Tools and Software
What this guide covers
The canonical tooling stack — what each tool does, whether it’s open-source or paid, self-hostability, and the commercial alternative it replaces. Structured for budget justification, vendor selection, and migration planning. It also covers the enterprise functionality (starting with SSO) to check before committing to any tool: the cheapest open-source option is worthless if it can’t meet your organization’s access and compliance requirements.
Who it’s for
Engineering leads, technical directors, and CTOs who need to compare options, write procurement justifications, or explain tooling costs to non-technical stakeholders. Also useful for engineers joining the platform who want to understand why each tool was chosen.
Part of the Procurement library. For how to actually buy these tools inside public-sector rules, see Federal Procurement and Maryland Procurement.
How to read this guide
Each table is a single procurement category. For every tool you’ll see:
- License / Model — the actual license (MIT, Apache 2, etc.) or billing model
- Self-host — whether you can run this on your own infrastructure
- Paid alternative — the commercial SaaS product this replaces (and what you’d pay instead)
- Why this, not that — the one-line procurement rationale
Default posture: Open-source and self-hostable first. The only times this stack accepts a closed/SaaS-only dependency are when (a) no mature OSS equivalent exists at the required scale, or (b) compliance requirements mandate a specific vendor. Those exceptions are flagged explicitly.
Frontend — UI & Design System
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| React 19 | MIT | n/a | None | Industry standard; deep ecosystem; team fluency |
| TypeScript | Apache 2 | n/a | None | Required for type safety at scale |
| Vite | MIT | n/a | None | Fastest dev server; native ESM; replaces CRA |
| Tailwind CSS | MIT | n/a | None | Utility-first; eliminates CSS drift across teams |
| class-variance-authority (CVA) | MIT | n/a | None | Variant management without runtime overhead |
| Storybook | MIT | Yes (static build) | Zeroheight () | OSS standard for component dev and docs |
| Lost Pixel | MIT | Yes | Chromatic ($99+/mo) | Visual regression at zero per-snapshot cost |
| Lucide React | ISC | n/a | Noun Project () | 1,400+ icons; MIT-compatible; consistent style |
| Motion (Framer Motion) | MIT | n/a | None | Best-in-class React animation; OSS |
Frontend — State, Data & Forms
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| TanStack Router | MIT | n/a | None | Type-safe file-based routing; OSS |
| TanStack Query | MIT | n/a | SWR (MIT; no paid tier), Apollo Client ($) | Caching, background sync, devtools |
| TanStack Table | MIT | n/a | AG Grid ($1,200+/dev) | Full-featured headless table; completely free |
| TanStack Form | MIT | n/a | Formik (MIT) | Tighter TanStack Router/Query integration |
| Zustand | MIT | n/a | Jotai (MIT), Redux Toolkit (MIT) | Minimal API; no boilerplate; OSS |
| Zod | MIT | n/a | Yup (MIT), Joi (BSD) | TS-first; single schema shared server + client |
| React Hook Form | MIT | n/a | Formik (MIT) | Minimal re-renders; Zod-resolver native |
| pnpm | MIT | n/a | Yarn Enterprise ($) | Fast installs; disk-efficient; monorepo support |
| Turborepo | MIT | n/a | Nx Enterprise ($) | Remote cache; simple config; Vercel donation |
| Biome | MIT | n/a | Prettier + ESLint (both MIT, but tooling cost) | Single binary; 10× faster; replaces two configs |
Backend
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Astro (server endpoints) | MIT | Yes | Vercel Functions () | Island architecture; SSG + SSR; zero-JS default |
| Hono | MIT | Yes | Express (MIT), Fastify (MIT) | Lightest TS API framework; edge-native |
| Go + Fiber v2 | MIT | Yes | None at this weight class | Compiled; low memory; best for high-concurrency APIs |
| GORM | MIT | Yes | Prisma (OSS + paid cloud), TypeORM (MIT) | Battle-tested Go ORM; composite key support |
| Zap (logging) | MIT | Yes | Datadog Logs () | Structured JSON logs; zero alloc at production |
| OpenTelemetry SDK | Apache 2 | Yes | Datadog APM () | Vendor-neutral tracing; no lock-in |
| Better-Auth | MIT | Yes | Auth0 (2+/MAU) | First-class TS; self-hosted OIDC; no MAU cost |
| River (Go background jobs) | MIT | Yes | Inngest ($), Trigger.dev (OSS + paid) | Postgres-backed; ACID guarantees; no infra add |
| BullMQ (TS background jobs) | MIT | Yes | Inngest ($), Quirrel (OSS, archived) | Redis-backed; mature; enterprise-proven |
