infraweaver/roadmap
Roadmap
Taken from the project's own planning documents, not from a wish list. Nothing here has a date attached, because this is a spare-time alpha and a date would be a lie.
Next up
From NEXT-FEATURES-PLAN.md. Small and mid-sized work with a clear shape.
The longer arc
From ENTERPRISE-WAVE-PLAN.md. These are the ten workstreams that would take
InfraWeaver from a homelab platform to something an organisation could defend in an audit.
They are directional, and several will change shape before they are built.
Boundaries and evidence
- Access boundariesWorkspaces with scope-enforced RBAC on every surface, not only on the ones that remembered.
- Evidence-grade audit pipelineAn audit trail that is worth something to someone other than the person who wrote it.
- Directory syncSCIM 2.0 provisioning and, more importantly, deprovisioning.
- Compliance engineSigned evidence packs generated from the running cluster rather than assembled by hand.
Control and scale
- Public API v1Service-account tokens, an
iwctlCLI, and an OpenTofu provider — the console stops being the only way in. - Sealed modeA provable air gap plus signed offline update bundles.
- Addon platformSigned, versioned extensions that a third party can publish and you can install.
- Multi-clusterOne control plane over several clusters, from the session cookie down.
- Supply-chain verificationProvenance gates and SBOMs, so "where did this image come from" has an answer.
- SLOs and game daysError budgets that mean something, and failure drills you actually run.
A hosted service, a paid tier, and a support contract. InfraWeaver installs on hardware you own and reconciles from a git server inside your own network; that property is the point, and none of the work above changes it.