Skip to content
QuenchWorks

Roadmap

What is shipped, what is next

195 datastores and tools are hardened and shipping today. Below is what is on deck, OSI-clean options first. Every entry is built from source on Wolfi, scanned to zero fixable CVEs, signed, and pinned by digest before it moves to available.

195/451
43% shipped
19543%
Shipped
22149%
On the roadmap
358%
Blocked

Available now

195

Analytical

1

Apps & productivity

13

Base image

1

Build tool

7

CI/CD & registry

12

Cache

5

Coordination

5

Coordination & mesh

3

Database

1

Databases & engines

2

Developer tools / IDE

1

Document

5

Gateway

9

Git

2

GitOps

2

Graph

1

Identity

6

Language runtime

13

Machine learning & AI

3

Media & streaming

3

Messaging

11

Metrics/Exporter

4

Object storage

3

Observability

18

PaaS

2

Registry

9

Relational

7

Runtime base

4

Search

6

Search & vector

1

Secrets

2

Secrets & identity

2

Security & supply chain

13

Storage & platform

3

Time series

4

Vector

1

Wide-column

2

Workflow

8

Held — built, not shipped

35

These build and test clean but can't reach 0 fixable CVEs yet — the app or its base pins a dependency below the version that fixes a known CVE, so we hold it rather than ship a vulnerable image. Each re-lists automatically the moment upstream ships the fix. Tapwhy blocked? for the exact pin.

Apps & productivity

6
  • Apache Supersetblocked

    Data exploration and business-intelligence dashboard platform backed by a metadata database and Redis.

    Apps & productivityApache-2.0
  • Flociblocked

    Local AWS cloud emulator and LocalStack Community successor, built from source into a Quarkus fast-jar on a hardened Wolfi JRE.

    Apps & productivityMIT
  • Floci (full)blocked

    Opt-in, NON-hardened companion to the floci image: it runs as root and expects the host Docker socket mounted, which lets it emulate all 65 of Floci's AWS services including the 10 Docker-backed ones (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune).

    Apps & productivityMIT
  • Ghostblocked

    Open-source Node.js publishing platform for blogs, newsletters, and membership sites.

    Apps & productivityMIT
  • Matomoblocked

    Privacy-respecting web analytics platform on PHP backed by MySQL or MariaDB.

    Apps & productivityGPL-3.0-only
  • Nextcloudblocked

    Nextcloud, the self-hosted file-sync and content-collaboration platform.

    Apps & productivityAGPL-3.0-only

CI/CD & registry

2
  • Gitnessblocked

    Self-hosted Git hosting with built-in pipelines from Harness.

    CI/CD & registryApache-2.0
  • Jenkinsblocked

    The leading open-source automation server for building, testing, and deploying software, with thousands of plugins.

    CI/CD & registryMIT

Coordination

1
  • Apache ZooKeeperblocked

    Centralized coordination service for distributed systems, providing configuration, naming, leader election, and synchronization primitives.

    CoordinationApache-2.0

Document

1
  • FerretDBblocked

    MongoDB-compatible document database that translates the MongoDB wire protocol onto PostgreSQL via the DocumentDB extension.

    DocumentApache-2.0

Graph

1
  • Neo4jblocked

    Graph database for highly connected data, queried with Cypher for traversals and relationship-heavy workloads.

    GraphGPL-3.0-only

Identity

3
  • Autheliablocked

    Open-source authentication and authorization server providing single sign-on and two-factor authentication via a web portal, designed as a companion for reverse proxies.

    IdentityApache-2.0
  • Keycloakblocked

    Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.

    IdentityApache-2.0
  • ZITADELblocked

    Cloud-native identity and access management (IAM) with OIDC/OAuth2/SAML, multi-tenancy, and a built-in admin console.

    IdentityAGPL-3.0-only

Messaging

3
  • Apache Kafkablocked

    Distributed event-streaming platform for high-throughput, durable, replayable publish-subscribe pipelines and stream processing.

    MessagingApache-2.0
  • Apache Pulsarblocked

    Cloud-native distributed messaging and streaming platform with multi-tenancy, geo-replication, and tiered storage that separates compute from storage.

    MessagingApache-2.0
  • Mattermostblocked

    Open-source, self-hosted team messaging and collaboration platform (a Slack alternative) with channels, direct messages, file sharing, and integrations.

    MessagingAGPL-3.0-only

Observability

9
  • Apache JMeterblocked

    Apache JMeter load-testing and performance-measurement tool, the official binary distribution running on a hardened Wolfi JRE.

    ObservabilityApache-2.0
  • Apache SkyWalkingblocked

    APM: distributed tracing, metrics, and service-topology analysis. [blocked: upstream CVEs / ES9 unsupported]

    ObservabilityApache-2.0
  • Grafanablocked

    Dashboards and visualization for metrics, logs, and traces across many data sources.

    ObservabilityAGPL-3.0-only
  • Grafana Alloyblocked

    OpenTelemetry-based collector distribution for metrics, logs, traces, and profiles.

    ObservabilityApache-2.0
  • Graylogblocked

    Graylog, the log-management and analysis server (search, dashboards, alerting, GELF/Beats inputs).

