Files
silverlinux-infra/docs/roadmap.md
T

344 lines
4.1 KiB
Markdown

# Roadmap
## Overview
This document tracks planned SilverLinux infrastructure improvements.
The roadmap focuses on observability, access control, security hardening, platform services and backup maturity.
---
## Planned Capabilities
### Collaboration And Storage
#### Nextcloud
Purpose:
* Self-hosted file sharing
* Team document storage
* Optional collaboration layer for internal operations
Status:
```text
Planned
```
---
### Observability
#### Grafana And Prometheus
Purpose:
* Metrics collection
* Dashboards and visualization
* Host and container health monitoring
* Alerting foundation
Status:
```text
Completed
```
Completed components:
* Prometheus
* Grafana
* Node Exporter
* cAdvisor
Validation:
* Prometheus UI validated
* Prometheus targets validated
* Grafana datasource connected to Prometheus
* Initial dashboards created and validated
---
#### Loki
Purpose:
* Central log aggregation
* Log exploration through Grafana
* Faster incident investigation
Status:
```text
Planned
```
---
#### Sentry
Purpose:
* Application error tracking
* Release health visibility
* Exception diagnostics for deployed apps
Status:
```text
Planned
```
---
### Identity And Access
#### Authelia
Purpose:
* Identity and access management for exposed admin areas
* SSO gateway for sensitive services
* Additional protection for DbGate, Portainer, Gitea admin areas and OpenProject admin areas
Status:
```text
Planned
```
---
### Security Hardening
#### Fail2Ban Upgrade
Purpose:
* Improve brute-force protection
* Expand jail coverage beyond SSH where practical
* Align detection with exposed administrative services
Status:
```text
Planned
```
---
#### CrowdSec
Purpose:
* Collaborative intrusion detection
* Behavior-based blocking
* Additional protection for public endpoints
Status:
```text
Planned
```
---
#### Cloudflare Rate Limiting And WAF
Purpose:
* Rate limiting for exposed admin areas
* WAF rules for common attack patterns
* Brute-force protection before traffic reaches SilverLinux
Target areas:
* DbGate
* Portainer
* Gitea administrator areas
* OpenProject administrator areas
* Prototype and demo endpoints where appropriate
Status:
```text
Planned
```
---
### Platform Services
#### Harbor
Purpose:
* Docker image registry
* Internal image distribution
* Container artifact management
Status:
```text
Planned
```
---
#### SonarQube
Purpose:
* Code quality scanning
* Security scanning
* Technical debt tracking
Status:
```text
Planned
```
---
#### Backstage
Purpose:
* Internal developer portal
* Service catalog
* Platform documentation entry point
Status:
```text
Planned
```
---
### Performance
#### Redis
Purpose:
* Caching layer for databases and high-traffic application reads
* Session storage where supported by applications
* Future scaling support
Status:
```text
Planned
```
---
### Backup And Restore
#### Restic
Purpose:
* Versioned backup jobs
* Restore workflows
* Encrypted backups
* Better backup retention management
Status:
```text
Planned
```
Current backup status:
```text
Backup v2 operational
```
Completed:
* Daily cron backup
* Email reports
* HTML reports
* Automatic archive generation
* Automatic cleanup
* Backup metrics export
* Restore validation
---
## Priority Phases
### Phase 1 - Immediate Impact
Items:
* Loki
* Redis
* Authelia
Completed:
* Grafana
* Prometheus
* Node Exporter
* cAdvisor
* Backup metrics integration
---
### Phase 2 - Security And Stability
Items:
* CrowdSec
* Sentry
* Fail2Ban upgrade
* Cloudflare rate limiting and WAF
Completed:
* Backup v2 automation
* Restore validation
---
### Phase 3 - Scale And Enterprise Services
Items:
* SonarQube
* Harbor Docker registry
* Backstage portal
* Nextcloud
---
## Documentation Requirements
Each roadmap item should receive documentation before deployment:
* Service purpose
* Docker Compose location
* Data and backup paths
* Network attachments
* Public exposure policy
* Authentication model
* Secrets required
* Restore procedure
---
## Related Documentation
* docs/services.md
* docs/security.md
* docs/network.md
* docs/backups.md
* docs/decisions.md