Data
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| PostgreSQL | PostgreSQL License (OSS) | Yes | Neon (39+/mo) | The default RDBMS — no substitute |
| CloudNativePG operator | Apache 2 | Yes (k8s) | Crunchy Data () | Production Postgres HA on k8s; fully OSS |
| SQLite / libSQL / Turso | MIT / Apache 2 | Yes | D1 () | Embedded DB for low-latency reads; self-host |
| Atlas (migrations) | Apache 2 | Yes | Flyway Pro () | Declarative schema; diff-based; OSS |
| Kysely | MIT | n/a | Prisma Data Platform ($), Drizzle Studio | Type-safe SQL builder; no ORM magic |
| Drizzle ORM | MIT | n/a | Prisma (OSS + paid cloud), TypeORM | Lighter than Prisma; SQL-like API |
| Valkey (Redis fork) | BSD 3-Clause | Yes | Redis Cloud () | Linux Foundation OSS; drop-in Redis replacement |
| Meilisearch | MIT | Yes | Algolia () | Instant search; typo-tolerant; fully self-hosted |
| Typesense | GPL / Cloud | Yes | Algolia ($1+/1k search) | Multi-tenant; fast at large scale |
| MinIO | AGPL / Commercial | Yes | AWS S3 (0.015/GB) | S3-compatible object store; own your data |
| Garage | AGPL | Yes | AWS S3, Cloudflare R2 | Multi-region OSS object store |
| pgvector | PostgreSQL License | Yes (in-Postgres) | Pinecone () | Vector search inside existing Postgres; no new DB |
Infrastructure & Delivery
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Docker | Apache 2 (Engine) | Yes | None | Industry standard container runtime |
| Kubernetes | Apache 2 | Yes | EKS (0.10+/hr) | Orchestration standard; own the control plane |
| GitHub Actions | MIT (runners OSS) | Partial | CircleCI () | Native GitHub integration; generous free tier |
| ArgoCD | Apache 2 | Yes | Flux CD (Apache 2), Spinnaker (Apache 2) | GitOps standard; UI + CLI; active community |
| Helm | Apache 2 | Yes | None | Kubernetes package manager standard |
| 1Password Connect | 1Password Business ($8+/seat/mo) | Partial (server is OSS) | HashiCorp Vault () | Developer-friendly; team plan; OSS server |
| Skaffold | Apache 2 | Yes | Tilt () | Local k8s dev loop; Google-backed OSS |
| Task (Taskfile) | MIT | Yes | Make (GPL), Just (MIT) | YAML-based; cross-platform; readable |
| ko (Go container builds) | Apache 2 | Yes | Kaniko (Apache 2), buildpack ($) | Zero-Dockerfile Go images; fast; OSS |
| Harbor | Apache 2 | Yes | Docker Hub (0.10+/GB) | Self-hosted OCI registry; RBAC + scanning |
Observability
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Prometheus | Apache 2 | Yes | Datadog Metrics () | The metrics standard; pull-model; OSS |
| Grafana | AGPL | Yes | Grafana Cloud () | Dashboards for Prometheus, Loki, Tempo |
| Loki | AGPL | Yes | Datadog Logs () | Log aggregation; Grafana-native; cheap at scale |
| Tempo | AGPL | Yes | Datadog APM ($), Jaeger (Apache 2) | Distributed tracing; Grafana-native; OSS |
| GlitchTip | MIT | Yes | Sentry () | Sentry-protocol-compatible; fully OSS; drop-in |
| Uptime Kuma | MIT | Yes | Better Uptime () | Status monitoring; no cloud dependency |
| Sloth | Apache 2 | Yes | Nobl9 () | SLO-to-Prometheus-rules generator; OSS |
| Pyroscope | AGPL | Yes | Datadog Continuous Profiler () | Continuous profiling; flame graphs; OSS |
Standard additions at scale
Communications & Product
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| PostHog | MIT (self-host) / Cloud () | Yes | Amplitude (25+/mo) | Events, funnels, replays, surveys — all OSS |
| GrowthBook + OpenFeature SDK | MIT | Yes | LaunchDarkly () | OSS feature flags; vendor-neutral SDK |
| Postal (email) | MIT | Yes | Resend (19.95+/mo) | Self-hosted SMTP with API; no per-email cost |
| React Email | MIT | n/a | MJML (MIT) | Build emails in React; OSS; Postal-compatible |
| Listmonk (newsletters) | AGPL | Yes | Mailchimp (9+/mo) | Self-hosted list management and broadcast |
Billing & Payments
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Lago | AGPL / Cloud ($) | Yes | Stripe Billing () | OSS metering engine; usage-based billing |
| Killbill | Apache 2 | Yes | Recurly () | OSS subscription billing; complex plan support |
| Stripe | Closed / 2.9%+0.30¢ | No | Braintree (2.59%+), Adyen ($) | Unavoidable closed dependency. Card processing requires a licensed gateway. Default to Stripe unless compliance requires otherwise; flag the cost explicitly in procurement |
Content & Documentation
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Astro Starlight | MIT | Yes | Gitbook () | Docs site on Astro; zero cost; markdown-first |
| Docusaurus | MIT | Yes | Readme.io () | React-based docs; Facebook-maintained OSS |