    ObservabilitySSPL-1.0
  • metrics-serverblocked

    Kubernetes resource-metrics API for HPA and kubectl top.

    ObservabilityApache-2.0
  • OpenSearch Dashboardsblocked

    Visualization and dashboards UI for OpenSearch.

    ObservabilityApache-2.0
  • Telegrafblocked

    Plugin-driven metrics collection agent from the InfluxData ecosystem.

    ObservabilityMIT
  • Thanosblocked

    Highly-available Prometheus setup with unlimited metric retention via object storage, adding a global query view, downsampling, and compaction across Prometheus servers.

    ObservabilityApache-2.0

PaaS

1
  • Coolify Helperblocked

    Coolify helper image carrying the build and deploy toolchain (buildpacks, git, ssh) that runs on target hosts to execute deployments. [blocked: upstream CVEs / ES9 unsupported]

    PaaSApache-2.0 AND AGPL-3.0-or-later

Relational

1
  • CockroachDBblocked

    Distributed SQL database with PostgreSQL wire compatibility and automatic horizontal scaling and survivability.

    RelationalBUSL-1.1

Search

3
  • Apache Solrblocked

    Enterprise search platform built on Apache Lucene, offering full-text search, faceting, and indexing over large document collections.

    SearchApache-2.0
  • Elasticsearchblocked

    Distributed search and analytics engine.

    SearchSSPL-1.0
  • OpenSearchblocked

    Search and analytics suite with a Kibana-style dashboards UI.

    SearchApache-2.0

Secrets & identity

2
  • Ory Hydrablocked

    OAuth 2.0 and OpenID Connect provider backed by a relational database.

    Secrets & identityApache-2.0
  • Ory Kratosblocked

    Identity and user-management server for login, registration, and MFA.

    Secrets & identityApache-2.0

Security & supply chain

1
  • Grypeblocked

    Anchore's vulnerability scanner for container images and filesystems, driven by the same SBOM engine as Syft.

    Security & supply chainApache-2.0

Workflow & data

1
  • n8nblocked

    Fair-code workflow automation with native AI. Source-available, not OSI.

    Workflow & dataSustainable Use License

On the roadmap

221

Candidates, not commitments. next = strongest near-term picks;planned and exploring follow. Items marked caution are source-available (not OSI) and would ship only with a loud license note and the clean alternative called out. (Apps that build but can't hit 0 fixable CVEs yet are in Held, above.) Each card also shows how it will ship: image + chart for a deployable service, orimage only for a base/CLI/sidecar utility (like busybox).

Secrets & identity

12
  • Dependency-Trackplanned

    SBOM and component-vulnerability analysis platform backed by a relational database.

    image + chartApache-2.0
  • EJBCAplanned

    Enterprise PKI certificate authority (Community Edition) backed by a relational database.

    image + chartLGPL-2.1-or-later
  • OPA Gatekeeperplanned

    OPA policy admission controller for Kubernetes.

    image + chartApache-2.0
  • OpenLDAPplanned

    LDAP directory server for centralized authentication and user data.

    image + chartOLDAP-2.8
  • Pinnipedplanned

    Authentication for Kubernetes clusters federating external identity providers.

    image + chartApache-2.0
  • Sealed Secretsplanned

    Encrypts Kubernetes Secrets so they can be stored safely in Git.

    image + chartApache-2.0
  • Secrets Store CSI Driverplanned

    CSI driver that mounts secrets from external stores (Vault, cloud KMS) as volumes.

    image + chartApache-2.0
  • SPIREplanned

    SPIFFE runtime for issuing workload identities across a fleet.

    image + chartApache-2.0
  • Teleportplanned

    Access plane providing identity-based SSH, Kubernetes, and database access. Community edition is AGPL-3.0.

    image + chartAGPL-3.0-onlyagpl
  • Vaultplanned

    HashiCorp Vault. Source-available, not OSI.

    clean alt: OpenBao (MPL-2.0) — the open fork, already shipped.

    image + chartBUSL-1.1caution
  • Polaris (Fairwinds)exploring

    Kubernetes configuration best-practice validation.

    image + chartApache-2.0
  • SATOSAexploring

    Proxy that translates between SAML and OIDC.

    image + chartApache-2.0

Gateways & proxies

14
  • Apache APISIXplanned

    Dynamic API gateway on Nginx + LuaJIT: hot-reloads plugins and config from etcd, with no relational-database dependency. A high-performance Kong alternative.

    image + chartApache-2.0
  • Contourplanned

    Envoy-based Kubernetes ingress controller.

    image + chartApache-2.0
  • Envoy Gatewayplanned

    CNCF implementation of the Kubernetes Gateway API on Envoy: standard K8s resources instead of vendor CRDs. The Kubernetes-first Kong alternative.

    image + chartApache-2.0
  • Gloo Edgeplanned

    Envoy-based gateway for microservices, monoliths, and serverless, with strong multi-protocol support: HTTP, gRPC, WebSockets, and FaaS.

    image + chartApache-2.0
  • Jettyplanned

    Lightweight Eclipse Jetty servlet server.

