The Portable DevSecOps Control Plane for Modern Web Apps

Deploy faster. Secure honestly. Operate with confidence.

Deploy, secure, monitor, and connect your applications from one powerful platform. Manage reverse proxies, apps, Docker, certificates, WAF, Security Center, VPN mesh, and cluster operations without stitching together ten different tools.

Download v{{VERSION}} Explore Features Getting Started
v{{VERSION}} · Security Center · .NET 8 · Windows 10/11 + Linux x64 · GUI ~222 MB (Full) / ~98 MB (Lite) · CLI ~27-40 MB
22
GUI Sidebar Views
20
REST API Endpoints
6
Starter Plugins
28
Compliance Controls
12
WAF Rules Built-in

Everything You Need

A complete development and production web stack that runs from any folder. No installation, no registry changes, no admin required.

🔒

TLS Termination & Reverse Proxy

Apache 2.4 reverse proxy with TLS 1.2/1.3, SNI multi-domain support, Let's Encrypt automation via bundled win-acme, self-signed cert generation with bundled OpenSSL. Auto-detects cert paths and generates vhost configs.

App Runner & Sub-Processes

Start, stop, and monitor backend apps with health checks, auto-restart on crash, and multi-stage sub-processes. Run Supabase + npm dev simultaneously. Auto-accept prompts for npx/npm commands. Per-app environment variables.

📦

Secure Project Import (Drag & Drop Deploy)

Drop a .zip/.7z project onto the Dashboard and ProxyStack extracts it, detects the stack — Node.js, Bun, Python, Go, .NET, Java, Ruby, PHP, Rust, Deno, Docker Compose, or a raw Dockerfile — and dry-runs executable stacks through the Process Reputation sandbox before ever presenting a command as trustworthy. Frontend builds can deploy as a static Site instead of a long-running process. Docker Compose imports get their own managed project tab with rollback, service status, profile/service selection, and logs. Auto Build shows a build plan, env-var guidance, and failure logs before you guess at fixes. Every import's full evidence trail is logged permanently.

🐳

Docker & PostgreSQL

Full Docker container management with Compose up/down, image pull, container logs. Portable PostgreSQL with one-click auto-install and progress bar. Database console for direct SQL queries. Supabase health monitoring.

🛡

SentinelAI Integration

Connect to your SentinelAI dashboard for 25+ real-time security monitors, 3-stage ML threat detection (local ML → heuristics → AI), ransomware canary files, fleet management, and remote agent commands.

OWASP Compliance Dashboard

10 automated checks against the OWASP Top 10 2025. Security score 0–100 with pass/fail breakdown per category. Color-coded OWASP cards for A01 through A10. Export compliance reports as CSV or TXT.

🛡

Web Application Firewall (WAF)

14 built-in rules covering SQL injection, XSS, path traversal, command injection, SSRF, and more. Custom rule editor with regex patterns. Block-mode rules are enforced inline (real 403s, not just logging) whenever the pattern can be safely compiled into config, on both Nginx and Apache. Export as ModSecurity .conf for a separately installed ModSecurity module.

🔍

Security Scanner

Quick Scan (11 checks) and Full Scan (18 checks) covering TLS config, headers, directory permissions, secrets exposure, network ports, containers, database security, and more. Severity breakdown: Critical, High, Medium, Low. Async scanning with progress bar. Results persisted and exportable.

🔑

Secrets Vault Pro

DPAPI-encrypted key-value store (Windows CurrentUser scope). 8 categories: General, Database, API Key, OAuth, SSL/TLS, Cloud, Service, Internal. Reveal with 5-second auto-hide. Copy with 30-second clipboard auto-clear. One-click rotation with 32-char cryptographic random. Export as .env file. Backward compatible with legacy format.

📋

Compliance Reporting

4 frameworks: SOC2 Type II (9 controls), GDPR (6 articles), PCI-DSS v4.0 (8 requirements), HIPAA (5 safeguards). "All Frameworks" mode runs all 28 checks at once. Each check evaluates real config and provides evidence. Compliance score with pass/fail/N/A. Export as CSV or formatted TXT.

