Roadmap
What is shipped, what is next
195 datastores and tools are hardened and shipping today. Below is what is on deck, OSI-clean options first. Every entry is built from source on Wolfi, scanned to zero fixable CVEs, signed, and pinned by digest before it moves to available.
- 19543%
- Shipped
- 22149%
- On the roadmap
- 358%
- Blocked
Available now
195
Analytical
1
Apps & productivity
13
→
adminerApps & productivitystandard→
drupalApps & productivitystandard→
excalidrawApps & productivitystandard→
filebrowserApps & productivitystandard→
flociApps & productivitystandard→
floci-fullApps & productivitystandard→
ghostApps & productivitystandard→
mailpitApps & productivitystandard→
minifluxApps & productivitystandard→
nextcloudApps & productivitystandard→
pocketbaseApps & productivitystandard→
vikunjaApps & productivitystandard→
wordpressApps & productivitystandard
Base image
1
Build tool
7
CI/CD & registry
12
→
ansibleCI/CD & registrystandard→
buildkite-agentCI/CD & registrystandard→
chartmuseumCI/CD & registrystandard→
jenkinsCI/CD & registrystandard→
jenkins-inbound-agentCI/CD & registrystandard→
kubectlCI/CD & registrystandard→
opentofuCI/CD & registrystandard→
pulumiCI/CD & registrystandard→
renovateCI/CD & registrystandard→
sonar-scanner-cliCI/CD & registrystandard→
tektonCI/CD & registrystandard→
woodpeckerCI/CD & registrystandard
Cache
5
Coordination
5
Coordination & mesh
3
Database
1
Databases & engines
2
Developer tools / IDE
1
Document
5
Gateway
9
Graph
1
Identity
6
Language runtime
13
→
bunLanguage runtimestandard→
denoLanguage runtimestandard→
dotnetLanguage runtimestandard→
elixirLanguage runtimestandard→
erlangLanguage runtimestandard→
goLanguage runtimestandard→
jdkLanguage runtimestandard→
nodeLanguage runtimestandard→
perlLanguage runtimestandard→
phpLanguage runtimestandard→
pythonLanguage runtimestandard→
rubyLanguage runtimestandard→
rustLanguage runtimestandard
Machine learning & AI
3
Media & streaming
3
Messaging
11
Metrics/Exporter
4
Object storage
3
Observability
18
→
AlertmanagerObservabilitystandard→
cadvisorObservabilitystandard→
corootObservabilitystandard→
Fluent BitObservabilitystandard→
graylogObservabilitystandard→
jaegerObservabilitystandard→
jmeterObservabilitystandard→
k6Observabilitystandard→
kube-state-metricsObservabilitystandard→
LokiObservabilitystandard→
mimirObservabilitystandard→
OpenTelemetry CollectorObservabilitystandard→
persesObservabilitystandard→
PrometheusObservabilitystandard→
pyroscopeObservabilitystandard→
TempoObservabilitystandard→
VectorObservabilitystandard→
victorialogsObservabilitystandard
Registry
9
Relational
7
Runtime base
4
Search
6
Search & vector
1
Secrets & identity
2
Security & supply chain
13
→
cert-manager-acmesolverSecurity & supply chainstandard→
cert-manager-cainjectorSecurity & supply chainstandard→
cert-manager-controllerSecurity & supply chainstandard→
cert-manager-webhookSecurity & supply chainstandard→
cosignSecurity & supply chainstandard→
external-secretsSecurity & supply chainstandard→
grypeSecurity & supply chainstandard→
kyvernoSecurity & supply chainstandard→
opaSecurity & supply chainstandard→
sealed-secretsSecurity & supply chainstandard→
step-caSecurity & supply chainstandard→
syftSecurity & supply chainstandard→
trivySecurity & supply chainstandard
Storage & platform
3
Time series
4
Vector
1
Held — built, not shipped
35
These build and test clean but can't reach 0 fixable CVEs yet — the app or its base pins a dependency below the version that fixes a known CVE, so we hold it rather than ship a vulnerable image. Each re-lists automatically the moment upstream ships the fix. Tapwhy blocked? for the exact pin.
Apps & productivity
6
- Apache Supersetblocked
Data exploration and business-intelligence dashboard platform backed by a metadata database and Redis.
Apps & productivityApache-2.0 - Flociblocked
Local AWS cloud emulator and LocalStack Community successor, built from source into a Quarkus fast-jar on a hardened Wolfi JRE.
Apps & productivityMIT - Floci (full)blocked
Opt-in, NON-hardened companion to the floci image: it runs as root and expects the host Docker socket mounted, which lets it emulate all 65 of Floci's AWS services including the 10 Docker-backed ones (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune).
Apps & productivityMIT - Ghostblocked
Open-source Node.js publishing platform for blogs, newsletters, and membership sites.
Apps & productivityMIT - Matomoblocked
Privacy-respecting web analytics platform on PHP backed by MySQL or MariaDB.
Apps & productivityGPL-3.0-only - Nextcloudblocked
Nextcloud, the self-hosted file-sync and content-collaboration platform.
Apps & productivityAGPL-3.0-only
CI/CD & registry
2
- Gitnessblocked
Self-hosted Git hosting with built-in pipelines from Harness.