    image + chartApache-2.0
  • Kong Gatewayplanned

    API gateway on nginx/OpenResty. Open-core (the OSS gateway is Apache-2.0; many features are gated behind the enterprise tier) and it depends on PostgreSQL. APISIX and Tyk are lighter, fully-open alternatives.

    image + chartApache-2.0
  • KrakenDplanned

    Stateless high-performance API gateway.

    image + chartApache-2.0
  • NGINX Unitplanned

    Polyglot application server from the nginx team.

    image + chartApache-2.0
  • OpenRestyplanned

    nginx + LuaJIT platform for scriptable web apps and gateways.

    image + chartBSD-2-Clause
  • Squidplanned

    Caching and forwarding HTTP proxy.

    image + chartGPL-2.0-or-lateragpl
  • Varnishplanned

    HTTP caching reverse proxy and web accelerator.

    image + chartBSD-2-Clause
  • WildFlyplanned

    JBoss Jakarta EE application server.

    image + chartLGPL-2.1
  • Apache TomEEexploring

    Tomcat plus the Jakarta EE stack.

    image + chartApache-2.0
  • Emissary-ingressexploring

    Envoy-based Kubernetes API gateway / ingress.

    image + chartApache-2.0

AI gateway

2
  • Bifrostplanned

    High-performance Go AI gateway: unified access, load balancing, and failover across 20+ LLM providers with near-zero overhead. An open alternative to bolt-on AI-gateway plugins.

    image + chartApache-2.0
  • LiteLLMplanned

    Lightweight Python proxy exposing one OpenAI-compatible API to call, monitor, and cost-map 100+ LLM providers.

    image + chartMIT

Observability

15
  • Fluentdplanned

    Unified logging layer for collecting, parsing, and routing logs.

    image + chartApache-2.0
  • Kibanaplanned

    Visualization and dashboards for Elasticsearch. Default distribution is Elastic-2.0, not OSI.

    clean alt: OpenSearch Dashboards (Apache-2.0) over OpenSearch, both open.

    image + chartElastic-2.0caution
  • Logstashplanned

    Server-side log and event processing pipeline. Default distribution is Elastic-2.0, not OSI.

    clean alt: Vector (MPL-2.0) or Fluentd (Apache-2.0), both open pipelines.

    image + chartElastic-2.0caution
  • mongodb-exporterplanned

    Prometheus exporter for MongoDB metrics.

    image + chartApache-2.0
  • mysqld-exporterplanned

    Prometheus exporter for MySQL/MariaDB metrics.

    image + chartApache-2.0
  • Netdataplanned

    Real-time per-second infrastructure monitoring agent.

    image + chartGPL-3.0agpl
  • OpenCostplanned

    Kubernetes cost monitoring and allocation (CNCF).

    image + chartApache-2.0
  • OpenTelemetry Operatorplanned

    Operator that manages OpenTelemetry Collector instances and auto-instrumentation.

    image + chartApache-2.0
  • Percona PMMplanned

    Percona Monitoring and Management — deep MySQL/PostgreSQL/MongoDB observability (query analytics) built on Prometheus, Grafana and VictoriaMetrics. AGPL, OSI-approved.

    image + chartAGPL-3.0
  • Promtailplanned

    Loki's agent for shipping pod and file logs.

    image + chartApache-2.0
  • Uptime Kumaplanned

    Self-hosted uptime and status-page monitor.

    image + chartMIT
  • Zabbixplanned

    Infrastructure and network monitoring platform; version 7 and later is AGPL-3.0.

    image + chartAGPL-3.0-onlyagpl
  • Zipkinplanned

    Distributed tracing system for collecting and querying timing data.

    image + chartApache-2.0
  • Cortexexploring

    Horizontally scalable, multi-tenant Prometheus storage.

    image + chartApache-2.0
  • kafka-exporterexploring

    Prometheus exporter for Kafka lag and topic metrics.

    image + chartApache-2.0

Search & vector

1
  • Milvusplanned

    Scalable vector database for AI workloads.

    image + chartApache-2.0

Workflow & data

17
  • Ansibleplanned

    Agentless IT automation and configuration management.

    image + chartGPL-3.0agpl
  • Apache Druidplanned

    Real-time analytics database for high-concurrency OLAP queries.

    image + chartApache-2.0
  • Apache Flinkplanned

    Stateful stream processing.

    image + chartApache-2.0
  • Apache NiFiplanned

    Visual dataflow automation for routing, transforming, and mediating data.

    image + chartApache-2.0
  • Apache Pinotplanned

    Real-time distributed OLAP datastore for low-latency analytics.

    image + chartApache-2.0
  • Apache Sparkplanned

    Unified batch and stream analytics engine.

    image + chartApache-2.0
  • Camundaplanned

    Process automation and BPMN orchestration including the Zeebe engine.

    image + chartApache-2.0
  • Dagsterplanned

    Data orchestrator for ML and analytics pipelines.

    image + chartApache-2.0
  • Prefectplanned

    Python-native workflow orchestration server for data pipelines.

    image + chartApache-2.0
  • Trinoplanned

    Distributed SQL query engine for federated analytics across data sources.

    image + chartApache-2.0
  • Unleashplanned

    Feature-flag and toggle management server backed by PostgreSQL.

    image + chartApache-2.0
  • WireMockplanned

    HTTP API mock server for testing.

