Self hosted PaaS solution
See the codeA lightweight, self-hosted, and modern Platform-as-a-Service (PaaS) built on Docker Swarm.
An open-source, resource-efficient alternative to Heroku, Render, and Coolify for managing and deploying applications on your own servers.
Features • Website & Demo • Quick Start • Architecture • Documentation • Contributing
demo · password HivePaaS@2026 (a read-only account)HivePaaS uses a clean two-tier network and node topology for maximum security and simplicity:
┌──────────────────────────────────────┐
│ Internet / Users │
└──────────────────┬───────────────────┘
│ (Port 80 / 443)
▼
┌────────────────────────────────────────────────────────────────────────┐
│ PRIMARY CONTROL-PLANE (Manager Node) │
│ │
│ ┌─────────────────┐ ┌────────────────┐ ┌───────────────┐ │
│ │ Traefik Proxy │◄─────►│ HivePaaS App │◄─────►│ PostgreSQL │ │
│ └────────┬────────┘ └───────┬────────┘ └───────────────┘ │
│ │ │ │
└───────────┼────────────────────────┼───────────────────────────────────┘
│ │ (gRPC Management)
(hivepaas_net overlay) ▼
┌───────────┼────────────────────────────────────────────────────────────┐
│ WORKER NODES (Multi-Node Cluster) │
│ │ │
│ ├────────────────────────┬────────────────────────┐ │
│ ▼ ▼ ▼ │
│ ┌─────────────────┐ ┌─────────────────┐ ┌────────────────┐ │
│ │ Web App (A) │ │ Web App (B) │ │ HivePaaS Agent │ │
│ │ (project_net) │ │ (project_net) │ │ (Global Mode) │ │
│ └─────────────────┘ └─────────────────┘ └────────────────┘ │
└────────────────────────────────────────────────────────────────────────┘
hivepaas_net: Shared Overlay network for Traefik to route ingress traffic to publicly exposed containers.project_env_net: Completely isolated private overlay networks for internal communication (e.g. App to Database/Redis).80 and 443 free and open to the internet.On the server:
curl -fsSL https://get.hivepaas.com | sudo bash
The installer asks for the admin's email and password and the dashboard's domain, sets up Docker Swarm, and deploys HivePaaS. To install without questions, see Silent install.
Open the domain you gave, such as https://hivepaas.example.com, and sign in with the admin's email and password.
Configuration changes that can make the dashboard unreachable - traefik's startup command, the HivePaaS routing and proxy settings - are applied on trial and undone automatically unless you confirm them. docs/recovery.md explains what catches what, and what to do by hand when nothing automatic can run.
To work on HivePaaS itself, see docs/DEVELOPMENT.md.
| Component | Technology | Required? | What it does |
|---|---|---|---|
| Backend | Go (Gin, Bun, lego) | Required | The API, the task queue and the dashboard's server |
| Agent | Go, gRPC | Required | Runs on every node: builds images, runs commands and backups, reads the node |
| Database | PostgreSQL 18 | Required | HivePaaS's state: projects, apps, settings, tasks |
| Cache & queue | Redis 8 | Required | Sessions, locks, the task queue and rate limiting |
| Orchestration | Docker Swarm (Docker 29.5+) | Required | Runs and schedules every container, on one node or many |
| Ingress | Traefik v3 | Required | Routing, TLS and the per-app rules |
| Image builds | BuildKit (docker buildx) | Required to build from Git and functions | Builds images from repositories and functions' code |
| Backups | Kopia | Optional - when you back up | Encrypted, deduplicated backups and restores |
| Logs & metrics | VictoriaLogs and vlagent | Optional - switched on in System › Logging | Log history, metrics and autoscaling |
| Routes & calls | OBI (OpenTelemetry eBPF Instrumentation) | Optional - per app | HTTP routes and outgoing calls of apps, without code changes |
| Registry | zot | Optional - switched on in System › Registry | A container registry of your own, for images built on a multi-node cluster |
| Function runtimes | hivepaas/function-runtimes | Optional - when you use functions | The images functions are built on |
| Dashboard | React 19, Vite, TypeScript, Tailwind CSS, TanStack Query | Required | The web interface |
Please report vulnerabilities privately, through GitHub's vulnerability reporting - never in a public issue. See SECURITY.md for what to include and what happens next.
Contributions, issues, and feature requests are welcome!
Setting up a development machine - the local cluster, the three ways to run the backend, and what to run before you push - is in docs/DEVELOPMENT.md.
git checkout -b feature/AmazingFeature)git commit -m 'feat: Add some AmazingFeature')git push origin feature/AmazingFeature)Distributed under the Apache 2.0 License. See LICENSE for more information.
