Your Whole Organisation
On One Platform

Rundoc brings your resources, access control, knowledge, collaboration, processes, automation, software templates, feature flags and self-service infrastructure into one place, and keeps them connected to the teams and services they belong to.

Self-hosted with Docker Compose. Open source core.

Open at the core

Rundoc's platform and plugin protocol are open source. Run it on your own infrastructure, write your own plugins, and talk to us when you need enterprise support.

View colwill/doc
Architecture

A Small Core, Everything Else a Plugin

The core authenticates, authorises, stores and routes. Plugins provide the features, so you can add only what your organisation needs.

Sign In Your Way

GitHub, GitHub Enterprise, or any OpenID Connect provider such as Entra ID, Google, Keycloak or Okta. You can run several at once, and each organisation picks its own.

Access by Rule

Onboarding rules turn a GitHub team into groups, permissions and attributes on first sign-in. Service accounts can never be granted more than their creator holds.

Hot-Reloaded Plugins

A new plugin version registers beside the old one and takes over its state, so the UI keeps working during upgrades. A plugin that fails is isolated and the previous version keeps serving.

Features

Everything Your Teams Look For

Who owns this service, where its docs live, who can reach it, and how to get a sandbox, all answered in one place.

Catalogue & Service Map

Organisations, teams, services, repositories and cloud resources, all linked to each other. Each service page shows who can reach it.

Knowledge Base

Import MkDocs and sync Confluence and Google Drive on a schedule. Results are permission-aware, and the knowledge base is searchable from any MCP client.

Watercooler

Discussions tagged to services, hackathons and events with ICS calendar feeds, farewell cards and kudos.

Processes & Automation

Recurring processes such as on-call handovers, with reminders and flags for missed occurrences. Automations triggered by events or webhooks, including posting to Slack.

Self-Service Infrastructure

Developers request sandboxes and cloud resources from templates, within limits their group allows. Resources are torn down when their lifetime ends.

Feature Flags

Built-in flags that any OpenFeature SDK can read over OFREP, with existing Runcfg, Unleash or Flagsmith providers read alongside them.

Software Templates

New services and tools in Go, Rust, Python, C++ or TypeScript, as a CLI, REST or gRPC API, or Kubernetes controller, wired into the platform from their first commit.

Observability Built In

A live status dashboard for every component and plugin, plus Grafana with traces, metrics and logs out of the box.

CLI & API

Everything in the UI is also available from the command line and a versioned REST API, using personal access tokens or service accounts in CI.

Golden paths

New Services, Already Connected

Answer a few questions and Rundoc creates the repository, commits the code and adds the service to the catalogue. It also sets up the service's first feature flags and tells you when everything is ready.

  • Check before create — every file is rendered for review before anything exists
  • Runs as you — each step uses your permissions and reports exactly which one it was missing
  • Lifecycle on every signal — experiments are labelled in the catalogue and on every trace, metric and log
  • Flag-controlled from day one — turn off accepting-traffic and the service withdraws within seconds, with no deployment
bash
# Load the catalogue and assign a service account
cli resources apply -f catalog.yaml
cli resources assign docs-bot service:card-gateway

# Grant it write-only access to the knowledge base
cli permissions grant --sa docs-bot plugin:kb:service:wo
# In CI: import docs, exit 0 when done
cli kb import docs/ --resource service:card-gateway --wait

# Keep a Confluence space in sync
cli kb sources add confluence --space platform \
    --resource service:card-gateway --flavour cloud \
    --space-key PAY --schedule "0 * * * *"

cli kb search "card tokenisation"
# Request a bucket your group is allowed to create
cli infra request aws-dev-bucket \
    --name fraud-scores \
    --team payments-core \
    --service card-gateway \
    --wait

# Torn down automatically when its lifetime ends
13+
Plugins out of the box
5
Template languages
Any
OpenID Connect provider
Live
Plugin upgrades without downtime
How Rundoc Compares

A Platform, Not a Framework

Backstage is a framework you build your own portal from, and Roadie runs that framework for you. Rundoc ships as a complete platform, with the catalogue, access, knowledge, templates, feature flags and self-service infrastructure already working together.

