No fluff, no beginner detours - just the repositories senior engineers actually reach for. π§ βοΈ
Distributed systems, cloud-native infra, the full LLM-engineering stack, and a serious security arsenal.
A deep, battle-tested catalog of 300+ production-grade repositories for senior software engineers, staff engineers, SREs, platform & infrastructure engineers, security engineers, ML/AI engineers, and data engineers.
π― Audience: Professionals & Advanced. This is the "senior engineer" companion to the 280+ comprehensive list (for everyone) and the 150 essentials list (for beginners & students). Everything here assumes you already ship software - it's about depth: distributed systems, cloud-native infra, observability, LLM engineering, and offensive/defensive security.
ποΈ Curated on 21 July 2026 from live research across GitHub Trending, the CNCF landscape, Papers-we-Love, and practitioner communities. Every link is a real, canonical GitHub repository.
- ποΈ System Design & Distributed Systems
- ποΈ Databases & Storage Engines
- π Data Engineering & Pipelines
- π‘ Message Queues, Streaming & Event-Driven
- β‘ LLM Serving & Inference
- π§© LLM App Frameworks & Orchestration
- π€ AI Agents & Multi-Agent Systems
- π RAG, Vector Databases & Agent Memory
- ποΈ Model Fine-Tuning & Training
- π§ͺ LLM Evaluation, Observability & Guardrails
- π¦ MLOps & Experiment Tracking
- βοΈ DevOps & Infrastructure-as-Code
- βΈοΈ Kubernetes & Cloud-Native
- π Observability & SRE
- π§΅ Backend Frameworks & API Tooling
- πΈοΈ Networking, Proxies & Service Mesh
- ποΈ Performance, Load Testing & Chaos
- ποΈ Platform Engineering & Internal Developer Platforms
- π‘οΈ Security, AppSec & Offensive/Defensive
- π¦ Systems Languages, Runtimes & Containers
- π¨ Advanced Frontend & Build Tooling
- π± Advanced Mobile
- π 2026 Breakouts (Pro Picks)
- System Design Primer - The canonical open-source guide to scaling systems, with deep treatment of caching, sharding, and consistency trade-offs.
- System Design 101 - ByteByteGo's visual explainers of real-world architectures used as shared vocabulary in design reviews.
- System Design (karanpratapsingh) - A book-length treatment of scalability, distributed patterns, and failure modes beyond interview trivia.
- Awesome Scalability - A curated firehose of engineering blog posts and papers on reliable, performant large-scale systems.
- Awesome System Design Resources - Concise reference of distributed-systems building blocks and case studies kept current for practitioners.
- Distributed Systems Topics - A dense index of microservices, scalability, and reliability topics with authoritative sources.
- Jepsen - Kyle Kingsbury's framework for verifying distributed database consistency under partitions; the industry standard for correctness testing.
- PingCAP Talent Plan - Hands-on courses that have you build a real distributed KV store and SQL layer in Rust/Go.
- Papers We Love - A community repo of foundational CS papers (consensus, storage, concurrency) for first principles.
- Awesome Distributed Systems - A tightly curated list of the seminal talks, papers, and books on distributed computing.
- Awesome Software Architecture - Deep, categorized resources on DDD, CQRS, event sourcing, and clean/hexagonal architecture.
- Awesome Distributed System Projects - Real open-source distributed systems organized for studying production implementations.
- PostgreSQL - The official mirror of the world's most advanced open-source RDBMS, the default backend for serious systems.
- CockroachDB - A distributed SQL database with serializable isolation and survivability, prized for global consistency without manual sharding.
- TiDB - A horizontally scalable HTAP database with MySQL compatibility for mixed transactional/analytical workloads.
- Vitess - The MySQL sharding and clustering system that powers YouTube and Slack.
- YugabyteDB - A Postgres-compatible distributed SQL database for resilient, geo-distributed deployments.
- ScyllaDB - A C++ Cassandra-compatible store with a shard-per-core architecture delivering predictable low latency.
- TiKV - A CNCF-graduated distributed transactional key-value store (Raft + Percolator).
- Apache Cassandra - The battle-tested wide-column store for write-heavy, multi-datacenter workloads.
- ClickHouse - The fastest open-source columnar OLAP database, the default for real-time analytics over billions of rows.
- DuckDB - An in-process analytical database ("SQLite for analytics") ubiquitous in data pipelines.
- Apache Doris - A high-performance real-time MPP analytical database for sub-second queries.
- TimescaleDB - A Postgres extension turning it into a scalable time-series database with hypertables.
- InfluxDB - A purpose-built time-series database and platform for metrics and events at scale.
- QuestDB - A high-throughput time-series database with SQL and nanosecond timestamps.
- VictoriaMetrics - A fast, cost-efficient time-series database and long-term Prometheus store.
- PgBouncer - The lightweight Postgres connection pooler, essentially mandatory for serverless and high-concurrency backends.
- Patroni - The de facto template for Postgres high availability and automated failover.
- RocksDB - Facebook's embeddable LSM-tree key-value engine that serves as the storage layer for countless databases.
- LevelDB - Google's classic embedded key-value store, still studied as the reference LSM implementation.
- BadgerDB - A fast pure-Go embeddable LSM key-value store for local persistence.
