboards.

    imagen + chartAGPL-3.0agpl
  • Moodleplanificado

    Sistema de gestión del aprendizaje en PHP respaldado por MySQL, MariaDB o PostgreSQL.

    imagen + chartGPL-3.0-or-lateragpl
  • Odooplanificado

    Suite de ERP y aplicaciones de negocio en Python (Community Edition) respaldada por PostgreSQL.

    imagen + chartLGPL-3.0-only
  • pgAdminplanificado

    Interfaz web de administración y gestión para PostgreSQL.

    imagen + chartPostgreSQL
  • phpMyAdminplanificado

    Interfaz web de administración en PHP para MySQL y MariaDB.

    imagen + chartGPL-2.0-onlyagpl
  • Redmineplanificado

    Gestión de proyectos y seguimiento de incidencias en Ruby on Rails respaldado por una base de datos relacional.

    imagen + chartGPL-2.0-or-lateragpl
  • Rocket.Chatplanificado

    Self-hosted team chat platform backed by MongoDB.

    imagen + chartMIT
  • SuiteCRMplanificado

    Aplicación de gestión de relaciones con clientes en PHP respaldada por MySQL o MariaDB.

    imagen + chartAGPL-3.0-onlyagpl
  • Backdrop CMSexplorando

    Drupal fork focused on simplicity, backed by MySQL.

    imagen + chartGPL-2.0-or-later
  • Chromiumexplorando

    Headless browser for rendering, scraping, and PDF export.

    imagen + chartBSD-3-Clause
  • Friendicaexplorando

    Federated social network server.

    imagen + chartAGPL-3.0agpl
  • Mongo Expressexplorando

    Web administration UI for MongoDB.

    imagen + chartMIT
  • Ploneexplorando

    Python enterprise CMS on Zope.

    imagen + chartGPL-2.0-or-later
  • Selenium Gridexplorando

    Distributed browser automation and testing grid.

    imagen + chartApache-2.0
  • XWikiexplorando

    Enterprise wiki and structured collaboration platform.

    imagen + chartLGPL-2.1
  • YOURLSexplorando

    Self-hosted URL shortener.

    imagen + chartMIT

Medios y streaming

2
  • Apache Guacamoleplanificado

    Pasarela de escritorio remoto sin cliente para RDP, VNC y SSH a través del navegador.

    imagen + chartApache-2.0
  • Jellyfinplanificado

    Servidor multimedia autoalojado para películas, música y TV en directo.

    imagen + chartGPL-2.0-onlyagpl

CI/CD y registro

21
  • Argo CDplanificado

    Entrega continua declarativa GitOps para Kubernetes.

    imagen + chartApache-2.0
  • Argo Eventsplanificado

    Event-driven workflow automation for Kubernetes.

    imagen + chartApache-2.0
  • Argo Rolloutsplanificado

    Progressive delivery (canary, blue-green) for Kubernetes.

    imagen + chartApache-2.0
  • Concourseplanificado

    Sistema de integración continua basado en pipelines respaldado por PostgreSQL.

    imagen + chartApache-2.0
  • Crossplaneplanificado

    Framework de plano de control para gestionar infraestructura en la nube mediante APIs de Kubernetes.

    imagen + chartApache-2.0
  • Daprplanificado

    Runtime de aplicaciones distribuidas que proporciona APIs de bloques de construcción para microservicios.

    imagen + chartApache-2.0
  • Fluxplanificado

    Conjunto de herramientas GitOps de controladores para entrega continua en Kubernetes.

    imagen + chartApache-2.0
  • GitHub Actions Runnerplanificado

    Self-hosted Actions runner — the runner the gitops-stack needs for a Gitea/Forgejo backend.

    imagen + chartMIT
  • GitLab Runnerplanificado

    CI job executor for GitLab pipelines; also a gitops-stack runner option.

    imagen + chartMIT
  • Gogsplanificado

    The original minimal Go Git service that Gitea forked from. Very small single-binary forge; an even lighter gitops-stack backend option.

    imagen + chartMIT
  • Jenkins Inbound Agentplanificado

    Jenkins JNLP inbound build agent. Image only, no chart. Build held: jenkins-docker-agent carries a CRITICAL jetty CVE (fix 2.560-r0 not yet in Wolfi).

    imagen + chartMIT
  • Terralistplanificado

    Private Terraform/OpenTofu registry for modules and providers (Go). Hardenable as a normal nonroot server image; unlocks the gitops-stack and registry-stack.

    imagen + chartMPL-2.0
  • vclusterplanificado

    Virtual Kubernetes clusters inside a namespace.

