nuggets
nuggets keeps compounding on the 2.0 rewrite — more pattern families, lighter install.
A side-by-side editorial comparison of Dokku and WorkOS — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Dokku | WorkOS |
|---|---|---|
| Sector | Infra & APIs | Infra & APIs |
| Velocity score | 5.0 | 8.8 |
| Sparks · 30d | 0 | 2 |
| Top themes | paas, kubernetes, k3s, cli-automation | identity, authentication, ai-agents, scim |
| Last editorial update | 5d ago | 15h ago |
| Website | Visit → | — |
Dokku is quietly turning into a k3s front-end with a JSON-first CLI.
The 0.38 patch line keeps shipping small releases with real features in them. v0.38.27 drops the local-image requirement for k3s deploys, reports Traefik DNS-provider variables as global keys, adds storage directory mode and removal flags, and introduces a vector-cron-sink so scheduled cron output has somewhere to go. It follows v0.38.26, which brought wildcard domains, custom cert issuers, and kernel sysctls to the k3s scheduler.
WorkOS is building identity for agents while quietly fixing the sign-up funnel.
WorkOS ships several small entries a week, and August splits cleanly in two. One half is authentication housekeeping for human users: an Android SDK, deliverability checks that reject undeliverable addresses at sign-up, invitation acceptance counting as email verification, and a reversible SCIM proxy for migrating directory connections without downtime. The other half is agent infrastructure — Agent Registration via the auth.md protocol, and the Pipes Token Proxy that calls third-party APIs on a user's behalf without the application ever touching their token.
The 0.38 patch line keeps shipping small releases with real features in them. v0.38.27 drops the local-image requirement for k3s deploys, reports Traefik DNS-provider variables as global keys, adds storage directory mode and removal flags, and introduces a vector-cron-sink so scheduled cron output has somewhere to go. It follows v0.38.26, which brought wildcard domains, custom cert issuers, and kernel sysctls to the k3s scheduler.
Two threads run through almost every release: closing the gap between the k3s scheduler and the classic single-host path, and making every command machine-readable. The k3s work has moved from basic scheduling to the operational details — certificates, DNS, sysctls, and now deploys that no longer assume a local Docker image — which is the sequence a project follows when it expects the Kubernetes path to become the default rather than the alternative.
Expect the remaining k3s parity gaps to keep closing one release at a time, and expect the logging work started with vector-cron-sink to extend to other task types that currently have no sink.
WorkOS ships several small entries a week, and August splits cleanly in two. One half is authentication housekeeping for human users: an Android SDK, deliverability checks that reject undeliverable addresses at sign-up, invitation acceptance counting as email verification, and a reversible SCIM proxy for migrating directory connections without downtime. The other half is agent infrastructure — Agent Registration via the auth.md protocol, and the Pipes Token Proxy that calls third-party APIs on a user's behalf without the application ever touching their token.
The agent work is the strategic line. Registration gives an agent an identity of its own instead of a borrowed human session; the token proxy means an application acting for a user never holds the credential. Together they describe a stack where an agent can be authorized, audited and revoked as a first-class principal. The human-auth releases are conversion and migration work — the deliverability check and SCIM Bridge both remove reasons a customer stalls — which is what a developer-infrastructure company does while its next category is still forming.
Registration and the token proxy leave scoping and revocation as the visible gaps, so expect per-agent permissions or consent surfaces next. Whether auth.md gains adoption beyond WorkOS is not something these entries can answer.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Dokku or WorkOS.
nuggets keeps compounding on the 2.0 rewrite — more pattern families, lighter install.
projoint spent a year on CRAN paperwork, then shipped a correctness fix it flagged itself.
eratosthenes spends 0.1.0 hardening inputs rather than adding chronology methods.
dqcheckr adds drift analysis, then removes the YAML a user had to hand-write.
An actuarial mainstay spends its releases on CI plumbing, not on new mathematics.
EDAForge is a data-quality auditor renamed mid-flight, still finding its CRAN footing.
See all Dokku alternatives → · See all WorkOS alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. WorkOS is currently shipping more aggressively (velocity 8.8 vs 5.0), with 2 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. WorkOS is currently shipping more aggressively (velocity 8.8 vs 5.0), with 2 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Dokku alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Dokku alternatives" section above for the current picks, or visit /alternatives/dokku for the full list with editorial commentary on each.
Top WorkOS alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "WorkOS alternatives" section above for the current picks, or visit /alternatives/workos for the full list with editorial commentary on each.