Hoja de ruta
Qué está publicado, qué sigue
195 bases de datos y herramientas están endurecidas y publicadas hoy. Debajo está lo que viene, primero las opciones limpias OSI. Cada entrada se compila desde el código fuente sobre Wolfi, se escanea hasta cero CVE corregibles, se firma y se fija por digest antes de pasar a disponible.
- 19543%
- Publicado
- 22149%
- En la hoja de ruta
- 358%
- Bloqueadas
Disponible ahora
195
Analítico
1
Aplicaciones y productividad
13
→
adminerAplicaciones y productividadstandard→
drupalAplicaciones y productividadstandard→
excalidrawAplicaciones y productividadstandard→
filebrowserAplicaciones y productividadstandard→
flociAplicaciones y productividadstandard→
floci-fullAplicaciones y productividadstandard→
ghostAplicaciones y productividadstandard→
mailpitAplicaciones y productividadstandard→
minifluxAplicaciones y productividadstandard→
nextcloudAplicaciones y productividadstandard→
pocketbaseAplicaciones y productividadstandard→
vikunjaAplicaciones y productividadstandard→
wordpressAplicaciones y productividadstandard
Imagen base
1
Herramienta de compilación
7
CI/CD y registro
12
→
ansibleCI/CD y registrostandard→
buildkite-agentCI/CD y registrostandard→
chartmuseumCI/CD y registrostandard→
jenkinsCI/CD y registrostandard→
jenkins-inbound-agentCI/CD y registrostandard→
kubectlCI/CD y registrostandard→
opentofuCI/CD y registrostandard→
pulumiCI/CD y registrostandard→
renovateCI/CD y registrostandard→
sonar-scanner-cliCI/CD y registrostandard→
tektonCI/CD y registrostandard→
woodpeckerCI/CD y registrostandard
Caché
5
Coordinación
5
Coordinación y malla
3
Database
1
Bases de datos y motores
2
Developer tools / IDE
1
Documental
5
Puerta de enlace
9
Grafos
1
Identidad
6
Entorno de ejecución de lenguaje
13
→
bunEntorno de ejecución de lenguajestandard→
denoEntorno de ejecución de lenguajestandard→
dotnetEntorno de ejecución de lenguajestandard→
elixirEntorno de ejecución de lenguajestandard→
erlangEntorno de ejecución de lenguajestandard→
goEntorno de ejecución de lenguajestandard→
jdkEntorno de ejecución de lenguajestandard→
nodeEntorno de ejecución de lenguajestandard→
perlEntorno de ejecución de lenguajestandard→
phpEntorno de ejecución de lenguajestandard→
pythonEntorno de ejecución de lenguajestandard→
rubyEntorno de ejecución de lenguajestandard→
rustEntorno de ejecución de lenguajestandard
Machine learning & AI
3
Medios y streaming
3
Mensajería
11
Métricas/Exportador
4
Almacenamiento de objetos
3
Observabilidad
18
→
AlertmanagerObservabilidadstandard→
cadvisorObservabilidadstandard→
corootObservabilidadstandard→
Fluent BitObservabilidadstandard→
graylogObservabilidadstandard→
jaegerObservabilidadstandard→
jmeterObservabilidadstandard→
k6Observabilidadstandard→
kube-state-metricsObservabilidadstandard→
LokiObservabilidadstandard→
mimirObservabilidadstandard→
OpenTelemetry CollectorObservabilidadstandard→
persesObservabilidadstandard→
PrometheusObservabilidadstandard→
pyroscopeObservabilidadstandard→
TempoObservabilidadstandard→
VectorObservabilidadstandard→
victorialogsObservabilidadstandard
Registro
9
Relacional
7
Base de ejecución
4
Búsqueda
6
Búsqueda y vectores
1
Secretos e identidad
2
Seguridad y cadena de suministro
13
→
cert-manager-acmesolverSeguridad y cadena de suministrostandard→
cert-manager-cainjectorSeguridad y cadena de suministrostandard→
cert-manager-controllerSeguridad y cadena de suministrostandard→
cert-manager-webhookSeguridad y cadena de suministrostandard→
cosignSeguridad y cadena de suministrostandard→
external-secretsSeguridad y cadena de suministrostandard→
grypeSeguridad y cadena de suministrostandard→
kyvernoSeguridad y cadena de suministrostandard→
opaSeguridad y cadena de suministrostandard→
sealed-secretsSeguridad y cadena de suministrostandard→
step-caSeguridad y cadena de suministrostandard→
syftSeguridad y cadena de suministrostandard→
trivySeguridad y cadena de suministrostandard
Almacenamiento y plataforma
3
Series temporales
4
Vectorial
1
Columna ancha
2
Retenidas — compiladas, sin publicar
35
Se compilan y prueban limpias pero aún no alcanzan 0 CVE corregibles — la app o su base fija una dependencia por debajo de la versión que corrige un CVE conocido, así que la retenemos en lugar de publicar una imagen vulnerable. Cada una se vuelve a listar automáticamente en cuanto el upstream publica la corrección. Toca ¿por qué bloqueada? para ver la fijación exacta.
Aplicaciones y productividad
6
- Apache Supersetbloqueada
Plataforma de exploración de datos y paneles de inteligencia de negocio respaldada por una base de datos de metadatos y Redis.
Aplicaciones y productividadApache-2.0 - Flocibloqueada
Emulador local de AWS autoalojado (Java), una alternativa a LocalStack Community tras su discontinuación en 2026. Los servicios en proceso (S3, DynamoDB, SQS, SNS, IAM) se ejecutan endurecidos como nonroot; los servicios respaldados por Docker (Lambda, RDS, ECS, EKS) necesitan el socket de Docker del host y root, por lo que quedan fuera del modelo endurecido.
Aplicaciones y productividadMIT - Floci (full)bloqueada
Opt-in, NON-hardened companion to the floci image: it runs as root and expects the host Docker socket mounted, which lets it emulate all 65 of Floci's AWS services including the 10 Docker-backed ones (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune).