CI/CD & registryApache-2.0 - Jenkinsblocked
The leading open-source automation server for building, testing, and deploying software, with thousands of plugins.
CI/CD & registryMIT
Coordination
1
- Apache ZooKeeperblocked
Centralized coordination service for distributed systems, providing configuration, naming, leader election, and synchronization primitives.
CoordinationApache-2.0
Document
1
- FerretDBblocked
MongoDB-compatible document database that translates the MongoDB wire protocol onto PostgreSQL via the DocumentDB extension.
DocumentApache-2.0
Graph
1
- Neo4jblocked
Graph database for highly connected data, queried with Cypher for traversals and relationship-heavy workloads.
GraphGPL-3.0-only
Identity
3
- Autheliablocked
Open-source authentication and authorization server providing single sign-on and two-factor authentication via a web portal, designed as a companion for reverse proxies.
IdentityApache-2.0 - Keycloakblocked
Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.
IdentityApache-2.0 - ZITADELblocked
Cloud-native identity and access management (IAM) with OIDC/OAuth2/SAML, multi-tenancy, and a built-in admin console.
IdentityAGPL-3.0-only
Messaging
3
- Apache Kafkablocked
Distributed event-streaming platform for high-throughput, durable, replayable publish-subscribe pipelines and stream processing.
MessagingApache-2.0 - Apache Pulsarblocked
Cloud-native distributed messaging and streaming platform with multi-tenancy, geo-replication, and tiered storage that separates compute from storage.
MessagingApache-2.0 - Mattermostblocked
Open-source, self-hosted team messaging and collaboration platform (a Slack alternative) with channels, direct messages, file sharing, and integrations.
MessagingAGPL-3.0-only
Observability
9
- Apache JMeterblocked
Apache JMeter load-testing and performance-measurement tool, the official binary distribution running on a hardened Wolfi JRE.
ObservabilityApache-2.0 - Apache SkyWalkingblocked
APM: distributed tracing, metrics, and service-topology analysis. [blocked: upstream CVEs / ES9 unsupported]
ObservabilityApache-2.0 - Grafanablocked
Dashboards and visualization for metrics, logs, and traces across many data sources.
ObservabilityAGPL-3.0-only - Grafana Alloyblocked
OpenTelemetry-based collector distribution for metrics, logs, traces, and profiles.
ObservabilityApache-2.0 - Graylogblocked
Graylog, the log-management and analysis server (search, dashboards, alerting, GELF/Beats inputs).
ObservabilitySSPL-1.0 - metrics-serverblocked
Kubernetes resource-metrics API for HPA and kubectl top.
ObservabilityApache-2.0 - OpenSearch Dashboardsblocked
Visualization and dashboards UI for OpenSearch.
ObservabilityApache-2.0 - Telegrafblocked
Plugin-driven metrics collection agent from the InfluxData ecosystem.
ObservabilityMIT - Thanosblocked
Highly-available Prometheus setup with unlimited metric retention via object storage, adding a global query view, downsampling, and compaction across Prometheus servers.
ObservabilityApache-2.0
PaaS
1
- Coolify Helperblocked
Coolify helper image carrying the build and deploy toolchain (buildpacks, git, ssh) that runs on target hosts to execute deployments. [blocked: upstream CVEs / ES9 unsupported]
PaaSApache-2.0 AND AGPL-3.0-or-later
Relational
1
- CockroachDBblocked
Distributed SQL database with PostgreSQL wire compatibility and automatic horizontal scaling and survivability.
RelationalBUSL-1.1
Search
3
- Apache Solrblocked
Enterprise search platform built on Apache Lucene, offering full-text search, faceting, and indexing over large document collections.
SearchApache-2.0 - Elasticsearchblocked
Distributed search and analytics engine.
SearchSSPL-1.0 - OpenSearchblocked
Search and analytics suite with a Kibana-style dashboards UI.
SearchApache-2.0
Secrets & identity
2
- Ory Hydrablocked
OAuth 2.0 and OpenID Connect provider backed by a relational database.
Secrets & identityApache-2.0 - Ory Kratosblocked
Identity and user-management server for login, registration, and MFA.
Secrets & identityApache-2.0
Security & supply chain
1
- Grypeblocked
Anchore's vulnerability scanner for container images and filesystems, driven by the same SBOM engine as Syft.
Security & supply chainApache-2.0
Workflow & data
1
- n8nblocked
Fair-code workflow automation with native AI. Source-available, not OSI.
Workflow & dataSustainable Use License
On the roadmap
221
Candidates, not commitments. next = strongest near-term picks;planned and exploring follow. Items marked caution are source-available (not OSI) and would ship only with a loud license note and the clean alternative called out. (Apps that build but can't hit 0 fixable CVEs yet are in Held, above.) Each card also shows how it will ship: image + chart for a deployable service, orimage only for a base/CLI/sidecar utility (like busybox).