- Pebble - CockroachDB's RocksDB-inspired storage engine in Go, a clean reference for modern LSM design.
- etcd - The distributed, strongly-consistent key-value store that backs Kubernetes.
- Redis - The ubiquitous in-memory data structure server for caching, queues, and real-time data.
- Valkey - The Linux Foundation's Redis fork that became the community standard after Redis's license change.
- Dragonfly - A multi-threaded, Redis/Memcached-compatible in-memory store with far higher per-node throughput.
- libSQL - Turso's open-contribution SQLite fork adding replication and server features.
- Turso Database - A ground-up SQLite rewrite in Rust with concurrent writes and async I/O.
- SurrealDB - A multi-model (document/graph/relational) database in Rust designed to collapse the backend data layer.
- Neo4j - The leading native graph database for connected-data workloads like fraud detection and knowledge graphs.
- Apache Airflow - The most widely deployed workflow orchestrator for authoring and scheduling data pipelines.
- Dagster - An asset-oriented orchestrator with strong typing, testing, and lineage that pros favor over Airflow.
- Prefect - Pythonic, dynamic workflow orchestration with a modern hybrid execution model.
- dbt Core - The transformation-layer standard for version-controlled, tested SQL analytics engineering.
- Apache Spark - The dominant distributed engine for large-scale batch and streaming data processing.
- Apache Flink - The reference stateful stream-processing engine for low-latency, exactly-once pipelines.
- Polars - A blazing-fast, multi-threaded Rust DataFrame library increasingly replacing pandas for performance.
- Apache Arrow - The columnar in-memory format and IPC standard underpinning the modern data stack.
- dlt - A Python-first, code-driven EL library for loading data into warehouses with schema evolution.
- Apache Iceberg - An open table format bringing ACID, schema evolution, and time travel to data lakes.
- Delta Lake - A storage layer adding ACID transactions and versioning to lakehouse architectures.
- Apache Hudi - A lakehouse platform bringing incremental processing and upserts to data lakes.
- Great Expectations - A framework for validating, documenting, and profiling data quality.
- SQLFluff - The dialect-flexible SQL linter and formatter for keeping analytics code clean in CI.
- Airbyte - An open-source ELT platform with the largest catalog of data connectors.
- Ibis - A portable Python dataframe API that compiles to 20+ SQL and dataframe backends.
- Apache Beam - A unified programming model for portable batch and streaming pipelines across runners.
- PRQL - A pipelined relational query language that compiles to SQL for more maintainable analytics.
- Apache Kafka - The dominant distributed event-streaming platform and the backbone of most event-driven architectures.
- Redpanda - A Kafka-API-compatible streaming engine in C++ with no ZooKeeper/JVM, valued for latency and simplicity.
- NATS Server - A tiny, ultra-fast messaging system with JetStream persistence, popular for microservice and edge messaging.
- RabbitMQ - The versatile, protocol-rich message broker that remains a default for reliable task queues.
- Apache Pulsar - A streaming/messaging platform with separated compute and storage, multi-tenancy, and geo-replication.
- Temporal - A durable execution platform for writing fault-tolerant, long-running workflows as ordinary code.
- Cadence - Uber's durable workflow orchestration engine (Temporal's predecessor) for long-running business logic.
- Apache RocketMQ - A high-throughput, low-latency distributed messaging and streaming platform proven at Alibaba scale.
- Debezium - The standard change-data-capture platform for streaming database changes into Kafka and beyond.
- Redpanda Connect (Benthos) - A declarative stream processor for glue-code-free data plumbing and transformation.
- RisingWave - A Postgres-compatible streaming database for building real-time materialized views in SQL.
- NSQ - A realtime distributed messaging platform in Go designed for simplicity, scale, and no SPOF.
- vLLM - The high-throughput PagedAttention serving engine that is the de facto open-source production inference standard.
- SGLang - A fast serving framework with RadixAttention prefix caching, prized for structured generation and low latency.
- llama.cpp - The C/C++ GGUF inference engine enabling efficient CPU/GPU/Apple-silicon local LLM deployment.
- Ollama - The most popular local model runner, giving a clean CLI/API over llama.cpp with model management.
- TensorRT-LLM - NVIDIA's compiler and runtime for squeezing maximum throughput out of Tensor Core GPUs.
- Text Generation Inference - Hugging Face's production Rust/Python inference server that powered many hosted endpoints.
- LMDeploy - InternLM's toolkit for compressing and serving LLMs with high-performance TurboMind kernels.
- LightLLM - A pure-Python, token-attention serving framework favored for lightweight, hackable high-concurrency inference.
- KTransformers - A framework for running huge MoE models on limited GPU/CPU hardware via offloading and kernel injection.
- Aphrodite Engine - A vLLM-derived engine focused on high-throughput serving with broad quantization support.
- LocalAI - A drop-in OpenAI-compatible API for self-hosted text, image, and audio models across many backends.
- Text Embeddings Inference - A blazing-fast Rust server for embedding and reranker models, a key RAG-stack component.
- NVIDIA Dynamo - A datacenter-scale distributed inference framework with disaggregated prefill/decode serving.
- llamafile - A Mozilla project that packages a model and runtime into a single cross-platform executable.