Aplicaciones y productividadMIT - Ghostbloqueada
Plataforma de publicación y boletines en Node.js respaldada por MySQL o MariaDB.
Aplicaciones y productividadMIT - Matomobloqueada
Plataforma de analítica web respetuosa con la privacidad en PHP respaldada por MySQL o MariaDB.
Aplicaciones y productividadGPL-3.0-only - Nextcloudbloqueada
Suite autoalojada de sincronización, compartición y colaboración de archivos en PHP respaldada por PostgreSQL o MariaDB.
Aplicaciones y productividadAGPL-3.0-only
CI/CD y registro
2
- Gitnessbloqueada
Alojamiento Git autoalojado con pipelines integrados, de Harness.
CI/CD y registroApache-2.0 - Jenkinsbloqueada
Servidor de automatización extensible para integración y entrega continuas.
CI/CD y registroMIT
Coordinación
1
- Apache ZooKeeperbloqueada
Centralized coordination service for distributed systems, providing configuration, naming, leader election, and synchronization primitives.
CoordinaciónApache-2.0
Documental
1
- FerretDBbloqueada
MongoDB-compatible document database that translates the MongoDB wire protocol onto PostgreSQL via the DocumentDB extension.
DocumentalApache-2.0
Grafos
1
- Neo4jbloqueada
Graph database for highly connected data, queried with Cypher for traversals and relationship-heavy workloads.
GrafosGPL-3.0-only
Identidad
3
- Autheliabloqueada
Pasarela de autenticación y 2FA para proxies inversos.
IdentidadApache-2.0 - Keycloakbloqueada
Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.
IdentidadApache-2.0 - ZITADELbloqueada
Cloud-native identity and access management (IAM) with OIDC/OAuth2/SAML, multi-tenancy, and a built-in admin console.
IdentidadAGPL-3.0-only
Mensajería
3
- Apache Kafkabloqueada
Distributed event-streaming platform for high-throughput, durable, replayable publish-subscribe pipelines and stream processing.
MensajeríaApache-2.0 - Apache Pulsarbloqueada
Cloud-native distributed messaging and streaming platform with multi-tenancy, geo-replication, and tiered storage that separates compute from storage.
MensajeríaApache-2.0 - Mattermostbloqueada
Plataforma de chat de equipo autoalojada; el servidor Team Edition es Apache-2.0 y funciona sobre PostgreSQL.
MensajeríaAGPL-3.0-only
Observabilidad
9
- Apache JMeterbloqueada
Herramienta de pruebas de carga y rendimiento para endpoints web y de servicios.
ObservabilidadApache-2.0 - Apache SkyWalkingbloqueada
APM: trazabilidad distribuida, métricas y análisis de topología de servicios.
ObservabilidadApache-2.0 - Grafanabloqueada
Dashboards and visualization for metrics, logs, and traces across many data sources.
ObservabilidadAGPL-3.0-only - Grafana Alloybloqueada
Distribución de colector basada en OpenTelemetry para métricas, logs, trazas y perfiles.
ObservabilidadApache-2.0 - Graylogbloqueada
Gestión y análisis centralizado de logs. De código disponible, no OSI.
ObservabilidadSSPL-1.0 - metrics-serverbloqueada
Kubernetes resource-metrics API for HPA and kubectl top.
ObservabilidadApache-2.0 - OpenSearch Dashboardsbloqueada
Interfaz de visualización y paneles para OpenSearch.
ObservabilidadApache-2.0 - Telegrafbloqueada
Agente de recopilación de métricas basado en plugins del ecosistema InfluxData.
ObservabilidadMIT - Thanosbloqueada
Almacenamiento a largo plazo y consulta global para Prometheus.
ObservabilidadApache-2.0
PaaS
1
- Coolify Helperbloqueada
Coolify helper image carrying the build and deploy toolchain (buildpacks, git, ssh) that runs on target hosts to execute deployments. [blocked: upstream CVEs / ES9 unsupported]
PaaSApache-2.0 AND AGPL-3.0-or-later
Relacional
1
- CockroachDBbloqueada
Distributed SQL database with PostgreSQL wire compatibility and automatic horizontal scaling and survivability.
RelacionalBUSL-1.1
Búsqueda
3
- Apache Solrbloqueada
Enterprise search platform built on Apache Lucene, offering full-text search, faceting, and indexing over large document collections.
BúsquedaApache-2.0 - Elasticsearchbloqueada
Distributed search and analytics engine.
BúsquedaSSPL-1.0 - OpenSearchbloqueada
Search and analytics suite with a Kibana-style dashboards UI.
BúsquedaApache-2.0
Secretos e identidad
2
- Ory Hydrabloqueada
Proveedor de OAuth 2.0 y OpenID Connect respaldado por una base de datos relacional.
Secretos e identidadApache-2.0 - Ory Kratosbloqueada
Servidor de identidad y gestión de usuarios para inicio de sesión, registro y MFA.
Secretos e identidadApache-2.0
Seguridad y cadena de suministro
1
- Grypebloqueada
Escáner de vulnerabilidades para imágenes de contenedor y SBOMs.
Seguridad y cadena de suministroApache-2.0
Flujo de trabajo y datos
1
- n8nbloqueada
Automatización de flujos de trabajo fair-code con IA nativa. De código disponible, no OSI.
Flujo de trabajo y datosSustainable Use License
En la hoja de ruta
221
Candidatos, no compromisos. próximo = las apuestas más sólidas a corto plazo; luego siguen planificado y explorando. Los elementos marcados como precaución son de código disponible (no OSI) y solo se publicarían con una nota de licencia visible y la alternativa limpia señalada. (Las apps que compilan pero aún no llegan a 0 CVE corregibles están en Retenidas, arriba.) Cada tarjeta también muestra cómo se publicará: imagen + chart para un servicio desplegable, osolo imagen para una utilidad base/CLI/sidecar (como busybox).