Secrets & identity
12
- Dependency-Trackplanned
SBOM and component-vulnerability analysis platform backed by a relational database.
image + chartApache-2.0 - EJBCAplanned
Enterprise PKI certificate authority (Community Edition) backed by a relational database.
image + chartLGPL-2.1-or-later - OPA Gatekeeperplanned
OPA policy admission controller for Kubernetes.
image + chartApache-2.0 - OpenLDAPplanned
LDAP directory server for centralized authentication and user data.
image + chartOLDAP-2.8 - Pinnipedplanned
Authentication for Kubernetes clusters federating external identity providers.
image + chartApache-2.0 - Sealed Secretsplanned
Encrypts Kubernetes Secrets so they can be stored safely in Git.
image + chartApache-2.0 - Secrets Store CSI Driverplanned
CSI driver that mounts secrets from external stores (Vault, cloud KMS) as volumes.
image + chartApache-2.0 - SPIREplanned
SPIFFE runtime for issuing workload identities across a fleet.
image + chartApache-2.0 - Teleportplanned
Access plane providing identity-based SSH, Kubernetes, and database access. Community edition is AGPL-3.0.
image + chartAGPL-3.0-onlyagpl - Vaultplanned
HashiCorp Vault. Source-available, not OSI.
clean alt: OpenBao (MPL-2.0) — the open fork, already shipped.
image + chartBUSL-1.1caution - Polaris (Fairwinds)exploring
Kubernetes configuration best-practice validation.
image + chartApache-2.0 - SATOSAexploring
Proxy that translates between SAML and OIDC.
image + chartApache-2.0
Gateways & proxies
14
- Apache APISIXplanned
Dynamic API gateway on Nginx + LuaJIT: hot-reloads plugins and config from etcd, with no relational-database dependency. A high-performance Kong alternative.
image + chartApache-2.0 - Contourplanned
Envoy-based Kubernetes ingress controller.
image + chartApache-2.0 - Envoy Gatewayplanned
CNCF implementation of the Kubernetes Gateway API on Envoy: standard K8s resources instead of vendor CRDs. The Kubernetes-first Kong alternative.
image + chartApache-2.0 - Gloo Edgeplanned
Envoy-based gateway for microservices, monoliths, and serverless, with strong multi-protocol support: HTTP, gRPC, WebSockets, and FaaS.
image + chartApache-2.0 - Jettyplanned
Lightweight Eclipse Jetty servlet server.
image + chartApache-2.0 - Kong Gatewayplanned
API gateway on nginx/OpenResty. Open-core (the OSS gateway is Apache-2.0; many features are gated behind the enterprise tier) and it depends on PostgreSQL. APISIX and Tyk are lighter, fully-open alternatives.
image + chartApache-2.0 - KrakenDplanned
Stateless high-performance API gateway.
image + chartApache-2.0 - NGINX Unitplanned
Polyglot application server from the nginx team.
image + chartApache-2.0 - OpenRestyplanned
nginx + LuaJIT platform for scriptable web apps and gateways.
image + chartBSD-2-Clause - Squidplanned
Caching and forwarding HTTP proxy.
image + chartGPL-2.0-or-lateragpl - Varnishplanned
HTTP caching reverse proxy and web accelerator.
image + chartBSD-2-Clause - WildFlyplanned
JBoss Jakarta EE application server.
image + chartLGPL-2.1 - Apache TomEEexploring
Tomcat plus the Jakarta EE stack.
image + chartApache-2.0 - Emissary-ingressexploring
Envoy-based Kubernetes API gateway / ingress.
image + chartApache-2.0
AI gateway
2
- Bifrostplanned
High-performance Go AI gateway: unified access, load balancing, and failover across 20+ LLM providers with near-zero overhead. An open alternative to bolt-on AI-gateway plugins.
image + chartApache-2.0 - LiteLLMplanned
Lightweight Python proxy exposing one OpenAI-compatible API to call, monitor, and cost-map 100+ LLM providers.
image + chartMIT
Observability
15
- Fluentdplanned
Unified logging layer for collecting, parsing, and routing logs.
image + chartApache-2.0 - Kibanaplanned
Visualization and dashboards for Elasticsearch. Default distribution is Elastic-2.0, not OSI.
clean alt: OpenSearch Dashboards (Apache-2.0) over OpenSearch, both open.
image + chartElastic-2.0caution - Logstashplanned
Server-side log and event processing pipeline. Default distribution is Elastic-2.0, not OSI.
clean alt: Vector (MPL-2.0) or Fluentd (Apache-2.0), both open pipelines.
image + chartElastic-2.0caution - mongodb-exporterplanned
Prometheus exporter for MongoDB metrics.
image + chartApache-2.0 - mysqld-exporterplanned
Prometheus exporter for MySQL/MariaDB metrics.
image + chartApache-2.0 - Netdataplanned
Real-time per-second infrastructure monitoring agent.
image + chartGPL-3.0agpl - OpenCostplanned
Kubernetes cost monitoring and allocation (CNCF).
image + chartApache-2.0 - OpenTelemetry Operatorplanned
Operator that manages OpenTelemetry Collector instances and auto-instrumentation.
image + chartApache-2.0 - Percona PMMplanned
Percona Monitoring and Management — deep MySQL/PostgreSQL/MongoDB observability (query analytics) built on Prometheus, Grafana and VictoriaMetrics. AGPL, OSI-approved.
image + chartAGPL-3.0 - Promtailplanned
Loki's agent for shipping pod and file logs.
image + chartApache-2.0 - Uptime Kumaplanned
Self-hosted uptime and status-page monitor.
