4.1 KiB
4.1 KiB
Roadmap
Overview
This document tracks planned SilverLinux infrastructure improvements.
The roadmap focuses on observability, access control, security hardening, platform services and backup maturity.
Planned Capabilities
Collaboration And Storage
Nextcloud
Purpose:
- Self-hosted file sharing
- Team document storage
- Optional collaboration layer for internal operations
Status:
Planned
Observability
Grafana And Prometheus
Purpose:
- Metrics collection
- Dashboards and visualization
- Host and container health monitoring
- Alerting foundation
Status:
Completed
Completed components:
- Prometheus
- Grafana
- Node Exporter
- cAdvisor
Validation:
- Prometheus UI validated
- Prometheus targets validated
- Grafana datasource connected to Prometheus
- Initial dashboards created and validated
Loki
Purpose:
- Central log aggregation
- Log exploration through Grafana
- Faster incident investigation
Status:
Planned
Sentry
Purpose:
- Application error tracking
- Release health visibility
- Exception diagnostics for deployed apps
Status:
Planned
Identity And Access
Authelia
Purpose:
- Identity and access management for exposed admin areas
- SSO gateway for sensitive services
- Additional protection for DbGate, Portainer, Gitea admin areas and OpenProject admin areas
Status:
Planned
Security Hardening
Fail2Ban Upgrade
Purpose:
- Improve brute-force protection
- Expand jail coverage beyond SSH where practical
- Align detection with exposed administrative services
Status:
Planned
CrowdSec
Purpose:
- Collaborative intrusion detection
- Behavior-based blocking
- Additional protection for public endpoints
Status:
Planned
Cloudflare Rate Limiting And WAF
Purpose:
- Rate limiting for exposed admin areas
- WAF rules for common attack patterns
- Brute-force protection before traffic reaches SilverLinux
Target areas:
- DbGate
- Portainer
- Gitea administrator areas
- OpenProject administrator areas
- Prototype and demo endpoints where appropriate
Status:
Planned
Platform Services
Harbor
Purpose:
- Docker image registry
- Internal image distribution
- Container artifact management
Status:
Planned
SonarQube
Purpose:
- Code quality scanning
- Security scanning
- Technical debt tracking
Status:
Planned
Backstage
Purpose:
- Internal developer portal
- Service catalog
- Platform documentation entry point
Status:
Planned
Performance
Redis
Purpose:
- Caching layer for databases and high-traffic application reads
- Session storage where supported by applications
- Future scaling support
Status:
Planned
Backup And Restore
Restic
Purpose:
- Versioned backup jobs
- Restore workflows
- Encrypted backups
- Better backup retention management
Status:
Planned
Current backup status:
Backup v2 operational
Completed:
- Daily cron backup
- Email reports
- HTML reports
- Automatic archive generation
- Automatic cleanup
- Backup metrics export
- Restore validation
Priority Phases
Phase 1 - Immediate Impact
Items:
- Loki
- Redis
- Authelia
Completed:
- Grafana
- Prometheus
- Node Exporter
- cAdvisor
- Backup metrics integration
Phase 2 - Security And Stability
Items:
- CrowdSec
- Sentry
- Fail2Ban upgrade
- Cloudflare rate limiting and WAF
Completed:
- Backup v2 automation
- Restore validation
Phase 3 - Scale And Enterprise Services
Items:
- SonarQube
- Harbor Docker registry
- Backstage portal
- Nextcloud
Documentation Requirements
Each roadmap item should receive documentation before deployment:
- Service purpose
- Docker Compose location
- Data and backup paths
- Network attachments
- Public exposure policy
- Authentication model
- Secrets required
- Restore procedure
Related Documentation
- docs/services.md
- docs/security.md
- docs/network.md
- docs/backups.md
- docs/decisions.md