hivepaas/hivepaas

Self hosted PaaS solution

Go

5

1,881 commits

updated Oct 6, 2026

See the code

See what people are saying

README

HivePaaS logo

HivePaaS

A lightweight, self-hosted, and modern Platform-as-a-Service (PaaS) built on Docker Swarm.

An open-source, resource-efficient alternative to Heroku, Render, and Coolify for managing and deploying applications on your own servers.

Go Version Docker Traefik License

Features • Website & Demo • Quick Start • Architecture • Documentation • Contributing


🌟 Key Features

  • Deploy anything: from a Docker image or a Git repository - with your Dockerfile, or one written for you for 15+ languages and frameworks - with deploy on push and pull request previews.
  • Functions: write a handler in Node.js/TypeScript, Bun, Python or Go; HivePaaS builds and runs it, over HTTP or on a schedule.
  • App Store: 300+ one-click templates - databases, CMSs, analytics, monitoring, automation.
  • Domains & TLS: Traefik v3 with automatic certificates (Let's Encrypt, ZeroSSL, Google Trust Services; wildcards through DNS), and redirects, basic auth, IP and rate limits per app.
  • Run & scale: health checks, resource limits, placement, autoscaling on requests and CPU, scheduled jobs, and multi-node Swarm clusters.
  • Observe: live logs and log history, a terminal into containers, CPU and memory metrics, and metrics of HTTP routes and outgoing calls through eBPF - no code changes.
  • Backups: encrypted, deduplicated backups (Kopia) to S3-compatible storage or a volume, scheduled, with restores; export, import and cloning of apps.
  • Teams & security: projects and environments, role-based access, API keys, an audit log, two-factor authentication, SSO (GitHub, GitLab, Google, Microsoft, OpenID Connect) and notifications.
  • API & AI: a REST API with OpenAPI docs, and an MCP server for AI assistants.
  • Light and safe: written in Go, a control plane of about 300 MB; signed releases (Ed25519 and ML-DSA-65); settings that could lock you out are applied on trial and rolled back unless you confirm them.

🌐 Website & Demo


🏗️ Architecture

HivePaaS uses a clean two-tier network and node topology for maximum security and simplicity:

               ┌──────────────────────────────────────┐
               │         Internet / Users             │
               └──────────────────┬───────────────────┘
                                  │ (Port 80 / 443)
                                  ▼
┌────────────────────────────────────────────────────────────────────────┐
│ PRIMARY CONTROL-PLANE (Manager Node)                                   │
│                                                                        │
│  ┌─────────────────┐       ┌────────────────┐       ┌───────────────┐  │
│  │  Traefik Proxy  │◄─────►│  HivePaaS App  │◄─────►│  PostgreSQL   │  │
│  └────────┬────────┘       └───────┬────────┘       └───────────────┘  │
│           │                        │                                   │
└───────────┼────────────────────────┼───────────────────────────────────┘
            │                        │ (gRPC Management)
    (hivepaas_net overlay)           ▼
┌───────────┼────────────────────────────────────────────────────────────┐
│ WORKER NODES (Multi-Node Cluster)                                      │
│           │                                                            │
│           ├────────────────────────┬────────────────────────┐          │
│           ▼                        ▼                        ▼          │
│  ┌─────────────────┐      ┌─────────────────┐      ┌────────────────┐  │
│  │   Web App (A)   │      │   Web App (B)   │      │ HivePaaS Agent │  │
│  │  (project_net)  │      │  (project_net)  │      │  (Global Mode) │  │
│  └─────────────────┘      └─────────────────┘      └────────────────┘  │
└────────────────────────────────────────────────────────────────────────┘
  • hivepaas_net: Shared Overlay network for Traefik to route ingress traffic to publicly exposed containers.
  • project_env_net: Completely isolated private overlay networks for internal communication (e.g. App to Database/Redis).

🚀 Quick Start

Prerequisites

  • A Linux server with root access: Debian, Ubuntu, Fedora, RHEL, Rocky, AlmaLinux, Amazon Linux, SLES, openSUSE, Arch or Alpine.
  • 4 CPUs, 8 GB of memory and 40 GB of disk recommended; HivePaaS runs on less.
  • Ports 80 and 443 free and open to the internet.
  • Docker 29.5 or newer - the installer installs or upgrades it if needed.

1. Install

On the server:

curl -fsSL https://get.hivepaas.com | sudo bash

The installer asks for the admin's email and password and the dashboard's domain, sets up Docker Swarm, and deploys HivePaaS. To install without questions, see Silent install.

2. Open the dashboard

Open the domain you gave, such as https://hivepaas.example.com, and sign in with the admin's email and password.

3. If a change locks you out

Configuration changes that can make the dashboard unreachable - traefik's startup command, the HivePaaS routing and proxy settings - are applied on trial and undone automatically unless you confirm them. docs/recovery.md explains what catches what, and what to do by hand when nothing automatic can run.