- exo - Runs a single large model as a distributed cluster across everyday devices.
- LangChain - The most widely adopted LLM app framework and integration layer for chains, tools, and retrieval.
- LlamaIndex - The data framework specializing in ingestion, indexing, and retrieval for production RAG.
- LangGraph - A graph-based runtime for stateful, human-in-the-loop agent workflows; the enterprise orchestration favorite.
- DSPy - A Stanford framework that programs and auto-optimizes prompts/weights instead of hand-tuning strings.
- Haystack - deepset's modular, production-grade pipeline framework for RAG and search applications.
- LiteLLM - A universal proxy/SDK giving one OpenAI-format interface to 100+ model providers with cost tracking.
- Dify - An open-source, visual low-code platform for building and operating LLM apps and agents.
- Langflow - A visual builder for RAG and multi-agent flows with a Python backend.
- Flowise - A drag-and-drop UI for assembling LLM orchestration flows.
- Semantic Kernel - Microsoft's enterprise SDK for planners, plugins, and agent orchestration across .NET/Python.
- Pydantic AI - A type-safe, Pydantic-native agent framework for structured, validated LLM outputs.
- Mastra - A TypeScript-first framework for agents, workflows, and RAG, popular in the JS/edge ecosystem.
- Portkey Gateway - A fast open-source AI gateway with routing, fallbacks, caching, and observability.
- Guidance - A constrained-generation language for interleaving control flow with token-level structure.
- Outlines - A structured generation library guaranteeing JSON-schema/regex/CFG-valid LLM outputs.
- BAML - A domain-specific language for building reliable, type-safe, testable LLM functions.
- Vercel AI SDK - The TypeScript toolkit for building AI apps and agents across many providers.
- AutoGen - Microsoft's multi-agent conversation framework and a research staple.
- CrewAI - A lean framework for orchestrating role-playing agent "crews" with minimal boilerplate.
- OpenHands - An autonomous software-engineering agent platform (formerly OpenDevin) that writes, runs, and tests code.
- MetaGPT - A multi-agent framework that simulates a software company with role-based SOPs.
- OpenAI Agents SDK - A lightweight, provider-agnostic framework for multi-agent workflows with handoffs and guardrails.
- smolagents - Hugging Face's minimalist code-writing agent library.
- Google ADK - Google's Agent Development Kit for building, evaluating, and deploying production agents.
- CAMEL - A research framework for communicative and role-playing multi-agent systems at scale.
- Agno - A high-performance framework/runtime for agents with memory, knowledge, and tools (formerly Phidata).
- SWE-agent - Princeton's benchmark-topping agent that autonomously resolves GitHub issues.
- Skyvern - Automates browser workflows using vision-LLMs that read pages via screenshots.
- Stagehand - An AI browser-automation SDK blending natural language with code for reliable web agents.
- LiveKit Agents - A framework for building real-time, low-latency voice and multimodal AI agents.
- ChatDev - A multi-agent virtual software company for collaborative code generation.
- E2B - Open-source secure cloud sandboxes for running AI-generated code.
- Milvus - A cloud-native vector database engineered for billion-scale similarity search.
- Qdrant - A Rust vector database praised for fast filtered search and simple production operations.
- Weaviate - A vector database with strong hybrid search and a built-in module ecosystem.
- Chroma - A developer-friendly embedding database that is the default for fast RAG prototyping.
- pgvector - The Postgres extension that adds vector search, the pragmatic default for teams already on Postgres.
- LanceDB - An embedded, multimodal vector database built on the columnar Lance format.
- FAISS - Meta's foundational library for efficient similarity search and vector clustering.
- Marqo - An end-to-end vector search engine with first-class multimodal embedding generation.
- RAGFlow - An end-to-end RAG engine with deep document understanding and agentic context construction.
- GraphRAG - Microsoft's knowledge-graph-based RAG approach for global reasoning over large corpora.
- Graphiti - Builds real-time, temporally-aware knowledge graphs for agent memory.
- cognee - A memory/knowledge-graph layer that replaces ad-hoc RAG with structured pipelines.
- txtai - An all-in-one embeddings database for semantic search, RAG, and LLM workflows.
- Unstructured - A preprocessing library that turns PDFs, HTML, and docs into clean, chunked LLM data.
- Mem0 - A universal memory layer giving agents persistent user/session/agent-scoped memory.
- Letta - An agent framework (formerly MemGPT) treating memory like an OS with self-managed context.
- Transformers - The foundational model library and hub interface underpinning most modern LLM work.
- Unsloth - Custom Triton kernels that make LoRA/QLoRA fine-tuning 2x+ faster with far less VRAM.
- Axolotl - A config-driven fine-tuning framework favored for reproducible, production training pipelines.
- LLaMA-Factory - A unified, GUI-friendly fine-tuning platform supporting 100+ models and every major PEFT method.
- PEFT - Hugging Face's parameter-efficient fine-tuning library (LoRA, adapters, prompt tuning) used everywhere.
- TRL - A post-training toolkit unifying SFT, DPO, GRPO, and RLHF trainers on the HF stack.
- Megatron-LM - NVIDIA's reference for large-scale tensor/pipeline-parallel transformer pretraining.