    image + chartApache-2.0
  • Apache Camel Kexploring

    Kubernetes-native integration framework.

    image + chartApache-2.0
  • Apache Polarisexploring

    Open REST catalog for Apache Iceberg tables.

    image + chartApache-2.0
  • Apache Tikaexploring

    Content and metadata extraction toolkit.

    image + chartApache-2.0
  • Cubeexploring

    Semantic layer and analytics API over your data.

    image + chartApache-2.0
  • Hyperledger Fabricexploring

    Permissioned enterprise blockchain platform.

    image + chartApache-2.0

Messaging & streaming

7
  • AKHQplanned

    Web UI to manage and browse Kafka — the console the messaging-stack needs.

    image + chartApache-2.0
  • Apache ActiveMQplanned

    Java JMS message broker, including the Artemis next-generation engine.

    image + chartApache-2.0
  • Apicurio Registryplanned

    API and schema registry for Kafka, Avro, and Protobuf.

    image + chartApache-2.0
  • Karapaceplanned

    Open schema registry and REST proxy for Kafka; an Apache-licensed alternative to the Confluent Community schema-registry.

    image + chartApache-2.0
  • Redpandaplanned

    Kafka-compatible streaming. Source-available, not OSI.

    clean alt: Kafka or Pulsar (Apache-2.0), both already shipped.

    image + chartBSL-1.1caution
  • Strimziplanned

    Kubernetes operator for running and managing Kafka.

    image + chartApache-2.0
  • Apache Stormexploring

    Distributed real-time stream processing.

    image + chartApache-2.0

Coordination & mesh

13
  • Calicoplanned

    eBPF/iptables CNI for networking and network policy.

    image + chartApache-2.0
  • Ciliumplanned

    eBPF-based networking, security, and observability for Kubernetes.

    image + chartApache-2.0
  • Consulplanned

    Service discovery and mesh. Source-available, not OSI.

    clean alt: etcd (Apache-2.0) for KV/coordination, already shipped.

    image + chartBUSL-1.1caution
  • Istioplanned

    Service mesh built on Envoy: traffic management, mTLS, and observability. Platform-scale, a multi-image wave (istiod control plane plus Envoy sidecars and gateways) rather than a single image.

    image + chartApache-2.0
  • Linkerdplanned

    Lightweight service mesh.

    image + chartApache-2.0
  • MetalLBplanned

    Load-balancer implementation for bare-metal Kubernetes clusters.

    image + chartApache-2.0
  • Nomadplanned

    Workload scheduler. Source-available, not OSI.

    image + chartBUSL-1.1caution
  • PowerDNSplanned

    Authoritative DNS server and recursor with database backends.

    image + chartGPL-2.0-onlyagpl
  • Unboundplanned

    Validating, recursive, caching DNS resolver.

    image + chartBSD-3-Clause
  • BIND 9exploring

    Authoritative and recursive DNS server.

    image + chartMPL-2.0
  • FRRoutingexploring

    Internet routing protocol suite (BGP, OSPF, etc.).

    image + chartGPL-2.0
  • kube-vipexploring

    Virtual IP and load balancer for the control plane and services.

    image + chartApache-2.0
  • Tailscaleexploring

    WireGuard-based mesh VPN with a Kubernetes operator.

    image + chartBSD-3-Clause

Databases & engines

23
  • Apache Kvrocksplanned

    Redis-protocol key-value database persisted on RocksDB.

    image + chartApache-2.0
  • Apache Nessieplanned

    Transactional catalog and versioning for data lakehouse tables.

    image + chartApache-2.0
  • ArangoDBplanned

    Multi-model database for documents, graphs, and key-value (Community Edition).

    image + chartApache-2.0
  • CloudNativePGplanned

    Kubernetes operator for PostgreSQL HA: streaming replication, automated failover, and backups/PITR to object storage, all via CRDs. CNCF project; the modern operator behind the pg-ha-stack.

    image + chartApache-2.0
  • CrateDBplanned

    Distributed SQL database for time-series and search.

    image + chartApache-2.0
  • Flywayplanned

    Versioned SQL database migrations.

    image + chartApache-2.0
  • Hasura GraphQL Engineplanned

    Instant GraphQL API over PostgreSQL and other databases.

    image + chartApache-2.0
  • JanusGraphplanned

    Distributed graph database over pluggable storage backends.

    image + chartApache-2.0
  • KeyDBplanned

    Multi-threaded Redis fork; BSD-licensed and Redis-protocol compatible.

    image + chartBSD-3-Clause
  • Liquibaseplanned

    Database schema change and migration management.

    image + chartApache-2.0
  • MariaDB Operatorplanned

    Kubernetes operator for MariaDB/MySQL: provisioning, Galera multi-primary HA, replication, backups, and user/grant management via CRDs.

    image + chartMIT
  • MongoDB Community Operatorplanned

    MongoDB Community Kubernetes Operator: replica-set HA, automated failover, and TLS via CRDs. The operator is Apache-2.0; note the MongoDB server it deploys is SSPL (not OSI).

    image + chartApache-2.0
  • Percona XtraDB Cluster Operatorplanned

    Operator for Percona XtraDB Cluster (MySQL): synchronous multi-primary HA via Galera, with automated backups and point-in-time recovery.