To work on HivePaaS itself, see docs/DEVELOPMENT.md.


🛠️ Tech Stack

ComponentTechnologyRequired?What it does
BackendGo (Gin, Bun, lego)RequiredThe API, the task queue and the dashboard's server
AgentGo, gRPCRequiredRuns on every node: builds images, runs commands and backups, reads the node
DatabasePostgreSQL 18RequiredHivePaaS's state: projects, apps, settings, tasks
Cache & queueRedis 8RequiredSessions, locks, the task queue and rate limiting
OrchestrationDocker Swarm (Docker 29.5+)RequiredRuns and schedules every container, on one node or many
IngressTraefik v3RequiredRouting, TLS and the per-app rules
Image buildsBuildKit (docker buildx)Required to build from Git and functionsBuilds images from repositories and functions' code
BackupsKopiaOptional - when you back upEncrypted, deduplicated backups and restores
Logs & metricsVictoriaLogs and vlagentOptional - switched on in System › LoggingLog history, metrics and autoscaling
Routes & callsOBI (OpenTelemetry eBPF Instrumentation)Optional - per appHTTP routes and outgoing calls of apps, without code changes
RegistryzotOptional - switched on in System › RegistryA container registry of your own, for images built on a multi-node cluster
Function runtimeshivepaas/function-runtimesOptional - when you use functionsThe images functions are built on
DashboardReact 19, Vite, TypeScript, Tailwind CSS, TanStack QueryRequiredThe web interface

📚 Documentation


🔒 Security

Please report vulnerabilities privately, through GitHub's vulnerability reporting - never in a public issue. See SECURITY.md for what to include and what happens next.


💬 Community & Support

  • Discord - questions, and help from the team and the community.
  • GitHub Issues - bugs and feature requests.
  • Getting help - what to include so a question gets an answer sooner.

🤝 Contributing

Contributions, issues, and feature requests are welcome!

Setting up a development machine - the local cluster, the three ways to run the backend, and what to run before you push - is in docs/DEVELOPMENT.md.

  1. Fork the Project
  2. Create your Feature Branch (git checkout -b feature/AmazingFeature)
  3. Commit your Changes (git commit -m 'feat: Add some AmazingFeature')
  4. Push to the Branch (git push origin feature/AmazingFeature)
  5. Open a Pull Request using our PR Template

📄 License

Distributed under the Apache 2.0 License. See LICENSE for more information.

hivepaas/hivepaas

Self hosted PaaS solution

Go

5

1,881 commits

updated Oct 6, 2026

See the code

See what people are saying

README

HivePaaS logo

HivePaaS

A lightweight, self-hosted, and modern Platform-as-a-Service (PaaS) built on Docker Swarm.

An open-source, resource-efficient alternative to Heroku, Render, and Coolify for managing and deploying applications on your own servers.

Go Version Docker Traefik License

Features • Website & Demo • Quick Start • Architecture • Documentation • Contributing


🌟 Key Features

  • Deploy anything: from a Docker image or a Git repository - with your Dockerfile, or one written for you for 15+ languages and frameworks - with deploy on push and pull request previews.
  • Functions: write a handler in Node.js/TypeScript, Bun, Python or Go; HivePaaS builds and runs it, over HTTP or on a schedule.
  • App Store: 300+ one-click templates - databases, CMSs, analytics, monitoring, automation.
  • Domains & TLS: Traefik v3 with automatic certificates (Let's Encrypt, ZeroSSL, Google Trust Services; wildcards through DNS), and redirects, basic auth, IP and rate limits per app.
  • Run & scale: health checks, resource limits, placement, autoscaling on requests and CPU, scheduled jobs, and multi-node Swarm clusters.
  • Observe: live logs and log history, a terminal into containers, CPU and memory metrics, and metrics of HTTP routes and outgoing calls through eBPF - no code changes.
  • Backups: encrypted, deduplicated backups (Kopia) to S3-compatible storage or a volume, scheduled, with restores; export, import and cloning of apps.
  • Teams & security: projects and environments, role-based access, API keys, an audit log, two-factor authentication, SSO (GitHub, GitLab, Google, Microsoft, OpenID Connect) and notifications.
  • API & AI: a REST API with OpenAPI docs, and an MCP server for AI assistants.
  • Light and safe: written in Go, a control plane of about 300 MB; signed releases (Ed25519 and ML-DSA-65); settings that could lock you out are applied on trial and rolled back unless you confirm them.

