Roadmap
Status: 2026-09-02. This page is the sole repository roadmap. A roadmap item is not an available product feature.
Current platform
Section titled “Current platform”The implemented product includes authentication, tenant and organization administration, users and permissions, audit, device and Device Type inventory, the V2 visual telemetry-flow system, fixed Device dashboards, the Netmore adapter, durable NATS JetStream processing, idempotent raw storage, the Platform-Admin raw view, container images, and the portable Helm topology.
The operational baseline includes the independent sens-platform-ops portal,
VictoriaMetrics, VictoriaLogs, Fluent Bit, vmalert, Alertmanager, public status,
monthly SLO reports, OpenBao, ESO, and restricted Argo CD and Kubernetes
identities. Automated OpenBao and broader platform-data backup with an isolated
restore proof remains a Production gate. Volumes alone are not backups.
Immediate delivery gates
Section titled “Immediate delivery gates”- Finish the current Test and Production CI/release alignment and verify version identity for every deployable and job.
- Execute the approved
SENS Cloud and SENS Ops rollout plan
in order: consolidate source, introduce transitive affected-scope CI, automate
first-party SENS Ops releases, publish independent OCI artifacts, rebuild
sens-platform-infra, initialize the two physical servers and k3s clusters, switch DNS, prove failure separation, remove the old runtime, and rehearse a clean customer-owned installation. - Complete the live Netmore gate with an anonymized test Device, 24-hour observation, QoS 1 evidence, capacity projection, and controlled outage.
- Prove target-cluster stream lag, sandbox isolation, SMTP delivery, alert delivery, and the explicit global Action switch before enabling Actions.
- Define external encrypted backup targets, retention, RPO/RTO, alerts, and an isolated restore exercise for OpenBao and TimescaleDB before real Production data is accepted.
- Keep the current Coolify operations topology only until the replacement SENS Ops and SENS Cloud phases have passed their live gates. No old data, repository history, parallel transition environment, or rollback runtime is required for this pre-customer hard cut.
Flow product integration — Phase 11
Section titled “Flow product integration — Phase 11”The durable pipeline after the raw commit is implemented: transactional outboxes, versioned events, idempotent relays, retries, replay, persistent Dead Letters, controlled redrive, and lag signals. The remaining work is to turn the existing Flow areas into one coherent operator journey:
- Studio owns Device-Type-bound graph authoring, validation, immutable versions, release, activation, fixtures, and parameter context.
- Scripts owns reviewed, checksum-bound custom capabilities and their sandbox release gates. A script is a Flow building block, not a parallel automation product.
- Templates owns reusable, UUID-free starting points. Instantiation should lead directly into Studio with the selected Device Type and newly instantiated Flow draft selected.
- Actions owns E-mail templates, scoped recipients, the tenant kill switch, jobs, Executions, Dead Letters, and redrive. Delivery remains downstream of the successful telemetry commit.
Product integration should preserve the selected Tenant, Device Type, Flow, version, and time context when moving between these areas. Execution and Dead Letter rows should deep-link to the exact Flow version and node; Studio action nodes should link to their template and recipient configuration. Permissions must govern capabilities consistently, and unavailable capabilities must have an explicit explanation rather than a disconnected empty tab.
The pipeline verifier must continuously prove the synthetic local path from the Netmore adapter boundary through JetStream, raw storage, Flow execution, Current Values, Measurements, Action delivery, retry, and Dead Letter without contacting the live broker or a real recipient.
Decisions that gate later work
Section titled “Decisions that gate later work”- Service accounts, personal access tokens, MFA, and tenant-specific OIDC.
- Export file shape, limits, storage, retention, expiry, and compression before asynchronous exports become scheduled work.
- TimescaleDB licensing for Production compression, retention, and aggregation.
- OpenBao and TimescaleDB backup targets, credentials, RPO/RTO, and restore cadence.
- OAuth-based Microsoft 365 delivery before password-based SMTP AUTH is finally removed.
See Open decisions for the maintained list.
Later directions
Section titled “Later directions”Later product directions include saved views and dashboard composition, asynchronous exports, Network Server synchronization, tenant-specific OIDC, advanced permissions, alarms and rules, Device commands, multiple Network Server adapters, dedicated hosted installations, customer-owned on-premise operation, high availability, analytics, and AI-assisted operations.
ADR-0012 defines the post-Coolify direction. The linked rollout plan is its authoritative execution sequence. A central management plane must never become a runtime dependency for customer ingestion, storage, or API access.
The temporary IOTA snapshot import remains a migration aid. Remove its route, UI, contracts, tests, documentation, and obsolete egress only after the V1 data migration is accepted; keep the migrated inventory and historical audit events.