Skip to content

The open components

The open components are the parts of PaaSbox you can run, read and change yourself: the building blocks for Kubernetes clusters on Hetzner, the platform and the PaaS layer on top, the catalog of connected apps, and the guardrails that let an agent operate an app. They are free. The building blocks are under Apache-2.0; the pool manager is source-available under BSL-1.1.

They are being prepared for publication. With one exception, nothing is published yet: the Garden Linux build for Hetzner, gardenlinux-hcloud, is public on GitHub with its node images as release assets, because servers download their node image from there. Several other repositories exist on GitHub and are empty. The licences below are the ones each component is published under.

The mechanism is open; the operation is a service. Whoever lets an agent touch their systems wants to read the format, the guardrails and the lab proofs, and to rerun them, so those are open: the building blocks, the catalog format, the action runner, the read proxy, the harness and the measured results. What costs work and money every month is closed or sold as a service: keeping clusters current (PaaSbox Clusters), the curated catalog at breadth with its restore drills and upgrade gates, and the operations themselves.

The components go public in three waves. The first comes before or together with ownpaas, because ownpaas builds its clusters from them.

WaveWhatStatus
1The building blocks for clusters on Hetzner with Cluster API and k3s, the platform, the Gardener extensions for Hetzner, the node images, and the pool managerIn progress prepared, and the checks every export must pass are green; the repositories go private first, then public
2The catalog (the format, validate and lint, the operability rubric, the lab rows), the PaaS layer with the pb CLI, the paasbox CLI and the exit kitPlanned after the catalog’s next merge and a cleanup of names and labels the export checks still find
3The open agent-operations pieces: the action runner and the MCP actions server, the read proxy, the harness, and the four golden entries completePlanned after the runner and the harness move out of ownpaas into the open catalog component

Every app runs on a Kubernetes cluster in your own Hetzner project. There are three ways to get one:

WayForStatus
The open building blocks, Cluster API with k3sa few clusters you run yourself, single-node clusters, the labBuilt measured on Hetzner, being prepared for publication
PaaSbox Clustersa single-node k3s cluster that the portal creates in your project and keeps current, one per stage and per app. It does not use Cluster API: the portal talks to Hetzner directly, and pbx-agent on the node does the restBuilt in a lab, not bookable yet
Gardenera fleet you run yourself: control planes as pods on a seed, workers in your project. Its Hetzner extensions are open componentsBuilt in a lab; PaaSbox does not offer Gardener clusters

The status in the third column is the component’s own: whether it runs, not whether it is published.

ComponentWhat it doesStatusLicenceWave
nodepool-coreThe node-pool core: adopts existing Hetzner servers as Kubernetes nodes that are never deleted; the library the providers below importBuiltApache-2.01
cluster-api-provider-nodepoolA Cluster API infrastructure provider whose machines are claimed from a pool of existing Hetzner servers and released back, never created or deletedBuiltApache-2.01
The patched Cluster API provider for Hetzner (CAPH)Cluster API on Hetzner Cloud, with the patches the k3s path needsBuiltApache-2.01
cloud-gatewayOne NAT gateway per Hetzner Cloud network, shared by the clusters on itBuiltApache-2.01
gardenlinux-hcloudThe Garden Linux build for Hetzner Cloud and dedicated servers: the recipe, the scripts and the node images, with k3s inside for the k3s imageBuiltApache-2.01, already public
hcloud-pool-managerThe fleet controller that keeps a fleet’s pooled servers, cloud and dedicatedBuiltBSL-1.1: source-available, free to use except to offer a managed pool or Kubernetes service to others; each release becomes Apache-2.0 three years after it1
ComponentWhat it doesStatusLicenceWave
saas-platformThe Platform kind and its capabilities: certificates, TLS, observability, a Postgres operator, backups, for small Kubernetes clusters; and SaaSApplication, one object per app with its processes, Postgres, cache, release hooks and URL. On PaaSbox Clusters it is the PaaSbox Platform add-onBuilt in a lab, on one k3s node; as the add-on of PaaSbox Clusters Built in a lab on 2026-10-11, not published yetApache-2.01
The PaaS layer (paasbox-paas) and the pb CLIApp, ManagedPostgres, ManagedValkey and ManagedTracing on a Gardener cluster, and a small CLI for what kubectl is bad atBuilt on real Hetzner shoots, measured until 2026-09-18; building from source and workspaces In progressApache-2.02
ComponentWhat it doesStatusLicenceWave
gardener-extension-provider-hcloudThe Gardener provider extension for Hetzner Cloud: infrastructure, control plane, workers, private egress and the NAT gatewayBuiltApache-2.01
machine-controller-manager-provider-hcloudGardener’s machine controller for Hetzner Cloud, with an in-place rebuild for adopted serversBuiltApache-2.01
gardener-extension-backupbucket-hcloudGardener’s backup buckets in Hetzner Object StorageBuiltApache-2.01
gardener-extension-dnsrecord-hcloudGardener’s DNS records in Hetzner DNSBuiltApache-2.01
cert-manager-webhook-hcloudcert-manager’s DNS-01 challenge with Hetzner DNSBuiltApache-2.01
The paasbox CLI and the exit kitYour own Gardener landscape on Hetzner Cloud in one command, and the kit that rebuilds a garden and seed in your projectBuiltApache-2.02