Secretos e identidad
12
- Dependency-Trackplanificado
Plataforma de análisis de SBOM y de vulnerabilidades de componentes respaldada por una base de datos relacional.
imagen + chartApache-2.0 - EJBCAplanificado
Autoridad certificadora de PKI empresarial (Community Edition) respaldada por una base de datos relacional.
imagen + chartLGPL-2.1-or-later - OPA Gatekeeperplanificado
OPA policy admission controller for Kubernetes.
imagen + chartApache-2.0 - OpenLDAPplanificado
Servidor de directorio LDAP para autenticación centralizada y datos de usuario.
imagen + chartOLDAP-2.8 - Pinnipedplanificado
Autenticación para clústeres de Kubernetes que federa proveedores de identidad externos.
imagen + chartApache-2.0 - Sealed Secretsplanificado
Cifra los Secrets de Kubernetes para que puedan almacenarse de forma segura en Git.
imagen + chartApache-2.0 - Secrets Store CSI Driverplanificado
CSI driver that mounts secrets from external stores (Vault, cloud KMS) as volumes.
imagen + chartApache-2.0 - SPIREplanificado
Runtime de SPIFFE para emitir identidades de carga de trabajo en toda una flota.
imagen + chartApache-2.0 - Teleportplanificado
Plano de acceso que proporciona acceso basado en identidad a SSH, Kubernetes y bases de datos. La edición community es AGPL-3.0.
imagen + chartAGPL-3.0-onlyagpl - Vaultplanificado
HashiCorp Vault. De código disponible, no OSI.
alt. limpia: OpenBao (MPL-2.0) — the open fork, already shipped.
imagen + chartBUSL-1.1precaución - Polaris (Fairwinds)explorando
Kubernetes configuration best-practice validation.
imagen + chartApache-2.0 - SATOSAexplorando
Proxy that translates between SAML and OIDC.
imagen + chartApache-2.0
Puertas de enlace y proxies
14
- Apache APISIXplanificado
Pasarela de API dinámica sobre Nginx + LuaJIT: recarga plugins y configuración en caliente desde etcd, sin dependencia de una base de datos relacional. Una alternativa de alto rendimiento a Kong.
imagen + chartApache-2.0 - Contourplanificado
Controlador de ingress de Kubernetes basado en Envoy.
imagen + chartApache-2.0 - Envoy Gatewayplanificado
Implementación CNCF de la Gateway API de Kubernetes sobre Envoy: recursos estándar de K8s en lugar de CRDs propios del proveedor. La alternativa a Kong centrada en Kubernetes.
imagen + chartApache-2.0 - Gloo Edgeplanificado
Pasarela basada en Envoy para microservicios, monolitos y serverless, con sólido soporte multiprotocolo: HTTP, gRPC, WebSockets y FaaS.
imagen + chartApache-2.0 - Jettyplanificado
Lightweight Eclipse Jetty servlet server.
imagen + chartApache-2.0 - Kong Gatewayplanificado
Pasarela de API sobre nginx/OpenResty. Open-core (la pasarela OSS es Apache-2.0; muchas funciones están restringidas al nivel empresarial) y depende de PostgreSQL. APISIX y Tyk son alternativas más ligeras y totalmente abiertas.
imagen + chartApache-2.0 - KrakenDplanificado
Stateless high-performance API gateway.
imagen + chartApache-2.0 - NGINX Unitplanificado
Polyglot application server from the nginx team.
imagen + chartApache-2.0 - OpenRestyplanificado
nginx + LuaJIT platform for scriptable web apps and gateways.
imagen + chartBSD-2-Clause - Squidplanificado
Proxy HTTP de caché y reenvío.
imagen + chartGPL-2.0-or-lateragpl - Varnishplanificado
Proxy inverso de caché HTTP y acelerador web.
imagen + chartBSD-2-Clause - WildFlyplanificado
JBoss Jakarta EE application server.
imagen + chartLGPL-2.1 - Apache TomEEexplorando
Tomcat plus the Jakarta EE stack.
imagen + chartApache-2.0 - Emissary-ingressexplorando
Envoy-based Kubernetes API gateway / ingress.
imagen + chartApache-2.0
Puerta de enlace de IA
2
- Bifrostplanificado
Pasarela de IA de alto rendimiento en Go: acceso unificado, balanceo de carga y conmutación por error entre más de 20 proveedores de LLM con una sobrecarga casi nula. Una alternativa abierta a los plugins de pasarela de IA añadidos.
imagen + chartApache-2.0 - LiteLLMplanificado
Proxy ligero en Python que expone una única API compatible con OpenAI para llamar, monitorizar y mapear costes de más de 100 proveedores de LLM.
imagen + chartMIT
Observabilidad
15
- Fluentdplanificado
Capa unificada de logging para recopilar, parsear y enrutar logs.
imagen + chartApache-2.0 - Kibanaplanificado
Visualización y paneles para Elasticsearch. La distribución por defecto es Elastic-2.0, no OSI.
alt. limpia: OpenSearch Dashboards (Apache-2.0) over OpenSearch, both open.
imagen + chartElastic-2.0precaución - Logstashplanificado
Pipeline de procesamiento de logs y eventos del lado del servidor. La distribución por defecto es Elastic-2.0, no OSI.
alt. limpia: Vector (MPL-2.0) or Fluentd (Apache-2.0), both open pipelines.
imagen + chartElastic-2.0precaución - mongodb-exporterplanificado
Prometheus exporter for MongoDB metrics.
imagen + chartApache-2.0 - mysqld-exporterplanificado
Prometheus exporter for MySQL/MariaDB metrics.
imagen + chartApache-2.0 - Netdataplanificado
Real-time per-second infrastructure monitoring agent.
imagen + chartGPL-3.0agpl - OpenCostplanificado
Kubernetes cost monitoring and allocation (CNCF).
imagen + chartApache-2.0 - OpenTelemetry Operatorplanificado
Operator that manages OpenTelemetry Collector instances and auto-instrumentation.