image + chartMIT - Zabbixplanned
Infrastructure and network monitoring platform; version 7 and later is AGPL-3.0.
image + chartAGPL-3.0-onlyagpl - Zipkinplanned
Distributed tracing system for collecting and querying timing data.
image + chartApache-2.0 - Cortexexploring
Horizontally scalable, multi-tenant Prometheus storage.
image + chartApache-2.0 - kafka-exporterexploring
Prometheus exporter for Kafka lag and topic metrics.
image + chartApache-2.0
Search & vector
1
- Milvusplanned
Scalable vector database for AI workloads.
image + chartApache-2.0
Workflow & data
17
- Ansibleplanned
Agentless IT automation and configuration management.
image + chartGPL-3.0agpl - Apache Druidplanned
Real-time analytics database for high-concurrency OLAP queries.
image + chartApache-2.0 - Apache Flinkplanned
Stateful stream processing.
image + chartApache-2.0 - Apache NiFiplanned
Visual dataflow automation for routing, transforming, and mediating data.
image + chartApache-2.0 - Apache Pinotplanned
Real-time distributed OLAP datastore for low-latency analytics.
image + chartApache-2.0 - Apache Sparkplanned
Unified batch and stream analytics engine.
image + chartApache-2.0 - Camundaplanned
Process automation and BPMN orchestration including the Zeebe engine.
image + chartApache-2.0 - Dagsterplanned
Data orchestrator for ML and analytics pipelines.
image + chartApache-2.0 - Prefectplanned
Python-native workflow orchestration server for data pipelines.
image + chartApache-2.0 - Trinoplanned
Distributed SQL query engine for federated analytics across data sources.
image + chartApache-2.0 - Unleashplanned
Feature-flag and toggle management server backed by PostgreSQL.
image + chartApache-2.0 - WireMockplanned
HTTP API mock server for testing.
image + chartApache-2.0 - Apache Camel Kexploring
Kubernetes-native integration framework.
image + chartApache-2.0 - Apache Polarisexploring
Open REST catalog for Apache Iceberg tables.
image + chartApache-2.0 - Apache Tikaexploring
Content and metadata extraction toolkit.
image + chartApache-2.0 - Cubeexploring
Semantic layer and analytics API over your data.
image + chartApache-2.0 - Hyperledger Fabricexploring
Permissioned enterprise blockchain platform.
image + chartApache-2.0
Messaging & streaming
7
- AKHQplanned
Web UI to manage and browse Kafka — the console the messaging-stack needs.
image + chartApache-2.0 - Apache ActiveMQplanned
Java JMS message broker, including the Artemis next-generation engine.
image + chartApache-2.0 - Apicurio Registryplanned
API and schema registry for Kafka, Avro, and Protobuf.
image + chartApache-2.0 - Karapaceplanned
Open schema registry and REST proxy for Kafka; an Apache-licensed alternative to the Confluent Community schema-registry.
image + chartApache-2.0 - Redpandaplanned
Kafka-compatible streaming. Source-available, not OSI.
clean alt: Kafka or Pulsar (Apache-2.0), both already shipped.
image + chartBSL-1.1caution - Strimziplanned
Kubernetes operator for running and managing Kafka.
image + chartApache-2.0 - Apache Stormexploring
Distributed real-time stream processing.
image + chartApache-2.0
Coordination & mesh
13
- Calicoplanned
eBPF/iptables CNI for networking and network policy.
image + chartApache-2.0 - Ciliumplanned
eBPF-based networking, security, and observability for Kubernetes.
image + chartApache-2.0 - Consulplanned
Service discovery and mesh. Source-available, not OSI.
clean alt: etcd (Apache-2.0) for KV/coordination, already shipped.
image + chartBUSL-1.1caution - Istioplanned
Service mesh built on Envoy: traffic management, mTLS, and observability. Platform-scale, a multi-image wave (istiod control plane plus Envoy sidecars and gateways) rather than a single image.
image + chartApache-2.0 - Linkerdplanned
Lightweight service mesh.
image + chartApache-2.0 - MetalLBplanned
Load-balancer implementation for bare-metal Kubernetes clusters.
image + chartApache-2.0 - Nomadplanned
Workload scheduler. Source-available, not OSI.
image + chartBUSL-1.1caution - PowerDNSplanned
Authoritative DNS server and recursor with database backends.
image + chartGPL-2.0-onlyagpl - Unboundplanned
Validating, recursive, caching DNS resolver.
image + chartBSD-3-Clause - BIND 9exploring
Authoritative and recursive DNS server.
image + chartMPL-2.0 - FRRoutingexploring
Internet routing protocol suite (BGP, OSPF, etc.).
image + chartGPL-2.0 - kube-vipexploring
Virtual IP and load balancer for the control plane and services.
image + chartApache-2.0 - Tailscaleexploring
WireGuard-based mesh VPN with a Kubernetes operator.
image + chartBSD-3-Clause
Databases & engines
23
- Apache Kvrocksplanned
Redis-protocol key-value database persisted on RocksDB.
image + chartApache-2.0 - Apache Nessieplanned
Transactional catalog and versioning for data lakehouse tables.
image + chartApache-2.0 - ArangoDBplanned
Multi-model database for documents, graphs, and key-value (Community Edition).
