{"id":51181058,"url":"https://github.com/johalputt/vayupress","last_synced_at":"2026-07-15T05:01:01.175Z","repository":{"id":364273147,"uuid":"1267169162","full_name":"johalputt/VayuPress","owner":"johalputt","description":"Your whole online presence in one sovereign Go binary — website, blog, and a private PGP mail server (VayuMail: SMTP/IMAP/POP3, DKIM, WKD) with an official mobile app, plus cookieless analytics and one admin panel (VayuOS). SQLite-first, zero telemetry, zero SDKs, strict CSP.","archived":false,"fork":false,"pushed_at":"2026-07-12T18:53:23.000Z","size":42275,"stargazers_count":3,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-07-12T19:13:31.521Z","etag":null,"topics":["blog-engine","cms","content-management-system","email-server","go","golang","imap","newsletter","pgp","privacy","publishing-platform","self-hosted","single-binary","smtp","sovereign","sqlite","vps","webmail","zero-telemetry"],"latest_commit_sha":null,"homepage":"https://vayupress.com","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/johalputt.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":"GOVERNANCE-CONSTITUTION.md","roadmap":"docs/ROADMAP-v1.9.md","authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":"docs/MAINTAINERS.md","copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"github":["johalputt"],"open_collective":"vayupress","custom":["https://vayupress.com/sponsors"]}},"created_at":"2026-06-12T09:34:44.000Z","updated_at":"2026-07-12T18:51:43.000Z","dependencies_parsed_at":"2026-06-27T07:00:49.911Z","dependency_job_id":null,"html_url":"https://github.com/johalputt/VayuPress","commit_stats":null,"previous_names":["johalputt/vayupress"],"tags_count":154,"template":false,"template_full_name":null,"purl":"pkg:github/johalputt/VayuPress","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/johalputt%2FVayuPress","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/johalputt%2FVayuPress/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/johalputt%2FVayuPress/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/johalputt%2FVayuPress/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/johalputt","download_url":"https://codeload.github.com/johalputt/VayuPress/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/johalputt%2FVayuPress/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35491351,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-15T02:00:06.706Z","response_time":131,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["blog-engine","cms","content-management-system","email-server","go","golang","imap","newsletter","pgp","privacy","publishing-platform","self-hosted","single-binary","smtp","sovereign","sqlite","vps","webmail","zero-telemetry"],"created_at":"2026-06-27T07:00:27.448Z","updated_at":"2026-07-15T05:01:01.079Z","avatar_url":"https://github.com/johalputt.png","language":"Go","funding_links":["https://github.com/sponsors/johalputt","https://opencollective.com/vayupress","https://vayupress.com/sponsors"],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cpicture\u003e\n    \u003csource media=\"(prefers-color-scheme: dark)\"  srcset=\"docs/assets/vayupress-mark-dark.png\"\u003e\n    \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"docs/assets/vayupress-mark-light.png\"\u003e\n    \u003cimg src=\"docs/assets/vayupress-mark-light.png\" alt=\"VayuPress\" width=\"150\"\u003e\n  \u003c/picture\u003e\n\u003c/p\u003e\n\n\u003ch1 align=\"center\"\u003eVayuPress\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eYour whole online presence — website, blog, and private mail — in one sovereign binary.\u003c/strong\u003e\u003cbr\u003e\n  One VPS. One process. One control panel. Zero telemetry, zero vendor lock-in, zero SDKs.