    image + chartApache-2.0
  • Pgpool-IIplanned

    Connection pooling, load balancing, and replication middleware for PostgreSQL.

    image + chartBSD-3-Clause
  • pgvectorplanned

    PostgreSQL with the pgvector extension for vector similarity search.

    image + chartPostgreSQL
  • ProxySQLplanned

    High-performance proxy for MySQL/MariaDB.

    image + chartGPL-3.0agpl
  • RethinkDBplanned

    Realtime document database with live queries.

    image + chartApache-2.0
  • SurrealDBplanned

    Multi-model database. Source-available, not OSI.

    image + chartBUSL-1.1caution
  • Vitessplanned

    Horizontal sharding for MySQL.

    image + chartApache-2.0
  • Aerospikeexploring

    Real-time key-value database; community edition is AGPL.

    image + chartAGPL-3.0agpl
  • Couchbaseexploring

    Distributed document database. Source-available, not OSI.

    clean alt: CouchDB (Apache-2.0), already shipped.

    image + chartBSL-1.1caution
  • OrientDBexploring

    Multi-model graph and document database.

    image + chartApache-2.0
  • Tiny RDMexploring

    Modern Redis/Valkey desktop GUI (Wails/Go+Vue). A desktop client, not a deployable server, so it falls outside the hardened in-cluster image model — a web Redis UI (e.g. redis-commander) would be the cache-stack UI instead.

    image + chartGPL-3.0agpl

Storage & platform

9
  • Apache Ozoneplanned

    Scalable distributed object store (S3 + HDFS).

    image + chartApache-2.0
  • Dokployplanned

    Self-hostable PaaS on Docker Swarm. Open-core: most is Apache-2.0, the /proprietary parts are source-available (DSAL-1.0). Not a fit for the hardened catalog: it requires root, the Docker socket, and an initialized Swarm, so it cannot run nonroot or read-only.

    clean alt: Coolify (Apache-2.0), already shipped.

    image + chartApache-2.0 + DSAL-1.0caution
  • Kuboplanned

    Reference IPFS implementation for distributed content-addressed storage.

    image + chartMIT
  • Longhornplanned

    Distributed block storage for Kubernetes with snapshots and backups.

    image + chartApache-2.0
  • MinIOplanned

    S3-compatible object storage; relicensed to AGPL-3.0.

    clean alt: SeaweedFS / Garage / RustFS (Apache-2.0), all already shipped.

    image + chartAGPL-3.0agpl
  • SonarQubeplanned

    Continuous code-quality and security inspection.

    image + chartLGPL-3.0
  • Woodpecker CIplanned

    Simple container-native CI engine.

    image + chartApache-2.0
  • Rookexploring

    Ceph storage orchestrator for Kubernetes (block/object/file).

    image + chartApache-2.0
  • Versity Gatewayexploring

    S3-compatible gateway fronting any storage backend.

    image + chartApache-2.0

Apps & productivity

24
  • Appsmithplanned

    Low-code internal-tools and admin-panel builder backed by PostgreSQL and Redis.

    image + chartApache-2.0
  • Discourseplanned

    Ruby discussion and forum platform backed by PostgreSQL and Redis.

    image + chartGPL-2.0-or-lateragpl
  • Gotenbergplanned

    Stateless HTML and Office to PDF conversion API.

    image + chartMIT
  • Gristplanned

    Self-hosted spreadsheet-database hybrid, an Airtable alternative.

    image + chartApache-2.0
  • Homepageplanned

    Self-hosted services and bookmarks dashboard with widget integrations.

    image + chartGPL-3.0-onlyagpl
  • Joomlaplanned

    PHP CMS backed by MySQL or MariaDB.

    image + chartGPL-2.0-or-lateragpl
  • Mastodonplanned

    Federated social network server (Ruby plus Node) backed by PostgreSQL and Redis.

    image + chartAGPL-3.0-onlyagpl
  • MediaWikiplanned

    The wiki engine behind Wikipedia, backed by MySQL or MariaDB.

    image + chartGPL-2.0-or-later
  • Metabaseplanned

    Friendly self-service BI and analytics dashboards.

    image + chartAGPL-3.0agpl
  • Moodleplanned

    PHP learning management system backed by MySQL, MariaDB, or PostgreSQL.

    image + chartGPL-3.0-or-lateragpl
  • Odooplanned

    Python ERP and business apps suite (Community Edition) backed by PostgreSQL.

    image + chartLGPL-3.0-only
  • pgAdminplanned

    Web administration and management UI for PostgreSQL.

    image + chartPostgreSQL
  • phpMyAdminplanned

    PHP web administration UI for MySQL and MariaDB.

    image + chartGPL-2.0-onlyagpl
  • Redmineplanned

    Ruby on Rails project management and issue tracker backed by a relational database.

    image + chartGPL-2.0-or-lateragpl
  • Rocket.Chatplanned

    Self-hosted team chat platform backed by MongoDB.

    image + chartMIT
  • SuiteCRMplanned

    PHP customer relationship management application backed by MySQL or MariaDB.