🔐

Zero Trust Security

mTLS (mutual TLS) toggle with CA certificate generation (RSA 4096-bit, 10yr) and server certificate generation (RSA 2048-bit, 2yr) with auto-SAN from configured domains. Certificate-based auth policies: CN, OU, Issuer, Fingerprint, SAN match. Network segmentation zones with CIDR, port, and direction rules. Trust score 0–100. Export Apache .conf with SSLVerifyClient and SSLRequire directives.

🛡

Security Center & Process Reputation

Unified status + threat timeline across WAF, SentinelAI, Cluster, Microsoft Defender, ClamAV, and Headscale VPN. Process Reputation monitors every ProxyStack-managed app's processes in real time - deterministic risk scoring, VirusTotal hash lookup, explicitly-gated sample submission, isolated low-privilege sandbox detonation, and policy enforcement (Kill/Quarantine/Block/Isolate/Approve), manual or fully automatic.

📈

Monitoring & Observability

Real-time CPU, RAM, and disk metrics. Real request rate and error rate parsed from live Nginx access logs. Latency percentiles shown when computable, honestly reported as unavailable otherwise - see Proof Status. Custom alert thresholds with email and Slack notifications.

👥

Team Collaboration

Multi-user RBAC with admin, editor, and viewer roles. Audit logging for all config changes. Share complete stack configs via .psxt templates (v1.1 bundles SSL certs as base64). Slack webhook notifications. Import creates missing site directories automatically.

🚀

Production Ready

Rate limiting per-IP and per-route (Nginx). Automated config backups with rotation. Load balancing across multiple backends. SSL certificate expiry monitoring via the Cert Expiry Notifier plugin. Remote management REST API for headless operation.

🔌

Integrations & Extensibility

REST API v2.0 with 20 endpoints for remote management. Real plugin runtime with 6 bundled starter plugins and a hosted marketplace for more. Multi-server cluster management with config sync, plus optional VPN mesh join. VS Code extension, CLI tool, 19 service blueprints (Next.js, Django, Flask, Express, etc.).

🔨

Advanced Features

Request/response rewriting with regex. HTTP caching layer with Redis support. API gateway with path-based versioning. Dark/light theme toggle. Auto-update system with SHA256 integrity verification and rollback. Classic UI mode via --classic flag.

🗂

Portable PostgreSQL

One-click PostgreSQL auto-install with progress bar. Start/stop/restart from the GUI. Database list, create/drop databases, and a built-in SQL query runner. No Docker required — runs as a portable binary from the postgres/ folder.

🔒

SSL Certificate Manager

Dedicated Certificates view for managing all SSL certs. Let's Encrypt automation via bundled win-acme (HTTP-01 validation). Self-signed cert generation via bundled OpenSSL. Auto-detect cert paths by domain name. Certificate expiry monitoring with alerts.

🛒

Plugin Marketplace

Real hook-based plugin runtime: 6 bundled starter plugins (Uptime Pinger, Cert Expiry Notifier, Deploy Webhook Notifier, Brute-Force IP Blocker, Config Git History, Daily Ops Digest), all disabled by default. Browse and one-click install more from the hosted marketplace, SHA256-verified, or install your own from a local ZIP.

🌐

Cluster Management

Multi-server node management from a single dashboard. Add remote ProxyStack instances, monitor health status, and push configuration to secondary nodes. Auto-refresh every 30 seconds. Enterprise license required.

💳

Licensing & Monetization

Built-in license activation on the Dashboard. Community (free), Pro, and Enterprise tiers with runtime feature gating. Stripe integration for checkout. License API (FastAPI) for validation, deactivation, and admin management. 14-day Pro trial included.

📋

Logs & Diagnostics

Centralized log viewer for Apache access/error logs and per-site logs. Real-time log tailing. Application settings management with theme toggle, auto-start configuration, and environment profile switching. All from dedicated Logs and Settings views.

