Kai A. Hartung

Kai A. Hartung

An office suite just set an all-time download record for what it left out. LibreOffice 26.8 hit 1,031,162 installs in a week with no AI, and a million people were escaping the feature Microsoft keeps adding to yours. In rented software, the next change is never yours to make.

MIT-licensed platform that builds, versions and hosts docs-as-code from Git, with pull-request previews and search. Self-hosting sidesteps the paid hosted tiers but runs a heavy multi-service stack.

Real-time distributed OLAP datastore for user-facing analytics at high concurrency. Apache-governed. A heavy multi-node cluster; managed ops and anomaly detection are the commercial StarTree.

Real-time analytics database for sub-second queries on streaming and batch data, Apache-governed. A heavy distributed cluster to operate; managed ops and the Pivot BI console are the commercial Imply.

Real-time MPP OLAP database that queries open lakehouse tables directly. Apache-licensed, Linux Foundation-governed. A distributed cluster to run; masking and managed ops are the commercial cloud.

Real-time MPP data warehouse, MySQL-compatible and Apache-governed, built to leave cloud warehouses like Snowflake. A distributed cluster to run; SSO and managed ops sit with the commercial VeloDB.

OCI-native container registry in a single static binary with RBAC, scanning and replication built in, no external database. Apache-licensed, no paid tier. A younger CNCF Sandbox project than Harbor.

Red Hat's Apache-licensed container registry with integrated Clair scanning, geo-replication and RBAC in the free core. Multi-service stack; roadmap steered by Red Hat and tied to OpenShift.

Minimal Apache-licensed OCI registry, formerly Docker Registry: stores and serves container images with pluggable S3 or filesystem storage. No built-in auth, RBAC or UI; you wrap it or run Harbor.

CNCF-graduated registry that stores, scans and signs OCI images. RBAC, replication and audit logging in the free Apache core, no paid tier. A multi-service stack, so weigh the operational weight.

High-performance web server, reverse proxy and load balancer with a permissive BSD core, proven at internet scale. Active health checks, JWT auth and dynamic config sit behind the paid Plus tier.

Web server and reverse proxy in a single Go binary that issues and renews HTTPS certificates automatically. Apache-licensed with no paid tier: every feature ships in the open build.

Reverse proxy and Kubernetes ingress that self-configures from service discovery, so routes update without restarts. MIT core, single binary. Advanced auth, WAF and multi-cluster are paid tiers.

Self-hosted AGPL Rust server reimplementing the Bitwarden API, unlocking the org policies, event logs and SSO the official tiers gate. One container. Single-maintainer, weigh the bus-factor risk.