The open components
The open components are the parts of PaaSbox you can run, read and change yourself: the building blocks for Kubernetes clusters on Hetzner, the platform and the PaaS layer on top, the catalog of connected apps, and the guardrails that let an agent operate an app. They are free. The building blocks are under Apache-2.0; the pool manager is source-available under BSL-1.1.
They are being prepared for publication. With one exception, nothing is published yet: the Garden Linux build for Hetzner, gardenlinux-hcloud, is public on GitHub with its node images as release assets, because servers download their node image from there. Several other repositories exist on GitHub and are empty. The licences below are the ones each component is published under.
The line between open and closed
Section titled “The line between open and closed”The mechanism is open; the operation is a service. Whoever lets an agent touch their systems wants to read the format, the guardrails and the lab proofs, and to rerun them, so those are open: the building blocks, the catalog format, the action runner, the read proxy, the harness and the measured results. What costs work and money every month is closed or sold as a service: keeping clusters current (PaaSbox Clusters), the curated catalog at breadth with its restore drills and upgrade gates, and the operations themselves.
Published in waves
Section titled “Published in waves”The components go public in three waves. The first comes before or together with ownpaas, because ownpaas builds its clusters from them.
| Wave | What | Status |
|---|---|---|
| 1 | The building blocks for clusters on Hetzner with Cluster API and k3s, the platform, the Gardener extensions for Hetzner, the node images, and the pool manager | In progress prepared, and the checks every export must pass are green; the repositories go private first, then public |
| 2 | The catalog (the format, validate and lint, the operability rubric, the lab rows), the PaaS layer with the pb CLI, the paasbox CLI and the exit kit | Planned after the catalog’s next merge and a cleanup of names and labels the export checks still find |
| 3 | The open agent-operations pieces: the action runner and the MCP actions server, the read proxy, the harness, and the four golden entries complete | Planned after the runner and the harness move out of ownpaas into the open catalog component |
Where a cluster comes from
Section titled “Where a cluster comes from”Every app runs on a Kubernetes cluster in your own Hetzner project. There are three ways to get one:
| Way | For | Status |
|---|---|---|
| The open building blocks, Cluster API with k3s | a few clusters you run yourself, single-node clusters, the lab | Built measured on Hetzner, being prepared for publication |
| PaaSbox Clusters | a single-node k3s cluster that the portal creates in your project and keeps current, one per stage and per app. It does not use Cluster API: the portal talks to Hetzner directly, and pbx-agent on the node does the rest | Built in a lab, not bookable yet |
| Gardener | a fleet you run yourself: control planes as pods on a seed, workers in your project. Its Hetzner extensions are open components | Built in a lab; PaaSbox does not offer Gardener clusters |
Every component
Section titled “Every component”The status in the third column is the component’s own: whether it runs, not whether it is published.
Clusters on Hetzner
Section titled “Clusters on Hetzner”| Component | What it does | Status | Licence | Wave |
|---|---|---|---|---|
nodepool-core | The node-pool core: adopts existing Hetzner servers as Kubernetes nodes that are never deleted; the library the providers below import | Built | Apache-2.0 | 1 |
cluster-api-provider-nodepool | A Cluster API infrastructure provider whose machines are claimed from a pool of existing Hetzner servers and released back, never created or deleted | Built | Apache-2.0 | 1 |
| The patched Cluster API provider for Hetzner (CAPH) | Cluster API on Hetzner Cloud, with the patches the k3s path needs | Built | Apache-2.0 | 1 |
cloud-gateway | One NAT gateway per Hetzner Cloud network, shared by the clusters on it | Built | Apache-2.0 | 1 |
gardenlinux-hcloud | The Garden Linux build for Hetzner Cloud and dedicated servers: the recipe, the scripts and the node images, with k3s inside for the k3s image | Built | Apache-2.0 | 1, already public |
hcloud-pool-manager | The fleet controller that keeps a fleet’s pooled servers, cloud and dedicated | Built | BSL-1.1: source-available, free to use except to offer a managed pool or Kubernetes service to others; each release becomes Apache-2.0 three years after it | 1 |
The platform and the PaaS layer
Section titled “The platform and the PaaS layer”| Component | What it does | Status | Licence | Wave |
|---|---|---|---|---|
saas-platform | The Platform kind and its capabilities: certificates, TLS, observability, a Postgres operator, backups, for small Kubernetes clusters; and SaaSApplication, one object per app with its processes, Postgres, cache, release hooks and URL. On PaaSbox Clusters it is the PaaSbox Platform add-on | Built in a lab, on one k3s node; as the add-on of PaaSbox Clusters Built in a lab on 2026-10-11, not published yet | Apache-2.0 | 1 |