| Payload CMS | MIT | Yes | Contentful () | TypeScript-native headless CMS; self-hosted |
| Directus | BSL (self-host free) | Yes | Contentful ($300+/mo), Strapi (MIT alt) | Auto-generates REST + GraphQL from schema |
Workflow & Scheduling
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Temporal | MIT | Yes | Conductor (Netflix OSS), Inngest ($) | Durable workflows with retry, signals, timers |
| XState | MIT | n/a | None | In-process state machines; complex UI flows |
Kubernetes Policy & Networking
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Kyverno | Apache 2 | Yes | OPA Gatekeeper (Apache 2), Styra ($) | Pure-YAML k8s policies; simpler than Rego |
| Linkerd | Apache 2 | Yes | Istio (Apache 2), Consul Connect ($) | Lightest service mesh; Rust data plane |
| cert-manager | Apache 2 | Yes | AWS ACM ($0.75+/cert/mo) | TLS cert automation in k8s; CNCF graduated |
| Traefik | MIT | Yes | NGINX Plus () | Reverse proxy + ingress; auto-TLS via ACME |
Identity & Access
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Authelia | Apache 2 | Yes | Okta (6+/user/mo) | SSO + MFA gateway; OIDC/SAML; OSS |
| Authentik | MIT | Yes | Okta () | Identity provider with workflows; richer UI |
Backups & Disaster Recovery
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Velero | Apache 2 | Yes | Kasten K10 () | Cluster backup + restore; CNCF project |
| pgBackRest | MIT | Yes | AWS RDS automated backups () | Point-in-time recovery for Postgres |
Internal Tools
| Tool | License / Model | Self-host | Paid alternative replaced | Why this |
|---|---|---|---|---|
| Refine | MIT | Yes | Retool ($10+/seat/mo), Tooljet (OSS alt) | React-based admin UI on the design system |
| Cachet / Statping | BSD / MIT | Yes | Statuspage.io () | Public-facing status pages; self-hosted |
Enterprise functionality — look before you buy
License cost is only half the procurement decision. The other half is functionality: a tool can be free, popular, and well-maintained and still be unbuyable for an enterprise or government team because it’s missing one capability that a security or compliance review treats as non-negotiable.
The single biggest one is SSO.
Single sign-on (SSO) is the enterprise gate
What it is
Single sign-on lets people log in to a tool with the organization’s central identity provider (IdP) — Entra ID (Azure AD), Okta, Google Workspace, Authentik, Authelia, Keycloak — instead of a tool-specific username and password. The two protocols that matter are SAML 2.0 and OIDC (OpenID Connect). The companion is SCIM, which automatically provisions and de-provisions accounts so that when someone leaves, their access disappears everywhere at once.
Why it’s the dealbreaker
For most enterprise and virtually every government buyer, SSO is not a nice-to-have — it is a control that security policy requires before a tool may touch organizational data:
- Offboarding / least privilege. Without SSO + SCIM, every tool keeps its own password list. When an employee or contractor leaves, someone has to remember to delete them from each tool by hand. That gap is exactly what auditors and incident responders look for.
- MFA and password policy enforcement. SSO inherits the IdP’s MFA, session length, and password rules. Per-tool logins don’t — so a single weak password on a forgotten SaaS account becomes the breach.
- Audit and compliance. FedRAMP, StateRAMP, CMMC, NIST 800-53 (AC family), and most agency security policies expect centralized authentication and a single audit trail of who logged in where.
- One identity, one revocation. Disable the account at the IdP and access is gone everywhere. That is the whole point.
The “SSO tax”
Many commercial SaaS products technically support SSO but lock it behind the most expensive “Enterprise” tier — sometimes 3–10× the base price — even though SSO is a baseline security control, not a premium feature. This pattern is widely documented (see sso.tax). When you compare two tools, compare the tier that actually includes SSO + SCIM, not the headline price. A “cheaper” tool whose SSO tier costs more than a competitor’s all-in plan is not cheaper.
Where open source falls short
This is the most common gap in otherwise-excellent OSS. Some projects ship SSO in the free/self-hosted edition; others gate it behind a paid “enterprise” build or a commercial license, and a few don’t support it at all. Always verify the edition — “the project supports SAML” often means “the paid build supports SAML.”
