Open source
Our open-source projects
We maintain libraries for our products and tools we use in production. Each project includes tests, documentation and guidance on its limitations. You can explore the code, try a package or contribute a fix.
Library · TypeScript
octaflow
Durable workflows on the Postgres you already have.
Declare a DAG of Zod-typed steps. The engine runs each step as soon as its dependencies complete, persists every transition, retries failures, and picks up where it left off after a restart.
Import octaflow into your application and run it on your existing Postgres database. The queue also uses Postgres, so there is no separate workflow server or control plane to operate.
Workflows are declared as a DAG that you can inspect before execution. This differs from an imperative workflow, where control flow is expressed in a function.
The engine supports retries, timeouts, durable sleep, concurrency caps, rate limits, cron starts, idempotent starts, dynamic fan-out, signals, sub-workflows, saga compensation and pluggable observability. It is pre-1.0 and has no dashboard or polyglot SDKs.
- TypeScript
- Zod
- PostgreSQL
- pg-boss
- Vitest
Monorepo · TypeScript
octabits
Libraries for multi-tenant SaaS and AI features with human review.
Individual packages provide row-level security, field encryption, data-subject requests, queues, events, telemetry and human review of AI proposals. They use your existing Postgres database.
Use individual packages in your Hono, Next.js, Nuxt, Vite or Express backend. Optional peer dependencies let you choose the drivers, ORM and UI framework you need.
Automated tests cover six design goals: RLS support, Postgres-only infrastructure, AI integration, data protection, EU deployment options and auditability.
These packages were developed in Reynt and proven in production there. They will be released as open source under the MIT licence in November 2026.
- TypeScript
- PostgreSQL
- Drizzle ORM
- Prisma
- Zod
- pg-boss
- Vue
- React
Kubernetes webhook · Go
cert-manager-webhook-porkbun
Wildcard certificates for Porkbun domains on Kubernetes.
An ACME DNS-01 solver that adds Porkbun support to cert-manager. We maintain this fork with a rewritten API client, security hardening and tests.
The upstream version could crash on malformed responses and gave limited information about API failures. It also lacked HTTP timeouts, used a TTL below the provider’s minimum and requested read access to every Secret in the cluster.
The rewritten client checks responses, handles missing values and reports API errors. Requests have timeouts and retry with backoff and jitter. Concurrent challenges are serialised, and the public suffix list is used to handle delegated sub-zones.
The container runs as uid 65532 on a distroless image, with a read-only root filesystem and all capabilities dropped. Access is restricted to named Secrets in named namespaces. Images are signed with cosign and include SBOM and provenance attestations. Weekly vulnerability scans check for issues discovered after release.
- Go
- Kubernetes
- cert-manager
- Helm
- Let’s Encrypt
- cosign
- Trivy
Contributing
Report a bug or contribute a fix
Pull requests are welcome. Please include steps to reproduce any bug you report. Each repository has a contribution guide covering setup, code checks and the requirements for new integrations.