imagen + chartApache-2.0 - Percona PMMplanificado
Percona Monitoring and Management — deep MySQL/PostgreSQL/MongoDB observability (query analytics) built on Prometheus, Grafana and VictoriaMetrics. AGPL, OSI-approved.
imagen + chartAGPL-3.0 - Promtailplanificado
Loki's agent for shipping pod and file logs.
imagen + chartApache-2.0 - Uptime Kumaplanificado
Self-hosted uptime and status-page monitor.
imagen + chartMIT - Zabbixplanificado
Plataforma de monitorización de infraestructura y red; la versión 7 y posteriores son AGPL-3.0.
imagen + chartAGPL-3.0-onlyagpl - Zipkinplanificado
Sistema de trazabilidad distribuida para recopilar y consultar datos de tiempos.
imagen + chartApache-2.0 - Cortexexplorando
Horizontally scalable, multi-tenant Prometheus storage.
imagen + chartApache-2.0 - kafka-exporterexplorando
Prometheus exporter for Kafka lag and topic metrics.
imagen + chartApache-2.0
Búsqueda y vectores
1
- Milvusplanificado
Base de datos vectorial escalable para cargas de trabajo de IA.
imagen + chartApache-2.0
Flujo de trabajo y datos
17
- Ansibleplanificado
Agentless IT automation and configuration management.
imagen + chartGPL-3.0agpl - Apache Druidplanificado
Base de datos de analítica en tiempo real para consultas OLAP de alta concurrencia.
imagen + chartApache-2.0 - Apache Flinkplanificado
Procesamiento de flujos con estado.
imagen + chartApache-2.0 - Apache NiFiplanificado
Automatización visual de flujos de datos para enrutar, transformar y mediar datos.
imagen + chartApache-2.0 - Apache Pinotplanificado
Almacén de datos OLAP distribuido en tiempo real para analítica de baja latencia.
imagen + chartApache-2.0 - Apache Sparkplanificado
Motor unificado de analítica por lotes y en streaming.
imagen + chartApache-2.0 - Camundaplanificado
Automatización de procesos y orquestación BPMN, incluido el motor Zeebe.
imagen + chartApache-2.0 - Dagsterplanificado
Orquestador de datos para pipelines de ML y analítica.
imagen + chartApache-2.0 - Prefectplanificado
Servidor de orquestación de flujos de trabajo nativo de Python para pipelines de datos.
imagen + chartApache-2.0 - Trinoplanificado
Motor de consultas SQL distribuido para analítica federada entre fuentes de datos.
imagen + chartApache-2.0 - Unleashplanificado
Servidor de gestión de feature flags y toggles respaldado por PostgreSQL.
imagen + chartApache-2.0 - WireMockplanificado
HTTP API mock server for testing.
imagen + chartApache-2.0 - Apache Camel Kexplorando
Kubernetes-native integration framework.
imagen + chartApache-2.0 - Apache Polarisexplorando
Open REST catalog for Apache Iceberg tables.
imagen + chartApache-2.0 - Apache Tikaexplorando
Content and metadata extraction toolkit.
imagen + chartApache-2.0 - Cubeexplorando
Semantic layer and analytics API over your data.
imagen + chartApache-2.0 - Hyperledger Fabricexplorando
Permissioned enterprise blockchain platform.
imagen + chartApache-2.0
Mensajería y streaming
7
- AKHQplanificado
Web UI to manage and browse Kafka — the console the messaging-stack needs.
imagen + chartApache-2.0 - Apache ActiveMQplanificado
Broker de mensajes JMS en Java, incluido el motor de nueva generación Artemis.
imagen + chartApache-2.0 - Apicurio Registryplanificado
API and schema registry for Kafka, Avro, and Protobuf.
imagen + chartApache-2.0 - Karapaceplanificado
Registro de esquemas y proxy REST abierto para Kafka; una alternativa con licencia Apache al schema-registry de Confluent Community.
imagen + chartApache-2.0 - Redpandaplanificado
Streaming compatible con Kafka. De código disponible, no OSI.
alt. limpia: Kafka or Pulsar (Apache-2.0), both already shipped.
imagen + chartBSL-1.1precaución - Strimziplanificado
Kubernetes operator for running and managing Kafka.
imagen + chartApache-2.0 - Apache Stormexplorando
Distributed real-time stream processing.
imagen + chartApache-2.0
Coordinación y malla
13
- Calicoplanificado
eBPF/iptables CNI for networking and network policy.
imagen + chartApache-2.0 - Ciliumplanificado
Redes, seguridad y observabilidad basadas en eBPF para Kubernetes.
imagen + chartApache-2.0 - Consulplanificado
Descubrimiento de servicios y malla. De código disponible, no OSI.
alt. limpia: etcd (Apache-2.0) for KV/coordination, already shipped.
imagen + chartBUSL-1.1precaución - Istioplanificado
Malla de servicios construida sobre Envoy: gestión de tráfico, mTLS y observabilidad. A escala de plataforma, una oleada de varias imágenes (plano de control istiod más sidecars y pasarelas de Envoy) en lugar de una sola imagen.
imagen + chartApache-2.0 - Linkerdplanificado
Malla de servicios ligera.
imagen + chartApache-2.0 - MetalLBplanificado
Implementación de balanceador de carga para clústeres de Kubernetes en bare-metal.
imagen + chartApache-2.0 - Nomadplanificado
Planificador de cargas de trabajo. De código disponible, no OSI.
imagen + chartBUSL-1.1precaución - PowerDNSplanificado
Servidor DNS autoritativo y recursor con backends de base de datos.
imagen + chartGPL-2.0-onlyagpl - Unboundplanificado
Resolutor DNS validador, recursivo y con caché.
imagen + chartBSD-3-Clause - BIND 9explorando
Authoritative and recursive DNS server.
imagen + chartMPL-2.0 - FRRoutingexplorando
Internet routing protocol suite (BGP, OSPF, etc.).