image + chartApache-2.0 - CloudNativePGplanned
Kubernetes operator for PostgreSQL HA: streaming replication, automated failover, and backups/PITR to object storage, all via CRDs. CNCF project; the modern operator behind the pg-ha-stack.
image + chartApache-2.0 - CrateDBplanned
Distributed SQL database for time-series and search.
image + chartApache-2.0 - Flywayplanned
Versioned SQL database migrations.
image + chartApache-2.0 - Hasura GraphQL Engineplanned
Instant GraphQL API over PostgreSQL and other databases.
image + chartApache-2.0 - JanusGraphplanned
Distributed graph database over pluggable storage backends.
image + chartApache-2.0 - KeyDBplanned
Multi-threaded Redis fork; BSD-licensed and Redis-protocol compatible.
image + chartBSD-3-Clause - Liquibaseplanned
Database schema change and migration management.
image + chartApache-2.0 - MariaDB Operatorplanned
Kubernetes operator for MariaDB/MySQL: provisioning, Galera multi-primary HA, replication, backups, and user/grant management via CRDs.
image + chartMIT - MongoDB Community Operatorplanned
MongoDB Community Kubernetes Operator: replica-set HA, automated failover, and TLS via CRDs. The operator is Apache-2.0; note the MongoDB server it deploys is SSPL (not OSI).
image + chartApache-2.0 - Percona XtraDB Cluster Operatorplanned
Operator for Percona XtraDB Cluster (MySQL): synchronous multi-primary HA via Galera, with automated backups and point-in-time recovery.
image + chartApache-2.0 - Pgpool-IIplanned
Connection pooling, load balancing, and replication middleware for PostgreSQL.
image + chartBSD-3-Clause - pgvectorplanned
PostgreSQL with the pgvector extension for vector similarity search.
image + chartPostgreSQL - ProxySQLplanned
High-performance proxy for MySQL/MariaDB.
image + chartGPL-3.0agpl - RethinkDBplanned
Realtime document database with live queries.
image + chartApache-2.0 - SurrealDBplanned
Multi-model database. Source-available, not OSI.
image + chartBUSL-1.1caution - Vitessplanned
Horizontal sharding for MySQL.
image + chartApache-2.0 - Aerospikeexploring
Real-time key-value database; community edition is AGPL.
image + chartAGPL-3.0agpl - Couchbaseexploring
Distributed document database. Source-available, not OSI.
clean alt: CouchDB (Apache-2.0), already shipped.
image + chartBSL-1.1caution - OrientDBexploring
Multi-model graph and document database.
image + chartApache-2.0 - Tiny RDMexploring
Modern Redis/Valkey desktop GUI (Wails/Go+Vue). A desktop client, not a deployable server, so it falls outside the hardened in-cluster image model — a web Redis UI (e.g. redis-commander) would be the cache-stack UI instead.
image + chartGPL-3.0agpl
Storage & platform
9
- Apache Ozoneplanned
Scalable distributed object store (S3 + HDFS).
image + chartApache-2.0 - Dokployplanned
Self-hostable PaaS on Docker Swarm. Open-core: most is Apache-2.0, the /proprietary parts are source-available (DSAL-1.0). Not a fit for the hardened catalog: it requires root, the Docker socket, and an initialized Swarm, so it cannot run nonroot or read-only.
clean alt: Coolify (Apache-2.0), already shipped.
image + chartApache-2.0 + DSAL-1.0caution - Kuboplanned
Reference IPFS implementation for distributed content-addressed storage.
image + chartMIT - Longhornplanned
Distributed block storage for Kubernetes with snapshots and backups.
image + chartApache-2.0 - MinIOplanned
S3-compatible object storage; relicensed to AGPL-3.0.
clean alt: SeaweedFS / Garage / RustFS (Apache-2.0), all already shipped.
image + chartAGPL-3.0agpl - SonarQubeplanned
Continuous code-quality and security inspection.
image + chartLGPL-3.0 - Woodpecker CIplanned
Simple container-native CI engine.
image + chartApache-2.0 - Rookexploring
Ceph storage orchestrator for Kubernetes (block/object/file).
image + chartApache-2.0 - Versity Gatewayexploring
S3-compatible gateway fronting any storage backend.
image + chartApache-2.0
Apps & productivity
24
- Appsmithplanned
Low-code internal-tools and admin-panel builder backed by PostgreSQL and Redis.
image + chartApache-2.0 - Discourseplanned
Ruby discussion and forum platform backed by PostgreSQL and Redis.
image + chartGPL-2.0-or-lateragpl - Gotenbergplanned
Stateless HTML and Office to PDF conversion API.
image + chartMIT - Gristplanned
Self-hosted spreadsheet-database hybrid, an Airtable alternative.
image + chartApache-2.0 - Homepageplanned
Self-hosted services and bookmarks dashboard with widget integrations.
image + chartGPL-3.0-onlyagpl - Joomlaplanned
PHP CMS backed by MySQL or MariaDB.
image + chartGPL-2.0-or-lateragpl - Mastodonplanned
Federated social network server (Ruby plus Node) backed by PostgreSQL and Redis.
image + chartAGPL-3.0-onlyagpl - MediaWikiplanned
The wiki engine behind Wikipedia, backed by MySQL or MariaDB.