- DeepSpeed - Microsoft's ZeRO-based training/inference optimization library for training massive models.
- Accelerate - A thin abstraction for launching PyTorch training across multi-GPU/TPU/mixed-precision setups.
- Diffusers - The standard toolkit for training and running diffusion models for image/audio/video.
- OpenRLHF - A Ray-based, high-performance RLHF framework for scalable PPO/GRPO alignment training.
- verl - Volcano Engine's flexible RL post-training library (HybridFlow), a 2026 favorite.
- ms-swift - ModelScope's framework for fine-tuning and deploying 400+ LLMs/MLLMs.
- XTuner - An efficient, flexible toolkit for fine-tuning LLMs and multimodal models.
- LitGPT - 20+ from-scratch LLM implementations with pretrain/finetune/deploy recipes.
- Langfuse - An open-source LLM engineering platform for tracing, evals, and prompt management; the observability leader.
- Ragas - A reference-free RAG evaluation library that pioneered faithfulness/relevancy metrics.
- DeepEval - "Pytest for LLMs" with 50+ metrics and CI/CD-friendly unit testing of model outputs.
- Phoenix - Arize's OpenTelemetry-native, self-hostable tracing and evaluation tool for LLM/agent apps.
- Guardrails - Adds input/output validators and structured-output guarantees around LLM calls.
- NeMo Guardrails - NVIDIA's toolkit for adding programmable safety/topical rails to conversational apps.
- OpenAI Evals - The widely-used framework and registry for building and running model evaluations.
- lm-evaluation-harness - EleutherAI's de facto harness for academic LLM benchmarking.
- promptfoo - A CLI/library for test-driven prompt evaluation and LLM red-teaming/security scanning.
- lighteval - Hugging Face's lightweight, all-in-one evaluation suite across multiple backends.
- Giskard - A testing framework that scans ML/LLM systems for vulnerabilities, bias, and robustness issues.
- LLM Guard - A security toolkit for defending against prompt injection and data leakage.
- OpenLLMetry - OpenTelemetry-based instrumentation for end-to-end LLM app observability.
- Helicone - An open-source LLM observability proxy for logging, caching, and cost monitoring.
- Opik - Comet's open-source platform for tracing, evaluating, and monitoring LLM applications.
- MLflow - The de facto open standard for experiment tracking, model registry, and GenAI evaluation.
- Ray - A distributed compute framework (Train/Tune/Serve/Data) underpinning much large-scale ML infra.
- BentoML - A framework for packaging models and building/serving production inference APIs.
- KServe - A Kubernetes-native, standardized model inference platform with autoscaling and vLLM support.
- ZenML - An extensible MLOps/LLMOps framework for portable, reproducible pipelines across stacks.
- Weights & Biases - The industry-standard experiment tracking, artifacts, and model management SDK.
- Aim - An open-source, self-hostable experiment tracker for high-volume run comparison.
- DVC - Git-based data and model version control for reproducible ML pipelines.
- Kubeflow - The Kubernetes-native ML platform for pipelines, training, and serving at scale.
- Flyte - A strongly-typed, Kubernetes-native workflow orchestrator for scalable ML/data pipelines.
- Metaflow - Netflix's human-centric framework for building and managing real-world data science projects.
- Feast - The leading open-source feature store for serving consistent features to training and inference.
- SkyPilot - Runs training/serving/batch jobs across any cloud or Kubernetes with cost and spot optimization.
- OpenLLM - Run and deploy open LLMs as OpenAI-compatible endpoints with one command.
- Terraform - The dominant multi-cloud IaC tool; fluency here is table stakes for infra engineers.
- OpenTofu - The Linux Foundation's open-source Terraform fork, increasingly adopted after the BSL relicense.
- Pulumi - IaC using real languages (TypeScript, Go, Python), valued where teams want tests, loops, and abstractions.
- Ansible - The agentless configuration-management and automation engine that remains a fleet-management workhorse.
- Crossplane - A CNCF-graduated control plane that manages cloud infra as Kubernetes resources.
- Packer - HashiCorp's tool for building identical machine images across clouds.
- Vault - The industry-standard secrets management and dynamic-credentials system for zero-trust infra.
- Consul - Service discovery, service mesh, and distributed KV for connecting and securing services.
- Nomad - A simple, flexible workload orchestrator scheduling containers and non-container workloads.
- SOPS - The standard for encrypting secrets in Git (YAML/JSON) with KMS/age.
- Terragrunt - A thin Terraform wrapper for keeping large multi-environment configs DRY.
- Infracost - Shows cloud cost diffs in pull requests so teams catch expensive infra changes before merge.
- LocalStack - A local AWS cloud emulator for developing and testing cloud apps without cost or latency.
- Dagger - A programmable, containerized CI/CD engine that lets you write pipelines as code and run them anywhere.
- Kubespray - Production-grade Ansible playbooks for deploying self-managed Kubernetes clusters.
- Salt - An event-driven automation and configuration-management platform for large infrastructures.
- AWX - The upstream open-source project behind Ansible Automation Platform.
- Earthly - Reproducible, container-native builds that run identically locally and in CI.
- Kubernetes - The container orchestration platform that defines cloud-native infrastructure.
- Helm - The de facto Kubernetes package manager for templating and releasing complex applications.
