π©Ί Vitals
- π’ Last active: 2026-07-26
- π¦ Latest release: v1.17.0 (2026-07-22)
- π Stars: 47
What do these metrics mean?
- Last active: when code was last pushed, as of our last check. The dot is green when that was recent, grey otherwise. A long gap can mean a tool is finished and stable, not only unmaintained.
- Latest release: the most recent tagged, packaged version the maintainers published. Not every healthy project tags releases.
- Stars: how many people bookmarked the project on its forge. A rough popularity signal, not a measure of quality.
ποΈ Profile
- Official: opendesk.eu
- Source: gitlab.opencode.de/bmi/opendesk
- License: Apache 2.0 orchestration Β· AGPL 3.0 components
- Deployment: Kubernetes (Helm)
- Data Model: PostgreSQL / MariaDB / S3 Object Storage
- Jurisdiction: Germany π©πͺ / EU πͺπΊ (ZenDiS GmbH, German state-owned)
- Compliance (SaaS): N/A (No First-Party SaaS)
- Compliance (Self-Hosted): GDPR Ready (IT-Grundschutz framework; infrastructure user-managed)
- Complexity: High (5/5) - Kubernetes cluster with a dozen integrated services and a shared IAM layer
- Maintenance: High (4/5) - Release-matrix-coordinated upgrades across the whole component stack
- Enterprise Ready: High (5/5) - Built for public administration: integrated IAM (Keycloak/Nubus), SSO and RBAC across the suite
1. The Executive Summary
What is it? openDesk is a sovereign digital workplace suite for public administration. It integrates established open-source products into one single-sign-on, web-based environment covering files and groupware, e-mail and calendar, office document editing, project management, knowledge management, real-time chat and video. It is developed and stewarded by ZenDiS GmbH, a German state-owned company created to reduce the public sector's dependence on proprietary vendors, and its source is published on openCode, the German public administration's code platform. openDesk integrates Nextcloud, Collabora Online, OpenProject, Element (Matrix), Jitsi Meet and CryptPad, with Open-Xchange and Dovecot for mail and Univention Nubus plus Keycloak for identity. It runs on Kubernetes, self-hosted or via qualified partner operators.
The Strategic Verdict:
- π΄ For organizations without mature Kubernetes and DevOps capability: Caution. openDesk is a Kubernetes-native distribution of roughly a dozen integrated services bound by a shared IAM layer; there is no single-binary or simple-VM path. A body without platform-engineering depth should consume openDesk through a qualified partner operator rather than self-host, or run the constituent products individually.
- π’ For European public bodies leaving Microsoft 365: Strong Buy. A workplace suite built and owned by the German state expressly to deliver digital sovereignty, integrating best-of-breed open source under one login and hostable on EU infrastructure beyond US CLOUD Act reach. The integration and identity work an organization would otherwise do itself is the product.
2. The "Hidden" Costs (TCO Analysis)
| Cost Component | Microsoft 365 (SaaS) | openDesk (Self-Hosted) |
|---|---|---|
| Per-seat Licensing | Monthly per-user fee across tiers | Open-source suite, no per-seat licence; you fund hosting and operations |
| Data Residency | US vendor, CLOUD Act exposure | Your own or partner EU infrastructure, German state steward |
| Integration & IAM | Bundled but proprietary and locked-in | Pre-integrated open source with shared SSO via Keycloak/Nubus |
| Enterprise Tax | E5 security and compliance tiers | Community Edition is complete; Enterprise adds Nextcloud LTS patches, the Guard app and SLA support |
3. The "Day 2" Reality Check
π Deployment & Operations
- Installation: openDesk ships as a Kubernetes distribution: Helm charts and a deployment repository on openCode, with a release matrix that pins compatible component versions. There is no Docker Compose or single-VM option. You bring a Kubernetes cluster, persistent storage and the operational maturity to run it, or you take the suite from a qualified partner operator.
- Scalability: Kubernetes-native, so horizontal scaling is the design assumption and each component (Nextcloud, the Matrix homeserver, Collabora, the database tier) scales independently. The trade-off is a high floor: this is not a suite you stand up on one server for a small team, and right-sizing the cluster is a real capacity-planning exercise.
π‘οΈ Security & Governance (Risk Assessment)
- Jurisdiction & Sovereignty: openDesk is built and owned by ZenDiS GmbH, whose sole shareholder is the Federal Republic of Germany through the Federal Ministry of the Interior, with several LΓ€nder having signed letters of intent to join. That places the steward, the roadmap and the code inside the German state and the EU, beyond the reach of the US CLOUD Act, under an explicit mandate of digital sovereignty for public administration. There is no first-party SaaS to create a foreign-control vector: you self-host, or use a German partner operator running in data centres aligned to the BSI C5 criteria catalogue. This is the strongest sovereignty posture of any suite in this category.
- The Compliance Shift: openDesk is designed around the BSI IT-Grundschutz methodology, and partner hosting is offered against the BSI C5 catalogue, but those are frameworks and operator attestations, not a badge the software hands a self-hoster. Running openDesk yourself means owning the security of a Kubernetes cluster, the IAM layer (Keycloak/Nubus), the databases and every integrated service, and passing your own audits. The suite supplies sovereignty-grade building blocks; the certified posture is something your platform team operates.
- License & Open-Core Reality: openDesk's own orchestration code is permissively Apache 2.0 licensed, but the suite is dominated by strong copyleft: AGPL 3.0 governs major components including Nextcloud, Element/Matrix and Univention Nubus. For a public body simply deploying and using openDesk this triggers no obligation, but anyone who modifies those components and offers them over a network inherits the AGPL's source-sharing duty. Separately, the Community Edition is fully open source and functionally complete, while the Enterprise Edition layers in proprietary Nextcloud Enterprise long-term-support patches, the closed Nextcloud Guard app, SLA-backed support and enterprise add-ons across components. The open-core line here is long-term patching and vendor support, not core functionality.
4. Market Landscape
π’ Proprietary Incumbents
- Microsoft 365: The dominant productivity suite. openDesk exists explicitly to give European public administrations an exit from its per-seat licensing, US jurisdiction and telemetry.
- Google Workspace: The other hyperscaler suite. The same sovereignty and data-residency objections drive public-sector interest in a self-hosted, EU-governed alternative.
π€ Open Source Ecosystem
- Nextcloud: The file, groupware and collaboration core of openDesk, and the most complete single-product sovereign suite you can run on its own when you do not need the full openDesk integration and IAM layer.
- Element: The Matrix-based real-time communication layer inside openDesk; a sovereign, federated alternative to Teams chat that organizations also deploy standalone.