How It Works

From download to production in under 5 minutes.

1

Download & Unzip

Download the portable ZIP (~138 MB). Extract to any folder. No installer needed.

2

Launch ProxyStack

Run ProxyStackGUI.exe. The modern dark-themed GUI opens with 22 sidebar views ready to use.

3

Add Your Sites

Configure domains, backends, and SSL certs from the Sites tab. Apache vhosts are auto-generated.

4

Start Apache

One click to start Apache. Your reverse proxy is live with TLS, security headers, and WAF protection.

22 Sidebar Views

Click any view to see what's inside. Every feature accessible from a modern dark-themed control panel.

01DashboardFree
02SitesFree
03AppsFree
04PostgreSQLFree
05DockerFree
06CertificatesFree
07MonitorFree
08SecurityFree
09ComplianceFree
10WAFFree
11ScannerFree
12Secrets VaultFree
13ReportsPro
14Zero TrustEnterprise
15SentinelAIPro
16TeamPro
17ObservabilityPro
18AdvancedFree
19ClusterEnterprise
20Security CenterEnterprise
21LogsFree
22SettingsFree

Dashboard

  • Start / Stop / Restart Apache
  • Service status cards (Apache, PostgreSQL, Docker)
  • Quick actions panel
  • Check for updates with SHA256 verification
  • License activation & 14-day Pro trial
  • Version info & system overview

Sites

  • Add / edit / remove domains
  • Reverse proxy target configuration
  • SSL certificate assignment
  • SPA fallback toggle
  • Per-path proxy routes (API + WebSocket)
  • Domain aliases
  • Auto-generate Apache vhost configs

Apps

  • Backend process manager
  • Sub-processes (e.g. Supabase + npm dev)
  • Auto-restart on crash
  • Health check monitoring
  • Per-app environment variables
  • Auto-accept npx/npm prompts

PostgreSQL

  • Start / stop / restart PostgreSQL
  • One-click auto-install with progress bar
  • Database list, create, drop
  • Built-in SQL query runner
  • Connection status monitoring
  • Portable binary (no Docker needed)

Docker

  • Container management (start, stop, restart, remove)
  • Docker Compose up/down
  • Image pull with progress
  • Container logs & inspect
  • 12 one-click container templates
  • Resource monitoring per container

Certificates

  • Let's Encrypt via bundled win-acme
  • Self-signed cert generation (OpenSSL)
  • Auto-detect cert paths by domain
  • Certificate expiry monitoring
  • Cert/key/chain file management

Monitor

  • Real-time CPU, RAM, disk metrics
  • Service health checks
  • Custom alert thresholds
  • Email & Slack notifications
  • 5-minute cooldown per service

Security

  • Security headers (HSTS, X-Frame, X-Content-Type, X-XSS) - enforced on both Nginx and Apache
  • IP whitelist / blacklist - enforced on both engines
  • REST API toggle (port 9090)
  • Auto-start with Windows
  • Environment profiles (dev/staging/prod)

Compliance (OWASP)

  • OWASP Top 10 2025 automated checks
  • Security score 0–100
  • Color-coded category cards (A01–A10)
  • Pass/fail breakdown per category
  • Export as CSV or TXT

Web Application Firewall

  • 14 built-in rules (SQLi, XSS, SSRF, etc.)
  • Custom rule editor with regex
  • Real inline blocking on both Nginx and Apache (403 before your site sees the request)
  • ModSecurity .conf export
  • Threat log (logs/waf-threats.jsonl) fed by real blocks plus a 60-second access-log scan

Security Scanner

  • Quick Scan (11 checks)
  • Full Scan (18 checks) — Pro
  • TLS, headers, permissions, secrets, ports
  • Severity: Critical / High / Medium / Low
  • Results saved to logs/security-scan.json

Secrets Vault

  • DPAPI-encrypted storage (Windows CurrentUser)
  • 8 categories (Database, API Key, OAuth, etc.)
  • 5-second auto-hide reveal
  • 30-second clipboard auto-clear
  • One-click 32-char rotation
  • Export as .env file