image + chartGPL-2.0-or-later - Metabaseplanned
Friendly self-service BI and analytics dashboards.
image + chartAGPL-3.0agpl - Moodleplanned
PHP learning management system backed by MySQL, MariaDB, or PostgreSQL.
image + chartGPL-3.0-or-lateragpl - Odooplanned
Python ERP and business apps suite (Community Edition) backed by PostgreSQL.
image + chartLGPL-3.0-only - pgAdminplanned
Web administration and management UI for PostgreSQL.
image + chartPostgreSQL - phpMyAdminplanned
PHP web administration UI for MySQL and MariaDB.
image + chartGPL-2.0-onlyagpl - Redmineplanned
Ruby on Rails project management and issue tracker backed by a relational database.
image + chartGPL-2.0-or-lateragpl - Rocket.Chatplanned
Self-hosted team chat platform backed by MongoDB.
image + chartMIT - SuiteCRMplanned
PHP customer relationship management application backed by MySQL or MariaDB.
image + chartAGPL-3.0-onlyagpl - Backdrop CMSexploring
Drupal fork focused on simplicity, backed by MySQL.
image + chartGPL-2.0-or-later - Chromiumexploring
Headless browser for rendering, scraping, and PDF export.
image + chartBSD-3-Clause - Friendicaexploring
Federated social network server.
image + chartAGPL-3.0agpl - Mongo Expressexploring
Web administration UI for MongoDB.
image + chartMIT - Ploneexploring
Python enterprise CMS on Zope.
image + chartGPL-2.0-or-later - Selenium Gridexploring
Distributed browser automation and testing grid.
image + chartApache-2.0 - XWikiexploring
Enterprise wiki and structured collaboration platform.
image + chartLGPL-2.1 - YOURLSexploring
Self-hosted URL shortener.
image + chartMIT
Media & streaming
2
- Apache Guacamoleplanned
Clientless remote desktop gateway for RDP, VNC, and SSH over the browser.
image + chartApache-2.0 - Jellyfinplanned
Self-hosted media server for movies, music, and live TV.
image + chartGPL-2.0-onlyagpl
CI/CD & registry
21
- Argo CDplanned
Declarative GitOps continuous delivery for Kubernetes.
image + chartApache-2.0 - Argo Eventsplanned
Event-driven workflow automation for Kubernetes.
image + chartApache-2.0 - Argo Rolloutsplanned
Progressive delivery (canary, blue-green) for Kubernetes.
image + chartApache-2.0 - Concourseplanned
Pipeline-based continuous integration system backed by PostgreSQL.
image + chartApache-2.0 - Crossplaneplanned
Control-plane framework for managing cloud infrastructure via Kubernetes APIs.
image + chartApache-2.0 - Daprplanned
Distributed application runtime providing building-block APIs for microservices.
image + chartApache-2.0 - Fluxplanned
GitOps toolkit of controllers for continuous delivery on Kubernetes.
image + chartApache-2.0 - GitHub Actions Runnerplanned
Self-hosted Actions runner — the runner the gitops-stack needs for a Gitea/Forgejo backend.
image + chartMIT - GitLab Runnerplanned
CI job executor for GitLab pipelines; also a gitops-stack runner option.
image + chartMIT - Gogsplanned
The original minimal Go Git service that Gitea forked from. Very small single-binary forge; an even lighter gitops-stack backend option.
image + chartMIT - Jenkins Inbound Agentplanned
Jenkins JNLP inbound build agent. Image only, no chart. Build held: jenkins-docker-agent carries a CRITICAL jetty CVE (fix 2.560-r0 not yet in Wolfi).
image + chartMIT - Terralistplanned
Private Terraform/OpenTofu registry for modules and providers (Go). Hardenable as a normal nonroot server image; unlocks the gitops-stack and registry-stack.
image + chartMPL-2.0 - vclusterplanned
Virtual Kubernetes clusters inside a namespace.
image + chartApache-2.0 - Cluster Autoscalerexploring
Scales Kubernetes node pools to match pending workloads.
image + chartApache-2.0 - GitLab CEexploring
Full DevOps platform (Git forge + CI/CD + registry). Heavy fit: a large Ruby monolith that bundles PostgreSQL, Redis, Gitaly, Sidekiq and Workhorse, and the gitlab-org/gitlab repo is mostly EE-proprietary — only the CE-flagged code is MIT. Far from the minimal one-purpose hardened model.
clean alt: Gitea or Forgejo — lightweight, fully-open Git forges that drop straight into the gitops-stack.
image + chartMITcaution - KubeVirtexploring
Run virtual machines as Kubernetes workloads.
image + chartApache-2.0 - kuredexploring
Safe automated node reboots for Kubernetes.
image + chartApache-2.0 - OneDevexploring
Self-hosted Git server with built-in CI/CD, issues and kanban (Java). Heavier than Gitea/Gogs but far lighter than GitLab; an all-in-one gitops-stack backend option.
image + chartMIT - Reloaderexploring
Rolls workloads when their ConfigMaps or Secrets change.
image + chartApache-2.0 - Terragruntexploring
Thin Terraform/OpenTofu wrapper for DRY configurations.
image + chartMIT - Vertical Pod Autoscalerexploring
Recommends and applies pod CPU/memory requests.