    imagen + chartApache-2.0
  • Cluster Autoscalerexplorando

    Scales Kubernetes node pools to match pending workloads.

    imagen + chartApache-2.0
  • GitLab CEexplorando

    Full DevOps platform (Git forge + CI/CD + registry). Heavy fit: a large Ruby monolith that bundles PostgreSQL, Redis, Gitaly, Sidekiq and Workhorse, and the gitlab-org/gitlab repo is mostly EE-proprietary — only the CE-flagged code is MIT. Far from the minimal one-purpose hardened model.

    alt. limpia: Gitea or Forgejo — lightweight, fully-open Git forges that drop straight into the gitops-stack.

    imagen + chartMITprecaución
  • KubeVirtexplorando

    Run virtual machines as Kubernetes workloads.

    imagen + chartApache-2.0
  • kuredexplorando

    Safe automated node reboots for Kubernetes.

    imagen + chartApache-2.0
  • OneDevexplorando

    Self-hosted Git server with built-in CI/CD, issues and kanban (Java). Heavier than Gitea/Gogs but far lighter than GitLab; an all-in-one gitops-stack backend option.

    imagen + chartMIT
  • Reloaderexplorando

    Rolls workloads when their ConfigMaps or Secrets change.

    imagen + chartApache-2.0
  • Terragruntexplorando

    Thin Terraform/OpenTofu wrapper for DRY configurations.

    imagen + chartMIT
  • Vertical Pod Autoscalerexplorando

    Recommends and applies pod CPU/memory requests.

    imagen + chartApache-2.0

Aprendizaje automático

11
  • JupyterHubplanificado

    Servidor de notebooks Jupyter multiusuario para equipos y aulas.

    imagen + chartBSD-3-Clause
  • KServeplanificado

    Kubernetes model inference serving with autoscaling.

    imagen + chartApache-2.0
  • KubeRayplanificado

    Operador para ejecutar clústeres de cómputo distribuido Ray en Kubernetes.

    imagen + chartApache-2.0
  • Label Studioplanificado

    Herramienta de etiquetado y anotación de datos para conjuntos de datos de ML.

    imagen + chartApache-2.0
  • Langflowplanificado

    Constructor visual de aplicaciones de LLM y flujos de trabajo de agentes.

    imagen + chartMIT
  • Langfuseplanificado

    Plataforma de observabilidad y trazabilidad de LLM respaldada por PostgreSQL.

    imagen + chartMIT
  • Open WebUIplanificado

    Interfaz web autoalojada para chatear con LLM locales y remotos.

    imagen + chartBSD-3-Clause
  • AnythingLLMexplorando

    Self-hosted chat-with-your-documents LLM application.

    imagen + chartMIT
  • DataHubexplorando

    Metadata platform and data catalog.

    imagen + chartApache-2.0
  • Kubeflow Pipelinesexplorando

    ML pipeline orchestration on Kubernetes.

    imagen + chartApache-2.0
  • TensorFlow Servingexplorando

    High-performance serving system for TensorFlow models.

    imagen + chartApache-2.0

Seguridad y cadena de suministro

26
  • Buildahplanificado

    Daemonless OCI image builder.

    imagen + chartApache-2.0
  • BuildKitplanificado

    Concurrent container image build engine.

    imagen + chartApache-2.0
  • Checkovplanificado

    Static security scanning for Terraform, Kubernetes, and more.

    imagen + chartApache-2.0
  • ClamAVplanificado

    Motor antivirus de código abierto para escanear archivos y correo.

    imagen + chartGPL-2.0-onlyagpl
  • Craneplanificado

    go-containerregistry CLI for registry interaction.

    imagen + chartApache-2.0
  • Daggerplanificado

    Programmable CI/CD engine that runs pipelines in containers.

    imagen + chartApache-2.0
  • Falcoplanificado

    Seguridad en tiempo de ejecución y detección de amenazas usando eventos del kernel y eBPF.

    imagen + chartApache-2.0
  • Gitleaksplanificado

    Secret scanner for git repos and files.

    imagen + chartMIT
  • Hadolintplanificado

    Dockerfile linter.

    imagen + chartGPL-3.0agpl
  • Kanikoplanificado

    Build container images inside Kubernetes without a daemon.

    imagen + chartApache-2.0
  • Kubescapeplanificado

    Kubernetes security, posture, and compliance scanner.

    imagen + chartApache-2.0
  • Kubescape Operatorplanificado

    In-cluster Kubescape components (operator, scanner, kubevuln) for continuous posture and vulnerability scanning. Distinct from the Kubescape CLI.