Compliance Reports Pro

  • SOC2 Type II (9 controls)
  • GDPR (6 articles)
  • PCI-DSS v4.0 (8 requirements)
  • HIPAA (5 safeguards)
  • "All Frameworks" mode (28 checks)
  • Export CSV / TXT

Zero Trust Enterprise

  • mTLS toggle with CA cert generation (RSA 4096)
  • Server cert generation (RSA 2048, auto-SAN)
  • Certificate auth policies (CN, OU, Issuer, Fingerprint, SAN)
  • Network segmentation zones (CIDR, port, direction)
  • Trust score 0–100
  • Export Apache .conf

SentinelAI Pro

  • Connect to SentinelAI dashboard
  • View agents & threat events
  • Launch Windows agent
  • 25+ real-time security monitors
  • 3-stage ML threat detection

Team Pro

  • Multi-user RBAC (Admin/Developer/Operator/Viewer)
  • Audit logging for all changes
  • .psxt template sharing (v1.2 bundles certs + files)
  • Slack webhook notifications
  • Up to 3 users (Pro), unlimited (Enterprise)

Observability Pro

  • Real request rate and error rate, parsed from live Nginx access logs
  • Latency percentiles (P50/P95/P99) shown when computable, honestly "n/a" otherwise - no per-request timing field in the access log yet
  • Recent request log

Advanced

  • Request/response rewriting and API gateway config editors (Classic UI - saved but not yet applied to live traffic)
  • Real per-site proxy caching (Nginx, via Sites tab)
  • Plugin Marketplace: 6 starter plugins + hosted marketplace (Pro to install)
  • Database console

Cluster Enterprise

  • Add/remove remote ProxyStack nodes
  • Health check all nodes (/api/status)
  • Push config to secondary nodes
  • Auto-refresh every 30 seconds
  • Node roles: Primary, Secondary, Standby, Worker
  • Activity log with timestamps
  • Optional VPN mesh join when adding a node (installs the ProxyStackVPN client on the remote node if needed) - cross-platform as of v14.17.0, Linux/macOS nodes included

Security Center Enterprise

  • Unified status cards + threat timeline across WAF, SentinelAI, Cluster, Microsoft Defender, ClamAV, and Headscale VPN
  • Process Reputation: real Windows process-tree monitoring for every ProxyStack-managed app, with deterministic risk scoring
  • Reputation lookup: local allowlist/blocklist plus a real VirusTotal hash-only lookup (never uploads a file automatically)
  • Controlled sample submission to VirusTotal (explicit privacy warning + confirmation required)
  • Sandbox detonation: runs a flagged sample in an isolated, network-restricted, low-integrity-privilege temp environment (~15s) to observe real behavior
  • Policy enforcement: Kill, Quarantine, Block re-launch, Isolate network, or Require approval - manual or fully automatic once explicitly enabled
  • Every card is a real provider call - an unreachable or not-installed provider is shown honestly, never hidden

Logs

  • Apache access & error logs
  • Per-site log files
  • Real-time log tailing
  • Log file viewer

Settings

  • Theme toggle (dark/light)
  • Auto-start Apache on launch
  • Auto-start with Windows
  • Environment profile switching
  • REST API configuration

Download ProxyStack

Unzip and run. No installation, no registry changes, no admin required. Built-in auto-updater keeps you current.

Lite Edition Windows GUI

~98 MB · v{{VERSION}}
Everything except PostgreSQL, ClamAV, and Headscale VPN - all three are one click away with the built-in "Download & Install" from the Docker/Security Center tabs whenever you need them. All 22 GUI views included.
Download Lite Edition

Cross-Platform CLI — 29 Commands, 5 Platforms

Single-binary, self-contained, no runtime needed. Docker, secure import, security scanning, backups, SentinelAI, monitoring — the portable control plane from the terminal.

