Open-source tools for the people who keep servers running.
Stackfly builds self-hosted software for infrastructure operators. No agent on your machines: just SSH, the repositories you already keep, and a clear record of what changed.
Playplane
Your Ansible, with a shared view of who ran what, where, and what happened.
Playplane runs real Ansible against your existing infrastructure. Your Git repository stays the source of truth; Playplane adds targeting, live execution and a history the whole team can read.
- Target preview See which hosts a run will touch before it starts.
- Live execution Per-host events and output as they happen, with check, diff, limit and cancel.
- Run history Every run kept with its author, targets and Git revision, plus an audit log.
- Access by project Viewer, Operator and Admin roles, enforced on the server.
- Encrypted credentials SSH keys, Git HTTPS and WinRM secrets, injected only at run time.
Run it locally with Docker Compose
git clone \
https://github.com/stackflyhq/playplane
cd playplane
make local-up
make create-admin Then open localhost:3000 and sign in.
- Playbook
- playbooks/site.yml
- Inventory
- inventory/production.yml
- Flags
- --diff
- Started by
- marcelinux
Therapon
Pre-alphaSafe, agentless maintenance and patching for Linux fleets.
Running a package update is the easy part. A wrong target, a failed reboot or an uncertain transaction is what turns routine patching into an outage. Therapon is being designed around that whole lifecycle, over plain SSH, with its own maintenance engine.
The specification and roadmap are public. There is no usable release yet, so please don't point it at production. Watch the repository to follow along.
How a rollout is planned to work
- 1 Preview Exact hosts and packages, frozen.
- 2 Approval A person signs off on the preview.
- 3 Pre-checks Fresh checks; drift needs a new approval.
- 4 Canary One host goes first.
- 5 Post-checks Services verified, then observed.
- 6 Validation A person approves expanding.
- 7 Next batch Bounded, and checked again from step 3.
Steps 3 to 7 repeat for every batch. The first critical incident or unknown result stops new changes.
Therapon must never trade uncertainty for automation.
Unknown stays unknown
When a change's outcome is uncertain, that host stays blocked until its real state is confirmed. No blind retries, and no timeout clears the doubt.
Checked before and after
Pre-checks and post-checks are mandatory. A package manager reporting success is not enough to call a host done.
Reboots are explicit
Nothing restarts without authorization. Automatic rollback and free-form shell commands are deliberately out of scope for the first version.
The same rules for everything we ship.
Agentless
We use the access you already have, SSH first. Nothing to install and keep patched on every host.
Self-hosted
You run it on your laptop or your own server. Your inventory and credentials stay with you.
Built in the open
Code, specifications and roadmaps are public on GitHub, including what isn't finished yet.