    imagen + chartApache-2.0
  • Notationplanificado

    Notary v2 OCI artifact signing and verification.

    imagen + chartApache-2.0
  • ORASplanificado

    Push and pull arbitrary artifacts to OCI registries.

    imagen + chartApache-2.0
  • Podmanplanificado

    Daemonless container engine and Docker CLI replacement.

    imagen + chartApache-2.0
  • ShellCheckplanificado

    Shell script static analysis linter.

    imagen + chartGPL-3.0agpl
  • Sigstoreplanificado

    Infraestructura de firma sin claves que incluye la CA Fulcio y el registro de transparencia Rekor.

    imagen + chartApache-2.0
  • Skopeoplanificado

    Inspect and copy container images between registries.

    imagen + chartApache-2.0
  • Tetragonplanificado

    Observabilidad y aplicación de seguridad en tiempo de ejecución basada en eBPF.

    imagen + chartApache-2.0
  • Trivy Operatorplanificado

    In-cluster continuous Trivy scanning via CRDs.

    imagen + chartApache-2.0
  • Wazuhplanificado

    Plataforma SIEM y XDR con componentes de manager, indexador y panel.

    imagen + chartGPL-2.0-onlyagpl
  • Connaisseurexplorando

    Admission controller enforcing image signature verification.

    imagen + chartApache-2.0
  • Diveexplorando

    Explore container image layers and wasted space.

    imagen + chartMIT
  • koexplorando

    Build and deploy Go container images with no Dockerfile.

    imagen + chartApache-2.0
  • OpenSCAPexplorando

    SCAP compliance and vulnerability scanning.

    imagen + chartLGPL-2.1
  • TruffleHogexplorando

    Deep secret scanner across repos and filesystems.

    imagen + chartAGPL-3.0agpl

Stacks

24
  • cache-stackplanificado

    Umbrella: Valkey + redis-exporter + Grafana dashboards — cache with metrics. All components built; ready to build.

    imagen + chartApache-2.0
  • postgres-ha-stackplanificado

    Umbrella: PostgreSQL + PgBouncer + postgres-exporter — pooled SQL with metrics. All components built; ready to build.

    imagen + chartApache-2.0
  • secrets-stackplanificado

    Umbrella: OpenBao + Keycloak — SSO in front of secrets management. All components built; ready to build.

    imagen + chartApache-2.0
  • ai-stackexplorando

    Ollama (or vLLM) + Open WebUI + Qdrant — self-hosted LLM serving, a chat UI, and a vector DB for retrieval-augmented generation. Qdrant is built; needs Ollama/vLLM + Open WebUI images.

    imagen + chartApache-2.0
  • analytics-stackexplorando

    Apache Superset + Trino + PostgreSQL — federated SQL analytics with self-service BI dashboards. PostgreSQL is built; needs Superset + Trino.

    imagen + chartApache-2.0
  • backup-stackexplorando

    Velero + MinIO — scheduled cluster backup/restore and PV snapshots to an in-cluster S3 target. Needs Velero + MinIO images.

    alt. limpia: Use any external S3 (SeaweedFS/Garage, already shipped) instead of MinIO to keep it fully Apache-2.0.

    imagen + chartApache-2.0
  • cost-stackexplorando

    OpenCost + Prometheus + Grafana — Kubernetes cost monitoring and allocation dashboards; an add-on to the observability stack. Prometheus + Grafana are built; needs OpenCost.

    imagen + chartApache-2.0
  • gitops-stackexplorando

    Umbrella: a pluggable Git backend + Atlantis + Terralist for Terraform/OpenTofu GitOps with a private module/provider registry. Pick your forge: Gitea (default, built) or Forgejo / Gogs (lightweight, clean) / OneDev (all-in-one) / GitLab CE (heavy, mixed license). Atlantis + Gitea charts built; needs a Terralist image, the chosen forge's image, and a runner — GitHub Actions Runner or GitLab Runner, both now on the roadmap (or run runner-less).

    imagen + chartApache-2.0
  • ingress-stackexplorando

    Traefik (or ingress-nginx) + cert-manager + external-dns — production ingress with automatic TLS and DNS records. Traefik + external-dns are built; needs cert-manager.

    imagen + chartApache-2.0
  • lakehouse-stackexplorando

    Trino + Apache Nessie (or Polaris) + MinIO — an Iceberg data lakehouse: query engine, versioned table catalog, and object store. Needs those images.