Linux ARM64 v14.19.0

~30 MB · .tar.gz
Raspberry Pi 4/5, AWS Graviton, Oracle Ampere, Apple Silicon VMs. Same 29 commands, same config format.
Download Linux ARM64

Windows x64 v14.19.0

~43 MB · .zip · Includes SentinelAI Agent
Server Core, CI/CD pipelines, SSH management. Same proxystack.json as the GUI. Bundled SentinelAI security agent. Full feature parity.
Download Windows x64

macOS x64 (Intel) v14.19.0

~31 MB · .tar.gz
Intel Macs (2012–2020). Manage Nginx/Apache, certs, Docker, security scans from Terminal.
Download macOS Intel

macOS ARM64 (Apple Silicon) v14.19.0

~29 MB · .tar.gz
M1/M2/M3/M4 Macs. Native Apple Silicon binary — no Rosetta needed. Full CLI feature parity.
Download macOS Apple Silicon

All builds also available via GitHub CI/CD with automated tests

Linux Quick Start → One-liner install instructions

SentinelAI Security Agent

Cross-platform endpoint security agent — monitors processes, network, files, auth logs, cron jobs, and SSH keys. Reports to the SentinelAI dashboard with ML-powered threat detection.

Linux x64 Agent v2.0.0

~12 MB · .tar.gz · Single binary, no Python needed
Ubuntu, Debian, RHEL, Arch. 6 monitors: process, network, file integrity, auth log brute force, cron persistence, SSH key tampering. Connects to SentinelAI dashboard.
Download Linux x64 Agent

Windows x64 Agent v2.0.0

~11 MB · .zip · Single EXE, no Python needed
Windows 10/11, Server 2016+. Process, network, and file monitoring with Windows-specific registry, event log, and service detection. ML-powered analysis.
Download Windows x64 Agent

macOS and ARM64 agent builds coming soon · SentinelAI Dashboard →

VirusTotal Scan Results

Every release is scanned with 70+ antivirus engines. Transparency matters.

ProxyStackGUI.exe

0 / 72
security vendors flagged this file
CLEAN

ProxyStackGUI.dll

1 / 72
security vendors flagged this file
UNDER REVIEW

ProxyStackUpdater.exe

0 / 71
security vendors flagged this file
CLEAN

Scanned March 12, 2026 · v14.3.3 · SHA256 hashes verified

Latest scans: GUI EXE and Updater are clean; DLL has one vendor flag currently under review.

System Requirements

ProxyStack GUI runs on Windows with .NET 8. The CLI runs on Windows and Linux with zero dependencies.

💻
Windows 10/11 64-bit, version 1809 or later (GUI + CLI)
🐧
Linux x64 Ubuntu, Debian, RHEL, Arch, etc. (CLI only, self-contained)
.NET 8 Runtime Desktop runtime (auto-prompted if missing)
💾
300 MB Disk Space ~138 MB download + room for logs, certs, backups
🔌
Ports 80 & 443 For Apache reverse proxy (configurable)
🐳
Docker (Optional) Only needed for container management features
🌐
Internet (Optional) For Let's Encrypt, updates, and SentinelAI. Works offline otherwise.

Stay Updated

Get notified about new releases, security advisories, and tips.

Changelog

Recent updates and improvements across all releases.