imagen + chartGPL-2.0 - kube-vipexplorando
Virtual IP and load balancer for the control plane and services.
imagen + chartApache-2.0 - Tailscaleexplorando
WireGuard-based mesh VPN with a Kubernetes operator.
imagen + chartBSD-3-Clause
Bases de datos y motores
23
- Apache Kvrocksplanificado
Base de datos clave-valor con protocolo de Redis persistida sobre RocksDB.
imagen + chartApache-2.0 - Apache Nessieplanificado
Catálogo transaccional y versionado para tablas de data lakehouse.
imagen + chartApache-2.0 - ArangoDBplanificado
Base de datos multimodelo para documentos, grafos y clave-valor (Community Edition).
imagen + chartApache-2.0 - CloudNativePGplanificado
Kubernetes operator for PostgreSQL HA: streaming replication, automated failover, and backups/PITR to object storage, all via CRDs. CNCF project; the modern operator behind the pg-ha-stack.
imagen + chartApache-2.0 - CrateDBplanificado
Distributed SQL database for time-series and search.
imagen + chartApache-2.0 - Flywayplanificado
Versioned SQL database migrations.
imagen + chartApache-2.0 - Hasura GraphQL Engineplanificado
API GraphQL instantánea sobre PostgreSQL y otras bases de datos.
imagen + chartApache-2.0 - JanusGraphplanificado
Base de datos de grafos distribuida sobre backends de almacenamiento intercambiables.
imagen + chartApache-2.0 - KeyDBplanificado
Fork multihilo de Redis; con licencia BSD y compatible con el protocolo de Redis.
imagen + chartBSD-3-Clause - Liquibaseplanificado
Database schema change and migration management.
imagen + chartApache-2.0 - MariaDB Operatorplanificado
Kubernetes operator for MariaDB/MySQL: provisioning, Galera multi-primary HA, replication, backups, and user/grant management via CRDs.
imagen + chartMIT - MongoDB Community Operatorplanificado
MongoDB Community Kubernetes Operator: replica-set HA, automated failover, and TLS via CRDs. The operator is Apache-2.0; note the MongoDB server it deploys is SSPL (not OSI).
imagen + chartApache-2.0 - Percona XtraDB Cluster Operatorplanificado
Operator for Percona XtraDB Cluster (MySQL): synchronous multi-primary HA via Galera, with automated backups and point-in-time recovery.
imagen + chartApache-2.0 - Pgpool-IIplanificado
Middleware de pooling de conexiones, balanceo de carga y replicación para PostgreSQL.
imagen + chartBSD-3-Clause - pgvectorplanificado
PostgreSQL with the pgvector extension for vector similarity search.
imagen + chartPostgreSQL - ProxySQLplanificado
Proxy de alto rendimiento para MySQL/MariaDB.
imagen + chartGPL-3.0agpl - RethinkDBplanificado
Realtime document database with live queries.
imagen + chartApache-2.0 - SurrealDBplanificado
Base de datos multimodelo. De código disponible, no OSI.
imagen + chartBUSL-1.1precaución - Vitessplanificado
Sharding horizontal para MySQL.
imagen + chartApache-2.0 - Aerospikeexplorando
Real-time key-value database; community edition is AGPL.
imagen + chartAGPL-3.0agpl - Couchbaseexplorando
Distributed document database. Source-available, not OSI.
alt. limpia: CouchDB (Apache-2.0), already shipped.
imagen + chartBSL-1.1precaución - OrientDBexplorando
Multi-model graph and document database.
imagen + chartApache-2.0 - Tiny RDMexplorando
Modern Redis/Valkey desktop GUI (Wails/Go+Vue). A desktop client, not a deployable server, so it falls outside the hardened in-cluster image model — a web Redis UI (e.g. redis-commander) would be the cache-stack UI instead.
imagen + chartGPL-3.0agpl
Almacenamiento y plataforma
9
- Apache Ozoneplanificado
Almacén de objetos distribuido escalable (S3 + HDFS).
imagen + chartApache-2.0 - Dokployplanificado
PaaS autoalojable sobre Docker Swarm. Open-core: la mayor parte es Apache-2.0, las partes /proprietary son de código disponible (DSAL-1.0). No encaja en el catálogo endurecido: requiere root, el socket de Docker y un Swarm inicializado, por lo que no puede ejecutarse como nonroot ni en modo de solo lectura.
alt. limpia: Coolify (Apache-2.0), already shipped.
imagen + chartApache-2.0 + DSAL-1.0precaución - Kuboplanificado
Implementación de referencia de IPFS para almacenamiento distribuido direccionado por contenido.
imagen + chartMIT - Longhornplanificado
Almacenamiento de bloques distribuido para Kubernetes con snapshots y copias de seguridad.
imagen + chartApache-2.0 - MinIOplanificado
S3-compatible object storage; relicensed to AGPL-3.0.
alt. limpia: SeaweedFS / Garage / RustFS (Apache-2.0), all already shipped.
imagen + chartAGPL-3.0agpl - SonarQubeplanificado
Inspección continua de calidad y seguridad del código.
imagen + chartLGPL-3.0 - Woodpecker CIplanificado
Motor de CI sencillo y nativo de contenedores.
imagen + chartApache-2.0 - Rookexplorando
Ceph storage orchestrator for Kubernetes (block/object/file).
imagen + chartApache-2.0 - Versity Gatewayexplorando
S3-compatible gateway fronting any storage backend.
imagen + chartApache-2.0
Aplicaciones y productividad
24
- Appsmithplanificado
Constructor low-code de herramientas internas y paneles de administración respaldado por PostgreSQL y Redis.
imagen + chartApache-2.0 - Discourseplanificado
Plataforma de debate y foros en Ruby respaldada por PostgreSQL y Redis.
imagen + chartGPL-2.0-or-lateragpl - Gotenbergplanificado
API sin estado de conversión de HTML y Office a PDF.
imagen + chartMIT - Gristplanificado
Self-hosted spreadsheet-database hybrid, an Airtable alternative.