🌐 Website & Demo


🏗️ Architecture

HivePaaS uses a clean two-tier network and node topology for maximum security and simplicity:

               ┌──────────────────────────────────────┐
               │         Internet / Users             │
               └──────────────────┬───────────────────┘
                                  │ (Port 80 / 443)
                                  ▼
┌────────────────────────────────────────────────────────────────────────┐
│ PRIMARY CONTROL-PLANE (Manager Node)                                   │
│                                                                        │
│  ┌─────────────────┐       ┌────────────────┐       ┌───────────────┐  │
│  │  Traefik Proxy  │◄─────►│  HivePaaS App  │◄─────►│  PostgreSQL   │  │
│  └────────┬────────┘       └───────┬────────┘       └───────────────┘  │
│           │                        │                                   │
└───────────┼────────────────────────┼───────────────────────────────────┘
            │                        │ (gRPC Management)
    (hivepaas_net overlay)           ▼
┌───────────┼────────────────────────────────────────────────────────────┐
│ WORKER NODES (Multi-Node Cluster)                                      │
│           │                                                            │
│           ├────────────────────────┬────────────────────────┐          │
│           ▼                        ▼                        ▼          │
│  ┌─────────────────┐      ┌─────────────────┐      ┌────────────────┐  │
│  │   Web App (A)   │      │   Web App (B)   │      │ HivePaaS Agent │  │
│  │  (project_net)  │      │  (project_net)  │      │  (Global Mode) │  │
│  └─────────────────┘      └─────────────────┘      └────────────────┘  │
└────────────────────────────────────────────────────────────────────────┘
  • hivepaas_net: Shared Overlay network for Traefik to route ingress traffic to publicly exposed containers.
  • project_env_net: Completely isolated private overlay networks for internal communication (e.g. App to Database/Redis).

🚀 Quick Start

Prerequisites

  • A Linux server with root access: Debian, Ubuntu, Fedora, RHEL, Rocky, AlmaLinux, Amazon Linux, SLES, openSUSE, Arch or Alpine.
  • 4 CPUs, 8 GB of memory and 40 GB of disk recommended; HivePaaS runs on less.
  • Ports 80 and 443 free and open to the internet.
  • Docker 29.5 or newer - the installer installs or upgrades it if needed.

1. Install

On the server:

curl -fsSL https://get.hivepaas.com | sudo bash

The installer asks for the admin's email and password and the dashboard's domain, sets up Docker Swarm, and deploys HivePaaS. To install without questions, see Silent install.

2. Open the dashboard

Open the domain you gave, such as https://hivepaas.example.com, and sign in with the admin's email and password.

3. If a change locks you out

Configuration changes that can make the dashboard unreachable - traefik's startup command, the HivePaaS routing and proxy settings - are applied on trial and undone automatically unless you confirm them. docs/recovery.md explains what catches what, and what to do by hand when nothing automatic can run.

To work on HivePaaS itself, see docs/DEVELOPMENT.md.


🛠️ Tech Stack

ComponentTechnologyRequired?What it does
BackendGo (Gin, Bun, lego)RequiredThe API, the task queue and the dashboard's server
AgentGo, gRPCRequiredRuns on every node: builds images, runs commands and backups, reads the node
DatabasePostgreSQL 18RequiredHivePaaS's state: projects, apps, settings, tasks
Cache & queueRedis 8RequiredSessions, locks, the task queue and rate limiting
OrchestrationDocker Swarm (Docker 29.5+)RequiredRuns and schedules every container, on one node or many
IngressTraefik v3RequiredRouting, TLS and the per-app rules
Image buildsBuildKit (docker buildx)Required to build from Git and functionsBuilds images from repositories and functions' code
BackupsKopiaOptional - when you back upEncrypted, deduplicated backups and restores
Logs & metricsVictoriaLogs and vlagentOptional - switched on in System › LoggingLog history, metrics and autoscaling
Routes & callsOBI (OpenTelemetry eBPF Instrumentation)Optional - per appHTTP routes and outgoing calls of apps, without code changes
RegistryzotOptional - switched on in System › RegistryA container registry of your own, for images built on a multi-node cluster
Function runtimeshivepaas/function-runtimesOptional - when you use functionsThe images functions are built on
DashboardReact 19, Vite, TypeScript, Tailwind CSS, TanStack QueryRequiredThe web interface

📚 Documentation


🔒 Security

Please report vulnerabilities privately, through GitHub's vulnerability reporting - never in a public issue. See SECURITY.md for what to include and what happens next.


💬 Community & Support

  • Discord - questions, and help from the team and the community.
  • GitHub Issues - bugs and feature requests.
  • Getting help - what to include so a question gets an answer sooner.

🤝 Contributing

Contributions, issues, and feature requests are welcome!

Setting up a development machine - the local cluster, the three ways to run the backend, and what to run before you push - is in docs/DEVELOPMENT.md.

  1. Fork the Project
  2. Create your Feature Branch (git checkout -b feature/AmazingFeature)
  3. Commit your Changes (git commit -m 'feat: Add some AmazingFeature')
  4. Push to the Branch (git push origin feature/AmazingFeature)
  5. Open a Pull Request using our PR Template

📄 License

Distributed under the Apache 2.0 License. See LICENSE for more information.