v{{VERSION}} (continued) - AI Runtime Manager: Local LLM Hosting, First-Class

July 24-25, 2026 (same version, no bump)
  • Run Local LLMs Like Any Other Deployment: a new AI Runtime Manager scans your hardware (CPU/RAM/GPU/disk), recommends models that will actually run well on it, detects or installs llama.cpp/Ollama, downloads a hash-verified model, and starts a real local OpenAI-compatible endpoint - managed with Start/Stop/Restart, health checks, logs, and an API key, the same way Sites and Apps already are. Available in the GUI's new "AI Runtime" view and via proxystack ai ... in the CLI, on Windows and Linux (real end-to-end WSL2 Ubuntu verification, including a real NVIDIA GPU detected through nvidia-smi passthrough).
  • 11 Curated, Hash-Verified Models: from TinyLlama 1.1B up through Phi-4 14B, spanning tiny/small/coder/mid/large tiers - every SHA256 confirmed against the real Hugging Face file, not trusted from a listing. Deliberately a small hand-picked catalog, not open Hugging Face browsing.
  • Ollama Support Too: if you already run Ollama, ProxyStack detects it and can list, pull, and unload its models directly - no separate tool needed.
  • Security Center Now Watches It: a new provider flags real misconfiguration - a server bound to every network interface instead of just localhost, an API key that isn't actually being enforced (checked with a real live probe, not just "is a key configured"), a deployment marked running whose process actually died, oversized logs, orphaned duplicate processes, and more - each with an explanation and a concrete fix, the same way every other Security Center finding works.
  • A Real, Previously-Unenforced API Key, Found and Fixed: the generated API key was stored and shown in the UI and sent by every client, but the server was reading the wrong environment variable and never actually checked it - anyone who could reach the port could call it with no authentication at all. Fixed and live-verified: a request with no key now gets a real 401.
  • Two Real Release-Packaging Bugs Caught Before Shipping: the Windows build was quietly shipping a broken placeholder copy of a system library that made hardware detection report 0MB of RAM on a fresh install, and the model catalog file itself was never being included in either download package. Both found by testing the actual release ZIP, not just the development build, and both fixed.

v14.19.0 (continued) - RBAC, Plugin Marketplace Proof, and a Real Production Incident Postmortem

July 21-24, 2026 (same version, no bump)
  • RBAC Gates Expanded: opt-in role-based access control now also covers Docker, managed Compose/DockerPro, plugin install/toggle/remove, Zero Trust removal, certificate generation/import/Let's Encrypt, and process-reputation enforcement/auto-detonation - not just the handful of call sites it started with.
  • Plugin Marketplace Gets Real Proof: the hosted marketplace now shows visible hash/size columns and ships a standalone verifier script, so a SHA256-verified install is something you can independently check, not just a claim in the UI.
  • Local Network Exposure Scanner: a new Security Center provider promotes the old Classic-UI-only port scanner into a real, always-on check - flags any TCP listener bound to a non-loopback interface that isn't one of ProxyStack's own managed ports, with process name and PID attached. Live-verified against a real machine: correctly found 13 genuinely unmanaged listeners while correctly excluding Nginx's own ports, Docker-published ports, and already-configured managed App ports.
  • Secure Import Gets Static Analysis: Python imports are now also scanned with Bandit (only if you already have it installed - never auto-installed) and folded into the same risk evidence as the existing behavioral sandbox. Verified against a synthetic reproduction of a real bug found the same day in an unrelated project: a hardcoded Flask session secret, debug=True, and a bind-all-interfaces host - exactly the class of issue a behavior-only sandbox would never catch.
  • Security Review Found and Fixed Two Real Gaps: the CLI's remote serve command had zero authentication on its mesh-join/promote/config-sync endpoints - any client that could reach the port could make the target machine join an attacker-controlled VPN mesh or overwrite its own config, with no credentials at all. Now gated by a constant-time API key check, fail-closed by default. Separately, the Classic UI's REST API toggle displayed a hardcoded "loopback-only" status while actually binding all interfaces key-less - fixed to generate/reuse a real key and show the real reachability state.
  • A Broader Hardening Audit Followed: the in-app updater now rejects ZIP-slip-style path traversal even after checksum verification; plugin installs validate that slugs and entry paths can't escape the plugin folder; the live License API moved portal passwords to PBKDF2-SHA256, restricted CORS and self-update downloads to HTTPS from our own domain, and removed a public fallback signing secret. SentinelAI API keys moved out of plaintext config and into the encrypted Secrets Vault.
  • A Real Production Incident, Diagnosed Live: a running instance was found pegging ~9 CPU cores continuously with 1,253 threads and climbing. Root cause: a 60-second timer with no re-entrancy guard, scanning two access logs that had grown past 200MB and 600MB - each overlapping scan pass spawned new threads that never got cleaned up. Fixed with a re-entrancy guard and a per-tick read cap, then followed up with the same guard applied to every other recurring timer in the app, real log rotation (which uncovered and fixed a genuine Windows-Nginx file-handle quirk along the way), and orphan cleanup for the VM sandbox tier at both startup and shutdown.
  • Solved a Long-Standing Mystery: a customer had a standing habit of always stopping Nginx before closing the app, otherwise it "seemed to crash." Pulled the actual Windows crash record instead of guessing - a real ObjectDisposedException from a background update callback racing the app's own shutdown. Fixed with a defensive invoke helper across every affected call site, verified with a harness that reproduces the exact race before confirming the fix stops it. Confirmed live: closing the app via the title-bar X with no manual workaround, no crash.