Feature Rundoc Backstage Roadie
Catalogue & Access
Software catalogue
Organisations, teams, services, repositories and cloud resources, linked together
Yes Yes Yes
Role-based access control
Groups and permissions managed from the UI, applied to every plugin
Yes Partial:
Permission framework; UI via community plugin
Yes
Growth plan
Who can reach each service
An access map on every service's page, built from your access rules
Yes No No
Knowledge
Docs as code
MkDocs sites imported and attached to the service they describe
Yes Yes
TechDocs
Yes
TechDocs
Confluence and Google Drive sources
Synced on a schedule into one permission-aware knowledge base
Yes Partial:
Confluence search via community plugin
Partial:
Confluence search indexing
Knowledge search for agents over MCP
Coding agents search the same docs your people do, with the same permissions
Yes Partial:
MCP for actions plugins register
Partial:
Catalog and API docs MCP servers, in beta
Golden Paths
Software templates
New services and tools from a form, with every file shown before it's created
Yes Yes
Scaffolder
Yes
Scaffolder
Connected from the first commit
One run creates the repository, catalogue entry, feature flags and telemetry wiring
Yes Partial:
Repo and catalogue; the rest needs custom actions
Partial:
Repo and catalogue; the rest needs custom actions
Flags & Infrastructure
Built-in feature flags
Flags for your services, readable by any OpenFeature SDK over OFREP
Yes No:
Shows flags from LaunchDarkly
No:
Shows flags from LaunchDarkly
Self-service infrastructure
Sandboxes and cloud resources on request, within limits each group allows
Yes Partial:
Via scaffolder actions you write
Partial:
Via scaffolder templates
Automatic teardown
Requested resources are removed when their lifetime ends
Yes No No
Running It
Ready to run, no app to build
Start the whole platform without writing or maintaining your own portal code
Yes No:
You build and maintain a TypeScript app
Yes
Runs on your own infrastructure
Your data stays on servers you control
Yes Yes Partial:
SaaS; Roadie Local in beta
Upgrade plugins without a rebuild
A new version takes over from the old one while the platform keeps serving
Yes Partial:
Dynamic plugin loading is experimental
Yes
Managed for you

Also built in

Onboarding rules

A GitHub team's members get their groups and permissions on first sign-in.

Recurring processes

On-call handovers and other routines, with reminders and missed occurrences flagged.

Automations

Run on platform events or webhooks, and post to Slack.

Watercooler

Discussions tagged to services, hackathons, calendar feeds and kudos.

Bounded service accounts

Never granted more than the person who created them holds.

Live status & telemetry

A status dashboard for every component, plus Grafana with traces, metrics and logs.

Comparison based on each project's public documentation as of October 2026. Partial means the capability depends on community plugins, custom code or a beta feature. Backstage and Roadie are trademarks of their respective owners.

Up on Your Own Hardware

Linux, Docker Compose and just are all it needs.

# Copy the environment file and change every password in it
cp .env.example .env

# Bootstrap, then storage, fabric, core, workers and plugins
just up

# Rundoc      http://127.0.0.1:8081
# API         http://127.0.0.1:8080/api/v1
# Grafana     http://127.0.0.1:3900
# GitHub sign-in and team sync
DOC_GITHUB_CLIENT_ID=Iv1.0123456789abcdef
DOC_GITHUB_ORGS=acme

# Or any OpenID Connect provider
DOC_OIDC_ISSUER=https://login.example.com/realms/staff
DOC_OIDC_CLIENT_ID=doc-platform
DOC_OIDC_TITLE="your work account"
# Log in with a personal access token
cli login --url http://127.0.0.1:8080 --token doc_pat_...

cli plugins list
cli permissions list --user alice
cli github sync

Bring your organisation together

See Rundoc running against your own GitHub organisation, and talk to us about enterprise support and rollout.