imagen + chartApache-2.0 - Homepageplanificado
Panel autoalojado de servicios y marcadores con integraciones de widgets.
imagen + chartGPL-3.0-onlyagpl - Joomlaplanificado
CMS en PHP respaldado por MySQL o MariaDB.
imagen + chartGPL-2.0-or-lateragpl - Mastodonplanificado
Servidor de red social federada (Ruby más Node) respaldado por PostgreSQL y Redis.
imagen + chartAGPL-3.0-onlyagpl - MediaWikiplanificado
The wiki engine behind Wikipedia, backed by MySQL or MariaDB.
imagen + chartGPL-2.0-or-later - Metabaseplanificado
Friendly self-service BI and analytics dashboards.
imagen + chartAGPL-3.0agpl - Moodleplanificado
Sistema de gestión del aprendizaje en PHP respaldado por MySQL, MariaDB o PostgreSQL.
imagen + chartGPL-3.0-or-lateragpl - Odooplanificado
Suite de ERP y aplicaciones de negocio en Python (Community Edition) respaldada por PostgreSQL.
imagen + chartLGPL-3.0-only - pgAdminplanificado
Interfaz web de administración y gestión para PostgreSQL.
imagen + chartPostgreSQL - phpMyAdminplanificado
Interfaz web de administración en PHP para MySQL y MariaDB.
imagen + chartGPL-2.0-onlyagpl - Redmineplanificado
Gestión de proyectos y seguimiento de incidencias en Ruby on Rails respaldado por una base de datos relacional.
imagen + chartGPL-2.0-or-lateragpl - Rocket.Chatplanificado
Self-hosted team chat platform backed by MongoDB.
imagen + chartMIT - SuiteCRMplanificado
Aplicación de gestión de relaciones con clientes en PHP respaldada por MySQL o MariaDB.
imagen + chartAGPL-3.0-onlyagpl - Backdrop CMSexplorando
Drupal fork focused on simplicity, backed by MySQL.
imagen + chartGPL-2.0-or-later - Chromiumexplorando
Headless browser for rendering, scraping, and PDF export.
imagen + chartBSD-3-Clause - Friendicaexplorando
Federated social network server.
imagen + chartAGPL-3.0agpl - Mongo Expressexplorando
Web administration UI for MongoDB.
imagen + chartMIT - Ploneexplorando
Python enterprise CMS on Zope.
imagen + chartGPL-2.0-or-later - Selenium Gridexplorando
Distributed browser automation and testing grid.
imagen + chartApache-2.0 - XWikiexplorando
Enterprise wiki and structured collaboration platform.
imagen + chartLGPL-2.1 - YOURLSexplorando
Self-hosted URL shortener.
imagen + chartMIT
Medios y streaming
2
- Apache Guacamoleplanificado
Pasarela de escritorio remoto sin cliente para RDP, VNC y SSH a través del navegador.
imagen + chartApache-2.0 - Jellyfinplanificado
Servidor multimedia autoalojado para películas, música y TV en directo.
imagen + chartGPL-2.0-onlyagpl
CI/CD y registro
21
- Argo CDplanificado
Entrega continua declarativa GitOps para Kubernetes.
imagen + chartApache-2.0 - Argo Eventsplanificado
Event-driven workflow automation for Kubernetes.
imagen + chartApache-2.0 - Argo Rolloutsplanificado
Progressive delivery (canary, blue-green) for Kubernetes.
imagen + chartApache-2.0 - Concourseplanificado
Sistema de integración continua basado en pipelines respaldado por PostgreSQL.
imagen + chartApache-2.0 - Crossplaneplanificado
Framework de plano de control para gestionar infraestructura en la nube mediante APIs de Kubernetes.
imagen + chartApache-2.0 - Daprplanificado
Runtime de aplicaciones distribuidas que proporciona APIs de bloques de construcción para microservicios.
imagen + chartApache-2.0 - Fluxplanificado
Conjunto de herramientas GitOps de controladores para entrega continua en Kubernetes.
imagen + chartApache-2.0 - GitHub Actions Runnerplanificado
Self-hosted Actions runner — the runner the gitops-stack needs for a Gitea/Forgejo backend.
imagen + chartMIT - GitLab Runnerplanificado
CI job executor for GitLab pipelines; also a gitops-stack runner option.
imagen + chartMIT - Gogsplanificado
The original minimal Go Git service that Gitea forked from. Very small single-binary forge; an even lighter gitops-stack backend option.
imagen + chartMIT - Jenkins Inbound Agentplanificado
Jenkins JNLP inbound build agent. Image only, no chart. Build held: jenkins-docker-agent carries a CRITICAL jetty CVE (fix 2.560-r0 not yet in Wolfi).
imagen + chartMIT - Terralistplanificado
Private Terraform/OpenTofu registry for modules and providers (Go). Hardenable as a normal nonroot server image; unlocks the gitops-stack and registry-stack.
imagen + chartMPL-2.0 - vclusterplanificado
Virtual Kubernetes clusters inside a namespace.
imagen + chartApache-2.0 - Cluster Autoscalerexplorando
Scales Kubernetes node pools to match pending workloads.
imagen + chartApache-2.0 - GitLab CEexplorando
Full DevOps platform (Git forge + CI/CD + registry). Heavy fit: a large Ruby monolith that bundles PostgreSQL, Redis, Gitaly, Sidekiq and Workhorse, and the gitlab-org/gitlab repo is mostly EE-proprietary — only the CE-flagged code is MIT. Far from the minimal one-purpose hardened model.
alt. limpia: Gitea or Forgejo — lightweight, fully-open Git forges that drop straight into the gitops-stack.
imagen + chartMITprecaución - KubeVirtexplorando
Run virtual machines as Kubernetes workloads.
imagen + chartApache-2.0 - kuredexplorando
Safe automated node reboots for Kubernetes.