\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/johalputt/vayupress/actions/workflows/ci.yml\"\u003e\u003cimg alt=\"CI\" src=\"https://github.com/johalputt/vayupress/actions/workflows/ci.yml/badge.svg\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/johalputt/vayupress/actions/workflows/security.yml\"\u003e\u003cimg alt=\"Security\" src=\"https://github.com/johalputt/vayupress/actions/workflows/security.yml/badge.svg\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/johalputt/vayupress/releases/latest\"\u003e\u003cimg alt=\"Latest release\" src=\"https://img.shields.io/github/v/release/johalputt/VayuPress?sort=semver\u0026color=0ea5e9\u0026label=release\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/johalputt/vayupress/stargazers\"\u003e\u003cimg alt=\"GitHub stars\" src=\"https://img.shields.io/github/stars/johalputt/VayuPress?style=flat\u0026logo=github\u0026color=f5c518\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://go.dev/\"\u003e\u003cimg alt=\"Go\" src=\"https://img.shields.io/badge/go-1.25-00ADD8?logo=go\u0026logoColor=white\"\u003e\u003c/a\u003e\n  \u003ca href=\"LICENSE\"\u003e\u003cimg alt=\"License\" src=\"https://img.shields.io/badge/license-Apache--2.0-green\"\u003e\u003c/a\u003e\n  \u003cimg alt=\"Telemetry\" src=\"https://img.shields.io/badge/telemetry-zero-success\"\u003e\n  \u003ca href=\"GOVERNANCE-CONSTITUTION.md\"\u003e\u003cimg alt=\"Constitution\" src=\"https://img.shields.io/badge/constitution-v6.0-blueviolet\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n## About\n\n**Vayu** is Sanskrit for *wind* — the invisible force that moves everything and is owned by no one. VayuPress moves your online presence the same way: entirely under your control, seen by no third party.\n\nVayuPress began as a publishing engine. It is now a **complete sovereign platform** — a business **website**, a **blog**, and a private **PGP email server** for your own domain, with an official **mobile mail app**, **privacy-first analytics**, and a single admin console (**VayuOS**) — all compiled into **one Go binary** that runs on a single modest VPS.\n\nPoint a domain at one server, run one install command, and you get:\n\n- a **website** at `yourdomain.com`,\n- a **blog** at `blog.yourdomain.com`,\n- a **mail server with automatic PGP** at `mail.yourdomain.com`,\n- **ephemeral, end-to-end-encrypted chat** at `talk.yourdomain.com`,\n\neach with a free Let's Encrypt certificate issued and renewed for you. No SaaS bill, no analytics harvesting, no plugin marketplace, no credentials on someone else's cloud. **You own the content, the mailbox, the data, and the machine.**\n\n\u003e *Own your content. Own your communication. Own your infrastructure.*\n\n---\n\n## What you get\n\n### 🌐 A real website\nServe a genuine business site at your domain — **11 elegant, modern-minimalist templates** (restaurant, café, shop, portfolio, agency, school, clinic, salon, gym, professional firm, hotel), edited entirely from VayuOS with live preview. You choose the hosting topology (website at the root or the blog at the root); an update never changes it for you.\n\n### ✍️ A Ghost-class blog — with a writer people actually enjoy\nA best-in-class **block editor** with whole-document **Markdown** and **HTML** modes (lossless round-trips), drag/drop/paste images or any `https` link, tables, toggles, task lists, math, callouts, code, self-hosted audio/video, Mermaid diagrams rendered server-side, a slash-command palette, live preview, autosave, and version-history diffs. The writing surface is tuned to disappear: **typewriter scrolling** keeps your line centered, a **focus-mode spotlight** dims everything but the block you're in, **paste-as-Markdown** turns a whole pasted draft into real blocks, a **live document outline** tracks your headings with click-to-jump, real **footnotes**, image **captions**, block **duplicate**, and full **keyboard block reordering**. Whole-site **themes** restyle every surface (nav, hero, feed, article, footer) with a live Theme Studio. Multi-author bylines, memberships, paywalls, newsletters, threaded comments, and SEO baked in.\n\n### 🛡️ Built-in bot shield \u0026 anti-DDoS (VayuShield \"Aegis\")\nAn **enterprise-grade, self-learning bot shield so you never need Cloudflare** — built into the same binary, defending in five layers with **zero operator commands**: an admin-sovereignty lane that keeps **Save and refresh working even during a volumetric flood**, a fixed-memory probabilistic fair-shed that catches spoofed botnets without ever touching a client within its fair budget, a reputation brain that jails offenders in minutes and **forgives automatically**, silent-first proof-of-work challenges that self-calibrate so they never bother real browsers, and optional kernel-level `nftables + XDP` offload. Search engines and AI assistants are always allowed; abuse is shed with a polite `503` (never a `4xx`), so **SEO and real users are structurally