    image + chartAGPL-3.0-onlyagpl
  • Backdrop CMSexploring

    Drupal fork focused on simplicity, backed by MySQL.

    image + chartGPL-2.0-or-later
  • Chromiumexploring

    Headless browser for rendering, scraping, and PDF export.

    image + chartBSD-3-Clause
  • Friendicaexploring

    Federated social network server.

    image + chartAGPL-3.0agpl
  • Mongo Expressexploring

    Web administration UI for MongoDB.

    image + chartMIT
  • Ploneexploring

    Python enterprise CMS on Zope.

    image + chartGPL-2.0-or-later
  • Selenium Gridexploring

    Distributed browser automation and testing grid.

    image + chartApache-2.0
  • XWikiexploring

    Enterprise wiki and structured collaboration platform.

    image + chartLGPL-2.1
  • YOURLSexploring

    Self-hosted URL shortener.

    image + chartMIT

Media & streaming

2
  • Apache Guacamoleplanned

    Clientless remote desktop gateway for RDP, VNC, and SSH over the browser.

    image + chartApache-2.0
  • Jellyfinplanned

    Self-hosted media server for movies, music, and live TV.

    image + chartGPL-2.0-onlyagpl

CI/CD & registry

21
  • Argo CDplanned

    Declarative GitOps continuous delivery for Kubernetes.

    image + chartApache-2.0
  • Argo Eventsplanned

    Event-driven workflow automation for Kubernetes.

    image + chartApache-2.0
  • Argo Rolloutsplanned

    Progressive delivery (canary, blue-green) for Kubernetes.

    image + chartApache-2.0
  • Concourseplanned

    Pipeline-based continuous integration system backed by PostgreSQL.

    image + chartApache-2.0
  • Crossplaneplanned

    Control-plane framework for managing cloud infrastructure via Kubernetes APIs.

    image + chartApache-2.0
  • Daprplanned

    Distributed application runtime providing building-block APIs for microservices.

    image + chartApache-2.0
  • Fluxplanned

    GitOps toolkit of controllers for continuous delivery on Kubernetes.

    image + chartApache-2.0
  • GitHub Actions Runnerplanned

    Self-hosted Actions runner — the runner the gitops-stack needs for a Gitea/Forgejo backend.

    image + chartMIT
  • GitLab Runnerplanned

    CI job executor for GitLab pipelines; also a gitops-stack runner option.

    image + chartMIT
  • Gogsplanned

    The original minimal Go Git service that Gitea forked from. Very small single-binary forge; an even lighter gitops-stack backend option.

    image + chartMIT
  • Jenkins Inbound Agentplanned

    Jenkins JNLP inbound build agent. Image only, no chart. Build held: jenkins-docker-agent carries a CRITICAL jetty CVE (fix 2.560-r0 not yet in Wolfi).

    image + chartMIT
  • Terralistplanned

    Private Terraform/OpenTofu registry for modules and providers (Go). Hardenable as a normal nonroot server image; unlocks the gitops-stack and registry-stack.

    image + chartMPL-2.0
  • vclusterplanned

    Virtual Kubernetes clusters inside a namespace.

    image + chartApache-2.0
  • Cluster Autoscalerexploring

    Scales Kubernetes node pools to match pending workloads.

    image + chartApache-2.0
  • GitLab CEexploring

    Full DevOps platform (Git forge + CI/CD + registry). Heavy fit: a large Ruby monolith that bundles PostgreSQL, Redis, Gitaly, Sidekiq and Workhorse, and the gitlab-org/gitlab repo is mostly EE-proprietary — only the CE-flagged code is MIT. Far from the minimal one-purpose hardened model.

    clean alt: Gitea or Forgejo — lightweight, fully-open Git forges that drop straight into the gitops-stack.

    image + chartMITcaution
  • KubeVirtexploring

    Run virtual machines as Kubernetes workloads.

    image + chartApache-2.0
  • kuredexploring

    Safe automated node reboots for Kubernetes.

    image + chartApache-2.0
  • OneDevexploring

    Self-hosted Git server with built-in CI/CD, issues and kanban (Java). Heavier than Gitea/Gogs but far lighter than GitLab; an all-in-one gitops-stack backend option.

    image + chartMIT
  • Reloaderexploring

    Rolls workloads when their ConfigMaps or Secrets change.

    image + chartApache-2.0
  • Terragruntexploring

    Thin Terraform/OpenTofu wrapper for DRY configurations.

    image + chartMIT
  • Vertical Pod Autoscalerexploring

    Recommends and applies pod CPU/memory requests.

    image + chartApache-2.0

Machine learning

11
  • JupyterHubplanned

    Multi-user Jupyter notebook server for teams and classrooms.

    image + chartBSD-3-Clause
  • KServeplanned

    Kubernetes model inference serving with autoscaling.

    image + chartApache-2.0
  • KubeRayplanned

    Operator for running Ray distributed-compute clusters on Kubernetes.

    image + chartApache-2.0
  • Label Studioplanned

    Data-labeling and annotation tool for ML datasets.

    image + chartApache-2.0
  • Langflowplanned

    Visual builder for LLM applications and agent workflows.

    image + chartMIT
  • Langfuseplanned

    LLM observability and tracing platform backed by PostgreSQL.