- Kustomize - Template-free, overlay-based Kubernetes configuration management built into kubectl.
- Argo CD - The leading declarative GitOps continuous-delivery controller for Kubernetes.
- Flux - A CNCF-graduated GitOps toolkit for keeping clusters continuously reconciled with Git.
- Argo Workflows - A Kubernetes-native workflow engine for orchestrating parallel jobs and data/ML pipelines.
- Argo Rollouts - Progressive delivery (canary, blue-green) with automated analysis and rollback.
- Istio - The most feature-complete service mesh, providing mTLS, traffic management, and telemetry.
- Linkerd - A lightweight, security-first service mesh valued for operational simplicity.
- k3s - A certified lightweight Kubernetes distribution ideal for edge, IoT, and CI.
- kind - Runs Kubernetes clusters in Docker, the standard for local testing and CI of cluster software.
- Rancher - A complete platform for managing fleets of Kubernetes clusters across on-prem and cloud.
- Cluster API - Declarative, Kubernetes-style APIs for managing the lifecycle of clusters themselves.
- KubeVirt - Runs traditional VMs alongside containers on Kubernetes.
- Open Policy Agent - A general-purpose policy engine (Rego) for authorization and admission control.
- Kyverno - A Kubernetes-native policy engine using YAML instead of a new language.
- Harbor - A CNCF-graduated container registry with vulnerability scanning, signing, and replication.
- Tekton Pipelines - A Kubernetes-native, reusable framework for building cloud-native CI/CD pipelines.
- cert-manager - Automates issuance and renewal of TLS certificates in Kubernetes.
- Kubebuilder - The SDK for building Kubernetes APIs and operators with CRDs.
- Knative Serving - Serverless scale-to-zero and request-driven autoscaling primitives on Kubernetes.
- KEDA - Event-driven autoscaling on queue depth, Kafka lag, and dozens of other sources.
- Velero - Backup, restore, and disaster recovery for Kubernetes resources and persistent volumes.
- Longhorn - A CNCF distributed block storage system for Kubernetes with replication and snapshots.
- Rook - A storage operator that turns Ceph into self-managing storage on Kubernetes.
- Prometheus - The de facto cloud-native metrics and alerting system; its data model defines modern monitoring.
- Grafana - The universal observability dashboard for metrics, logs, and traces across any backend.
- Loki - A cost-efficient, label-based log aggregation system that indexes metadata instead of full text.
- Tempo - A high-scale distributed tracing backend that needs only object storage to run.
- Mimir - Horizontally scalable, long-term Prometheus storage handling a billion+ active series.
- Pyroscope - A continuous-profiling database to debug CPU/memory down to the line of code in production.
- OpenTelemetry Collector - The vendor-neutral pipeline for receiving, processing, and exporting all telemetry.
- Jaeger - The CNCF-graduated distributed tracing system for root-causing latency across microservices.
- Thanos - Adds global query, unlimited retention, and HA to Prometheus via object storage.
- Vector - A blazing-fast Rust observability data pipeline for collecting, transforming, and routing telemetry.
- Fluent Bit - A lightweight, high-throughput log/metric processor and forwarder for edge and containers.
- Netdata - Real-time, per-second infrastructure monitoring with zero-config auto-discovery.
- SigNoz - An OpenTelemetry-native, all-in-one APM and observability platform (open-source Datadog).
- OpenObserve - A petabyte-scale observability platform with dramatically lower storage cost.
- Parca - Always-on eBPF-based continuous profiling to cut CPU and memory usage across a fleet.
- Pixie - eBPF-powered, no-instrumentation observability for Kubernetes with automatic protocol tracing.
- Coroot - An eBPF-based observability tool that auto-generates service maps and SLO-driven insights.
- Grafana OnCall - Open-source on-call scheduling and incident escalation, an alternative to PagerDuty.
- Keep - An open-source AIOps and alert-correlation platform to tame alert fatigue.
- Robusta - Automation and enrichment that adds context and remediation to Kubernetes alerts.
- Gin - The most popular Go HTTP framework, valued for speed and a minimal API.
- Echo - A high-performance, minimalist Go web framework with strong middleware ergonomics.
- Fiber - An Express-inspired Go framework built on fasthttp for maximum throughput.
- chi - A lightweight, idiomatic Go router that composes cleanly with the standard library.
- gRPC-Go - The Go implementation of gRPC, the default for high-performance internal APIs.
- Connect-Go - A simpler, browser-compatible RPC framework interoperable with gRPC.
- sqlc - Generates fully type-safe Go from raw SQL, a favorite for teams avoiding heavyweight ORMs.
- Ent - Facebook's graph-based, schema-as-code ORM for Go with strong static typing.
- GORM - The full-featured Go ORM that remains the most-used data access layer.
- golang-migrate - Database schema migrations as a library and CLI for every major database.
- Tokio - The asynchronous runtime that anchors virtually all production Rust network services.
- Axum - The Tokio team's ergonomic, modular web framework, now the mainstream Rust choice.
- Actix Web - An extremely fast, mature Rust web framework topping throughput benchmarks.
- SQLx - Async, compile-time-checked SQL for Rust with no DSL.