Self hosted PaaS solution
See the codeA lightweight, self-hosted, and modern Platform-as-a-Service (PaaS) built on Docker Swarm.
An open-source, resource-efficient alternative to Heroku, Render, and Coolify for managing and deploying applications on your own servers.
Features • Website & Demo • Quick Start • Architecture • Documentation • Contributing
demo · password HivePaaS@2026 (a read-only account)HivePaaS uses a clean two-tier network and node topology for maximum security and simplicity:
┌──────────────────────────────────────┐
│ Internet / Users │
└──────────────────┬───────────────────┘
│ (Port 80 / 443)
▼
┌────────────────────────────────────────────────────────────────────────┐
│ PRIMARY CONTROL-PLANE (Manager Node) │
│ │
│ ┌─────────────────┐ ┌────────────────┐ ┌───────────────┐ │
│ │ Traefik Proxy │◄─────►│ HivePaaS App │◄─────►│ PostgreSQL │ │
│ └────────┬────────┘ └───────┬────────┘ └───────────────┘ │
│ │ │ │
└───────────┼────────────────────────┼───────────────────────────────────┘
│ │ (gRPC Management)
(hivepaas_net overlay) ▼
┌───────────┼────────────────────────────────────────────────────────────┐
│ WORKER NODES (Multi-Node Cluster) │
│ │ │
│ ├────────────────────────┬────────────────────────┐ │
│ ▼ ▼ ▼ │
│ ┌─────────────────┐ ┌─────────────────┐ ┌────────────────┐ │
│ │ Web App (A) │ │ Web App (B) │ │ HivePaaS Agent │ │
│ │ (project_net) │ │ (project_net) │ │ (Global Mode) │ │
│ └─────────────────┘ └─────────────────┘ └────────────────┘ │
└────────────────────────────────────────────────────────────────────────┘
hivepaas_net: Shared Overlay network for Traefik to route ingress traffic to publicly exposed containers.project_env_net: Completely isolated private overlay networks for internal communication (e.g. App to Database/Redis).80 and 443 free and open to the internet.On the server:
curl -fsSL https://get.hivepaas.com | sudo bash
The installer asks for the admin's email and password and the dashboard's domain, sets up Docker Swarm, and deploys HivePaaS. To install without questions, see Silent install.
Open the domain you gave, such as https://hivepaas.example.com, and sign in with the admin's email and password.
Configuration changes that can make the dashboard unreachable - traefik's startup command, the HivePaaS routing and proxy settings - are applied on trial and undone automatically unless you confirm them. docs/recovery.md explains what catches what, and what to do by hand when nothing automatic can run.
To work on HivePaaS itself, see docs/DEVELOPMENT.md.
| Component | Technology | Required? | What it does |
|---|---|---|---|
| Backend | Go (Gin, Bun, lego) | Required | The API, the task queue and the dashboard's server |
| Agent | Go, gRPC | Required | Runs on every node: builds images, runs commands and backups, reads the node |
| Database | PostgreSQL 18 | Required | HivePaaS's state: projects, apps, settings, tasks |
| Cache & queue | Redis 8 | Required | Sessions, locks, the task queue and rate limiting |
| Orchestration | Docker Swarm (Docker 29.5+) | Required | Runs and schedules every container, on one node or many |
| Ingress | Traefik v3 | Required | Routing, TLS and the per-app rules |
| Image builds | BuildKit (docker buildx) | Required to build from Git and functions | Builds images from repositories and functions' code |
| Backups | Kopia | Optional - when you back up | Encrypted, deduplicated backups and restores |
| Logs & metrics | VictoriaLogs and vlagent | Optional - switched on in System › Logging | Log history, metrics and autoscaling |
| Routes & calls | OBI (OpenTelemetry eBPF Instrumentation) | Optional - per app | HTTP routes and outgoing calls of apps, without code changes |
| Registry | zot | Optional - switched on in System › Registry | A container registry of your own, for images built on a multi-node cluster |
| Function runtimes | hivepaas/function-runtimes | Optional - when you use functions | The images functions are built on |
| Dashboard | React 19, Vite, TypeScript, Tailwind CSS, TanStack Query | Required | The web interface |
Please report vulnerabilities privately, through GitHub's vulnerability reporting - never in a public issue. See SECURITY.md for what to include and what happens next.
Contributions, issues, and feature requests are welcome!
Setting up a development machine - the local cluster, the three ways to run the backend, and what to run before you push - is in docs/DEVELOPMENT.md.
git checkout -b feature/AmazingFeature)git commit -m 'feat: Add some AmazingFeature')git push origin feature/AmazingFeature)Distributed under the Apache 2.0 License. See LICENSE for more information.