Skip to content

Latest commit

 

History

History
57 lines (45 loc) · 4.6 KB

File metadata and controls

57 lines (45 loc) · 4.6 KB

Roadmap

M0 — OCI bootstrap

  • Establish Alpine-first / Debian-fallback policy.
  • Add non-root multi-stage OCI skeleton.
  • Add Compose security baseline.
  • Add CI structure validation.
  • Identify canonical Dancer 4.16 SourceForge release.
  • Pin canonical source URL and SHA-256.
  • Verify the pinned Dancer 4.16 archive contains its GNU GPL license (COPYING) during every build.
  • Carry forward the known gnu89 build requirement.
  • Qualify native amd64 build on Alpine/musl in GitHub Actions.
  • Confirm executable/configuration runtime semantics: Dancer loads dancer.config from /data and remains running after startup.
  • Qualify deterministic non-root UID/GID 10001:10001 and writable /data.
  • Qualify Compose security/runtime contract: read-only rootfs, no-new-privileges, all capabilities dropped, init, restart policy, /data bind mount, and /tmp tmpfs.
  • Qualify isolated local IRC registration/handshake in CI.
  • Qualify amd64 and arm64 in CI.
  • Publish first qualified GHCR image (v0.1.0) for amd64 and arm64 with SBOM, provenance, and attestation.

M1

  • Harden runtime and health checking: native Dancer PID healthcheck qualified in CI.
  • Add SBOM/provenance generation and registry attestation (delivered with v0.1.0).
  • Qualify arm/v7 and 386 builds in CI alongside amd64 and arm64.
  • Extend IRC integration coverage beyond registration: PING/PONG, join/channel behavior, and container-level reconnect/recovery.

M2 — Release hardening and operations

  • Publish the qualified four-architecture image (amd64, arm64, arm/v7, 386) in v0.2.0.
  • Add release smoke tests against the published GHCR manifest; v0.2.0 release workflow passed.
  • Document upgrades, rollback, backup, and restore for /data.
  • Add configuration validation/preflight before production startup: entrypoint requires a readable /data/dancer.config and CI qualifies the missing-config failure contract (exit 64).
  • Document Dancer 4.16 reconnect semantics and container restart recovery.
  • Add dependency/base-image update automation with CI qualification: weekly Dependabot updates are gated by the existing full PR CI.
  • Add release notes/changelog workflow and define the next stable release gate.

M3 — Modern operations and IRC integration

No-fork policy: Ploos-AS/dancer packages upstream Dancer; it does not maintain a feature fork. Upstream source modifications are limited to minimal, documented compatibility fixes required to build or operate Dancer on supported platforms. New operational functionality belongs in external tooling, container integration, CI, or sidecars.

  • Document and CI-enforce the no-fork boundary and inventory every upstream compatibility patch.
  • Add secrets/config overlays without storing IRC credentials in Git: opt-in Compose secret mount, syntax-preserving runtime generation, restrictive permissions, CI qualification, and local secret ignore rules.
  • Add external configuration generation and syntax-aware validation based on documented upstream Dancer 4.16 semantics: pinned-reference generator, syntax-preserving overlays, conservative validator, runtime preflight, CI negative tests, and OCI tooling.
  • Add connection-aware readiness distinct from the process healthcheck: external IRC observer, fail-closed watcher/state contract, freshness-aware probe, isolated Compose roles, and CI-qualified deployment boundaries.
  • Add external observability/Prometheus metrics for uptime, IRC connection state, reconnects, and channel state without modifying Dancer feature code: observer-derived state, Prometheus text exposition, isolated metrics sidecar, deployment adapter, documentation, and CI-qualified values/boundaries.
  • Qualify Dancer against a matrix of modern IRC daemons in isolated CI.
  • Define and qualify a secure TLS transport strategy; prefer an external proxy/sidecar if native Dancer 4.16 TLS is insufficient.
  • Add a tested configuration deployment/restart procedure.
  • Add automated /data backup/restore verification.
  • Add migration tooling for existing Dancer 4.16 installations.
  • Document M3 deployment profiles suitable for Compose and LeanPi-style appliances.

M3 release gate

M3 passes when upstream Dancer remains clearly identifiable and reproducible from the pinned 4.16 archive, all compatibility patches are minimal and documented, secrets can be deployed without Git, connection readiness and basic operational metrics are available externally, and the packaged bot is qualified against multiple modern IRCd implementations using the documented secure transport strategy.