v14.19.0 - Secure Project Import: Competitive Expansion

July 20, 2026
  • Ten More Stacks Recognized: after reviewing how "drop a ZIP, any language" competitor Jade Hosting positions itself, detection now covers Bun, Go, .NET, Java, Ruby (Rails-aware), PHP (Laravel-aware), Rust, and Deno, plus a raw Dockerfile as a broad fallback - builds the image, runs it detached, reads its EXPOSE for the container port, and picks a free host port automatically.
  • Docker Compose Becomes Managed, Not One-Shot: imported Compose projects now get their own tab with persisted project records, service/image/port summaries, start/stop/restart/down/logs actions, service status, profile/service selection, version history, and rollback. Compose imports also preflight the rendered config and report exact port conflicts before ever calling up.
  • Auto Build Is Operator-Reviewed: Railpack/Nixpacks Auto Build now shows a build-plan preview with runtime confidence, image/container names, port mapping, env keys from .env.example, exact build/run commands, and listen-probe behavior. If a container starts but does not listen, ProxyStack shows logs plus likely fixes.
  • More Real GitHub ZIP Proof: round-2 corpus testing covered Phoenix/Elixir, Laravel, Next.js server-mode Docker, Rust Dockerfile, Go Compose, Rails, Spring Boot monorepo, and Rust/Axum app repos with controlled dry-run results.
  • Frontend Projects Can Deploy as a Static Site: a detected React/Vite/etc. build now offers building from a disposable copy and hosting the output as a Site, instead of only ever running as a long-lived App process.
  • Real Bugs Found Dogfooding This: generated Flask/Django/Vite commands could bind the wrong port when ProxyStack picked a different free one to avoid a collision - fixed with a real PORT environment variable. A dropped Compose project's nested compose file was detected correctly but still triggered the manual file picker - fixed to use it directly. A shared refresh flag could hide a successful Compose Up from the container list - fixed.
  • Also Fixed - Live SSL Renewal Incident: a stale provider certificate paired with a renewed private key took brainlock.bygheart.com's Nginx down entirely, and five more sites showed untrusted-certificate warnings from stale fullchain files despite fresh Let's Encrypt files already on disk. Certificate renewal now always updates a site's cert/key/chain mapping to the matching set together, and Let's Encrypt renewal no longer needs to stop Nginx or request elevation to bind port 80.

Version Archive

Release history. We recommend always using the latest version.

Version Date Highlights Full Lite
v{{VERSION}} (latest) Jul 20, 2026 Secure Project Import: competitive expansion. Ten more stacks recognized (Bun, Go, .NET, Java, Ruby, PHP, Rust, Deno, plus Dockerfile as a broad fallback with automatic image build/run). Docker Compose imports become managed, persisted projects with lifecycle actions, service status, profile/service selection, version history, and rollback, with published-port preflight before every up. Frontend builds can deploy as a static Site instead of a long-running process. Auto Build adds a build-plan preview, env-var guidance, and logs/fix guidance when a container does not listen. Also fixes a generated-command port mismatch for Flask/Django/Vite, a Docker Compose file-picker/refresh bug, and a live SSL cert/key mismatch incident. Download Download