v1.0.0
OLS (Open Local Server) v1.0.0: First Public Release
Release date: 2026-09-29 · Platform: Windows 10/11 (64-bit) · License: GPL-3.0-only
OLS is a local development environment manager for Windows: runtimes, sites, databases, and trusted HTTPS, with no manual system edits. It succeeds XAMPP and Laragon with broader runtime coverage and full extensibility. One core engine (ols-core) powers three front doors: a desktop GUI, a CLI (ols), and a local HTTP API. Every project gets isolated runtimes, its own .test domain, and trusted local HTTPS.
✨ Key Features
Runtimes & Toolchain
- Side-by-side versions with a version manager (search, install, default badge, per-version paths).
- Managed: PHP NTS 8.1–8.5 (per-version extensions, Xdebug, PECL), Node 22/24 (corepack), Composer, Python venvs, portable Git, k6.
- Online catalogs with 24h cache and resume-safe, atomic installs. You can also register existing PHP/Node/Python installs.
- Resolution order: project manifest pin > auto-detected > global default. Changing the default never touches project files.
Sites, Web Servers & HTTPS
- Custom domains with wildcard subdomains, automatic
<folder>.test, static sites, and reverse proxy to any host:port. - Trusted HTTPS via an on-device CA: 397-day certificates, auto-renewed under 30 days.
- Nginx 1.28, Apache 2.4, and Caddy 2.11, each with its own HTTP/HTTPS ports, and per-site PHP versions.
- Generated configs (Managed / Advanced / Manual) with validate-before-reload, rollback, drift detection, and diff/restore history.
localhost/<prefix>routes proxy to the site's own vhost (HTTPS when available).- Built-in wildcard DNS for
.test/.localhost/.internal, plus an optional elevated helper that avoids repeated UAC prompts.
Projects & Reproducible Environments
- Auto-detects frameworks from
composer.json,package.json,manage.py, and markers. - Manifests (
.openlocalserver/*.yaml) and a 14-step setup pipeline (plan → dry-run → apply) with journaling and rollback. - Profiles (Development / Testing / Debugging / Demo), snapshots, and a lossless
.enveditor. - 13 Quick App recipes (Laravel, Symfony, WordPress, Express, React/Vite, Vue, Next.js, Django, FastAPI, static, reverse proxy) and one-click Composer/npm scripts.
- The project name autofills the folder, domain, and route together.
Databases & Services
- MariaDB 11.4, PostgreSQL 17, MongoDB, Redis (community
redis-windowsbuild), Mailpit, SQLite, and custom services (any program + port + health check). - Per-engine DB/user management, backup/restore with a safety copy, and one-click HeidiSQL, pgAdmin 4, NoSQLBooster, and Tiny RDM.
- Live importers for Laragon, XAMPP, and WampServer databases (no SQL dumps needed).
- Mailpit capture per framework, and a dedicated log per service.
Dashboard & Monitoring
- Services card with color-coded controls; unavailable actions render flat grey.
- Responsive layout, fixed-column web-server ports tab, and in-app number steppers.
- CPU/RAM/disk donuts and a traffic graph from the access log.
- Diagnostics and Doctor report each finding as Problem / Cause / Fix, with safe one-click repair.
- Unified log viewer, process manager, command palette (
Ctrl+Shift+P), and global search (Ctrl+K).
Resource Limits
- Memory and CPU caps for databases, cache, mail, custom services, and all three web servers.
- CPU limits use the vendored
cpulimitutility (share of total CPU or thread count). - A cap that can't be applied is refused with a fix, never silently ignored.
Sharing & Tunnels
- Cloudflare, ngrok, LocalTunnel, and Tailscale, with exposure confirmation, optional password, and one-click stop.
- Traffic inspector with redacted log, replay, and webhook tester.
CLI, API & Automation
olsCLI (setup,doctor,repair,status,start,stop, and more) with a background daemon that runs with the GUI closed.- Local HTTP API on
127.0.0.1:7420with bearer token, origin rejection, and read-only vs operate scopes. - Workers (Procfile.dev import), cron scheduler, integrated terminals, and a full Git manager.
- k6 load testing, and an AI assistant (LM Studio, Ollama, Hugging Face, OpenRouter, or OpenAI-compatible), off by default and bring-your-own-model.
- Signed plugin catalogs, a signed self-updater, tray icon, and start with Windows.
Reliability
- A single "Stop all" shared by the tray, Dashboard, and API; it names any process the OS refuses to kill.
- Recovery from a poisoned core mutex, deadlines and retry on site settings reads, and timeouts on helper replies.
- Backups accept database names with
-,., or spaces. - Faster site removal, and the confirm dialog names what will be deleted.
Settings & State
- Configurable default TLD, and visible, dated, undoable site/project exclusions.
- State in SQLite (
data/app.db);OLS_HOMEoverrides all paths.
🛠️ Technical Highlights
- Architecture:
GUI (React) / CLI / HTTP API → Core::dispatch(CoreCommand) → Managers, with a single command dispatcher, single response type, and a single error shapeDiagnostic{problem,cause,fix}. - Stack: Rust (Tokio, serde, reqwest/rustls, rcgen, portable-pty, sysinfo), Tauri 2.11, React 19, Vite 8, Tailwind 4, shadcn/ui, CodeMirror 6, xterm.js.
- Safety: operation journal with rollback, config versioning, and a ProcessSupervisor with crash restart and tree-kill.
- Privilege separation: the main app is never elevated.
ols-helperexposes a closed, validated set (hosts/NRPT/service).
🔒 Security
- All runtime downloads are SHA-256 verified. The local CA key never leaves the device.
- Secrets live in the OS keyring only, and are redacted from logs, tunnel inspector, and AI prompts.
- Tunnels need explicit first-exposure confirmation.
- AI: prompt preview, per-request confirmation for remote providers, and allowlisted steps that run only after approval.
- The
cpulimithash is self-pinned (upstream publishes no release asset); provenance is invendor/cpulimit/README.mdand re-checked at installer build. - Report vulnerabilities privately via GitHub Security → "Report a vulnerability" (see
SECURITY.md).
⚠️ Known Limitations
- Tunnel binaries (
cloudflared,ngrok) are located or placed by hand, not downloaded. - The traffic inspector skips WebSocket upgrades and streamed/chunked responses.
- Memory limits apply at the next service start.
- The scheduler runs only while the app or
ols daemonis open. - The installer hasn't yet passed a clean-VM release gate.
- Python venvs are managed, but the Python runtime itself is not.
- Redis is a community Windows build.
- Windows only; Linux is planned for 2.0.
📋 Getting Started
Download OLS-1.0.0-setup.exe from the release assets, run it on Windows 10/11 64-bit, and verify it against OLS-1.0.0-SHA256SUMS.txt.