imagen + chartApache-2.0 - OneDevexplorando
Self-hosted Git server with built-in CI/CD, issues and kanban (Java). Heavier than Gitea/Gogs but far lighter than GitLab; an all-in-one gitops-stack backend option.
imagen + chartMIT - Reloaderexplorando
Rolls workloads when their ConfigMaps or Secrets change.
imagen + chartApache-2.0 - Terragruntexplorando
Thin Terraform/OpenTofu wrapper for DRY configurations.
imagen + chartMIT - Vertical Pod Autoscalerexplorando
Recommends and applies pod CPU/memory requests.
imagen + chartApache-2.0
Aprendizaje automático
11
- JupyterHubplanificado
Servidor de notebooks Jupyter multiusuario para equipos y aulas.
imagen + chartBSD-3-Clause - KServeplanificado
Kubernetes model inference serving with autoscaling.
imagen + chartApache-2.0 - KubeRayplanificado
Operador para ejecutar clústeres de cómputo distribuido Ray en Kubernetes.
imagen + chartApache-2.0 - Label Studioplanificado
Herramienta de etiquetado y anotación de datos para conjuntos de datos de ML.
imagen + chartApache-2.0 - Langflowplanificado
Constructor visual de aplicaciones de LLM y flujos de trabajo de agentes.
imagen + chartMIT - Langfuseplanificado
Plataforma de observabilidad y trazabilidad de LLM respaldada por PostgreSQL.
imagen + chartMIT - Open WebUIplanificado
Interfaz web autoalojada para chatear con LLM locales y remotos.
imagen + chartBSD-3-Clause - AnythingLLMexplorando
Self-hosted chat-with-your-documents LLM application.
imagen + chartMIT - DataHubexplorando
Metadata platform and data catalog.
imagen + chartApache-2.0 - Kubeflow Pipelinesexplorando
ML pipeline orchestration on Kubernetes.
imagen + chartApache-2.0 - TensorFlow Servingexplorando
High-performance serving system for TensorFlow models.
imagen + chartApache-2.0
Seguridad y cadena de suministro
26
- Buildahplanificado
Daemonless OCI image builder.
imagen + chartApache-2.0 - BuildKitplanificado
Concurrent container image build engine.
imagen + chartApache-2.0 - Checkovplanificado
Static security scanning for Terraform, Kubernetes, and more.
imagen + chartApache-2.0 - ClamAVplanificado
Motor antivirus de código abierto para escanear archivos y correo.
imagen + chartGPL-2.0-onlyagpl - Craneplanificado
go-containerregistry CLI for registry interaction.
imagen + chartApache-2.0 - Daggerplanificado
Programmable CI/CD engine that runs pipelines in containers.
imagen + chartApache-2.0 - Falcoplanificado
Seguridad en tiempo de ejecución y detección de amenazas usando eventos del kernel y eBPF.
imagen + chartApache-2.0 - Gitleaksplanificado
Secret scanner for git repos and files.
imagen + chartMIT - Hadolintplanificado
Dockerfile linter.
imagen + chartGPL-3.0agpl - Kanikoplanificado
Build container images inside Kubernetes without a daemon.
imagen + chartApache-2.0 - Kubescapeplanificado
Kubernetes security, posture, and compliance scanner.
imagen + chartApache-2.0 - Kubescape Operatorplanificado
In-cluster Kubescape components (operator, scanner, kubevuln) for continuous posture and vulnerability scanning. Distinct from the Kubescape CLI.
imagen + chartApache-2.0 - Notationplanificado
Notary v2 OCI artifact signing and verification.
imagen + chartApache-2.0 - ORASplanificado
Push and pull arbitrary artifacts to OCI registries.
imagen + chartApache-2.0 - Podmanplanificado
Daemonless container engine and Docker CLI replacement.
imagen + chartApache-2.0 - ShellCheckplanificado
Shell script static analysis linter.
imagen + chartGPL-3.0agpl - Sigstoreplanificado
Infraestructura de firma sin claves que incluye la CA Fulcio y el registro de transparencia Rekor.
imagen + chartApache-2.0 - Skopeoplanificado
Inspect and copy container images between registries.
imagen + chartApache-2.0 - Tetragonplanificado
Observabilidad y aplicación de seguridad en tiempo de ejecución basada en eBPF.
imagen + chartApache-2.0 - Trivy Operatorplanificado
In-cluster continuous Trivy scanning via CRDs.
imagen + chartApache-2.0 - Wazuhplanificado
Plataforma SIEM y XDR con componentes de manager, indexador y panel.
imagen + chartGPL-2.0-onlyagpl - Connaisseurexplorando
Admission controller enforcing image signature verification.
imagen + chartApache-2.0 - Diveexplorando
Explore container image layers and wasted space.
imagen + chartMIT - koexplorando
Build and deploy Go container images with no Dockerfile.
imagen + chartApache-2.0 - OpenSCAPexplorando
SCAP compliance and vulnerability scanning.
imagen + chartLGPL-2.1 - TruffleHogexplorando
Deep secret scanner across repos and filesystems.
imagen + chartAGPL-3.0agpl
Stacks
24
- cache-stackplanificado
Umbrella: Valkey + redis-exporter + Grafana dashboards — cache with metrics. All components built; ready to build.
imagen + chartApache-2.0 - postgres-ha-stackplanificado
Umbrella: PostgreSQL + PgBouncer + postgres-exporter — pooled SQL with metrics. All components built; ready to build.
imagen + chartApache-2.0 - secrets-stackplanificado
Umbrella: OpenBao + Keycloak — SSO in front of secrets management. All components built; ready to build.
imagen + chartApache-2.0 - ai-stackexplorando
Ollama (or vLLM) + Open WebUI + Qdrant — self-hosted LLM serving, a chat UI, and a vector DB for retrieval-augmented generation. Qdrant is built; needs Ollama/vLLM + Open WebUI images.
imagen + chartApache-2.0 - analytics-stackexplorando
Apache Superset + Trino + PostgreSQL — federated SQL analytics with self-service BI dashboards. PostgreSQL is built; needs Superset + Trino.