- Serde - The foundational Rust serialization framework used by essentially every Rust backend.
- Tower - Composable middleware powering timeouts, retries, and load-shedding in Rust services.
- Spring Boot - The dominant JVM framework for production microservices and enterprise backends.
- Quarkus - A Kubernetes-native Java stack with fast startup and low memory via AOT compilation.
- Micronaut - A modern JVM framework using compile-time DI to avoid reflection.
- Ktor - JetBrains' asynchronous Kotlin framework for connected server and client applications.
- Netty - The asynchronous event-driven network framework underpinning much JVM networking.
- NestJS - A structured, TypeScript-first Node framework bringing DI and modular architecture to backends.
- Fastify - A high-throughput, low-overhead Node framework with schema-based validation.
- Hono - An ultrafast, runtime-agnostic web framework that runs on Workers, Deno, Bun, and Node.
- tRPC - End-to-end type-safe APIs without codegen, popular in TypeScript monorepos.
- Prisma - A type-safe ORM and toolkit that has become a default data layer for TypeScript backends.
- gRPC - The core multi-language RPC framework for efficient, contract-first service communication.
- Protocol Buffers - Google's language-neutral serialization format, the schema backbone of gRPC.
- Buf - Modern Protobuf tooling with linting, breaking-change detection, and a schema registry.
- OpenAPI Specification - The standard for describing REST APIs that drives codegen, docs, and contract testing.
- Envoy - The CNCF-graduated L7 proxy at the heart of most service meshes and modern edge infra.
- Traefik - A cloud-native reverse proxy and ingress with automatic service discovery and Let's Encrypt.
- Caddy - A Go web server/proxy with automatic HTTPS by default, valued for operational simplicity.
- Cilium - eBPF-based networking, security, and observability; the leading modern CNI.
- Kong - A high-performance, plugin-extensible API gateway built on Nginx/OpenResty.
- HAProxy - The battle-hardened, ultra-reliable TCP/HTTP load balancer for demanding traffic.
- CoreDNS - The CNCF-graduated, plugin-based DNS server providing service discovery inside Kubernetes.
- MetalLB - A load-balancer implementation for bare-metal Kubernetes clusters.
- Pingora - Cloudflare's Rust framework for fast, programmable proxies, serving 40M+ requests/second.
- Tetragon - eBPF-based runtime security observability and enforcement with low overhead.
- Hubble - Cilium's eBPF-powered network, service, and security observability layer.
- Kubeshark - An API traffic analyzer ("Wireshark for Kubernetes") for real-time network visibility.
- k6 - A developer-centric, scriptable load-testing tool (JavaScript) that has become the modern standard.
- Locust - Distributed load testing with scenarios defined in Python.
- Vegeta - A versatile HTTP load-testing tool for constant-rate attacks with rich reporting.
- Gatling - A high-performance load-testing framework with an expressive DSL for the JVM ecosystem.
- FlameGraph - Brendan Gregg's flame graph visualization, the canonical way to interpret CPU profiles.
- bpftrace - A high-level tracing language for Linux eBPF, indispensable for deep production performance analysis.
- BCC - A toolkit of eBPF-based tools for advanced kernel tracing, profiling, and networking observability.
- async-profiler - A low-overhead sampling profiler for the JVM without safepoint bias.
- wrk2 - A constant-throughput wrk fork with corrected latency measurement.
- hyperfine - A command-line benchmarking tool with statistical rigor for comparing program performance.
- Chaos Mesh - A CNCF cloud-native chaos-engineering platform for injecting faults into Kubernetes.
- Litmus - A CNCF chaos-engineering framework for practicing resilience testing.
- Toxiproxy - Shopify's TCP proxy for deterministically simulating network failures and latency in tests.
- Backstage - Spotify's CNCF developer portal and software catalog, the de facto standard for IDPs.
- Kratix - A platform orchestrator that delivers self-service APIs between portals and infrastructure.
- Score - A platform-agnostic workload specification decoupling developer intent from environment config.
- Porter - An internal developer platform that deploys apps to your own cloud with a Heroku-like experience.
- Devtron - An open-source Kubernetes-native software delivery platform unifying CI/CD, GitOps, and security.
- werf - A CNCF GitOps CLI tying Git, build, and Helm deploy into reproducible delivery pipelines.
- Kusion - An intent-driven platform orchestrator for building app-centric internal developer platforms.
- Semgrep - Fast, rule-based static analysis (SAST) with pattern-as-code, widely adopted in CI security gates.
- TruffleHog - Scans repos, history, and systems for leaked credentials and verifies them live.
- Gitleaks - A fast, CI-friendly secrets scanner that is a standard pre-commit and pipeline check.
- Trivy - The all-in-one scanner for container images, IaC, SBOMs, and secrets, ubiquitous in DevSecOps.
- Grype - A fast vulnerability scanner for container images and filesystems, often paired with Syft.
- Syft - Generates SBOMs (SPDX/CycloneDX) from images and filesystems, foundational to supply-chain security.
- Cosign - Sigstore's tool for signing and verifying container images and artifacts.
- Checkov - Policy-as-code static analysis for Terraform, CloudFormation, and Kubernetes.
- OWASP ZAP - The leading open-source DAST web app scanner and proxy for runtime vulnerabilities.