protected**. Everything is visible and tunable with no restart from the Bot Shield console and its live Aegis layer map. *([architecture →](docs/adr/ADR-0111-vayushield-bot-protection-and-analytics.md))*\n\n### 📧 A sovereign PGP mail server (VayuMail)\nYour own mail server for your domain — **SMTP send + receive, IMAP and POP3**, RFC-6376 **DKIM signing**, direct-to-MX delivery with STARTTLS, automatic **MX / SPF / DKIM / DMARC** records with live DNS health checks, per-mailbox quotas, junk filtering, and a full webmail surface. **PGP is native and automatic** (VayuPGP): keypairs are generated per account, private keys are AES-256-GCM encrypted at rest, and your public keys are published via **Web Key Directory (WKD)** so any client can find them. Mail never leaves your server unencrypted to a third party.\n\n### 💬 Ephemeral end-to-end-encrypted chat (VayuTalk)\nReal-time private messaging built into the same binary — a **PGP end-to-end-encrypted chat** for your domain that interoperates seamlessly across the **web console and the mobile app over one shared relay**: a message typed on the web reaches the phone and vice-versa, indistinguishable to the server. Every message is encrypted to the recipient's key, relayed through a **bounded in-memory store that never touches disk**, and **read-destroyed** — it vanishes the moment it is read or when its short TTL (5 min – 1 h) elapses. Out-of-band **safety-number verification** (shown identically on web and app) defeats a man-in-the-middle key swap. The relay auto-serves on a dedicated **`talk.yourdomain.com`** subdomain that bypasses any CDN in front of your site, so the long-lived event stream is never buffered or bot-challenged — provisioned automatically by the installer the moment you point that one DNS record. *([architecture →](docs/adr/ADR-0131-vayutalk-ephemeral-messaging.md))*\n\n### 📱 An official mobile app (VayuMail Mobile)\n[**johalputt/VayuMail-Mobile**](https://github.com/johalputt/VayuMail-Mobile) — a pure-Go Android app that reads and sends your PGP mail *and* carries VayuTalk chat from your own domain. Connect in **one scan**: the admin's rotating setup QR carries a per-device app password (never your real password, revocable anytime), or auto-detect the whole account from just your email address via VayuPress's first-party autoconfig endpoint. No tracking pixels, no remote content, no telemetry.\n\n### 📊 Privacy-first analytics (VayuAnalytics)\nReal product analytics — pageviews, sessions, top pages, referrers, UTM campaigns, custom events, funnels, retention, revenue, and a live visitor panel — stored locally in SQLite. Visitor identity is a **server-side daily-rotating salted hash**: no cookies, no `localStorage`, no IP or User-Agent ever stored, **no consent banner required**, nothing to leak on a database compromise. Visitor country is resolved from an **embedded offline table** — no external GeoIP service, no phone-home.\n\n### 🛠️ One control panel (VayuOS)\nEverything above is run from a single, fast, strict-CSP admin at `/os` — dashboard, editor, media library, themes, members, newsletter, mail, **VayuTalk chat**, analytics, **Bot Shield**, SEO, API keys, and one-click **update \u0026 encrypted backup**. The dashboard opens on a real **14-day publishing area chart** (server-rendered SVG, hover tooltips, zero JavaScript) and live stat cards; every data table folds into phone-friendly cards on mobile. TOTP two-factor, role-based access, WORM audit log, and an adaptive policy-governed runtime underneath. Built with **HTMX + lightweight hand-written CSS** — no SPA framework, no build step, negligible RAM/CPU.\n\n---\n\n## Quick start\n\nOne command stands up the whole stack — website, blog, and PGP mail — on a fresh VPS:\n\n```bash\ncurl -sSL https://raw.githubusercontent.com/johalputt/vayupress/main/scripts/deploy-vayupress.sh | bash\n```\n\nOr clone and deploy manually:\n\n```bash\ngit clone https://github.com/johalputt/vayupress.git\ncd vayupress\nsudo ./scripts/deploy-vayupress.sh\n```\n\nThe installer provisions the binary, systemd service, Nginx, and Let's Encrypt certificates for your website, blog, and mail hostnames. A fresh install auto-creates an `admin@yourdomain` account (random password, saved to a root-only file) and forces a password change on first sign-in — no extra CLI step.