HivePaaS
A lightweight, self-hosted, and modern Platform-as-a-Service (PaaS) built on Docker Swarm.
An open-source, resource-efficient alternative to Heroku, Render, and Coolify for managing and deploying applications on your own servers.
Features • Website & Demo • Quick Start • Architecture • Documentation • Contributing
🌟 Key Features
- Deploy anything: from a Docker image or a Git repository - with your Dockerfile, or one written for you for 15+ languages and frameworks - with deploy on push and pull request previews.
- Functions: write a handler in Node.js/TypeScript, Bun, Python or Go; HivePaaS builds and runs it, over HTTP or on a schedule.
- App Store: 300+ one-click templates - databases, CMSs, analytics, monitoring, automation.
- Domains & TLS: Traefik v3 with automatic certificates (Let's Encrypt, ZeroSSL, Google Trust Services; wildcards through DNS), and redirects, basic auth, IP and rate limits per app.
- Run & scale: health checks, resource limits, placement, autoscaling on requests and CPU, scheduled jobs, and multi-node Swarm clusters.
- Observe: live logs and log history, a terminal into containers, CPU and memory metrics, and metrics of HTTP routes and outgoing calls through eBPF - no code changes.
- Backups: encrypted, deduplicated backups (Kopia) to S3-compatible storage or a volume, scheduled, with restores; export, import and cloning of apps.
- Teams & security: projects and environments, role-based access, API keys, an audit log, two-factor authentication, SSO (GitHub, GitLab, Google, Microsoft, OpenID Connect) and notifications.
- API & AI: a REST API with OpenAPI docs, and an MCP server for AI assistants.
- Light and safe: written in Go, a control plane of about 300 MB; signed releases (Ed25519 and ML-DSA-65); settings that could lock you out are applied on trial and rolled back unless you confirm them.
🌐 Website & Demo
- Website: hivepaas.com
- Demo servers: Demo1 (EU) · Demo2 (Asia) · Demo3 (US)
- Sign in with: username
demo· passwordHivePaaS@2026(a read-only account)
🏗️ Architecture
HivePaaS uses a clean two-tier network and node topology for maximum security and simplicity:
┌──────────────────────────────────────┐
│ Internet / Users │
└──────────────────┬───────────────────┘
│ (Port 80 / 443)
▼
┌────────────────────────────────────────────────────────────────────────┐
│ PRIMARY CONTROL-PLANE (Manager Node) │
│ │
│ ┌─────────────────┐ ┌────────────────┐ ┌───────────────┐ │
│ │ Traefik Proxy │◄─────►│ HivePaaS App │◄─────►│ PostgreSQL │ │
│ └────────┬────────┘ └───────┬────────┘ └───────────────┘ │
│ │ │ │
└───────────┼────────────────────────┼───────────────────────────────────┘
│ │ (gRPC Management)
(hivepaas_net overlay) ▼
┌───────────┼────────────────────────────────────────────────────────────┐
│ WORKER NODES (Multi-Node Cluster) │
│ │ │
│ ├────────────────────────┬────────────────────────┐ │
│ ▼ ▼ ▼ │
│ ┌─────────────────┐ ┌─────────────────┐ ┌────────────────┐ │
│ │ Web App (A) │ │ Web App (B) │ │ HivePaaS Agent │ │
│ │ (project_net) │ │ (project_net) │ │ (Global Mode) │ │
│ └─────────────────┘ └─────────────────┘ └────────────────┘ │
└────────────────────────────────────────────────────────────────────────┘
hivepaas_net: Shared Overlay network for Traefik to route ingress traffic to publicly exposed containers.project_env_net: Completely isolated private overlay networks for internal communication (e.g. App to Database/Redis).
🚀 Quick Start
Prerequisites
- A Linux server with root access: Debian, Ubuntu, Fedora, RHEL, Rocky, AlmaLinux, Amazon Linux, SLES, openSUSE, Arch or Alpine.
- 4 CPUs, 8 GB of memory and 40 GB of disk recommended; HivePaaS runs on less.
- Ports
80and443free and open to the internet. - Docker 29.5 or newer - the installer installs or upgrades it if needed.
1. Install
On the server:
curl -fsSL https://get.hivepaas.com | sudo bash
The installer asks for the admin's email and password and the dashboard's domain, sets up Docker Swarm, and deploys HivePaaS. To install without questions, see Silent install.
2. Open the dashboard
Open the domain you gave, such as https://hivepaas.example.com, and sign in with the admin's email and password.
3. If a change locks you out
Configuration changes that can make the dashboard unreachable - traefik's startup command, the HivePaaS routing and proxy settings - are applied on trial and undone automatically unless you confirm them. docs/recovery.md explains what catches what, and what to do by hand when nothing automatic can run.
To work on HivePaaS itself, see docs/DEVELOPMENT.md.
🛠️ Tech Stack
| Component | Technology | Required? | What it does | | :--- | :--- | :--- | :--- | | Backend | Go (Gin, Bun, lego) | Required | The API, the task queue and the dashboard's server | | Agent | Go, gRPC | Required | Runs on every node: builds images, runs commands and backups, reads the node | | Database | PostgreSQL 18 | Required | HivePaaS's state: projects, apps, settings, tasks | | Cache & queue | Redis 8 | Required | Sessions, locks, the task queue and rate limiting | | Orchestration | Docker Swarm (Docker 29.5+) | Required | Runs and schedules every container, on one node or many | | Ingress | Traefik v3 | Required | Routing, TLS and the per-app rules | | Image builds | BuildKit (docker buildx) | Required to build from Git and functions | Builds images from repositories and functions' code | | Backups | Kopia | Optional - when you back up | Encrypted, deduplicated backups and restores | | Logs & metrics | VictoriaLogs and vlagent | Optional - switched on in System › Logging | Log history, metrics and autoscaling | | Routes & calls | OBI (OpenTelemetry eBPF Instrumentation) | Optional - per app | HTTP routes and outgoing calls of apps, without code changes | | Registry | zot | Optional - switched on in System › Registry | A container registry of your own, for images built on a multi-node cluster | | Function runtimes | hivepaas/function-runtimes | Optional - when you use functions | The images functions are built on | | Dashboard | React 19, Vite, TypeScript, Tailwind CSS, TanStack Query | Required | The web interface |
📚 Documentation
- User documentation: docs.hivepaas.com - installation, deploying apps, domains, backups, clusters and troubleshooting.
- REST API: the API reference, from the OpenAPI description in docs/openapi/swagger.json.
- Developing HivePaaS: docs/DEVELOPMENT.md and docs/ARCHITECTURE.md.
- Releasing: docs/RELEASING.md.
🔒 Security
Please report vulnerabilities privately, through GitHub's vulnerability reporting - never in a public issue. See SECURITY.md for what to include and what happens next.
💬 Community & Support
- Discord - questions, and help from the team and the community.
- GitHub Issues - bugs and feature requests.
- Getting help - what to include so a question gets an answer sooner.
🤝 Contributing
Contributions, issues, and feature requests are welcome!
Setting up a development machine - the local cluster, the three ways to run the backend, and what to run before you push - is in docs/DEVELOPMENT.md.
- Fork the Project
- Create your Feature Branch (
git checkout -b feature/AmazingFeature) - Commit your Changes (
git commit -m 'feat: Add some AmazingFeature') - Push to the Branch (
git push origin feature/AmazingFeature) - Open a Pull Request using our PR Template
📄 License
Distributed under the Apache 2.0 License. See LICENSE for more information.