    imagen + chartApache-2.0
  • messaging-stackexplorando

    Umbrella: Kafka + ZooKeeper (or NATS) + a console UI — event backbone. Needs a Kafka UI image first — AKHQ (Apache-2.0) is now on the roadmap for exactly this.

    imagen + chartApache-2.0
  • mongodb-ha-stackexplorando

    Operator-based HA MongoDB: MongoDB Community Operator + a metrics exporter — replica-set failover. CRD-driven. The operator is Apache-2.0, but MongoDB itself is SSPL (not OSI), so the stack inherits that caution.

    alt. limpia: FerretDB (Apache-2.0) on the pg-ha-stack — a MongoDB-compatible, fully-open document database over PostgreSQL.

    imagen + chartSSPL-1.0precaución
  • mysql-ha-stackexplorando

    Operator-based HA MySQL: a MySQL operator (Percona XtraDB Cluster, or MariaDB Operator with Galera) + a metrics exporter — synchronous multi-primary replication and backups. CRD-driven. Needs the chosen operator image first.

    imagen + chartApache-2.0
  • orchestration-stackexplorando

    Apache Airflow + PostgreSQL + Valkey — data-pipeline scheduling (Airflow needs a metadata DB and a broker). PostgreSQL + Valkey are built; needs Airflow.

    imagen + chartApache-2.0
  • pg-ha-stackexplorando

    Operator-based HA PostgreSQL: CloudNativePG + PgBouncer + postgres-exporter — streaming replication, automated failover, and backups/PITR to object storage. NOTE: unlike the operator-free observability stacks, this is CRD-driven (it installs the CloudNativePG operator). Needs a CloudNativePG image first.

    imagen + chartApache-2.0
  • pki-stackexplorando

    step-ca + cert-manager + trust-manager — an internal certificate authority with automated issuance and cluster-wide trust-bundle distribution. Needs those images.

    imagen + chartApache-2.0
  • policy-stackexplorando

    Kyverno + Policy Reporter + Polaris (Fairwinds) — Kubernetes policy enforcement, violation reporting, and configuration best-practice validation. Operator-light (admission webhooks). Needs those images.

    imagen + chartApache-2.0
  • profiling-stackexplorando

    Grafana Pyroscope + Grafana — continuous CPU/memory profiling; the missing 'P' that completes LGTM(P) alongside the observability/logging/tracing stacks. Needs a Pyroscope image.

    imagen + chartApache-2.0
  • registry-stackexplorando

    Umbrella: Harbor (container images + OCI Helm charts + Trivy scanning) + Terralist (Terraform/OpenTofu modules & providers) — one self-hosted artifact registry for every kind of artifact. Harbor chart built; needs a Terralist image+chart.

    imagen + chartApache-2.0
  • runtime-security-stackexplorando

    Falco + Tetragon — eBPF-based runtime threat detection and enforcement. Privileged host/kernel access by design (like node-exporter). Needs those images.

    imagen + chartApache-2.0
  • search-stackexplorando

    Umbrella: OpenSearch + OpenSearch Dashboards — search with a UI. Needs an opensearch-dashboards image first.

    imagen + chartApache-2.0
  • streaming-stackexplorando

    Kafka + Apache Flink + Apicurio Registry — end-to-end stream processing with schema governance. Kafka is built; needs Flink + Apicurio.

    imagen + chartApache-2.0
  • supply-chain-stackexplorando

    Trivy Operator + Kubescape + Dependency-Track — continuous image, cluster-posture, and SBOM vulnerability scanning in one place. Needs those images.

    imagen + chartApache-2.0
  • temporal-stackexplorando

    Umbrella: Temporal + Elasticsearch for advanced visibility. Marginal — the Temporal chart already bundles its own PostgreSQL, so a stack only adds optional ES visibility search.

    imagen + chartApache-2.0
bloqueada

Por qué se retienen algunas apps

QuenchWorks no publica nada que tenga un CVE corregible. Algunas apps compilan limpias pero aún no llegan a ese nivel: la propia app fija una dependencia por debajo de la versión que corrige un CVE conocido, así que parchearla rompería sus propias restricciones declaradas. Se marcan como bloqueadas: compiladas y probadas, retenidas (sin publicar) hasta que el upstream relaje la fijación o retroporte la corrección. Se publican en cuanto eso ocurre. Nada que ya esté en el catálogo tiene un CVE corregible conocido.

¿Quieres priorizar algo? Solicita una app y la ubicaremos en la hoja de ruta.

bloqueada

Probada y retenida: no alcanza 0 CVE corregibles