- Nuclei - Template-driven, high-speed vulnerability scanning, the standard for automated detection.
- Subfinder - A fast passive subdomain enumeration tool, a staple of recon workflows.
- httpx - A fast, multi-purpose HTTP toolkit for probing and fingerprinting hosts at scale.
- naabu - A fast, reliable port scanner in Go built for large-scale recon pipelines.
- Amass - OWASP's in-depth attack-surface mapping and external asset discovery framework.
- sqlmap - The definitive automated SQL injection detection and exploitation tool.
- Sliver - Bishop Fox's cross-platform adversary-emulation C2 framework, a modern Cobalt Strike alternative.
- Havoc - A modern, malleable post-exploitation C2 framework popular in red-team engagements.
- BloodHound - Graph-based analysis of Active Directory/Azure attack paths.
- NetExec - The maintained successor to CrackMapExec for automating network and AD assessments.
- PayloadsAllTheThings - The go-to reference of payloads and bypass techniques for web app pentesting.
- SecLists - The essential collection of wordlists for fuzzing, brute-forcing, and discovery.
- hashcat - The world's fastest GPU-accelerated password recovery tool.
- Metasploit Framework - The canonical exploitation framework for penetration testing and exploit development.
- PEASS-ng - The definitive privilege-escalation enumeration scripts (linPEAS/winPEAS).
- Prowler - Multi-cloud security assessments (AWS/Azure/GCP/K8s) mapped to CIS and compliance benchmarks.
- kube-bench - Checks Kubernetes clusters against the CIS Kubernetes Benchmark.
- Kubescape - A Kubernetes security platform for misconfiguration, RBAC, and image scanning.
- Cloud Custodian - A YAML rules engine for cloud governance, cost, and security guardrails at scale.
- ScoutSuite - NCC Group's multi-cloud security auditing tool.
- Pacu - An open-source AWS exploitation framework for offensive cloud security testing.
- Wazuh - An open-source SIEM/XDR platform for threat detection, integrity monitoring, and compliance.
- Velociraptor - Endpoint visibility and digital forensics/incident response at fleet scale.
- TheHive - A scalable security incident response platform for SOC collaboration.
- Falco - The CNCF runtime security engine detecting anomalous behavior via eBPF/syscalls.
- CrowdSec - A collaborative, behavior-based intrusion prevention system with crowd-sourced threat intel.
- OSSF Scorecard - Automatically scores open-source projects' security posture for supply-chain risk.
- Go - The reference implementation of the Go language and standard library, essential for backend engineers.
- Rust - The Rust compiler and standard library, the foundation of the memory-safe systems ecosystem.
- Zig - A simple, explicit systems language and toolchain increasingly used as the build layer under other projects.
- Awesome Go - The definitive curated index of Go libraries and tools.
- Awesome Rust - The canonical curated catalog of Rust libraries, applications, and systems tooling.
- Go Project Layout - The widely referenced conventions for structuring real-world Go applications.
- Uber Go Style Guide - Uber's battle-tested Go style guide adopted by many teams as their standard.
- fasthttp - A zero-allocation HTTP implementation for Go with order-of-magnitude throughput gains.
- conc - Sourcegraph's structured-concurrency toolkit for correct, ergonomic goroutine management.
- Rayon - Data-parallelism for Rust that makes CPU-bound code parallel with a one-line change.
- clap - The full-featured, ergonomic command-line argument parser powering most Rust CLIs.
- Firecracker - AWS's Rust microVM tech powering Lambda/Fargate, the reference for secure lightweight virtualization.
- containerd - The CNCF-graduated industry-standard container runtime underpinning Docker and Kubernetes.
- runc - The OCI reference low-level runtime for spawning containers.
- Podman - A daemonless, rootless container engine that has become the secure Docker alternative on Linux.
- CRI-O - A lightweight, Kubernetes-dedicated container runtime implementing the CRI.
- Wasmtime - The Bytecode Alliance's fast, secure WebAssembly/WASI runtime and Component Model reference.
- Wasmer - A leading universal WebAssembly runtime for running Wasm across languages and platforms.
- Bun - An all-in-one JS runtime, bundler, and package manager built for speed.
- Deno - A secure-by-default, TypeScript-first runtime with a modern standard library.
- Ruff - Astral's extremely fast Rust-written Python linter and formatter.
- uv - Astral's ultra-fast Rust package/project manager rapidly replacing pip/Poetry.
- Biome - A Rust-based, all-in-one formatter and linter positioned as a fast Prettier/ESLint replacement.
- SWC - A Rust platform for fast TS/JS compilation and transformation used inside many toolchains.
- typescript-go - Microsoft's native Go port of the TypeScript compiler (the basis of TS 7) targeting ~10x speedups.
- React - The core UI library whose Server Components and compiler define much of modern frontend.
- Next.js - The dominant React meta-framework for SSR/SSG/RSC production apps.
- Svelte - A compiler-based framework (v5 runes) delivering minimal-runtime, high-performance UIs.
- SvelteKit - The official application framework for building Svelte apps.
- SolidJS - A fine-grained reactive library offering React-like ergonomics with near-vanilla performance.
- Astro - A content-focused framework with islands architecture that ships zero JS by default.