    image + chartMIT
  • Open WebUIplanned

    Self-hosted web UI for chatting with local and remote LLMs.

    image + chartBSD-3-Clause
  • AnythingLLMexploring

    Self-hosted chat-with-your-documents LLM application.

    image + chartMIT
  • DataHubexploring

    Metadata platform and data catalog.

    image + chartApache-2.0
  • Kubeflow Pipelinesexploring

    ML pipeline orchestration on Kubernetes.

    image + chartApache-2.0
  • TensorFlow Servingexploring

    High-performance serving system for TensorFlow models.

    image + chartApache-2.0

Security & supply chain

26
  • Buildahplanned

    Daemonless OCI image builder.

    image + chartApache-2.0
  • BuildKitplanned

    Concurrent container image build engine.

    image + chartApache-2.0
  • Checkovplanned

    Static security scanning for Terraform, Kubernetes, and more.

    image + chartApache-2.0
  • ClamAVplanned

    Open-source antivirus engine for scanning files and mail.

    image + chartGPL-2.0-onlyagpl
  • Craneplanned

    go-containerregistry CLI for registry interaction.

    image + chartApache-2.0
  • Daggerplanned

    Programmable CI/CD engine that runs pipelines in containers.

    image + chartApache-2.0
  • Falcoplanned

    Runtime security and threat detection using kernel and eBPF events.

    image + chartApache-2.0
  • Gitleaksplanned

    Secret scanner for git repos and files.

    image + chartMIT
  • Hadolintplanned

    Dockerfile linter.

    image + chartGPL-3.0agpl
  • Kanikoplanned

    Build container images inside Kubernetes without a daemon.

    image + chartApache-2.0
  • Kubescapeplanned

    Kubernetes security, posture, and compliance scanner.

    image + chartApache-2.0
  • Kubescape Operatorplanned

    In-cluster Kubescape components (operator, scanner, kubevuln) for continuous posture and vulnerability scanning. Distinct from the Kubescape CLI.

    image + chartApache-2.0
  • Notationplanned

    Notary v2 OCI artifact signing and verification.

    image + chartApache-2.0
  • ORASplanned

    Push and pull arbitrary artifacts to OCI registries.

    image + chartApache-2.0
  • Podmanplanned

    Daemonless container engine and Docker CLI replacement.

    image + chartApache-2.0
  • ShellCheckplanned

    Shell script static analysis linter.

    image + chartGPL-3.0agpl
  • Sigstoreplanned

    Keyless signing infrastructure including Fulcio CA and the Rekor transparency log.

    image + chartApache-2.0
  • Skopeoplanned

    Inspect and copy container images between registries.

    image + chartApache-2.0
  • Tetragonplanned

    eBPF-based runtime security observability and enforcement.

    image + chartApache-2.0
  • Trivy Operatorplanned

    In-cluster continuous Trivy scanning via CRDs.

    image + chartApache-2.0
  • Wazuhplanned

    SIEM and XDR platform with manager, indexer, and dashboard components.

    image + chartGPL-2.0-onlyagpl
  • Connaisseurexploring

    Admission controller enforcing image signature verification.

    image + chartApache-2.0
  • Diveexploring

    Explore container image layers and wasted space.

    image + chartMIT
  • koexploring

    Build and deploy Go container images with no Dockerfile.

    image + chartApache-2.0
  • OpenSCAPexploring

    SCAP compliance and vulnerability scanning.

    image + chartLGPL-2.1
  • TruffleHogexploring

    Deep secret scanner across repos and filesystems.

    image + chartAGPL-3.0agpl

Stacks

24
  • cache-stackplanned

    Umbrella: Valkey + redis-exporter + Grafana dashboards — cache with metrics. All components built; ready to build.

    image + chartApache-2.0
  • postgres-ha-stackplanned

    Umbrella: PostgreSQL + PgBouncer + postgres-exporter — pooled SQL with metrics. All components built; ready to build.

    image + chartApache-2.0
  • secrets-stackplanned

    Umbrella: OpenBao + Keycloak — SSO in front of secrets management. All components built; ready to build.

    image + chartApache-2.0
  • ai-stackexploring

    Ollama (or vLLM) + Open WebUI + Qdrant — self-hosted LLM serving, a chat UI, and a vector DB for retrieval-augmented generation. Qdrant is built; needs Ollama/vLLM + Open WebUI images.

    image + chartApache-2.0
  • analytics-stackexploring

    Apache Superset + Trino + PostgreSQL — federated SQL analytics with self-service BI dashboards. PostgreSQL is built; needs Superset + Trino.

    image + chartApache-2.0
  • backup-stackexploring

    Velero + MinIO — scheduled cluster backup/restore and PV snapshots to an in-cluster S3 target. Needs Velero + MinIO images.

    clean alt: Use any external S3 (SeaweedFS/Garage, already shipped) instead of MinIO to keep it fully Apache-2.0.

    image + chartApache-2.0
  • cost-stackexploring

    OpenCost + Prometheus + Grafana — Kubernetes cost monitoring and allocation dashboards; an add-on to the observability stack. Prometheus + Grafana are built; needs OpenCost.