The PaaS layer (paasbox-paas) and the pb CLI | App, ManagedPostgres, ManagedValkey and ManagedTracing on a Gardener cluster, and a small CLI for what kubectl is bad at | Built on real Hetzner shoots, measured until 2026-09-18; building from source and workspaces In progress | Apache-2.0 | 2 |
Gardener on Hetzner
Section titled “Gardener on Hetzner”| Component | What it does | Status | Licence | Wave |
|---|---|---|---|---|
gardener-extension-provider-hcloud | The Gardener provider extension for Hetzner Cloud: infrastructure, control plane, workers, private egress and the NAT gateway | Built | Apache-2.0 | 1 |
machine-controller-manager-provider-hcloud | Gardener’s machine controller for Hetzner Cloud, with an in-place rebuild for adopted servers | Built | Apache-2.0 | 1 |
gardener-extension-backupbucket-hcloud | Gardener’s backup buckets in Hetzner Object Storage | Built | Apache-2.0 | 1 |
gardener-extension-dnsrecord-hcloud | Gardener’s DNS records in Hetzner DNS | Built | Apache-2.0 | 1 |
cert-manager-webhook-hcloud | cert-manager’s DNS-01 challenge with Hetzner DNS | Built | Apache-2.0 | 1 |
The paasbox CLI and the exit kit | Your own Gardener landscape on Hetzner Cloud in one command, and the kit that rebuilds a garden and seed in your project | Built | Apache-2.0 | 2 |
These are for a Gardener landscape you run yourself, the next level once a fleet of clusters needs one control point. PaaSbox does not offer Gardener clusters, and no landscape runs for customers. Gardener on Hetzner.
The catalog and the guardrails
Section titled “The catalog and the guardrails”| Component | What it does | Status | Licence | Wave |
|---|---|---|---|---|
| The catalog | The entry format, resolve and render, the providers, validate and lint, the operability rubric and the lab rows that prove an entry | Built in a lab | Apache-2.0 | 2 |
| The four golden entries | Forgejo, Vaultwarden, Listmonk and Umami, complete with their operate skills and evals | Built in a lab | Apache-2.0 | 3 |
| The action runner and the MCP actions server | An entry’s typed actions as MCP tools: destructive ones refused unless allowed, approvals where the entry asks for one, an audit log | Built in ownpaas, in a lab; Planned its move into the open catalog component | Apache-2.0 | 3 |
| The harness | Has an agent operate a live app through its operate skill and its evals, approvals simulated and recorded, graded | Built in a lab; Planned its move into the open catalog component | Apache-2.0 | 3 |
The read proxy (paasbox-kube-read) | Gives agents kubectl for reading only, refuses Secrets, and redacts secret values in every answer and log line | In progress on a branch, tested on a throwaway cluster | Apache-2.0 | 3 |
| The community catalog | Imported and contributed entries | Planned | Apache-2.0 | later |
Agents operating your apps says what these pieces did in the lab.
PaaSbox Clusters’ node agent
Section titled “PaaSbox Clusters’ node agent”| Component | What it does | Status | Licence | Wave |
|---|---|---|---|---|
pbx-agent | The program on each node of a PaaSbox Clusters cluster: it calls the portal over outbound HTTPS, applies the desired state and runs a fixed list of operations | Built in a lab, on real Hetzner servers | Not decided yet; its source files carry the Apache-2.0 header | not scheduled |
pbx-agent runs as root on your server, so its source is meant to be readable. The portal it talks to stays closed. pbx-agent describes it.
What stays closed
Section titled “What stays closed”| Part | Licence | Status |
|---|---|---|
| PaaSbox Clusters: the portal, its hub and its provisioner, which create your clusters and keep them current | closed, sold as software as a service | Built the hub and the provisioner, in a lab; In progress the create form, billing through Paddle, the REST API and MCP tools; not live |
| The entry agent’s pipeline, run as the onboarding service in the portal | closed, a service | Built the entry agent, in a lab; Planned the service in the portal |
| The curated catalog at breadth, with the operate skills of its entries | closed, by subscription | Planned |
| Fleet operations (the agent engine, the approvals inbox, telemetry) and the managed service | closed, a service | Planned |
| The portal behind paasbox.com, and ownpaas | closed | ownpaas Planned, to be sold later |
The PaaS layer
Section titled “The PaaS layer”The PaaS layer is an open component on a Gardener cluster. Its pages are kept as they were written, each with its status at the top:
- The PaaS layer: what it adds to a cluster, and what is proven where.
- Deploy an app, Databases, Redis-compatible caches, Tracing for AI applications, Preview environments.
- Example: a Django SaaS and the
pbCLI.
Where they will be
Section titled “Where they will be”The repositories are being prepared under github.com/paasbox-cloud. Each public repository gets one commit per release, with its licence, a security policy and the way to contribute.