imagen + chartApache-2.0 - backup-stackexplorando
Velero + MinIO — scheduled cluster backup/restore and PV snapshots to an in-cluster S3 target. Needs Velero + MinIO images.
alt. limpia: Use any external S3 (SeaweedFS/Garage, already shipped) instead of MinIO to keep it fully Apache-2.0.
imagen + chartApache-2.0 - cost-stackexplorando
OpenCost + Prometheus + Grafana — Kubernetes cost monitoring and allocation dashboards; an add-on to the observability stack. Prometheus + Grafana are built; needs OpenCost.
imagen + chartApache-2.0 - gitops-stackexplorando
Umbrella: a pluggable Git backend + Atlantis + Terralist for Terraform/OpenTofu GitOps with a private module/provider registry. Pick your forge: Gitea (default, built) or Forgejo / Gogs (lightweight, clean) / OneDev (all-in-one) / GitLab CE (heavy, mixed license). Atlantis + Gitea charts built; needs a Terralist image, the chosen forge's image, and a runner — GitHub Actions Runner or GitLab Runner, both now on the roadmap (or run runner-less).
imagen + chartApache-2.0 - ingress-stackexplorando
Traefik (or ingress-nginx) + cert-manager + external-dns — production ingress with automatic TLS and DNS records. Traefik + external-dns are built; needs cert-manager.
imagen + chartApache-2.0 - lakehouse-stackexplorando
Trino + Apache Nessie (or Polaris) + MinIO — an Iceberg data lakehouse: query engine, versioned table catalog, and object store. Needs those images.
imagen + chartApache-2.0 - messaging-stackexplorando
Umbrella: Kafka + ZooKeeper (or NATS) + a console UI — event backbone. Needs a Kafka UI image first — AKHQ (Apache-2.0) is now on the roadmap for exactly this.
imagen + chartApache-2.0 - mongodb-ha-stackexplorando
Operator-based HA MongoDB: MongoDB Community Operator + a metrics exporter — replica-set failover. CRD-driven. The operator is Apache-2.0, but MongoDB itself is SSPL (not OSI), so the stack inherits that caution.
alt. limpia: FerretDB (Apache-2.0) on the pg-ha-stack — a MongoDB-compatible, fully-open document database over PostgreSQL.
imagen + chartSSPL-1.0precaución - mysql-ha-stackexplorando
Operator-based HA MySQL: a MySQL operator (Percona XtraDB Cluster, or MariaDB Operator with Galera) + a metrics exporter — synchronous multi-primary replication and backups. CRD-driven. Needs the chosen operator image first.
imagen + chartApache-2.0 - orchestration-stackexplorando
Apache Airflow + PostgreSQL + Valkey — data-pipeline scheduling (Airflow needs a metadata DB and a broker). PostgreSQL + Valkey are built; needs Airflow.
imagen + chartApache-2.0 - pg-ha-stackexplorando
Operator-based HA PostgreSQL: CloudNativePG + PgBouncer + postgres-exporter — streaming replication, automated failover, and backups/PITR to object storage. NOTE: unlike the operator-free observability stacks, this is CRD-driven (it installs the CloudNativePG operator). Needs a CloudNativePG image first.
imagen + chartApache-2.0 - pki-stackexplorando
step-ca + cert-manager + trust-manager — an internal certificate authority with automated issuance and cluster-wide trust-bundle distribution. Needs those images.
imagen + chartApache-2.0 - policy-stackexplorando
Kyverno + Policy Reporter + Polaris (Fairwinds) — Kubernetes policy enforcement, violation reporting, and configuration best-practice validation. Operator-light (admission webhooks). Needs those images.
imagen + chartApache-2.0 - profiling-stackexplorando
Grafana Pyroscope + Grafana — continuous CPU/memory profiling; the missing 'P' that completes LGTM(P) alongside the observability/logging/tracing stacks. Needs a Pyroscope image.
imagen + chartApache-2.0 - registry-stackexplorando
Umbrella: Harbor (container images + OCI Helm charts + Trivy scanning) + Terralist (Terraform/OpenTofu modules & providers) — one self-hosted artifact registry for every kind of artifact. Harbor chart built; needs a Terralist image+chart.
imagen + chartApache-2.0 - runtime-security-stackexplorando
Falco + Tetragon — eBPF-based runtime threat detection and enforcement. Privileged host/kernel access by design (like node-exporter). Needs those images.
imagen + chartApache-2.0 - search-stackexplorando
Umbrella: OpenSearch + OpenSearch Dashboards — search with a UI. Needs an opensearch-dashboards image first.
imagen + chartApache-2.0 - streaming-stackexplorando
Kafka + Apache Flink + Apicurio Registry — end-to-end stream processing with schema governance. Kafka is built; needs Flink + Apicurio.
imagen + chartApache-2.0 - supply-chain-stackexplorando
Trivy Operator + Kubescape + Dependency-Track — continuous image, cluster-posture, and SBOM vulnerability scanning in one place. Needs those images.
imagen + chartApache-2.0 - temporal-stackexplorando
Umbrella: Temporal + Elasticsearch for advanced visibility. Marginal — the Temporal chart already bundles its own PostgreSQL, so a stack only adds optional ES visibility search.
imagen + chartApache-2.0
Por qué se retienen algunas apps
QuenchWorks no publica nada que tenga un CVE corregible. Algunas apps compilan limpias pero aún no llegan a ese nivel: la propia app fija una dependencia por debajo de la versión que corrige un CVE conocido, así que parchearla rompería sus propias restricciones declaradas. Se marcan como bloqueadas: compiladas y probadas, retenidas (sin publicar) hasta que el upstream relaje la fijación o retroporte la corrección. Se publican en cuanto eso ocurre. Nada que ya esté en el catálogo tiene un CVE corregible conocido.
¿Quieres priorizar algo? Solicita una app y la ubicaremos en la hoja de ruta.