\n\n**Add VayuTalk chat (optional, one DNS record).** VayuTalk works on the main domain out of the box; for the seamless real-time relay behind a CDN, point one `A`/`AAAA` record — `talk.yourdomain.com` → your server, **CDN proxy OFF** (the same \"DNS-only\" mode you use for `mail.`) — and re-run the installer (or let the next update run it). It adds the subdomain's TLS certificate, writes its Nginx vhost, and advertises it to the app automatically. Nothing else to configure. *(See [docs/TROUBLESHOOTING.md](docs/TROUBLESHOOTING.md) → \"VayuTalk\".)*\n\nRuns comfortably on a single **8 GB RAM / 4 vCPU / 50 GB NVMe** VPS.\n\n---\n\n## Why VayuPress\n\n|  | VayuPress | Typical stack |\n|---|---|---|\n| **What it replaces** | Website builder **+** blog **+** mail provider **+** analytics **+** admin | Four or five separate SaaS bills |\n| **Where your data lives** | Your VPS, your SQLite file | Vendor clouds you don't control |\n| **Telemetry** | None — verifiable, it's open source | \"Anonymized analytics\" |\n| **Mail** | Your own server, PGP automatic | Google/Microsoft reads the metadata |\n| **Private messaging** | Built-in, E2E-encrypted, ephemeral (VayuTalk) | A separate Signal/Slack account \u0026 server |\n| **Tracking of readers** | Cookieless, no PII, no consent banner | Cookies + third-party pixels |\n| **Bot \u0026 DDoS protection** | Built-in, self-learning (VayuShield Aegis) | A separate Cloudflare/WAF subscription |\n| **Dependencies** | One Go binary + SQLite + Nginx | Node, databases, Redis, queues, SDKs |\n| **Extensibility** | Sandboxed, capability-gated plugins | Marketplace plugins with full access |\n| **Lock-in** | Open standards, plain export | Proprietary formats, export friction |\n\n---\n\n## One binary, by design\n\nVayuPress is a single Go binary and a single SQLite database. There is no second service to install, secure, or keep alive — search, comments, analytics, mail, and PGP all run in-process.\n\n```text\n                         Internet ──HTTPS──▶ Nginx (TLS, static, CSP)\n                                                  │ 127.0.0.1:8080\n                    ┌─────────────────────────────▼──────────────────────────────┐\n                    │                     VayuPress (one Go binary)               │\n                    │                                                             │\n                    │   VayuShield Aegis (L0 lane · L2 fair-shed · L5 brain)      │\n                    │   Website · Blog · Block editor · Themes · Members          │\n                    │   VayuMail (SMTP/IMAP/POP3 · DKIM · MX/SPF/DMARC)           │\n                    │   VayuTalk (ephemeral E2E chat · SSE relay · read-once)     │\n                    │   VayuPGP (keys · WKD)   VayuFind (search)   Analytics      │\n                    │   VayuOS control panel   Newsletter   Media   API           │\n                    │                                                             │\n                    │   ── Platform kernel (immutable) ──                         │\n                    │   signing · migrations · outbox · policy · modes · audit    │\n                    │                                                             │\n                    │                    SQLite (WAL mode)                        │\n                    └─────────────────────────────────────────────────────────────┘\n```\n\nUnder the hood: an **immutable platform kernel** (Ed25519 article signing, checksum-verified migrations, transactional event outbox, WORM audit log, a policy engine and six adaptive system modes), an async SQLite write queue with dead-letter replay, sandboxed out-of-process plugins with seccomp + capability enforcement, and full observability (structured logs, tracing, SLO error budgets). Architecture and every decision are recorded in [`docs/`](docs/) and the [ADR registry](docs/adr/).\n\n---\n\n## Showcase\n\n### Website \u0026 blog\n![VayuPress homepage](docs/screenshots/homepage.png)\n*Public homepage — article grid with tag filtering, dark/light toggle, zero-telemetry footer. Styled entirely from your own origin (strict `style-src 'self'` CSP).*\n\n![VayuPress article](docs/screenshots/article-page.png)\n*A rendered article — JSON-LD schema, author/date meta, tag strip, reading time, and zero third-party requests.