    image + chartApache-2.0
  • gitops-stackexploring

    Umbrella: a pluggable Git backend + Atlantis + Terralist for Terraform/OpenTofu GitOps with a private module/provider registry. Pick your forge: Gitea (default, built) or Forgejo / Gogs (lightweight, clean) / OneDev (all-in-one) / GitLab CE (heavy, mixed license). Atlantis + Gitea charts built; needs a Terralist image, the chosen forge's image, and a runner — GitHub Actions Runner or GitLab Runner, both now on the roadmap (or run runner-less).

    image + chartApache-2.0
  • ingress-stackexploring

    Traefik (or ingress-nginx) + cert-manager + external-dns — production ingress with automatic TLS and DNS records. Traefik + external-dns are built; needs cert-manager.

    image + chartApache-2.0
  • lakehouse-stackexploring

    Trino + Apache Nessie (or Polaris) + MinIO — an Iceberg data lakehouse: query engine, versioned table catalog, and object store. Needs those images.

    image + chartApache-2.0
  • messaging-stackexploring

    Umbrella: Kafka + ZooKeeper (or NATS) + a console UI — event backbone. Needs a Kafka UI image first — AKHQ (Apache-2.0) is now on the roadmap for exactly this.

    image + chartApache-2.0
  • mongodb-ha-stackexploring

    Operator-based HA MongoDB: MongoDB Community Operator + a metrics exporter — replica-set failover. CRD-driven. The operator is Apache-2.0, but MongoDB itself is SSPL (not OSI), so the stack inherits that caution.

    clean alt: FerretDB (Apache-2.0) on the pg-ha-stack — a MongoDB-compatible, fully-open document database over PostgreSQL.

    image + chartSSPL-1.0caution
  • mysql-ha-stackexploring

    Operator-based HA MySQL: a MySQL operator (Percona XtraDB Cluster, or MariaDB Operator with Galera) + a metrics exporter — synchronous multi-primary replication and backups. CRD-driven. Needs the chosen operator image first.

    image + chartApache-2.0
  • orchestration-stackexploring

    Apache Airflow + PostgreSQL + Valkey — data-pipeline scheduling (Airflow needs a metadata DB and a broker). PostgreSQL + Valkey are built; needs Airflow.

    image + chartApache-2.0
  • pg-ha-stackexploring

    Operator-based HA PostgreSQL: CloudNativePG + PgBouncer + postgres-exporter — streaming replication, automated failover, and backups/PITR to object storage. NOTE: unlike the operator-free observability stacks, this is CRD-driven (it installs the CloudNativePG operator). Needs a CloudNativePG image first.

    image + chartApache-2.0
  • pki-stackexploring

    step-ca + cert-manager + trust-manager — an internal certificate authority with automated issuance and cluster-wide trust-bundle distribution. Needs those images.

    image + chartApache-2.0
  • policy-stackexploring

    Kyverno + Policy Reporter + Polaris (Fairwinds) — Kubernetes policy enforcement, violation reporting, and configuration best-practice validation. Operator-light (admission webhooks). Needs those images.

    image + chartApache-2.0
  • profiling-stackexploring

    Grafana Pyroscope + Grafana — continuous CPU/memory profiling; the missing 'P' that completes LGTM(P) alongside the observability/logging/tracing stacks. Needs a Pyroscope image.

    image + chartApache-2.0
  • registry-stackexploring

    Umbrella: Harbor (container images + OCI Helm charts + Trivy scanning) + Terralist (Terraform/OpenTofu modules & providers) — one self-hosted artifact registry for every kind of artifact. Harbor chart built; needs a Terralist image+chart.

    image + chartApache-2.0
  • runtime-security-stackexploring

    Falco + Tetragon — eBPF-based runtime threat detection and enforcement. Privileged host/kernel access by design (like node-exporter). Needs those images.

    image + chartApache-2.0
  • search-stackexploring

    Umbrella: OpenSearch + OpenSearch Dashboards — search with a UI. Needs an opensearch-dashboards image first.

    image + chartApache-2.0
  • streaming-stackexploring

    Kafka + Apache Flink + Apicurio Registry — end-to-end stream processing with schema governance. Kafka is built; needs Flink + Apicurio.

    image + chartApache-2.0
  • supply-chain-stackexploring

    Trivy Operator + Kubescape + Dependency-Track — continuous image, cluster-posture, and SBOM vulnerability scanning in one place. Needs those images.

    image + chartApache-2.0
  • temporal-stackexploring

    Umbrella: Temporal + Elasticsearch for advanced visibility. Marginal — the Temporal chart already bundles its own PostgreSQL, so a stack only adds optional ES visibility search.

    image + chartApache-2.0
blocked

Why some apps are held

QuenchWorks ships nothing that carries a fixable CVE. A few apps build cleanly but can't reach that bar yet: the app itself pins a dependency below the version that fixes a known CVE, so patching it would break the app's own declared constraints. Those are marked blocked: built and tested, held (not shipped) until upstream relaxes the pin or backports the fix. They go live the moment that lands. Nothing already in the catalog carries a known fixable CVE to get there faster.

Want something prioritized? Request an app and we will slot it into the roadmap.

blocked

Tested and held: cannot reach 0 fixable CVEs