Kai A. Hartung

Kai A. Hartung

Schema-driven .env management adding type-safety, validation, and AI-safe secret redaction over plain .env files: keeps credentials out of AI prompts, logs, and client bundles.

MIT-core autonomous AI software engineer that resolves whole coding tasks in a sandboxed runtime you host yourself, though SSO, RBAC, and audit logs sit behind a commercial enterprise tier.

AGPL-licensed platform for self-hosted cloud development environments: provision Terraform-defined workspaces and govern AI coding agents on infrastructure you control, with no per-seat SaaS fees.

Zero-knowledge office suite (docs, sheets, slides, forms): the server stores only ciphertext, so even the admin cannot read your files. AGPL, EU-based; only managed hosting is paid.

AGPL terminal multiplexer for running AI coding agents in parallel, tracking which is working or waiting. A local Rust binary, no cloud; a one-maintainer project with a commercial-license waiver.

A memory layer for AI agents: extracts and recalls facts across sessions so the LLM stops re-sending history. Apache-2.0, self-hostable on Postgres and Qdrant; SSO and audit logs are Enterprise-gated.

AI-native embedding database for RAG: runs embedded via pip or as a Docker server, with portable SQLite/Parquet storage for clean data exit. Apache-2.0, but the OSS core ships without built-in auth.

Kubernetes-native backup and disaster recovery: snapshot cluster state and volumes to object storage you own, then restore or migrate. Apache-2.0; a CNCF governance move off Broadcom is unsettled.

CNCF-graduated Kubernetes operator that runs Ceph as self-healing storage: object, block, and file from cluster disks. Fully open; the cost is the Ceph expertise it abstracts but never removes.

CNCF Kubernetes storage running in userspace, with pluggable engines from local volumes to replicated NVMe-oF. Apache-2.0 core, but external KMS and management GUI sit in DataCore's commercial tier.

CNCF-governed, fully open block storage for Kubernetes: HA volumes with encryption, synchronous replication, and S3/NFS backup. No open-core paywall: the only paid tier is optional vendor support.

Apache-2.0 distributed storage with S3 and POSIX, tuned for billions of small files, simpler than Ceph. Day-2 self-healing repair and point-in-time recovery sit behind a paid Enterprise tier.

AGPLv3 self-hosted collaborative LaTeX editor for academic and scientific writing. The free Community Edition omits SSO, per-user sandboxing, and Git sync, which sit behind the paid Server Pro tier.

Local-first AI voice studio powered by Qwen3-TTS and six more engines. Clones voices and synthesizes speech fully on your machine, with no per-character metering, though your own GPU does the work.

AGPLv3 self-hosted task manager: List, Kanban, Gantt, and Table views, free for unlimited users. Catch: admin panel, audit logs, and time tracking stay Pro-gated even when self-hosted.

Unified distributed storage that serves one cluster as S3 object, block, and POSIX file. Foundation-governed, standards-based, with no per-GB cloud fees, but it demands real cluster-ops expertise.

AGPL-3.0 personal cloud OS: a sandboxed K3s app platform for self-hosting files, services, and local AI on hardware you own. Trade-offs are a dedicated-hardware footprint and AGPL network copyleft.

Foundation-governed AI agent for coding and workflow automation. Runs locally via desktop, CLI, or API, is model-agnostic through MCP, and carries no per-seat lock-in.

AGPL-3.0 self-hosted AI workspace: local-model chat, agents, research, and email in one stack with zero telemetry. Trade-offs are single-maintainer governance and AGPL network-copyleft embedding risk.

A Dutch 'sovereign' cloud almost became American overnight, and only a last-minute government veto stopped it. Real digital sovereignty was never just about where your data sits. It is about whose courts can reach it, and Europe's billion-euro plan still misses the point.