These are for a Gardener landscape you run yourself, the next level once a fleet of clusters needs one control point. PaaSbox does not offer Gardener clusters, and no landscape runs for customers. Gardener on Hetzner.

ComponentWhat it doesStatusLicenceWave
The catalogThe entry format, resolve and render, the providers, validate and lint, the operability rubric and the lab rows that prove an entryBuilt in a labApache-2.02
The four golden entriesForgejo, Vaultwarden, Listmonk and Umami, complete with their operate skills and evalsBuilt in a labApache-2.03
The action runner and the MCP actions serverAn entry’s typed actions as MCP tools: destructive ones refused unless allowed, approvals where the entry asks for one, an audit logBuilt in ownpaas, in a lab; Planned its move into the open catalog componentApache-2.03
The harnessHas an agent operate a live app through its operate skill and its evals, approvals simulated and recorded, gradedBuilt in a lab; Planned its move into the open catalog componentApache-2.03
The read proxy (paasbox-kube-read)Gives agents kubectl for reading only, refuses Secrets, and redacts secret values in every answer and log lineIn progress on a branch, tested on a throwaway clusterApache-2.03
The community catalogImported and contributed entriesPlannedApache-2.0later

Agents operating your apps says what these pieces did in the lab.

ComponentWhat it doesStatusLicenceWave
pbx-agentThe program on each node of a PaaSbox Clusters cluster: it calls the portal over outbound HTTPS, applies the desired state and runs a fixed list of operationsBuilt in a lab, on real Hetzner serversNot decided yet; its source files carry the Apache-2.0 headernot scheduled

pbx-agent runs as root on your server, so its source is meant to be readable. The portal it talks to stays closed. pbx-agent describes it.

PartLicenceStatus
PaaSbox Clusters: the portal, its hub and its provisioner, which create your clusters and keep them currentclosed, sold as software as a serviceBuilt the hub and the provisioner, in a lab; In progress the create form, billing through Paddle, the REST API and MCP tools; not live
The entry agent’s pipeline, run as the onboarding service in the portalclosed, a serviceBuilt the entry agent, in a lab; Planned the service in the portal
The curated catalog at breadth, with the operate skills of its entriesclosed, by subscriptionPlanned
Fleet operations (the agent engine, the approvals inbox, telemetry) and the managed serviceclosed, a servicePlanned
The portal behind paasbox.com, and ownpaasclosedownpaas Planned, to be sold later

The PaaS layer is an open component on a Gardener cluster. Its pages are kept as they were written, each with its status at the top:

The repositories are being prepared under github.com/paasbox-cloud. Each public repository gets one commit per release, with its licence, a security policy and the way to contribute.