Roadmap

What exists is tested code; what does not exist is labeled. The current planning source is the blueprint set and the 2026-07-07 status audit, not the older stage shorthand.

Current audited baseline

AreaStatusNotes
Core control plane and SDK built Endpoint leases, per-service config watches, flags, canary controller, load-aware picking, mTLS/SPIFFE, Rust SDK, Go conformance peer.
Deployment pipeline built Artifacts, releases, deployments, manual holds, mutation audit, and CLI verbs exist. Environment drivers are metadata, not placement actuators.
Identity and sovereignty built with gaps Federation cells, node attestation, workload SVID grants, signed reports, and offline verifier exist. Some grant/verifier and external anchoring gaps remain documented.
Ingress, edge, auth, console built with gaps Public routing, route auth, DNS/cert reconciliation, auth helper, and operator console exist. Control-plane RBAC and console self-auth remain gaps.
Observe foundation built gRPC ingest/query, memory/ClickHouse stores, spool, and collect stream exist. OTLP receiver, explorers, monitors, SLOs, incidents, and compatibility endpoints are pending.
Directory stubbed Object namespace protos and relay/connector/directory crates are present for D-track work. The Directory product is not shipped.
Packaging and distribution local built Release tarballs and local install scripts are tested. Hosted get.dodona.dev and ghcr.io/dodona-dev/* images are placeholders.

Next substrate work

  • Scheduler and placement loop: one capacity view, agent actuation, deployment status tied to placement and health.
  • Kubernetes skin: hosted apiserver path, virtual-kubelet style actuation, registry mirroring, and CRD/YAML/Helm surfaces.
  • Store HA: wire raft-backed durable state into the brain, membership, failover, and upgrade mechanics.
  • Driver framework and breadth: live autoscaling and additional providers after explicit billable-resource approval.
  • Resource registry: typed schemas across native gRPC and Kubernetes-style consumption.

Next Directory work

  • A0 relay and connector MVP over the object namespace and existing identity model.
  • A1 delegation, tenancy, MCP gateway, and policy/UX for the zero-cluster product path.
  • A2 federation decisions tied back to cells, workload principals, observe, and the substrate store/identity hardening.

Observability roadmap

  • Native OTLP receiver for traces, metrics, and logs.
  • Browser explorers for logs, metrics, traces, errors, and Kubernetes inventory over the gRPC query API.
  • Full Kubernetes collector, Sentry-compatible error ingest, Datadog-compatible ingestion, monitors, SLOs, incidents, retention, quotas, and residency controls.

Public performance numbers

No public benchmark numbers yet. The older site listed unmeasured targets. This page now avoids publishing performance or scale numbers until a measured rig and its command transcript are available.

Open decisions

  • Second SDK language after Go and Rust, chosen by actual design-partner demand.
  • Depth of Kubernetes compatibility beyond the declared subset.
  • Hosted distribution and registry operations for public install paths.
  • BYOK/HYOK, SSO/SCIM, and external audit-head publication shape.