Skip to content
SENS Platform Docs

Roadmap

Status: 2026-09-02. This page is the sole repository roadmap. A roadmap item is not an available product feature.

The implemented product includes authentication, tenant and organization administration, users and permissions, audit, device and Device Type inventory, the V2 visual telemetry-flow system, fixed Device dashboards, the Netmore adapter, durable NATS JetStream processing, idempotent raw storage, the Platform-Admin raw view, container images, and the portable Helm topology.

The operational baseline includes the independent sens-platform-ops portal, VictoriaMetrics, VictoriaLogs, Fluent Bit, vmalert, Alertmanager, public status, monthly SLO reports, OpenBao, ESO, and restricted Argo CD and Kubernetes identities. Automated OpenBao and broader platform-data backup with an isolated restore proof remains a Production gate. Volumes alone are not backups.

  • Finish the current Test and Production CI/release alignment and verify version identity for every deployable and job.
  • Execute the approved SENS Cloud and SENS Ops rollout plan in order: consolidate source, introduce transitive affected-scope CI, automate first-party SENS Ops releases, publish independent OCI artifacts, rebuild sens-platform-infra, initialize the two physical servers and k3s clusters, switch DNS, prove failure separation, remove the old runtime, and rehearse a clean customer-owned installation.
  • Complete the live Netmore gate with an anonymized test Device, 24-hour observation, QoS 1 evidence, capacity projection, and controlled outage.
  • Prove target-cluster stream lag, sandbox isolation, SMTP delivery, alert delivery, and the explicit global Action switch before enabling Actions.
  • Define external encrypted backup targets, retention, RPO/RTO, alerts, and an isolated restore exercise for OpenBao and TimescaleDB before real Production data is accepted.
  • Keep the current Coolify operations topology only until the replacement SENS Ops and SENS Cloud phases have passed their live gates. No old data, repository history, parallel transition environment, or rollback runtime is required for this pre-customer hard cut.

The durable pipeline after the raw commit is implemented: transactional outboxes, versioned events, idempotent relays, retries, replay, persistent Dead Letters, controlled redrive, and lag signals. The remaining work is to turn the existing Flow areas into one coherent operator journey:

  • Studio owns Device-Type-bound graph authoring, validation, immutable versions, release, activation, fixtures, and parameter context.
  • Scripts owns reviewed, checksum-bound custom capabilities and their sandbox release gates. A script is a Flow building block, not a parallel automation product.
  • Templates owns reusable, UUID-free starting points. Instantiation should lead directly into Studio with the selected Device Type and newly instantiated Flow draft selected.
  • Actions owns E-mail templates, scoped recipients, the tenant kill switch, jobs, Executions, Dead Letters, and redrive. Delivery remains downstream of the successful telemetry commit.

Product integration should preserve the selected Tenant, Device Type, Flow, version, and time context when moving between these areas. Execution and Dead Letter rows should deep-link to the exact Flow version and node; Studio action nodes should link to their template and recipient configuration. Permissions must govern capabilities consistently, and unavailable capabilities must have an explicit explanation rather than a disconnected empty tab.

The pipeline verifier must continuously prove the synthetic local path from the Netmore adapter boundary through JetStream, raw storage, Flow execution, Current Values, Measurements, Action delivery, retry, and Dead Letter without contacting the live broker or a real recipient.

  • Service accounts, personal access tokens, MFA, and tenant-specific OIDC.
  • Export file shape, limits, storage, retention, expiry, and compression before asynchronous exports become scheduled work.
  • TimescaleDB licensing for Production compression, retention, and aggregation.
  • OpenBao and TimescaleDB backup targets, credentials, RPO/RTO, and restore cadence.
  • OAuth-based Microsoft 365 delivery before password-based SMTP AUTH is finally removed.

See Open decisions for the maintained list.

Later product directions include saved views and dashboard composition, asynchronous exports, Network Server synchronization, tenant-specific OIDC, advanced permissions, alarms and rules, Device commands, multiple Network Server adapters, dedicated hosted installations, customer-owned on-premise operation, high availability, analytics, and AI-assisted operations.

ADR-0012 defines the post-Coolify direction. The linked rollout plan is its authoritative execution sequence. A central management plane must never become a runtime dependency for customer ingestion, storage, or API access.

The temporary IOTA snapshot import remains a migration aid. Remove its route, UI, contracts, tests, documentation, and obsolete egress only after the V1 data migration is accepted; keep the migrated inventory and historical audit events.