*\n\n### VayuOS — the single control panel\n![VayuOS dashboard](docs/screenshots/admin-os-dashboard.png)\n*The dashboard (`/os`) — grouped sidebar, stat cards, publishing-trend sparkline, activity feed, and a `⌘K` command palette.*\n\n![VayuOS block editor](docs/screenshots/admin-os-editor.png)\n*The block editor — typed-block document rendered server-side through escape + bluemonday, slash-command palette, autosave, live preview, and inline version-history diff.*\n\n![Theme Studio](docs/screenshots/admin-os-theme.png)\n*Theme Studio (`/os/theme`) — a preset gallery and design-token editor with instant live preview, compiled to one sovereign stylesheet served from your own origin.*\n\n![VayuAnalytics](docs/screenshots/admin-os-analytics.png)\n*VayuAnalytics — cookieless, no-PII product analytics computed entirely from your local SQLite database.*\n\n### 🛡️ VayuShield — the built-in bot shield\n![Bot Shield \u0026 Analytics](docs/screenshots/admin-os-shield.png)\n*The Bot Shield console (`/os/shield`) — a live Aegis layer map (L0 sovereignty lane · L2 fair-shed · L4 challenges · L5 reputation brain · L1 kernel offload), protection toggles that apply with no restart, learned-signature review queue, and cookieless engagement analytics. Self-learning and self-healing: it protects availability automatically, never blocks a real reader or a search/AI crawler, and needs no Cloudflare.*\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eMore of VayuOS\u003c/strong\u003e — posts, media, SEO, security, and the operator control plane\u003c/summary\u003e\n\n| | |\n|---|---|\n| ![Posts](docs/screenshots/admin-os-posts.png) | ![Media](docs/screenshots/admin-os-media.png) |\n| *Post manager with live status pills* | *Content-addressed media library* |\n| ![SEO](docs/screenshots/admin-os-seo.png) | ![Security](docs/screenshots/admin-os-security.png) |\n| *SEO readiness dashboard* | *Security \u0026 PGP surface (admin-only)* |\n| ![Sign-in](docs/screenshots/os-login.png) | ![Member signup](docs/screenshots/member-signup.png) |\n| *Strict-CSP, self-hosted sign-in* | *Branded passwordless member signup* |\n\nThe adaptive-governance runtime is fully inspectable from inside VayuOS — system modes, the policy provenance inspector, a live runtime-topology graph, the dead-letter replay explorer, the fault manager, and the ADR registry.\n\n| | |\n|---|---|\n| ![System modes](docs/screenshots/policy-modes.png) | ![Policy inspector](docs/screenshots/policy-inspector.png) |\n| ![Runtime topology](docs/screenshots/runtime-topology.png) | ![Replay explorer](docs/screenshots/replay-explorer.png) |\n\n\u003c/details\u003e\n\n\u003e Screenshots are regenerated from a live instance by the [screenshots CI workflow](.github/workflows/screenshots.yml).\n\n---\n\n## Security \u0026 sovereignty\n\n- **Zero telemetry, zero third-party reader requests.** Strict CSP (no `unsafe-eval`, no `unsafe-inline`, per-request nonces); all assets served same-origin. No CDNs.\n- **Encrypted at rest.** PGP private keys and stored third-party secrets are AES-256-GCM encrypted; operator backups are a single AES-256-GCM + Argon2id archive of everything (DB, settings, media, mailboxes, keys).\n- **Sandboxed extensibility.** Out-of-process plugins run under seccomp + namespace isolation with deny-by-default capabilities.\n- **Governed by construction.** A machine-enforced [Constitution](GOVERNANCE-CONSTITUTION.md), an [Ethical AI Charter](ETHICS.md) (no training on user data, no telemetry), signed releases, and a WORM audit log. AI assistance is strictly opt-in and local-only (Ollama) — nothing leaves your server.\n\n---\n\n## Documentation\n\n- **[CHANGELOG.md](CHANGELOG.md)** — every release and what changed, version by version.\n- **[docs/adr/](docs/adr/)** — Architecture Decision Records: every design decision, recorded.\n- **[GOVERNANCE-CONSTITUTION.md](GOVERNANCE-CONSTITUTION.md)** — the binding rules, mechanically enforced by CI.\n- **[ETHICS.md](ETHICS.md)** — the Ethical AI Charter.\n- **[VayuMail-Mobile](https://github.com/johalputt/VayuMail-Mobile)** — the official mobile mail app.\n\n## License\n\nApache License 2.0 — see [LICENSE](LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjohalputt%2Fvayupress","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjohalputt%2Fvayupress","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjohalputt%2Fvayupress/lists"}