image + chartApache-2.0
Machine learning
11
- JupyterHubplanned
Multi-user Jupyter notebook server for teams and classrooms.
image + chartBSD-3-Clause - KServeplanned
Kubernetes model inference serving with autoscaling.
image + chartApache-2.0 - KubeRayplanned
Operator for running Ray distributed-compute clusters on Kubernetes.
image + chartApache-2.0 - Label Studioplanned
Data-labeling and annotation tool for ML datasets.
image + chartApache-2.0 - Langflowplanned
Visual builder for LLM applications and agent workflows.
image + chartMIT - Langfuseplanned
LLM observability and tracing platform backed by PostgreSQL.
image + chartMIT - Open WebUIplanned
Self-hosted web UI for chatting with local and remote LLMs.
image + chartBSD-3-Clause - AnythingLLMexploring
Self-hosted chat-with-your-documents LLM application.
image + chartMIT - DataHubexploring
Metadata platform and data catalog.
image + chartApache-2.0 - Kubeflow Pipelinesexploring
ML pipeline orchestration on Kubernetes.
image + chartApache-2.0 - TensorFlow Servingexploring
High-performance serving system for TensorFlow models.
image + chartApache-2.0
Security & supply chain
26
- Buildahplanned
Daemonless OCI image builder.
image + chartApache-2.0 - BuildKitplanned
Concurrent container image build engine.
image + chartApache-2.0 - Checkovplanned
Static security scanning for Terraform, Kubernetes, and more.
image + chartApache-2.0 - ClamAVplanned
Open-source antivirus engine for scanning files and mail.
image + chartGPL-2.0-onlyagpl - Craneplanned
go-containerregistry CLI for registry interaction.
image + chartApache-2.0 - Daggerplanned
Programmable CI/CD engine that runs pipelines in containers.
image + chartApache-2.0 - Falcoplanned
Runtime security and threat detection using kernel and eBPF events.
image + chartApache-2.0 - Gitleaksplanned
Secret scanner for git repos and files.
image + chartMIT - Hadolintplanned
Dockerfile linter.
image + chartGPL-3.0agpl - Kanikoplanned
Build container images inside Kubernetes without a daemon.
image + chartApache-2.0 - Kubescapeplanned
Kubernetes security, posture, and compliance scanner.
image + chartApache-2.0 - Kubescape Operatorplanned
In-cluster Kubescape components (operator, scanner, kubevuln) for continuous posture and vulnerability scanning. Distinct from the Kubescape CLI.
image + chartApache-2.0 - Notationplanned
Notary v2 OCI artifact signing and verification.
image + chartApache-2.0 - ORASplanned
Push and pull arbitrary artifacts to OCI registries.
image + chartApache-2.0 - Podmanplanned
Daemonless container engine and Docker CLI replacement.
image + chartApache-2.0 - ShellCheckplanned
Shell script static analysis linter.
image + chartGPL-3.0agpl - Sigstoreplanned
Keyless signing infrastructure including Fulcio CA and the Rekor transparency log.
image + chartApache-2.0 - Skopeoplanned
Inspect and copy container images between registries.
image + chartApache-2.0 - Tetragonplanned
eBPF-based runtime security observability and enforcement.
image + chartApache-2.0 - Trivy Operatorplanned
In-cluster continuous Trivy scanning via CRDs.
image + chartApache-2.0 - Wazuhplanned
SIEM and XDR platform with manager, indexer, and dashboard components.
image + chartGPL-2.0-onlyagpl - Connaisseurexploring
Admission controller enforcing image signature verification.
image + chartApache-2.0 - Diveexploring
Explore container image layers and wasted space.
image + chartMIT - koexploring
Build and deploy Go container images with no Dockerfile.
image + chartApache-2.0 - OpenSCAPexploring
SCAP compliance and vulnerability scanning.
image + chartLGPL-2.1 - TruffleHogexploring
Deep secret scanner across repos and filesystems.
image + chartAGPL-3.0agpl
Stacks
24
- cache-stackplanned
Umbrella: Valkey + redis-exporter + Grafana dashboards — cache with metrics. All components built; ready to build.
image + chartApache-2.0 - postgres-ha-stackplanned
Umbrella: PostgreSQL + PgBouncer + postgres-exporter — pooled SQL with metrics. All components built; ready to build.
image + chartApache-2.0 - secrets-stackplanned
Umbrella: OpenBao + Keycloak — SSO in front of secrets management. All components built; ready to build.
image + chartApache-2.0 - ai-stackexploring
Ollama (or vLLM) + Open WebUI + Qdrant — self-hosted LLM serving, a chat UI, and a vector DB for retrieval-augmented generation. Qdrant is built; needs Ollama/vLLM + Open WebUI images.
image + chartApache-2.0 - analytics-stackexploring
Apache Superset + Trino + PostgreSQL — federated SQL analytics with self-service BI dashboards. PostgreSQL is built; needs Superset + Trino.
image + chartApache-2.0 - backup-stackexploring
Velero + MinIO — scheduled cluster backup/restore and PV snapshots to an in-cluster S3 target. Needs Velero + MinIO images.
clean alt: Use any external S3 (SeaweedFS/Garage, already shipped) instead of MinIO to keep it fully Apache-2.0.