- Nuxt - The intuitive Vue meta-framework for hybrid-rendered, full-stack applications.
- Qwik - A resumable framework eliminating hydration for instant-loading web apps.
- Vite - The near-universal dev server and build tool that became the frontend tooling backbone.
- Turborepo - A Rust-based high-performance build system with caching for JS/TS monorepos.
- Nx - An extensible monorepo build system with computation caching and rich generators.
- Rolldown - A Rust-based, Rollup-compatible bundler becoming Vite's unified production bundler.
- Oxc - A Rust suite of ultra-fast JS/TS tools (parser, linter, resolver, minifier).
- Rspack - A Rust bundler with a webpack-compatible API for drop-in speed on large codebases.
- TanStack Query - The standard async-state/data-fetching library for React and other frameworks.
- TanStack Router - A fully type-safe router with first-class search-param and data-loading APIs.
- React Router - The routing standard that absorbed Remix into a full-stack React framework.
- shadcn/ui - The copy-in, unstyled-by-default component collection that redefined design systems.
- Tailwind CSS - The utility-first CSS framework whose v4 Oxide engine is a modern styling default.
- React Native - The cross-platform native app framework whose New Architecture closed the performance gap.
- Expo - The recommended production toolchain for React Native with builds, OTA updates, and native modules.
- Compose Multiplatform - JetBrains' declarative UI sharing Compose across Android, iOS, desktop, and web.
- The Composable Architecture - Point-Free's state-management library for testable, scalable SwiftUI apps.
- React Native Reanimated - The high-performance native-thread animation library essential to serious RN apps.
- Now in Android - Google's reference app showcasing modern Android architecture and Compose best practices.
- Capacitor - A native runtime for building cross-platform apps with web tech and full native API access.
- Tamagui - A universal UI kit and optimizing compiler for React Native + web from one codebase.
Repositories that broke out or went viral between late 2025 and mid-2026 - the newest additions to a senior engineer's radar.
- OpenClaw - Self-hosted personal AI assistant that wires any LLM into WhatsApp/Telegram/Slack/Signal; went from ~9k to 250k+ stars in early 2026, the fastest-growing repo of the year.
- Codex CLI - OpenAI's Rust-rewritten open-source terminal coding agent (~95k+ stars in 2025).
- Gemini CLI - Google's open-source terminal AI agent embedding Gemini, one of the most-watched dev tools of 2025-2026.
- OpenCode - A fast, provider-flexible terminal coding agent that became a dominant open CLI agent in 2026.
- Crush - Charm's polished Go TUI coding agent with multi-model and MCP support.
- Cline - The leading autonomous VS Code coding agent with human-in-the-loop approval and MCP tools.
- Kilo Code - An all-in-one agentic VS Code extension merging Roo/Cline ideas, a fast-growing 2025-2026 fork.
- Goose - Block's extensible on-machine agentic coding assistant, now under Linux Foundation governance.
- Pi (pi-mono) - A radically minimal terminal coding agent + harness toolkit that blew up on a sub-1k-token system prompt.
- MCP Servers - The reference collection of Model Context Protocol servers, the standard for connecting agents to tools/data.
- GitHub MCP Server - GitHub's official MCP server for repo/issue/PR/Actions access from agents.
- Playwright MCP - Microsoft's browser-automation MCP server, the go-to way to give agents a real browser.
- gpt-oss - OpenAI's first open-weight models (120b/20b, Apache-2.0) since GPT-2, a shock release in Aug 2025.
- DeepSeek-V3.2-Exp - A MoE model introducing DeepSeek Sparse Attention for cheap long-context inference.
- Kimi-K2 - Moonshot's trillion-parameter MoE built for agentic, long-horizon tasks.
- Qwen3 - Alibaba's Apache-2.0 dense + MoE family with hybrid thinking modes, a default open-weight backbone.
- GLM-4.5 - Z.ai's agentic/reasoning/coding foundation models, a top open coding/agent model.
- Crawl4AI - An LLM-friendly web crawler that hit #1 GitHub trending as RAG data-ingestion demand exploded.
- Firecrawl - Turns entire websites into LLM-ready Markdown/structured data via a scrape-and-crawl API.
- Docling - Parses PDFs and office docs into structured formats for GenAI (LF AI & Data).
- Motia - A unified backend framework merging APIs, jobs, queues, workflows, and AI agents.
- Better Auth - A comprehensive, framework-agnostic TypeScript authentication library.
- Ghostty - A fast, GPU-accelerated, native cross-platform terminal emulator.
- Zed - A high-performance multiplayer code editor from the creators of Atom.
Found a production-grade repo that belongs here? See CONTRIBUTING.md and open a pull request. Advanced, real-world, actively-maintained repositories only.
| List | Audience | Link |
|---|---|---|
| 150 Essentials | Beginners & Students | awesome-learn-to-code |
| 280+ Comprehensive | Everyone | Main README |
| 300+ Advanced | Professionals & Senior Engineers | (you are here) |
Built for people who ship. βοΈ
If a repo here saved you a war-room at 3 a.m., pay it forward with a PR.
π Licensed under Apache 2.0 Β Β·Β π§ Curated by md8-habibullah
If this helped, star β and share it with your team.