SSO support in this stack’s self-hostable tools
This is a procurement checklist, not a guarantee — verify against the current version and edition before relying on it.
| Tool | SSO in free / self-host edition? | Notes |
|---|---|---|
| Authentik / Authelia / Keycloak | ✓ (they are the IdP) | These provide SSO to everything else; OIDC + SAML + LDAP |
| Grafana | ✓ SAML/OIDC in OSS; some advanced features Enterprise-only | Team sync / role mapping refinements are gated |
| GitLab CE | OIDC/SAML for self-managed; SCIM is paid (Premium+) | Classic SSO-tax split |
| PostHog | SAML is a paid add-on even when self-hosted | Verify per plan |
| Storybook / Lost Pixel | n/a (no per-user auth) | Auth handled at the reverse proxy (Traefik + Authelia) |
| Refine / internal tools | Inherited from your IdP | Wire to OIDC via Better-Auth/Authelia |
| Harbor, ArgoCD, Temporal | ✓ OIDC in OSS | Configure against your IdP |
The cheap escape hatch for OSS that lacks SSO: put it behind an identity-aware reverse proxy. Authelia or Authentik in front of Traefik adds SSO + MFA to any web app that has no native support — the app sees an authenticated, header-asserted user and never has to implement SAML itself. This is the single highest-leverage way to get enterprise-grade access control across a self-hosted stack at $0 in license fees.
Other functionality gates to check before procurement
SSO is first, but a complete tool evaluation should confirm each of these before selection — any one of them can disqualify an otherwise-cheaper option:
| Capability | Why a buyer requires it |
|---|---|
| SSO (SAML/OIDC) + SCIM | Centralized auth, MFA, automatic de-provisioning (above) |
| Audit logs | Who did what, when — required for incident response and compliance |
| RBAC / granular permissions | Least privilege; separation of duties |
| Data residency / self-host | Sovereignty, FedRAMP/StateRAMP, records retention |
| Data export / no lock-in | Exit strategy; avoids captive-vendor renewals |
| Accessibility (WCAG 2.2 AA, VPAT/ACR) | Section 508 / state accessibility law — non-negotiable for gov |
| API + automation | Integration without manual re-keying |
| Encryption at rest & in transit | Baseline security control |
| SLA / support tier | Enforceable response times for production systems |
| BAA / DPA availability | Required when handling PII/PHI |
When you score two tools, score them on total cost at the tier that includes the functionality you actually need — not on the sticker price of a plan you can’t legally deploy.
Procurement posture summary
| Category | All-OSS | Mixed (OSS + 1 closed dependency) | Unavoidable Closed |
|---|---|---|---|
| Frontend | ✓ | — | — |
| Backend | ✓ | — | — |
| Data | ✓ | — | — |
| Infrastructure | — | ✓ (1Password) | — |
| Observability | ✓ | — | — |
| Payments | — | — | ✓ (payment gateway) |
| Identity | ✓ | — | — |
| Communications | ✓ | — | — |
Bottom line: Every category runs on self-hosted OSS except payments (a regulated, unavoidable closed category) and secrets management (where 1Password’s self-hosted Connect server mitigates most lock-in). The total cost of the OSS stack — excluding infrastructure compute — is $0 in license fees.
Budget justification template
Use this block verbatim or adapt it for a procurement request:
This engineering stack is built entirely on open-source, self-hostable software. License costs are 0.30 per transaction, unavoidable for PCI compliance) and optionally 1Password Business ($8/seat/month for secrets management, with a self-hosted server option that reduces cloud dependency).
The stack replaces the following paid SaaS tools with OSS equivalents:
- Sentry → GlitchTip (savings: 300+/month)
- Amplitude/Mixpanel → PostHog self-hosted (savings: 995+/month)
- LaunchDarkly → GrowthBook (savings: $12/seat/month)
- AG Grid Enterprise → TanStack Table (savings: $1,200+/developer)
- Chromatic → Lost Pixel (savings: $99+/month)
- Algolia → Meilisearch self-hosted (savings: $1+/1,000 searches)
Total estimated annual savings vs. equivalent closed SaaS: 60,000+ depending on team size and data volume.
Related resources
- Procurement — Overview — the procurement library index
- Federal Procurement — FAR thresholds, GSA Schedules, SAM.gov, set-asides
- Maryland Procurement — BPW, eMMA, COMAR Title 21, purchasing-card limits
- STANDARDS.md — §3 Default Tech Stack — full stack with selection rationale
- DECISION_DEFAULTS.md — first-lookup defaults before any new tooling decision
- don’t-reinvent-wheel.md — when to reach for a library vs. build
- Engineering Discovery — Overview — the full readiness library