image + chartApache-2.0 - cost-stackexploring
OpenCost + Prometheus + Grafana — Kubernetes cost monitoring and allocation dashboards; an add-on to the observability stack. Prometheus + Grafana are built; needs OpenCost.
image + chartApache-2.0 - gitops-stackexploring
Umbrella: a pluggable Git backend + Atlantis + Terralist for Terraform/OpenTofu GitOps with a private module/provider registry. Pick your forge: Gitea (default, built) or Forgejo / Gogs (lightweight, clean) / OneDev (all-in-one) / GitLab CE (heavy, mixed license). Atlantis + Gitea charts built; needs a Terralist image, the chosen forge's image, and a runner — GitHub Actions Runner or GitLab Runner, both now on the roadmap (or run runner-less).
image + chartApache-2.0 - ingress-stackexploring
Traefik (or ingress-nginx) + cert-manager + external-dns — production ingress with automatic TLS and DNS records. Traefik + external-dns are built; needs cert-manager.
image + chartApache-2.0 - lakehouse-stackexploring
Trino + Apache Nessie (or Polaris) + MinIO — an Iceberg data lakehouse: query engine, versioned table catalog, and object store. Needs those images.
image + chartApache-2.0 - messaging-stackexploring
Umbrella: Kafka + ZooKeeper (or NATS) + a console UI — event backbone. Needs a Kafka UI image first — AKHQ (Apache-2.0) is now on the roadmap for exactly this.
image + chartApache-2.0 - mongodb-ha-stackexploring
Operator-based HA MongoDB: MongoDB Community Operator + a metrics exporter — replica-set failover. CRD-driven. The operator is Apache-2.0, but MongoDB itself is SSPL (not OSI), so the stack inherits that caution.
clean alt: FerretDB (Apache-2.0) on the pg-ha-stack — a MongoDB-compatible, fully-open document database over PostgreSQL.
image + chartSSPL-1.0caution - mysql-ha-stackexploring
Operator-based HA MySQL: a MySQL operator (Percona XtraDB Cluster, or MariaDB Operator with Galera) + a metrics exporter — synchronous multi-primary replication and backups. CRD-driven. Needs the chosen operator image first.
image + chartApache-2.0 - orchestration-stackexploring
Apache Airflow + PostgreSQL + Valkey — data-pipeline scheduling (Airflow needs a metadata DB and a broker). PostgreSQL + Valkey are built; needs Airflow.
image + chartApache-2.0 - pg-ha-stackexploring
Operator-based HA PostgreSQL: CloudNativePG + PgBouncer + postgres-exporter — streaming replication, automated failover, and backups/PITR to object storage. NOTE: unlike the operator-free observability stacks, this is CRD-driven (it installs the CloudNativePG operator). Needs a CloudNativePG image first.
image + chartApache-2.0 - pki-stackexploring
step-ca + cert-manager + trust-manager — an internal certificate authority with automated issuance and cluster-wide trust-bundle distribution. Needs those images.
image + chartApache-2.0 - policy-stackexploring
Kyverno + Policy Reporter + Polaris (Fairwinds) — Kubernetes policy enforcement, violation reporting, and configuration best-practice validation. Operator-light (admission webhooks). Needs those images.
image + chartApache-2.0 - profiling-stackexploring
Grafana Pyroscope + Grafana — continuous CPU/memory profiling; the missing 'P' that completes LGTM(P) alongside the observability/logging/tracing stacks. Needs a Pyroscope image.
image + chartApache-2.0 - registry-stackexploring
Umbrella: Harbor (container images + OCI Helm charts + Trivy scanning) + Terralist (Terraform/OpenTofu modules & providers) — one self-hosted artifact registry for every kind of artifact. Harbor chart built; needs a Terralist image+chart.
image + chartApache-2.0 - runtime-security-stackexploring
Falco + Tetragon — eBPF-based runtime threat detection and enforcement. Privileged host/kernel access by design (like node-exporter). Needs those images.
image + chartApache-2.0 - search-stackexploring
Umbrella: OpenSearch + OpenSearch Dashboards — search with a UI. Needs an opensearch-dashboards image first.
image + chartApache-2.0 - streaming-stackexploring
Kafka + Apache Flink + Apicurio Registry — end-to-end stream processing with schema governance. Kafka is built; needs Flink + Apicurio.
image + chartApache-2.0 - supply-chain-stackexploring
Trivy Operator + Kubescape + Dependency-Track — continuous image, cluster-posture, and SBOM vulnerability scanning in one place. Needs those images.
image + chartApache-2.0 - temporal-stackexploring
Umbrella: Temporal + Elasticsearch for advanced visibility. Marginal — the Temporal chart already bundles its own PostgreSQL, so a stack only adds optional ES visibility search.
image + chartApache-2.0
Why some apps are held
QuenchWorks ships nothing that carries a fixable CVE. A few apps build cleanly but can't reach that bar yet: the app itself pins a dependency below the version that fixes a known CVE, so patching it would break the app's own declared constraints. Those are marked blocked: built and tested, held (not shipped) until upstream relaxes the pin or backports the fix. They go live the moment that lands. Nothing already in the catalog carries a known fixable CVE to get there faster.
Want something prioritized? Request an app and we will slot it into the roadmap.